DevilishLemonBar πŸ¦₯βš‘πŸ³οΈβ€πŸŒˆ's avatar
DevilishLemonBar πŸ¦₯βš‘πŸ³οΈβ€πŸŒˆ
_@slothy.win
npub1y3k2...vp4j
Electrical "Engineer" Aggie'20. Onlyfans (NSFW): http://tx.ag/Igebcre β‚ΏIP-47: http://helali.me/bip47 ⚑Node (shutdown): 03817596435f25a156da4a89c9dabf2a3e4f9a74418543f3de6b77cab780a473a1 Ω…ΩŽΨ³Ω’ΩƒΩΩˆΩ†ΩŒ Ω‡ΩŽΨ°ΩŽΨ§ الجِنُّ بِΨ₯ِنْسْ.
With so many Spark wallets popping up, can someone ELI5 to me why we're OK with a trust model that requires that all spark operators don't collude given that from what I can see there are only 3(?) Spark operators and no clear understanding of how you'd become a Spark operator? I'm sure I'm missing something, but if not, seems crap.
Also, not having an optional first-party companion app is a major downside. This could've been handled much faster and with less friction if there was an app flow that a) alerted to a signer having a vulnerable firmware. b) initiated a migration tx to a new seed as soon as the device firmware is updated (possibly a hop to a software key in the interim if the signer can only have one active private key). If Bitkey can do it (ex: the enhanced privacy upgrade requiring a new key - seamless flow) every company should have a similar flow ready for this type of situation. It should only take a couple of clicks.
A somewhat gross but nonetheless true statement: In the grand scheme of things ~90M USD in drained ColdCard wallets is a drop in the ocean. I'd wager that ColdCard's marketshare isn't even that significant in the grand scheme of things. What particularly sucks is that these are pretty much all from plebs who worked their assess off to stack that corn. And ironically from those who probably tried to go the extra mile to get something more "sophisticated". It's "only" 90M but the impact this loss has on those affected is immense.
I feel like the "dice roll only" advice is going to bite some noobs or people who mishandle it. There is nothing wrong with hardware RNG or the RNG sources used by any hardware signer. What happened to ColdCard is a fail-open fallback to software PRNG. At least ask that people use methods that use dice rolls as a supplementary entropy source, not the sole one - if at all.
↑