Ungovernable's avatar
Ungovernable
ungovernablemisfits@nostrplebs.com
npub1jcym...2890
An Ungovernable Bitcoin & Privacy Movement
Ungovernable's avatar
Ungovernable 15 hours ago
The revised Clarity Act text landed on 10 September with the 126 changes the Democrats asked for. The one that matters here: the Blockchain Regulatory Certainty Act, the part that stops non-custodial software developers being treated as money transmitters, now only covers civil enforcement. The language protecting developers from criminal prosecution for unlicensed money transmission was removed after pressure from prosecutors. That is one of the charges brought against the Samourai developers. So writing non-custodial software should be shielded from regulators, but not from a criminal case. The cloture vote needs 60. Republicans hold 53. Prediction markets had it around 25 percent.
Ungovernable's avatar
Ungovernable 20 hours ago
HODL HODL shipped coin security scoring on 18 September and pulled it a day later after the backlash. Worth being precise about what that scoring actually does. It is not the case that they can see your coins came from a hack, traced them to your UTXO and frozen those. It is that you used Whirlpool, or a coinjoin of any kind, or anything else to protect yourself, and that is what gets flagged. You're assumed criminal for trying to protect yourself. That's fucked. @Hodl Hodl @MaxUM
Ungovernable's avatar
Ungovernable 23 hours ago
The Revolut leak is not a random dump, and the attackers were happy to explain why. A hacked email account on a real Italian government domain, a fake law enforcement request, and Revolut's Lithuanian bank handed over identity documents, KYC selfies, bank statements and transaction histories for at least 680 customers. Then they ran blockchain analysis and picked the accounts with significant crypto holdings. 6,000 XMR demanded, roughly three million dollars, inside twenty four hours. The deadline passed on 17 September and samples are already circulating on Telegram. You cannot warn anybody, because nobody gets told they are on the list.
"There is an insidious group trying to control our access to intelligence, very similar to how they're trying to control our access to money or the tools around money." "And we actually have tools to fight back now." That is the whole argument for local AI, put in terms this audience already understands. You did not run a node because it was convenient. You ran it because the alternative was asking permission. @MaxUM
"That is what I trained for and did professionally for a long time, and it's better than me and faster than me." Systems administration. Site reliability. Cybersecurity engineering. That was the career. Max asks whether it pisses him off. It does not, because he got bored of doing it years ago and would rather have the thing that makes Cake Wallet more reliable. Then the part that will land badly for a lot of people listening. "If you're a site reliability engineer or an IT engineer right now, you should be worried. Because I can do the vast majority of that simply while I'm also doing a thousand other things." @Seth For Privacy
Ungovernable's avatar
Ungovernable 4 days ago
Mix To is the feature more people should know about. You add a watch only wallet to Ashigaru Desktop with an xpub or an output descriptor, in this case a Passport Prime, and set a minimum number of mixes. Say five. Once a coin has been through that many, the coinjoin output goes straight to a fresh address on the hardware wallet instead of landing back in your post mix account. @Foundation No manual send, no address copied by hand, no remembering to do it later. @Foundation
Ungovernable's avatar
Ungovernable 5 days ago
Survive or die? @Jon lays out three different types of scenario. Scenario one: We continue on in our cushy western life where everything is good, the supply chains are long and cheap, but you should still be prepared for a storm. a little generator, a gas stove, extra food and a First aid kit.
Ungovernable's avatar
Ungovernable 5 days ago
Max, on why he started caring about any of this. "Tying your identity to Bitcoin is very dangerous in the physical world. You can be attacked by all sorts of different entities. You could pay your plumber to go and do some work for you, and then they can suddenly see, if you haven't managed your UTXOs properly, how much money you have, and they might come back and crack your skull to take the rest." Privacy on Bitcoin can be life or death. @MaxUM
Ungovernable's avatar
Ungovernable 6 days ago
The reason it feels like every week now is that it is every week now. If you run a software project or a hardware project or anything that handles Bitcoin, people are attacking your shit right now. Not eventually. Right now. Think about it from their side. Steal personal information and you still have to find a buyer. Steal from the software that holds the money and you are done. It is a no brainer. Bitcoin is taking that pain first, and it comes out the other side harder for it. Expect at least another six months of this. @QnA
Ungovernable's avatar
Ungovernable 6 days ago
The reason it feels like every week now is that it is every week now. If you run a software project or a hardware project or anything that handles Bitcoin, people are attacking your shit right now. Not eventually. Right now. Think about it from their side. Steal personal information and you still have to find a buyer. Steal from the software that holds the money and you are done. It is a no brainer. Bitcoin is taking that pain first, and it comes out the other side harder for it. Expect at least another six months of this. @QnA
Ungovernable's avatar
Ungovernable 6 days ago
On 9 September, customers of Trezor, BitBox and CoinTracking received emails warning of an STM32 entropy vulnerability and asking them to take action on their hardware wallet. The emails came from those companies' real domains. SPF passed. DKIM passed. Every check your mail provider runs to prove a message came from where it claims to have come from, passed, because it genuinely had. Attackers had access to Brevo, the email marketing platform those companies send through, and created API keys inside their accounts. The weak point was never the wallet maker. It was the vendor they trusted to send their post. No wallet company will ever email you asking for your seed words, telling you to connect your device urgently, or asking you to verify your wallet. Ever.
Ungovernable's avatar
Ungovernable 6 days ago
KYC: kill your customer. This is where the name of the episode came from. An attacker now holds your personal information and your Bitcoin withdrawal history in the same file. They do not have to guess whether you are worth robbing, and they do not have to guess where you live. He lives down the road from me. I am going to go and get a very big wrench. None of this was a choice anybody made. The data existed because a regulator required it to be collected, from people who had no way to opt out, in the name of protecting them.
Ungovernable's avatar
Ungovernable 1 week ago
"So what I actually like about this application: there's no spend functionality in the wallet. You can only receive in here, and you can't spend." That is a design decision, not a missing feature. Ashigaru Desktop receives and it mixes. Spending is done on Ashigaru mobile, or you open the same wallet file in Sparrow, which reads it and the labels without complaint. Stay in your lane and there is less of you to attack. @jordan
Ungovernable's avatar
Ungovernable 1 week ago
Max, on the Revolut leak: I guarantee you, people will die from this. Q's answer was that it sounds hyperbolic, and he is not wrong. Nobody gets a list. Revolut is not going to write to an individual customer and tell them that a file saying they own this much Bitcoin is now sitting with criminals. You cannot even warn a friend, because you have no way of knowing whether they are on it. What you get instead is people outside on the security camera with knives. Or a phone that rings every day. Or nothing at all, for years, until it is not nothing. We are treated like criminals for trying to protect ourselves and our families. We are not wrong. @MaxUM
Ungovernable's avatar
Ungovernable 1 week ago
Mix To is the feature more people should know about. You add a watch only wallet to Ashigaru Desktop with an xpub or an output descriptor, in this case a Passport Prime, and set a minimum number of mixes. Say five. Once a coin has been through that many, the coinjoin output goes straight to a fresh address on the hardware wallet instead of landing back in your post mix account. No manual send, no address copied by hand, no remembering to do it later. @Foundation