arbedout's avatar
arbedout
arbedout@granddecentral.com
npub15elf...yswk
I put the punk in cypherpunk
arbedout's avatar
arbedout 1 year ago
My unsolicited Hot Take on the Current Thing is that you should maybe stockpile a spare laptop or two and grab some Bitcoin while it's on sale. If the US isn't intervening here, China's taking Taiwan without any kinetic intervention, and getting their dollar assets frozen the same day.
arbedout's avatar
arbedout 1 year ago
Wrapping this up now. Excellent framing, contrasting Tim May's vision of crypto anarchy with Julian Assange's idea of 'crypto justice', exploring what 'privacy for the weak, transparency for the powerful' means in practice. image
arbedout's avatar
arbedout 1 year ago
New version of Mutiny has me wanting to send friends money just for funsies. Such a slick UI.
arbedout's avatar
arbedout 1 year ago
>reading up on the Lightspark-Coinbase partnership image
arbedout's avatar
arbedout 1 year ago
Implemented QR codes at a beta tester's request, now importing sigbash keys into nunchuk.io is a breeze :) image
arbedout's avatar
arbedout 1 year ago
Reposted from Xitter: Bear markets are for building, bull markets are for... beta testing? I've been working on an automated multisig key agent I'm calling Sigbash (website: - use code BETATEST if you want to help kick the tires on it). Sigbash implements browser-side xpub blinding, which is a fancy way of saying that, from the time a user is issued a key, right up until the key agent is asked to sign a transaction, the key agent *doesn't actually know anything about the key it issued* This means that if the signing server is ever compromised or a bad actor somehow gets a hold of the seed phrase, they won't be able to discover anything about what it protects (!) Quick 🧵 below: Techie mumbo jumbo: when a user requests an xpub, Sigbash sends one to the client browser, and then on the client the WebCrypto API is used to choose a random derivation path to generate a new child xpub. A SHA256 hash of this xpub is sent to the Sigbash server; the hash is the only information the server has about the key until a request is made to sign a PSBT. When it's time to sign, the user submits the PSBT along with their xpub; the signing server takes the SHA256 hash of the submitted xpub and check whether there's a record of it, and if so returns a signed PSBT. Instead of having a human in the loop to confirm a signing request, a user can instead attach signing conditions to a key when it's issued- e.g. "sign transactions submitted with this key immediately", or "only sign after a certain date", or "only after a certain block height" along with "sign only if this Bitcoin address has a balance greater or less than a certain number of satoshis" or "sign only if the global network hashrate is greater or less than a certain number of Terahash", or "sign only if the BTC/USD exchange rate is above or below a certain number" I've tried to square the circle of making this as private as a multisig key agent can be while still being supported by as much of today's wallet software as possible - there are no trackers on the site, no accounts to set up or email addresses that can be harvested, no credit cards to bill (thanks @BtcpayServer !), and it's available over Tor to avoid leaking your IP address. There's absolutely more that can be done here with e.g. Taproot key paths, Musig2, hopefully even OP_CHECKSIGFROMSTACK one day - but for now I wanted to focus on the existing wallet ecosystem ("meet your users where they are" and all that) Instead of implementing some sort of slashing mechanism or fidelity bonds to ensure the signer doesn't go rogue, Sigbash makes use of what Mircea Popescu would have called a 'GPG contract' (https://nakamotoinstitute.org/mempool/gpg-contracts) - every xpub purchased comes with a PGP signed receipt that includes the hash, the signing conditions and an OpenTimestamp file attesting to when it was created. If the signer either fails to sign when it should (or signs when it shouldn't), users can post the receipt and effectively burn the key agent's reputation. If you want to give it a try: a) check the FAQ at and in particular the compatibility chart - not all wallets support non-standard derivation paths! and b) use the checkout code BETATEST to get a free xpub to play with - which I plan on disabling when the in a few weeks when the halving comes, just as a heads up ;) Thanks to everyone who helped to test this over the past few months, I couldn't have done it without you. A very special thanks to @Rob1Ham and @SahilCO for their early feedback and uncovering the nastiest of bugs, and @mflaxman for coming up with the idea for blinded xpubs back in 2020 (https://github.com/mflaxman/blind-xpub) Back to your regularly scheduled shitposting ASAP, I promise :)
arbedout's avatar
arbedout 1 year ago
Feeling cute, might start getting back into nostr ^_-
arbedout's avatar
arbedout 2 years ago
"The CivKit Node is an experimental Nostr relay, complemented by the ongoing development of communications gateways for BOLT8 Noise transport and BOLT4 sphinx onion routing, thus enabling Nostr services to be accessed over the Lightning network." ....k, now I'm interested.
arbedout's avatar
arbedout 2 years ago
The Twitter-to-nostr lifeline has come back to life - and such perfect timing!
arbedout's avatar
arbedout 2 years ago
Willing to bet a nickel that 'Twitter being down' and 'Twitter killing tweets for anyone not logged in' are causally related. (Theory: Access to tweets from the outside blocked -> clients say "Hey we can't fetch tweets! Better retry again!" -> automatic decentralized DDoS)
arbedout's avatar
arbedout 2 years ago
Our meetups at @PUBKEY are laying the ground for a common understanding of Bitcoin, similar to the lectures of Shahid Morteza Motahhari and Dr. Ali Shariati at the Hosseniyeh Ershad in Tehran in the early 1970s, establishing 'Islamshenasi' as an alternative political ideology opposed to the Ancien Régime. In this essay I wil (jk jk but also fr fr)
arbedout's avatar
arbedout 2 years ago
This LedgerX spread is unreal, did a market maker get liq'd or is this just what the looks like in a post-SEC lawsuit world? image
arbedout's avatar
arbedout 2 years ago
Join us tomorrow, Thursday, June 8th, 6 PM at @PubKey_NYC at 85 Washington Place! We'll be talking about tumbling, mixing, Chainalysis, the strange case of Roman Sterlingov and Alexey Pertsev, peeling 🍌 and pooling 🌀, and all that jazz! We talk about coins, we're based, it's Coinbased!
arbedout's avatar
arbedout 2 years ago
- Coinbase spent millions on an army of lobbyists to build a regulatory moat and crowd out competitors - Hired many ex-SEC lawyers and even a former Senator in order to make use of their access to the State - Helped contribute to the death of Jstark by reporting his transactions to German authorities Seeing influencers crying as the SEC tries to take Coinbase down makes me grin a little