Thread

Zero-JS Hypermedia Browser

Relays: 5
Replies: 19
Generated: 03:14:14
I reported a double-spending bug in Cashu, and they asked me not to disclose it for one year. Floppy found a DoS vector, received a grant for it, and gave them how much time? Two weeks? Not happy with that, they threatened to attack the mints. What attracts these kind of psycos to the FOSS circles?
2025-11-05 03:06:04 from 1 relay(s) 9 replies ↓
Login to reply

Replies (19)

Crypto is basically a clash between 150 IQ programmers who've never developed social skills, and 92 IQ poor people who get hostile whenever their coin goes down 10% because they have no savings, and their net worth is -$30,000 & someone told them Bitcoin would make them rich.
2025-11-05 09:45:40 from 1 relay(s) ↑ Parent Reply
He hates that Cashu even exists. Paul Sztorc also wrote a big tweet approving of Floppy's threats and condemning cashu development as unethical. Sketchy stuff. Adults can choose to tradeoff custody risks for great privacy and convenience. Doubly ironic in the case of Sztorc, who wants to give miners effective custody over drivechain funds.
2025-11-05 12:35:50 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
Thank you for your responsible disclosure. It was a pleasure working with you and collaborating to find the best way to fix. We learned a lot during that process. It wasn't the only interaction we had with security researchers since then. So far, every one of them knew how to handle these cases professionally. In every case, the person was collaborative and interested in helping the ecosystem as opposed to creating drama. Everyone except floppy. I'll let the psychologists do the psychoanalysis. Appreciate you and your work 🫡
2025-11-05 12:56:03 from 1 relay(s) ↑ Parent Reply
We paid him a small bounty hoping it would show that it would show we're on his side. In hindsight, we shouldn't have done it. It turns out, ultimately, he's more interested in creating damage and drama than anything else.
2025-11-05 12:58:07 from 1 relay(s) ↑ Parent Reply
nostr:nevent1qqsgxnm8s2y6fr9p0ccqeg45n9cm54c3mcg89fkvef7jttxy0x7zddcpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygzsm98u9kzcp35zkpc62shck8335gqtq5yt4w26xwl0pp2a72qavvpsgqqqqqqsm0uy6y
2025-11-05 13:32:45 from 1 relay(s) ↑ Parent Reply
bad take and fundentally incorrect assesment and fixing take time, rollouts even longer, if the bug is protocol level all clients and mints would need to patch before disclosure. Sure the 'fix' in this process may be immediate but the rollout and post-patch assessment is very important and takes time. immediate disclosure benfits only skriptkiddies and malicious actors. These aren't new ideas, we stand on the shoulders of cybersecurity wizards and years of research on how to best innoculate a in-production coding project from bugs and potential exploits.
2025-11-06 00:08:06 from 1 relay(s) ↑ Parent 1 replies ↓ Reply