For wise-asses moving the goalpost of securing your bitcoin today, you can royally go fuck yourself. If a person has taken the steps to: 1. Buy a bitcoin only hardware wallet, which is widely respected and mentioned by most of the big bitcoin proponents in the space where one might be getting their info from, such as podcasters etc 2. Keeping it airgapped 3. Not even sharing home address during purchase to avoid wrench attacks 4. Taking good care to stamp seed on steel 5. Maybe even doing yearly drills to check up on funds and hardware 6. And lost their funds today despite all the above measures 7. NOT following the vendors guide under the subpage /paranoia 8. Being told to only do multi-sig only if very comfortable to avoid locking yourself out of funds Then don't be coming at them today and say "you should have known you needed to roll dice too, it's your own fault" The steps this person has taken were FAR BEYOND what is imaginable for a non-techie person and accusing them of not taking enough care to secure funds is bat-shit crazy to me and is simply evidence that this experiment has failed. Bitcoin has not been secure today. Loss of funds from highly secure setups has occurred. "Best devs in the world" claim thoroughly debunked, now both on the bitcoin software implementations side AND the bitcoin hardware side. This event is devastating and as much as the loss of funds breaks my heart it is also an identity crisis on my effort and belief in this incredible project. Bitcoin has not been secure today and the threshold to actually make it secure has shown to be overwhelming and not at all ready for anyone who is not an expert in cryptography. I'm just so devastated and this has been a hard day and i'm extremely tired and sad.

Replies (34)

bitcoin is secure, software isnt im sorry but important distinction that NEEDS to be made. who you should be mad at are the people who have repeatedly said dont trust verify, while shiling a product they didnt even care to verify.. point the anger where its due not at the ones reminding others of steps that can enhance the security of your stack
This. It's the classic story of "I did everything right and I still got fucked." Because even though you can own your Bitcoin keys, you MUST trust the code that generates that key. And that trust was breached with this incident. Which is why it feels so tragic.
zaytun's avatar zaytun
For wise-asses moving the goalpost of securing your bitcoin today, you can royally go fuck yourself. If a person has taken the steps to: 1. Buy a bitcoin only hardware wallet, which is widely respected and mentioned by most of the big bitcoin proponents in the space where one might be getting their info from, such as podcasters etc 2. Keeping it airgapped 3. Not even sharing home address during purchase to avoid wrench attacks 4. Taking good care to stamp seed on steel 5. Maybe even doing yearly drills to check up on funds and hardware 6. And lost their funds today despite all the above measures 7. NOT following the vendors guide under the subpage /paranoia 8. Being told to only do multi-sig only if very comfortable to avoid locking yourself out of funds Then don't be coming at them today and say "you should have known you needed to roll dice too, it's your own fault" The steps this person has taken were FAR BEYOND what is imaginable for a non-techie person and accusing them of not taking enough care to secure funds is bat-shit crazy to me and is simply evidence that this experiment has failed. Bitcoin has not been secure today. Loss of funds from highly secure setups has occurred. "Best devs in the world" claim thoroughly debunked, now both on the bitcoin software implementations side AND the bitcoin hardware side. This event is devastating and as much as the loss of funds breaks my heart it is also an identity crisis on my effort and belief in this incredible project. Bitcoin has not been secure today and the threshold to actually make it secure has shown to be overwhelming and not at all ready for anyone who is not an expert in cryptography. I'm just so devastated and this has been a hard day and i'm extremely tired and sad.
View quoted note →
Look up the x profiles of the people mentioned. They have different takes. Everyone is different with their stack amount, technical capability etc.
Chris's avatar
Chris 4 days ago
To secure your life savings!!?!? 😳 Oh, I get it. You were being sarcastic.
Given that you were advised to *NOT* roll dice is where the injustice lies. I never trusted a hardware wallet, no matter how securely it is shipped, no matter how "reputable" the supplier. There can be no guarantee the hardware isn't compromised upstream of manufacturing. But I wouldn't expect the average techie to have this level of paranoia. The claim "you should have rolled the dice" is directed at techies who know better, and their bad advice to those who don't.
You and many others fell for Bitcoin maximslist ideology. Many Bitcoin OGs have warned you about the maximalist trap. Ignorance, a sense of superority and a cult like mindless followership are a bad combo when the security and privacy of family and friends are at stake. Maybe some people now can break free and take the advice from Bitcoin OGs/Monero Bros for what it is. A deep caring for the space and the people involved When we talk OpSec and privacy we are not shitting on Bitcoin. We mean well and hpe for the betterment of all.
ProfAnarch's avatar
ProfAnarch 4 days ago
Well, I was shitting on Bitcoin, and I was happy to do so. Because the time we've wasted -and are still wasting- on this nonsense is a real shame and the biggest tragedy.
weev's avatar
weev 4 days ago
We already had Trezor. It is perfectly secure and uses multiple sources of randomness (both the device, and a connected computer) for key generation. The Trezor is an extremely well connected device. It should be obvious from both physiognomy (disgusting fat Mexican) and behavior (deranged, pompous, scammy, hubristic, always slandered more qualified and honest devs) that nvk was a fucking scammer. But because he made a “Bitcoin only!” device and paid podcast grifters for promotion, the “Bitcoin community” of scammers and grifters supported him over the existing good infrastructure. This is not a failure of Bitcoin. This is a failure of grifters, centered around Matt Odell et al, people doing nothing but podcasts and scams, and a failure of maxis ignoring obvious facts to ball fan and suck off anyone who does “Bitcoin only” stuff. Until these people are excised, Bitcoin can’t go on.
The thing about multivendor is, it shouldn't matter what signer you're using because NONE of them should be generating your keys. But if you are going with stateful signers, and trusting them to keep your keys secret, then perhaps it could add some benefit to use different options. The issue is, the best signers are all the stateless DIY ones. Coldcard was the only stateful one I don't have at least 3-5 issues with that didn't magically go away just because Coldcard had a key generation flaw.
weev's avatar
weev 4 days ago
Yes. The same people that promoted ColdCard brought us a whole decade of completely broken fake Lightning implementations, have squashed every attempt to implement the features Satoshi himself advocated, have done everything possible to turn Bitcoin into an insane festival of grifting and failure. Every single thing they do is waste and fraud. If society would sane they would be dragged out of their homes and beaten.
Not shitting on them. Just not gonna take away their agency either. The amount of people trying to make this about us needing tools that are more user friendly to protect people from themselves is sickening. Sorry people learned a lesson the hard way. But not gonna deny the lesson itself to walk more into the next one.
Krux works, and Jade can do stateless well, which cuts out it's phone home routine. Stateful Jade I'm not fond of unless you're gonna run your own oracle with QR support which is nontrivial.
Well they do use the RNG for some other stuff. Part of why I'm not panicked though is that it's an airgapped device, and your psbt's are transparent. There's just a very small attack surface. Deterministic nonces are a concern though so it's not nothing.