How were you on the board of Opensats this long and never suspected that Coinkite's blatant contempt for open source development wasn't a clear red flag that their products may also be affected by such a stance, that NVK's own judgement as a board member would be affected?
Open source code is not secure because more people read it, it's secure because more people use it and exercise it. No one sits and reads code unless they have a worthwhile reason to do so. And with no one able to actually use Coldcard code in their own work, no one had any incentive to externally review the code.
A hasty migration between cryptography libraries introduced this zero day bug 5 years ago that could have been caught if people were building on Coldcard's code. That's just in one part of the codebase. Who knows what other zero days are lurking in any Coinkite product because of their stance on so-called "cloners?"
I'm glad to see NVK stepping down from Opensats board. But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. It's crucial to continue educating users about safe practices. But I believe it's equally crucial that you educate people about how this bug really came to be, from more than a technical standpoint. So that a disaster like this can be prevented in the future.
Login to reply
Replies (4)
But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him.
blah blah blah
stop making shit up
nvk is nvk
open sats gives money to good projects
they dont need your trust
what has this bug to do with opensats, really
Do you see the pattern. No one is directly calling @NVK fault.
“Oh you should have used dice”
This is not a zero day… it’s clear to me that people’s wallets have been getting drained since this bad update came out…
It’s just been "covered up and disregarded" by coinkite as a company…