Ungovernable's avatar
Ungovernable
ungovernablemisfits@nostrplebs.com
npub1jcym...2890
An Ungovernable Bitcoin & Privacy Movement
Ungovernable's avatar
Ungovernable 1 week ago
Mix To is the feature more people should know about. You add a watch only wallet to Ashigaru Desktop with an xpub or an output descriptor, in this case a Passport Prime, and set a minimum number of mixes. Say five. Once a coin has been through that many, the coinjoin output goes straight to a fresh address on the hardware wallet instead of landing back in your post mix account. No manual send, no address copied by hand, no remembering to do it later. @Foundation
Ungovernable's avatar
Ungovernable 1 week ago
"Anything that I've used to try and gain privacy will get flagged, will get seized, and getting it back is a fucking nightmare because you've gotta show provenance." Break the links with tools that actually work, then try to walk back into the regulated side, and you are the one proving where every coin came from. Where did you get them, proof of income, source of funds. @MaxUM
Ungovernable's avatar
Ungovernable 1 week ago
The advice, after all the war stories. "You have two different ways of interacting with Bitcoin. You have proper Bitcoin that's more private, and you use that peer to peer. And then you have the whitelisted, KYC version if you're gonna interact with KYC services." "Keep these two things separate." Not because the regulation is right. Max is clear that it is not, and that it gets people kidnapped and worse. It is still the reality you have to route around. @MaxUM
Ungovernable's avatar
Ungovernable 1 week ago
KYC - Kill Your customer. The full list of what Revolut handed over: a copy of your passport or driving licence, a verification selfie of you holding said document, your full name, your date of birth, your occupation, your home address, your email, your phone number, your IBAN account details, your account statements, your withdrawal records, and your full transaction history including Bitcoin. It went to someone using an email account on a real government agency domain. Revolut treated the request as genuine and sent the files. Let that sink in.
Ungovernable's avatar
Ungovernable 1 week ago
"I think in today's AI economy, there's no excuse to come out with a new product now without a proper graphical user interface." @QnA There is really one game in town for privacy on Bitcoin, and until recently the way in was a terminal. Plenty of people will tell you that if you cannot be bothered to learn it, you do not deserve the tools. Max put the counter better than I did. This should not just be for the big brains. It should be there for the crayon eaters who want privacy too.
Ungovernable's avatar
Ungovernable 1 week ago
Max, on why he started caring about any of this. "Tying your identity to Bitcoin is very dangerous in the physical world. You can be attacked by all sorts of different entities. You could pay your plumber to go and do some work for you, and then they can suddenly see, if you haven't managed your UTXOs properly, how much money you have, and they might come back and crack your skull to take the rest." Privacy on Bitcoin can be life or death. @MaxUM
Ungovernable's avatar
Ungovernable 1 week ago
Your weekly reminder to get your funds off an exchange has got a lot harder to give. Get them on chain. Don't use Lightning, you might get hacked. I would not use Liquid, it is probably not safe. Don't use a sidechain. Don't use a second layer. Bring them into self custody, but make sure your entropy is good, and think very carefully about who you trust as your hardware provider. Have self custody. Don't have all your eggs in one basket. Ask the questions. And don't trust any cunt.
Ungovernable's avatar
Ungovernable 1 week ago
Orange Surf pointed at something uncomfortable in his analysis. The fix for the bug that drained Liquid had a commit dated the 3rd of August. The pull request carrying it was still open on the 1st of September. Which means the patch was public while the hole it closed was still live on the network. Anyone reading that repo could see exactly what to look for. If you are sitting on 4,000 Bitcoin of other people's money, an open pull request is a map for anyone who bothers to read it. @npub18h0w...ws8m
Ungovernable's avatar
Ungovernable 1 week ago
"He went ahead and just deleted everything and then fucked off of the comms channels, taking a load of code with him, which pissed me off no end." So Dojo Bay has a button on it that downloads the whole source. Anyone can take it, run the installer on any Ubuntu box that already has a Dojo, and have their own directory up in a couple of minutes.
Ungovernable's avatar
Ungovernable 1 week ago
"Why do you need a VPN? My traffic is all encrypted with TLS." Carl Dong: that is half right, which is the most frustrating type of right. TLS does encrypt your traffic. But when the connection starts, the client hello carries a field called SNI, and SNI shows the hostname you are visiting in plain text, to everybody on the path. WikiLeaks, your bank, whatever it is. Encrypted contents, fully legible destination. @Obscura VPN
Ungovernable's avatar
Ungovernable 1 week ago
Pocket Bitcoin leaked compliance records for 291 customers, tying identity information and documents to Bitcoin addresses. Another 5,120 had names, IBANs and payment amounts exposed. No private keys were touched, and it barely matters. An address on its own doesn't identify anybody. A leaked compliance file does exactly that, permanently, against a public ledger. Max put it better than I could. The safest way to use Bitcoin is the way that causes you the most trouble. Buy peer to peer, hold your own funds, jump through hoops to keep it away from your identity, manage your UTXOs, and then you cannot spend it in normie world because you cannot prove where it came from. That is the cost of KYC. This information gets leaked because it had to be collected in the first place, by people making decisions for your safety who do not understand what they are regulating.
