I propose fundraising to have @SeedSigner given a formal third party independent code review.
How is this done properly? Is this something @npub1fft9...6sxp is interested in?
Login to reply
Replies (4)
My primary concerns are to have a way to validate whether a darkskippy attack could be present and whether the key generation actually guarantees sufficient entropy.
They can pay for their own code review.
Why would an open source nonprofit like seedsigner pay for that? Yes, certainly coinkite should pay for their own review.
Why don’t we all just point AI at the repo?