For every minute I spend analyzing and criticizing others, I spend probably an hour or more on myself.
There's nothing wrong with pointing out the issues with competitors (I appreciate it when it's done in a healthy way). Just spend more time looking at your own work and not demeaning anyone who points out concerns for what you're doing. It could be the case that you spent so much energy preparing for edge case splinters and preventing competition that you completely missed the plank in your own eye.
External and internal criticism are both important. Ego has no place when lives are at stake. Practice both fairly.
Matt - Not Your Entropy, Not Your Coins
matt@gitcitadel.com
npub1l6sc...j5rc
Probably a spook ๐ป
https://zapmeacoffee.com/npub1l6scds4yv7xmcsmhqnhdy9sggm520q09lvts2m5mkvecgr2mmmeqsuj5rc
I don't want anyone at CC to be harassed or harmed. That said, there needs to be serious general discussion around the ineffectiveness of ego and being an asshole to anyone who dares to suggest that something isn't right.
I called out concerns for not being FOSS and got demeaned for it. Would that have prevented this? I don't know. But my concern was that there was no longer an incentive for the code to be used and viewed by anyone outside CC. And certainly no economic incentive outside of paid audits. That's a big fucking problem. Again, total speculation, but I have a hard time believing this would have gone undiscovered had the codebase remained FOSS, and it probably wouldn't have been an issue at all without the code changes that were made to rip FOSS out (from what I've read).
I also use several alternatives that were heavily shit on and nothing has been rekt yet. So maybe we should work together on the things that matter most and not treat each other like shit for daring to think differently. Alienating people with concerns just creates blind spots for everyone.
And stop gaslighting users who did what they were supposed to do. If you claim to be the best and alienate others, you goddamn better have your shit straight. It is not the user's fault. I've read the guides. I've went through the flow. There was no indication these people were doing anything wrong.
I wouldn't fault anyone for moving some to Lightning wallets, Strike (etc) or whatever is necessary to not have their entire stack in a CC setup, regardless of whether dice or passphrases were used.
View quoted note โ
Ad reads with claims that may or may not be true shouldn't build reputation. And that's basically where we are these days.
View quoted note โ
Exchanges today


If it's truly "best practice," something advertised as "ultra-secure" and the best should encourage it by default, not as an optional afterthought at the end of the flow. And either way, that would do nothing to address the underlying ultra-security failure.
Besides, passphrase is meant to help protect your seed if it's physically found out, not as a bandage for security fuck ups at the point of generation. Gaslighting.
Now I lay me down to sleep; I pray the Trezor my stack to keep. Amen.
25% vaulted gold
25% self-custody gold
50% Bitcoin (split between several setups, including self-custody)
Questioning whether I had it right the first time.
I'd appreciate having my upgrade strategy critiqued. Right now, I'm drawing my own seed words from a bowl of BIP-39 words (they're double sided so I'm dropping it on a hard surface and going with the word facing up wherever it lands. Mix back in really well, repeat 23x) and generating the 24th using a SeedSigner. No cameras, etc. Completely alone.
Will likely bake in pass phrases and/or multi-vendor device multisig. Currently, that's SeedSigner and a Trezor Model T since that's what I have right now (other than a couple CCs I never used for anything serious).
Rip me apart. Where am I being retarded?
What are your favorite guides on multi-vendor multisig setups?
Proof of Entropy
Physical entropy maxis unite.
View quoted note โ
Gold bugs unaffected ๐

13k back in play? Lol