calle's avatar
calle
calle@cashu.me
npub12rv5...85vg
DM @callebtc:matrix.org
calle's avatar
calle 1 month ago
Without Lightning, none of the Layer 2s make sense. Without it, every Layer 2 would be a useless silo and a centralization vector. Maybe Lightning was Bitcoin's Layer 3 all along. image
calle's avatar
calle 1 month ago
CLN action priority list: - restart with —offline - if you can’t, turn off - if you can’t, pray
calle's avatar
calle 1 month ago
Restart your CLN node with `--offline` and keep an eye out for updates. Note that shutting it down for too long can expose you to force closure risk. Starting it with `--offline` will still observe the chain for malicious channel closures. View quoted note →
calle's avatar
calle 1 month ago
this too shall pass 🟥
calle's avatar
calle 1 month ago
🟥 URGENT: Critical vulnerability in Core Lightning Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know! image
calle's avatar
calle 1 month ago
cashu .me is now fully integrated with the latest version of npub .cash – that means your lightning address now works across all mints settings -> Lightning address -> choose your mint thank you @Egge image
calle's avatar
calle 1 month ago
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon. - we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good) - everything is broken, bitcoin is burning - bitcoin is becoming stronger through this - bitcoin is the obvious first target but the rest of the world will follow shortly - sometimes old things need to burn so new things can grow on healthy soil - humans should never code in c (just stop) - lightning is complicated and is more broken than the average (sorry) - verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it. - those projects that started AI audits months ago are in a completely different position than those who didn’t - projects need their own AI audit pipeline going into the future - the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now. - unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI - multiple concurrent, diverse human approaches have proven to be the best vulnerability search method - external red teaming will probably have to continue forever - we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done. - we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings. - response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days. - red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back. - did i mention that humans should not code in c?
↑