Either malice or incompetence — both ways CoinKite is done for. What a desaster and it keeps getting worse with every layer of that rotten onion that gets peeled.
View quoted note →
Dennis
dennis@einundzwanzig.space
npub14j7w...gtpf
🎙 Co-hosting and tech @Einundzwanzig
💬 DM on Signal please @d11n.21
🔑 F768 60F8 449D 2F39
Man kann zu der Haltefrist-Petition stehen wie man mag, aber da ist mehr los als beim BIP-110 Signaling.
Petitionen: Verwendung von Cookies nicht aktiviert
Crazy indeed, but tbh the circulating theory of an inside job doesn't really make sense to me and seems overblown. I dunno, but...
They'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation.
I totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown.
View quoted note →
"Das ist eine Lüge. Und diese Katastrophe ist das Resultat des Glaubens an diese Lüge."
Ist das noch ein Artikel zur ColdCard oder geht es da schon um die deutsche Politik?
View article →
With what's known by now, this seems to be the most likely scenario.
View quoted note →
On a positive note: you don't have to charter a yacht for that boating accident to be plausible now.
Dringende Info für die ColdCard-Nutzer unter euch: Alle Seeds die mit den Firmwares ab Anfang 2021 generiert wurden, nutzen nicht genügend Entropie und können recht einfach geknackt werden. Sofern ihr eine Passphrase nutzt ist das kurzfristig gut, aber auch hier ist dringend das Migrieren auf einen neuen Seed (im Idealfall mit eigener Entropie per Würfeln) geraten.
So wie es aussieht, sind Seeds die mit vorherigen Versionen der ColdCard generiert wurden sicher. Dennoch solltet ihr euch generell auch da Gedanken bzgl. Nutzung von Passphrases oder MultiSig Gedanken machen — ich gehe davon aus, dass das nicht der letzte solcher Fälle bleiben wird.


COINKITE Blog
Coldcard Security Advisory
Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rolls and the wallet lacks a strong, unique BIP-39 pa...
One should also note, that only seeds generated after their license change (end 2020) seem to be affected. The first version after the code changes causing this shipped March 1st 2021 — so seeds generated prior should be safe for now, at least in theory.
Nevertheless, moving to a new, more secure setup with self-rolled dive entropy and passphrase seem to be a no-brainer now. Evaluate multi-vendor multisig as an option as well.
View quoted note →
Looks like @N gets his slice of the humble pie.


COINKITE Blog
Technical Deep Dive into the Entropy Issue
Technical Deep Dive into the Entropy Issue
GM. What a wonderful thing, to collect veggies from the garden for breakfast. 🌞🤩🌶️


More pathetic whining:
> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people.
As if the US and Anthropic aren't trying to achieve the same 😅

Our position on open-weights models
Anthropic CEO Dario Amodei on open-weights models
Indoor grow finished stretch and bloom is in full swing. It might get frosty and I hope the purple will come out some more — let's see, around six more weeks until it'll be ready. 🥦 #weedstr #growstr