Ungovernable's avatar
Ungovernable 1 week ago
On the surface, an 11 of 15 multisig to peg out Bitcoin sounds unbreakable. How are you going to compromise 11 geographically distributed companies? You don't have to. The federation keys were never touched. The withdrawal had valid authorisation because it went through the normal service. The failure happened earlier, when the network accepted liquid Bitcoin that should never have existed. Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure.
Ungovernable's avatar
Ungovernable 1 week ago
Roughly 4,000 Bitcoin was withdrawn from Liquid after a software bug allowed LBTC that should never have existed to be accepted as valid. Initial reporting put it at around 320 million dollars. To be clear about the scale, there was something like 150 or 200 Bitcoin left on the network afterwards. Essentially every coin on Liquid went out the door in one go. Blocks stopped. If you had funds on Liquid, you could not move them.
Ungovernable's avatar
Ungovernable 2 weeks ago
A single hop VPN is the only middleman, so it sees everything. Your home IP, which is basically your identity, and every host you visit through TLS SNI and DNS. Two hops splits that in half. First hop sees who you are and never where you are going. Second hop sees where you are going and only ever sees packets arriving from the first hop. No single party can bind your identity to your browsing history. Carl Dong on why that is the whole game.
Ungovernable's avatar
Ungovernable 2 weeks ago
The negotiation over 4,000 Bitcoin is happening in transaction metadata, in public, where anyone can read it. The attacker put an OP_RETURN in the peg out saying they were white hats and to contact them on chain. Blockstream answered an hour later with an OP_RETURN pointing at a support email address. Six hours after that they sent an encrypted message to the hacker's PGP key. The hacker came back with: bug first. The chain is under risk at latest commit right now. Make sure every node is patched, then we will transfer the money back safely after confirming the fix. Three minutes later, Blockstream said thank you. @Blockstream
Ungovernable's avatar
Ungovernable 2 weeks ago
On the surface, an 11 of 15 multisig to peg out Bitcoin sounds unbreakable. How are you going to compromise 11 geographically distributed companies? You don't have to. The federation keys were never touched. The withdrawal had valid authorisation because it went through the normal service. The failure happened earlier, when the network accepted liquid Bitcoin that should never have existed. Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure.
Ungovernable's avatar
Ungovernable 2 weeks ago
Max Tannahill, on Freedom Tech Friday, with a story I had not heard before. When Keonne Rodriguez had to make the Bitcoin payment for his fine, he had no node of his own to connect to. He used Max's Dojo, found through Dojo Bay. "When you've actually got the developer of Samurai wallet comfortable in a set of trade offs using someone else's node, I think it kinda tells you that some people are a bit too prescriptive on you must always use your own node." Preferable and mandatory are not the same word.
Ungovernable's avatar
Ungovernable 2 weeks ago
The VPN industry is built on horrible YouTube sponsorships, scare tactics, fake top 10 lists and ownership structures you would need a private investigator to untangle. And underneath all of it sits one fact the influencers skip over. Your provider can see who you are and everything you do. Every single one of them. "No logs" is a pinky promise that nobody can truly verify, because you have no way to check it. @Obscura VPN
Ungovernable's avatar
Ungovernable 2 weeks ago
The thing that changed with Dojo Bay is not the technology, it is who there is to serve paper on. Samourai was a known legal entity running the back end. A directory has none of that. It does not hold your transactions, it is not running the Dojo you connected to, and the page gives no indication which of the twenty listed you picked. Operators are in Spain, Singapore, the UK, the US and Canada. Max Tannahill's point: if you are in the US, why would you put your XPub on a box in the US.
Ungovernable's avatar
Ungovernable 2 weeks ago
Best explanation of the two hop model I have heard. Think of the packets you hand Obscura as a box locked with a key only Mullvad has. Carl's words: "we have no idea what the fuck is in it. All we can do is hand it over." Mullvad opens the box and talks to Google for you. It sees thousands of users' packets arriving from Obscura and cannot tell which one is you. Obscura knows who. Mullvad knows what. Neither knows both.