Gm
Hi
GM ! been working on some interesting ideas for entropy and verification. Here’s where I’ve landed so far:
The user sees 256 bits of entropy generated from the Secure Element and can verify it, then does the same again with 256 bits from the camera sensor. The two are XORed together, so a compromised Secure Element vendor can’t backdoor the seed and the whole process is as verifiable as possible.
GM, I hope everyone is well. It has Been a rough week.
Been working on entropy generation and verification, using different methods, should hopefully be interesting to some. I will try and have something to share soon.
Felt sick after this attack on Coldcard users, still not feeling right.
My thoughts are with everyone who lost coins.
I don't own one. I had been seriously considering it. I believe diversity in storage and in manufacturers is critical, precisely as insurance against a backdoor or a code error in any single vendor.
I wasn't affected. But I managed to reach friends in time who were.
And note how this was found, the firmware was open. Anyone could read it, reproduce it, verify it. Closed firmware has the same class of bug, you just never get told. Proprietary code is an exposure waiting to happen.
This is a lesson learnt, and it will strengthen Bitcoin. But it's a hard one.
We are only as sovereign as the seed we generate.
Going forward this will need to be just as important as our methods of self custody.
Anyone using noStrudel?
Anyone using noStrudel?
Test
Air gapped signing … video attached
GM, demo of Air-gapped Nostr signing.
GM, airgap note
GM, Nostr ☕️ have a great day
GM ☕️ Been heads down building voice and video calls straight into the Favilla KEY. Will Post a demo soon!