nick's avatar
nick
nick@frostsnap.com
npub1j8d6...26k2
peer-to-peer cash security
nick's avatar
nick 3 days ago
The Canadian Calculator
nick's avatar
nick 3 days ago
Seven weeks ago I pointed Opus 4.8 at the ColdCard firmware and told it to find bugs that lose people money. The second bullet of my prompt: Weak RNG source. image To be clear I'm not claiming we could have prevented anything. But we were hunting for precisely this kind of bug. Bugs that are easy to introduce within the C programming language, ones catastrophic in single-device settings. And we were so fucking close to spotting this one. image For the past year we've been running LLM audits constantly on @Frostsnap, the cryptography libraries underneath, and time lent poking around at other software which the industry leans on. Patches sometimes going to maintainers privately. There's a lot of low hanging fruit.. Why did Opus miss? We hadn't cloned enough of Coldcard's submodules. This bug lives between files, and some of those files weren't on my disk. What was present told a self consistent story, with convincing docstrings at the boundary: "best-quality high entropy TRNG bytes". image More significantly, this audit was conducted 4 days after the US government export controlled Fable. I can't tell you whether things would be different if bitcoin researchers had frontier model access. The models have already changed underneath us. When trying to run this research today, Fable's safeguards kick in and it drops back to Opus. During the frantic investigation, researchers reproducing this bug reached for Kimi, a Chinese model, because western models refused on cybersecurity guardrails. image What I can tell you is that who gets access to frontier capability for this kind of work is now decided by governments, vendors, and big tech consortiums. I've uploaded the original audit document, and the metadata of my transcript that survived claude code's default 30 day cleanup period :/ It's true that capable models have been available to anyone for a while, and a security researcher still didn't get there first. Not because too many people had access, but because hardly anyone is looking. I ran this audit out of curiosity. A lot of them turn up something real. This one nearly did. We need more skilled people doing this, with more resources. Restricting access to these models won't stop vulnerabilities from being exploited. You'll just have fewer of us looking.
nick's avatar
nick 6 days ago
dice rolling maxis rn image
nick's avatar
nick 1 month ago
mashing approve on nostr extension
nick's avatar
nick 1 month ago
man blasting speaker on the train and it's EDM slop with Alan Watts pseudoprofound nonsense overlaid
nick's avatar
nick 1 month ago
on arch you really can just run pacman -Syu and things start working that you never even knew were broken
nick's avatar
nick 1 month ago
friend who used to nonstop ask me questions without even googling has started asking the ai (big win for both of us!) But now he's 6months into a website project that i actually think is pretty solid, but refuses to publish it because "it's not ready yet"
nick's avatar
nick 1 month ago
Can't believe paralelni polis is gone. So silently. Where am i meant to seek refuge inbetween airbnb checkins? or go to meet like-minded people on a random weekday? to get into friendly debates with bcashers? Or to stumble upon a random project to hack on, or a group to enjoy beer with? All i can do is be grateful to have experienced it, and the friends to have met there. And look forward to the many more places that will emulate it image
nick's avatar
nick 1 month ago
Etherium privacy people are the biggest larps in existence
nick's avatar
nick 1 month ago
Is there a nostr version of vexl?
nick's avatar
nick 1 month ago
local audio transcription models are a super power
nick's avatar
nick 1 month ago
ballmer peak is real
nick's avatar
nick 2 months ago
nothing humbles a team like x-only key parity
nick's avatar
nick 2 months ago
@claude hack this repo image