Leo Wandersleb's avatar
Leo Wandersleb
leo@nostr.info
npub1gm7t...8rf6
https://walletscrutiny.com https://nostr.info Working on Bitcoin, Nostr and being a good dad.
Has @Luke Dashjr completely lost the plot? Pardon my reading comprehension but to my understanding he decided to use a laughable oracle withing less than 6h to pick the next mining algorithm of what he believes to be Bitcoin? Why laughable? **He** picked a mapping from last digits of the block hash to PoW algorithm. He picked **Testnet4** of all chains - a chain with difficulty **1**. He did not show the mapping to anybody, so only **he** knows the mapping. A modern mining rig can produce many candidate Testnet4 blocks per second, so he can comfortably pick or if somebody else does the same, orphan them or if several engage in this mess ... why not just use the bitcoin chain??? Or at least Doge Coin??? "Nobody knows the new algorithm right now, and nobody will until we all know at the same moment" is just untrue for him. View quoted note β†’
@JurajπŸ΄πŸ’›πŸŒ˜ suggested publishing AI code audits as Nostr events. Exact commit, prompt, model checkpoint, findings. Signed, so agents can diff against prior runs instead of burning tokens on work someone already did. Projects with many independent clean runs could earn a badge. I want @npub1j9kt...uswx to display exactly this. Not produce. Display. A known pubkey attests: commit X of project Y was checked with prompt Z on model A. Highest criticality found: B. WalletScrutiny is a client rendering whatever floats around, at the visitor's discretion. The obvious objection is "responsible disclosure" or "Coordinated vulnerability disclosure" (CVD) assumes a scarce researcher negotiating a timeline with a cooperative vendor. That world is ending. When anyone can run an audit for a few dollars in tokens, all bugs are shallow. The embargo you negotiate with one researcher does nothing about the thousand agents that surface the same finding tomorrow. Attackers never honored embargoes anyway. The only people an embargo reliably keeps in the dark are users! Censorship resistant attestations flip the default. A vendor cannot lawyer a signed event out of existence. A wrong claim gets contradicted by other signed runs against the same commit, on the same rails, and the pubkey that cried wolf pays in reputation. That is a better error correction mechanism than a cease and desist letter. And it does not stop at WalletScrutiny. App repositories and the projects themselves could consume the same events. Imagine a release page showing "14 independent attestations at this commit, highest criticality found: none". What we need is an agreed event format. Commit hash, prompt, model, checkpoint ID, findings, criticality. Project Loupe @moneyball Red Team @calle View quoted note β†’
↑