armstrys's avatar
armstrys
npub1eq94...er58
Yellow squash from the garden and jalenpeño cheddar brats from a local farm picked up at the farmers market. Brats were beer-braised (Mack and Jacks) with onions and topped with apple cider vinegar picked onions and brown mustard. Grilled to finish and served on a brioche bun… I should probably just never cook a brat again so I can stop while I’m ahead 🤤 #foodstr image
Sunday salmon and steak! Steak was a touch overdone but still good. Smoked over cherry and finished in butter, garlic, and rosemary. Chard from the garden stir fried with ginger, garlic, soy sauce, rice wine vinegar, and sesame oil. Chard and summer squash were the first good batch of veggies from the garden! #foodstr
@Keith Mukai I built a security audit skill for Claude a while back that tries to establish a strong security system for software based on the documented claims. I pointed it at seedsigner this morning to see what it would do. It’s relatively opinionated and there are pieces like a CI/CD check for audit on each release that might be overkill, BUT I think it flagged some interesting things. It also drafted a SECURITY.md. Posted it as a draft PR in my fork so I could share. Key suggestions: - one instance of a potential string injection - suggests to pin dependencies to hashes instead of versions to decrease supply chain risk - establishes a SECURITY.md with clear claims
How ironic is it that ColdCard got bit by a general purpose function in their execution environment after endlessly complaining about the security of using general purpose hardware as a hardware wallet? Woops!
Also how are we turning a blind eye so fast on open sats… sometime you have to hold integrity over money. I hear rumors of big donations to catching up on the audit backlog - great… but there had better be a lot more resignations or governance changes in the next couple weeks before we accept open sats as a neutral actor. One spurt of money doesn’t fix a decade of biased decision making. @calle
Have been pulled over to x during the coldcard situation. Feed become less useful and more random ass content over time. How do we convince the bitcoiners still using that shit platform to escape?
Just finding out about loupe by spiral - man, the teams at block really deliver. What timing given the current conversations around CoinKite
I wrote a brief review about the cultural shift that HAS to happen within the bitcoin space to ensure self-custody is successful. The biggest community failure leading up to the ColdCard incident was an inability to recognize the problem - masked by advertising and social reputation. It is quite literally the opposite of “don’t trust, verify” and it is something we should be able to fix as long as we shift our expectations. View quoted note →
Open questions to the bitcoin community: - why did we not trust the banks, but we trusted hardware providers like coinkite? Was this purely an education gap about seeds or was it a double standard? - how did we not catch a software error in a critical piece of code that was “source-available”? Are there bounty programs for vulnerabilities like this? If not, why not? - why don’t more hardware wallets directly support dice rolls? I know seedsigner does, but is that it now that the coldcard is toast? Are these paths thoroughly tested for reliability?
Seems like a good time to remind folks of the great multisig guide from seedsigner. Even if you don’t have a seedsigner there are some great bitcoin security tidbits in here like the section on “Creating Secure Private Keys in a Trust-Minimized Way”. The ColdCard exploit is a great reminder of the importance of minizing vendor risk. The same exploit could have been found in SeedSigner or any other vendor. If you aren’t making an effort to take vendor risk out of each part of the process then you should re-evaluate your strategy.
So now that we’re all running agents… who has hindsight wired in for memory? If you don’t you’re missing out.
I know we are all caught up in the agent hype, but did anyone recognize that this is blocks attempt to fully. Replace the GitHub interface? Not sure how I feel about it yet - wish it was integrated with existing git over nostr solutions that are more decentralized. Hopefully some discussion to come.