Seth For Privacy's avatar
Seth For Privacy
sethforprivacy@primal.net
npub1tr4d...2y5g
Privacy is a human right and necessary for freedom. - VP of Operations at Cake Wallet - Privacy advocate - Host of optoutpod.com, a privacy-focused podcast
Everything actionable you need to know about what this indictment means for you as a Samourai Wallet (SW) or Whirlpool user πŸ‘‡ As a Samourai Wallet user (no Dojo) Unfortunately, the architecture of SW meant that your xpub (a master public key, allowing anyone holding it to derive all your past/present/future Bitcoin addresses) was at some point in time held by Samourai, and could now possible in the hands of the DOJ. Though it's a worst-case scenario, you should assume that your xpub was compromised, and thus all previous mixes you have done have been unwound and are now traceable. You should also assume that the gov can now derive all past/present/future addresses of yours and track movement of funds if so desired. In addition, Samourai's coordinator and backend sync server was seized, and so SW will no longer sync, show received funds, or allow sending funds out. As such, you have to migrate funds to another wallet like @SparrowWallet following the docs here: In addition, I would recommend migrating funds to a new seed phrase to prevent anyone holding the xpub from seeing all future received/spent funds. You should also disable automatic updates in the Play Store (if used) to ensure no malicious updates are pushed. As a Samourai Wallet user (using your own Dojo) Thankfully, you avoided having your xpub potentially compromised. The worst case scenario for you is that your previous mixes may not have the full anon set you expected if non-Dojo users xpubs were compromised. You will still be able to sync/send/receive from your Samourai Wallet app, but should also migrate funds eventually as no further updates will come out for Samourai Wallet. If you want to migrate, use the docs below: You should, however, disable automatic updates in the Play Store (if used) to ensure no malicious updates are pushed. As a Sparrow Wallet user Thankfully, you avoided having your xpub potentially compromised as well. The worst case scenario for you is that your previous mixes may not have the full anon set you expected if non-Dojo/Sparrow users xpubs were compromised. There is no real need to rotate to a new wallet etc, and Sparrow is still an excellent option. Unfortunately you will no longer be able to mix in Sparrow as the Samourai coordinator was seized. Next steps for privacy If you (like me) relied on Samourai Wallet for privacy on Bitcoin, it's time to look elsewhere sadly. As of today I have two recommendations: Use Monero for spending, keep using Bitcoin for savings Yes, this isn't Bitcoin, but its by far the most used and most practical privacy coin out there with strong (and growing) ways to swap in/out of it without a centralized, KYC exchange. My recommendation is buying enough to cover your normal spending of Bitcoin for a month at least, and spend out of that lump sum as needed. Learn more: getmonero.org Where to get Monero: bisq.network Trocador.app In Cake Wallet's exchange feature Wallets: Feather Wallet Cake Wallet Monerujo Wallet Merchants that accept Monero: monerica.com cryptwerk.com/pay-with/xmr/ Use JoinMarket JoinMarket is a decentralized Coinjoin protocol that brings together peers to mix funds together, gaining strong privacy without relying on a central coordinator, without giving fees to a central entity, etc. The best way to get started today is using the new UI built around JoinMarket, @jamapporg: jamapp.org Have any more questions? Drop them below and I'll do my best to answer them.
GM β˜•οΈ Heading to Dallas for Finney Forum, pumped to reconnect with old friends, learn about new freedom tech, and be in the midst of some of the best community crossovers in the space. Any of you Nostriches attending?
Been secretly enjoying RBF and the new address and amount formats for what feels like an eternity πŸ˜… Now it’s live for all you lovely Envoy users out there on all platforms 🫑 View quoted note β†’
Who do I need to follow here? My β€œLatest” feed is a bit dead a lot of the time. Help me fix it πŸ«‚
Stop trying to use dice-rolled seeds unless you're an expert ❌ Just had yet another person (hard to count the total now) reach out about a low-entropy seed they generated and were allowed to import into a certain hardware wallet. A lot of the blame for these lost funds falls on influencers who shill users on overly-complex security setups without properly explaining the massive risks and tradeoffs associated for the average user. What happened: Less than 10min after funds were sent to what they thought was secure storage, they were swept to an attackers address. They used <10 dice rolls, meaning the private key had <25bits of entropy when the minimum for strong security is 50 dice rolls (128 bits of entropy). Wallets should not allow a user to import a seed that they know is completely insecure. Staying safe: As I have said many times, if you don't know the ins and outs of dice rolls, entropy, verification of the resulting seed offline, etc. please do not use dice rolls alone for seed generation. 99.99999% of users are better off allowing good, multi-source, open-source random number generation like we do on Passport. To date I have heard of zero compromised seeds that were generated using on-board RNG due to entropy issues, while there are countless examples of users losing funds due to improper dice rolls. Stay safe out there, folks.
Bringing back #Bitcoin #SkepticismSundays 😎 One of the things that showed me the intellectual honesty of the Monero community and helped to force the community to stay grounded in reality and always laser focused on their core ethos was their weekly "Skepticism Sunday" Reddit threads. These threads allowed the community to come together, ask hard and skeptical questions about the design of Monero, the privacy provided, the economic approach, and much more. In my time in Bitcoin I've never seen anything similar, but the nuanced and high-signal crowd on Nostr seems like a perfect fit to fire things up and see how it goes. The goal of this thread (which I'll post weekly on Sunday's) is for discussing the uncertainties, shortcomings, and concerns some may have about Bitcoin. Things like what makes it difficult for you to use Bitcoin, what pain-points you have, etc. NOT the positive aspects of it. Discussing things with a critical thinking approach and level-headed discussion helps us learn where Bitcoin and its community can improve and go from there. P.S. -- I try to take a break from social media on Sundays so I will follow up and reply whwre I can tomorrow!
If we can't have honest, divergent opinions about the state of Nostr without people being abject assholes about it, then my bearishness will 100% prove true. Being able to openly discuss issues with each other without purely strawman, insulting replies is vital to the success of any project like this, even more so because its success relies on social networks. Read through the replies to this and enjoy a healthy response to criticism πŸ˜… View quoted note β†’
↑