The Coldcard RNG failure was not due to a weakness in HW/SE RNGs.
The CC firmware’s multiple layers of complexity meant that the secure RNG was swapped for an insecure one. (They also never used SE RNG in Mk3)
I estimate that there is only <64 bits of entropy in these seeds
⚠️ I have strong reasons to believe Mk4/5 is also at risk, with those devices only having somewhat more entropy.
CHANGE YOUR SEEDS!!
semisol
semisol@nostr.land
npub12262...grkj
👨💻 software developer
📨 nostr.land relay
all opinions are my own.
On Nostr, you are free to do anything, except to criticise Bitcoin
On chain data could be stored before Taproot, always.
Rolling back Taproot because it could store on chain data is the same as burning down your house to kill a cockroach.
You can just kill the cockroach (implement a relay policy)
e.V.’s are amazing.
Why does absolutely none exist for Nostr and why are we shoveling money at privately owned “charities” that have failed to achieve much on Nostr?
View quoted note →
I have still yet to see the AI agent hype materialize.
“Agents will pay agents” “SaaS is going to die”
I cannot tell a single thing different from 1.5 years ago except:
- more people are now cosplaying software development
- more digital pollution
Neither NIPs or NostrHub are a good solution to the problem that Nostr specifications are a disorganized mess.
Reinventing the wheel every time in different ways is harmful to the development of the protocol.
This has already been solved by basically every other protocol by making a standards body, but somehow we have failed to do this on Nostr.
One should also exist on Nostr, ideally with the following properties:
- It should be open for anyone to participate, but with some commitments.
- Members should in general be required to participate on a lot of topics, to prevent drive-by slop.
- Maybe a small membership fee to cover the hosting of the infrastructure and to again prevent drive-by slop.
- A process for discussing and creating standards should exist, that is not too restrictive but does offer some resistance.
- There should be bylaws to prevent bad-faith actors and to ensure the main goals do not get derailed.
Or maybe something like the C2SP.
I cannot find a single person outside of Nostr who wants to actually use AI vibeslop vomit.
Maybe because they care that their software works, and is not blasting them with AI overexplanation syndrome?
If you are concerned about the BIP-110 fork and your LN node: don’t
As long as you do not care about the fork-coins (in either side), nothing changes for you. You need to take 0 action.
There are two types of AI users:
- Those who use Pi
- Those who don’t use Pi yet, but won’t switch back once they do
It seems that we are now in the part of the bubble where AI companies try to profit.
In a year, the price of models has gone up 3x for OpenAI models, for example. This has especially impacted nano and mini models.
Same with Gemini, 2.5 => 3.1 going up in price 5x for output tokens.
as part of regular testing, I have deleted all data on a production storage node
it works as designed and there was no effect