Alan ₿'s avatar
Alan ₿
alanbwt@primal.net
npub1r0fj...uzz3
"This is it." Author @npub109gj5765thuet2hj2nk2j9r89a03xm2cpd0jp8rel2mqd68cn04s5wvahd | Dev @npub1fjh05rc223et4emdwex3ec34qya339szfe2w6yf8vcguuqrclh6s8us2yr
Alan ₿'s avatar
alanbwt 10 hours ago
The more you learn about Bitcoin security, the more you become a SeedSigner (or more broadly a general-purpose air-gapped computer) maximalist: generate the seed entirely offline with dice or other analog entropy, and ideally never load it onto a device that remembers or stores it. Even when you spend, use a stateless device so the seed only exists temporarily in RAM and is wiped on power-off. Add a strong dice-generated passphrase and/or a geographically distributed multi-sig quorum, and you have ironclad security for your stack.
Alan ₿'s avatar
alanbwt 4 days ago
Nice side by side visual of what a healthy random number generator output looks like v a compromised one image
Alan ₿'s avatar
alanbwt 4 days ago
When I first took the orange pill after learning about the difficulty adjustment and having the “aha” moment, I was all set to self-custody my stack. Then I realized I had to use someone’s software to broadcast transactions and set up my self-custody hardware the standard way (granted, I could roll dice to generate it offline, but even then I’d need to connect to software to move coins), and it struck me as the most vulnerable part of Bitcoin hodling. Using FOSS mitigates the risks tremendously over closed source, but I still stand by that part of the tech stack being the most worthy of caution. Self-custody remains infinitely superior to trusting a third party to hold your keys if you know what you are doing, but it requires eternal vigilance.
Alan ₿'s avatar
alanbwt 4 days ago
The duality of the coldcard fiasco is that it is both worse than Mt Gox in that it happened to Bitcoiners who adhered to “not your keys, not your coins,” and at the same time it is far less bad than Mt Gox in that 1K BTC was taken vs 850K, so it’s barely registering in the market cap or as a mainstream news story.
Alan ₿'s avatar
alanbwt 4 days ago
The reality of closed source RNG image
Alan ₿'s avatar
alanbwt 4 days ago
Open source > closed source Multiple vendors > one vendor Multi-signature > single-signature Multiple baskets > all in one basket Offline entropy > random # generator
Alan ₿'s avatar
alanbwt 4 days ago
Just as it takes a good guy with a gun to stop a bad guy with a gun, it takes a good guy hardening systems with AI to stop a bad guy finding exploits in those systems with AI. One of the silver linings of this recent coldcard exploit is it has spurred white-hat hackers into action. And thankfully, cryptography itself favors defenders.
Alan ₿'s avatar
alanbwt 5 days ago
SeedSigner proponents have been right about a lot of things. image
Alan ₿'s avatar
alanbwt 5 days ago
Spent much of today helping people I know move their funds from their coldcard devices elsewhere. A few reflections / lessons: First, money is not everything. If you lost your life savings, or some portion thereof, know that this is not the end, even if it may feel like it. Second, move the funds you do have in any coldcard as quickly and calmly as possible to another place. Even a hot wallet is a fine temporary intermediary. But choose a respectable one. Long term, “Not your entropy, not your keys” will be a major takeaway of this event. Better to generate your own randomness via dice, cards, coins, or other irl methods than to rely on computer-generated randomness. If you are capable of it, multi-signature set-ups using different, ideally fully open source, hardware wallet manufacturers are preferable moving forward as far as self custody goes. And when given the choice for extra entropy such as a passphrase, take it. And in any case, it is better not to keep all your eggs in one basket. Those who were most affected had all their coins on a single device. Do not rely on any one device, any one manufacturer, any single point of failure. My heart goes out to all. God bless.