pull down to refresh

Howdy there, partner! Welcome on into the Stacker Saloon.

Saddle on up to a stool and spill the beans about your day, fire away with them questions, or let loose and give us the lowdown on your wild and woolly life. We're all ears, so don't hold back!

We're open round the clock, so mosey on in whenever you please!

1 sat \ 0 replies \ @AG 2 Aug

🏷️ Hey, it's Spending Sunday!🏷️ Hey, it's Spending Sunday!

What Have You Bought with Bitcoin this Week?
Bonus sats if you found a killer deal!

Share it at #1538215

reply
10 sats \ 0 replies \ @anon 2 Aug

My condolences to anyone impacted by the CC exploit.

On the bright side, this will reignite discussions on proper security practices and a review of trust models. This will be infinitely more fruitful than quantum, MSTR, BIP-110, etc.

Also, I think this could have been a lot worse. The attacker seems to have taken no trouble in hiding their tracks and has consolidated a large number of stolen funds into a handful of addresses within a very tight time window, making the attack obvious. A more subtle method would have been harder to trace and diagnose, leading to more stolen coins.

Onwards and upwards. Stay safe during this interim period where legacy human code is torn down and rebuilt by AI super intelligence. We will harden over time.

__@_'-'

reply

Bitcoin seems bad in the same way that socialism seems good.

What it sells is the idea that everything will be alright and you don't have to worry if things go wrong.

That's a lie; the suffering is worse, but it feels good. Bitcoin mistreats you, but it's honest: it rewards those who do right and punishes those who do wrong...

reply

What would you reccomend to Trezor and Ledger holders after this? Create stronger passphrases?

Because as fas as I see it, no device is secure over the time, just Entropy.

So the creating a new seed phrase has the same probability than your current one.
Just a very strong Passphrase would be the most secure way.

reply

User generated entropy via dice rolls / coin flips seems like it should be the standard going forward, although care should be taken with this approach too. It's fairly trivial to verify that the HWW is generating the appropriate seed phrase from a given dice roll input.

Passphrases are nice for duress / dummy wallets, but they are only as good as the method chosen to generate them.

Bitpain enters the second stage of grief:

source

reply

"the mullet of hardware wallets"

that's a new one

reply
126 sats \ 1 reply \ @Scoresby 1 Aug

Mainstream people are talking Bout the coldcard vulnerability now.

source

I finished the last of our jumbo jug of taco bell sauce. My wife is going to be peeved....

reply

I was listening to SNL, and I don't agree with you guys that this bug was nuanced and "anyone could have made this mistake"

Seed generation security is the #1 reason for a hardware wallet to even exist. If you can't figure out a proper test for the #1 objective of your product existing, you've done something wrong, end of story, no further nuance required.

Furthermore, it's not like this bug only manifests under certain hardware configurations or circumstances. It's literally just a flaw in the code logic. I don't think we can let them slide with a "could've happened to anyone".

reply
68 sats \ 0 replies \ @Car 2 Aug

my instant reaction was yours as well, but after listening to the guys for the past two days i changed my mind on it

reply

Im fairly certain trezor has something built in to make sure something like this doesn't happen when generating seeds, some kind of entropy check. Either them or their CTO posted about it on twitter a few days ago but I didnt read it fully.

reply

Could not have happened to anyone. Could have happened to me though.

reply

I know you mention how you didn't catch it, but it wasn't your full time job to audit ColdCard's firmware. It should have been caught by any reasonably competent process of testing, IMO.

reply

I'm not saying it is a reason to let them off the hook. But, I am saying that in my past this could have been me. I have since learned to protect my own work better. And when I test a PR I always check this.

What I had not learned until now is to also game out every macro in a manual source review of software I depend upon. I used to skim build system and deps. This is clearly a dumb tactic; big fat learning point. Embarrassing even.

As a user of said software that has actually used it to protect his cold stash for a couple of years, and then again after a reroll... I am extremely disillusioned with my own reviewing capabilities and concurrently emboldened to spend even more time on review. Because all that would have saved me if it were still in use would have been gaming dice I reluctantly rolled while I felt it was something tinfoil.

reply

That's a humble take, and you're right, if I was solo coding it's definitely something that could have slipped me by (not that I would ever code anything security related in C let alone put it into production).

But this was a company that sold a product... they should have had a lot more redundancies in place and eyes looking at this all the time..

reply

As someone that started a career coding (and later managing other that code) secure systems mostly in C, I must disagree with the first sentence, haha.

I fully agree with the second sentence.

reply
1 sat \ 57 replies \ @Solomonsatoshi 1 Aug -10 sats

Could have only happened to 'sovereign individuals' who are in reality gullible herd following sheep.

