Avatar
SeedSigner
f2c96c97f6419a538f84cf3fa72e2194605e1848096e6e5170cce5b76799d400
Build your own airgapped, stateless bitcoin signing device for less than most hardware wallets. 🤘 Not set up for zaps, if you'd like to donate to our contributors please go to https://donate.seedsigner.com

Max was the only podcaster who reached out after the dark skippy "novel" attack debacle, said that people seemed confused about it, and offered to have someone from the project on the show to explain how it related to SeedSigner. Literally the only one. He and QnA sincerely and passionately care about freedom tools. Consider putting them in your regular rotation if they are not already. nostr:note165uvykn8ded67erzs920kzdty6wdqnq53xyxzayrhct42qplln3qdt3pa4

My family, who knows where the secrets are, also know which technically capable bitcoiners we trust and how to contact them if something happens to me. Multisig is the most theft-resistant and seizure resistant way to store bitcoin; if it isn't a good solution for most people then we're not doing it right yet.

The sleeping like a baby part has been my goal with our project all along. Different people have different concerns; given my unique background and perspective, SeedSigner is what has brought myself, as well as many others peace. Proud to be helping to build one of several different approaches to sleeping like a baby when it comes to saving with bitcoin. 🧡 nostr:note162tjeannk4702vhwkxyqw8g8evwkynp6lm62saarf6p56zz9uacs2phfmp

X-posting this from the bird app, a continuation of my thoughts from earlier.

cc nostr:npub1a2cww4kn9wqte4ry70vyfwqyqvpswksna27rtxd8vty6c74era8sdcw83a

I continue to think about this and the challenge is that it's much harder to profit from freedom tech (it's users are generally more anonymous and the software more freely distributed); centrally controlled systems are much easier to monetize and extract value from.

But it realistically costs time and money to build things, especially to build them well, so if funding is given it has to come from a place of idealism and hope with few strings, rather than from a place that is in search of investment multiples. Even grant money for FOSS tech in the bitcoin/nostr spaces is often tied to for-profit business models -- the nexus of venture and grant funding is a tricky place fraught with ethical pitfalls.

Just find capable people with proven track records who are building for the greater good and support them. The nostr:npub17xvf49kht23cddxgw92rvfktkd3vqvjgkgsdexh9847wl0927tqsrhc9as does this best as an organization IMHO (kudos to nostr:npub1trr5r2nrpsk6xkjk5a7p6pfcryyt6yzsflwjmz6r7uj7lfkjxxtq78hdpu nostr:npub1cf3zeytdnwgwzz5pk2ax0vvmmlzad03xcft4d50ejrfhsh8pxcdsefx7gk et al). But also, personally dig in and really learn about projects that build freedom tech, and then give directly to the ones you think are doing important work. There are tons of high quality devs who work on freedom tech part time, or who flatly won't provide identity info for money. Direct donations reach these individuals whereas grants & bundled funds primarily target those working full time and who are willing to provide identity info for payment.

Lastly, retroactive support for builders is highly underrated, and it's just ethically right. Capital allocaters and givers get too caught up in incentivizing what they think should be the next thing. If someone has built freedom tech that works and is contributing to the cause, financially thanking them puts some great incentives into play in that they feel appreciated (a deep human need), they will feel incentivized to improve / maintain what they've built, and they will often feel motivated to build the next important thing that no one else has thought of yet.

You’re asking some of the right questions, and coming at this from a place of humility is a great approach.

Make it a great day. 🧡

It's also important to have permissionless bitcoin tools that aren't provisioned by centralized or capturable companies...

If you'd like to help support our project or our contributors Lyn, feel free to get in touch. nostr:note19ykg6ksdc8cqnmz47ec27afqzpmxrka5042ve5q3qv6vf8s9a8rsrjx0sz

Solid take from a member of our Telegram community on how our approach differs from commercial HWWs. Tradeoffs. For those who want to trust less and are willing to take on more responsibility, our approach is just as viable.

Replying to Avatar Matt

Consider supporting nostr:npub17tyke9lkgxd98ruyeul6wt3pj3s9uxzgp9hxu5tsenjmweue6sqq4y3mgl. They are doing crucial work.

nostr:note1yp4ahz9g64fgvk6e3ycr7mdmyehhu2h4fulluque2vk8s5zvrcrs9kgaxx

🧡

🚨 Announcing SeedSigner 0.8.0 ! 🚨

Our release notes have gotten so good that one of my release announcement threads doesn't make sense!

Just go and check out all of the details for yourself:

https://github.com/SeedSigner/seedsigner/releases/tag/0.8.0

I have an idea for nostr:nprofile1qqs09jtvjlmyrxjn37zv70a89csegcz7rpyqjmnw29cveedhv7vagqqprpmhxue69uhkummnw3ezuendwsh8w6t69e3xj7302gfp7r. There's a concern that the seed signer doesn't verify its own firmware. Which, as I understand it, it's because the human writes the SD each time.

Other wallets verify their firmware with a signature. But that's not entirely the truth. Because the bootrom of the microcontroller typical inherently trusts the user bootloader in flash. So what verifies that on boot? Nothing. It's assumed secure because it's hard to access in flash (which is not true see the recent book on Microcontroller Exploits by Travis Goodspeed).

So here's the idea: boot from a CDROM. It's how we used to do it. The image doesn't change. It might need a modification to uboot and the kernel to allow the cdrom file system, but it should be possible.

It also supports seed signers goal of obfuscation. It will appear like the user is just into CDs.

This makes me think of some of the microSD cards with write-once functionality.

But b/c you potentially must verify that the cdrom is the cdrom you think it is (or that the microSD is the microSD you think it is) by inspecting the data it holds, you haven't really solved the issue?

👀 nostr:note1xq9jzh6u2vnp82yd5p5qugd03enyyqha0n0ew2w2sk6hzrjs9jrs74qmv3