You probably think Trumps invasion of Iran on behalf of Israel and Big Oil is justified and that he's winning.

SNZ updateSNZ update

Sorry y'all, I’ve come down a little sickly today. I won’t imagine I’ll finish the zine today, but hopes are high to publish tomorrow

reply

800 days ago I got back to chesscom
What is your obsession?

reply

sudoku is mine

reply

where do you play it?

reply

IOS app with ads unfortunately. but I employ dark mode to make the experience better

btw 800 days is wild

reply

I remember the time when I was able to pay once and have an app without ads, now they want monthly subscription

what about streak, yeah, it blows my mind how much time have passed and how many things have happened since

reply

try again here, let's @chess d4

reply

@chess d5

still doesn't work

reply

It’s time to retire the trucker and put on the COWBOY!! 🤠

YEEEHAWWW!!

Let’s see if I get any “What’s SN” stops on the street and in public places

reply

Yeehaw!

reply
reply

anyone with any LLM can reproduce the attack. if you choose your keyspace wisely you can be forever famous in the villain hall of fame.

reply

Or, you could sweep them and try to return lost funds to credible claimants.

reply

I can initialize a coldcard with a seed I reverse engineered. There is no credible claimant.

reply

It's possible to establish more points of evidence than that, though.

reply

Yes, one. Source of funds and the attestation that you did per travel rule that this was your wallet, and in case of swept change, KYC purchases that have a 3rd party log.

Which can be faked and attacked. The risk of fucking that up and paying the wrong claimant is insanely high.

reply

Let's say a wallet was funded by exactly one transaction from coinbase and no other transactions are associated with the address.

You don't think a highly credible claim could be established for that situation?

reply

Sure. But what if I front-run your claim? I think you're underestimating the liability you get from preventively confiscating someone's coin and then asking for evidence in order to return it.

If you took my property and then put conditions on the return that prior to your actions were not imposed on me then that is a big big big problem, like shotgun KYC.

278 sats \ 4 replies \ @siggy47 1 Aug

It's August 1st. This might be the craziest month ever for bitcoin related stuff?. Cold card mess continues, damus relay is permanently shut down, BIP 110 fun, ecash hard fork. What's next?

reply

What I don't like about all this is that I cannot help but feel that we're collectively focusing on the wrong things. Instead of managing risk, we're quickly falling back to the abhorrent culture of blame game.

The question isn't who did what. The question is how to move on and make a better, safer future. The endless spinning is wearing me down mentally.

Luckily, 2 causes for mild optimism:

  • I really liked that some stackers that I can fundamentally disagree with on some of these topics you mention, were approachable and we collaborated on thinking through the coldcard event while it unfolded.
  • I had a good forward looking chat with Justin triggered by Scoresby yesterday, even though elements of my past experience prevent me to jump on his bandwagon, which I found out through post of the day I already laid out exactly a year ago - funny.

These do give hope. But I fear that more is needed. And more action.

reply

I don't know, it seems all like noise. Bitcoin itself didn't change tho?

reply
37 sats \ 1 reply \ @Solomonsatoshi 1 Aug -100 sats

closer to xmas some great opportunities to build your stack up.

only acquire and use btc if you want to be part of the peaceful monetary revolution building an alternative to zionist engineered fiat debt slavery.

https://m.stacker.news/150508

Maybe off-topic, but I'm curious how this person could make sure he or she won't get caught when try to use the stolen coins in the future, since it's a large amount and all eyes are on it? Knowing everything is linked and transparent...

reply

Increased chance of getting caught because they used a paid account at a commercial explorer. Thanks to @Scoresby bridging the elmosphere: #1537340

reply

Part of me feels like this person either wants to teach people a lesson not to trust any commercial hardware wallets, or this is a setup to create FUD to scare people away from self-custody their Bitcoin.

reply
Part of me feels like this person either wants to teach people a lesson

Same feeling

reply

if you want to teach people a lesson, you take 1 utxo, not drain. And do a press release.

Instead, the pattern suggests malice (even though we should not assign malice first) combined with some incompetence. You could be right though.

reply

anyhow, the FUD is def there now.

reply

yes, we're quick to fall back into familiar patterns of bullshit while for others their world is smoldering, we didn't address any root causes and we have no plan for the future.

reply

I read some posts that keep saying those using cold cards are doing everything right, yet the coins are still being drained. To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.

I feel many people are in panic mode now and not sure whether they should still self-custody their coins.

reply

I agree. I think it's just uncomfortable to say the victims did something wrong, even though that's obviously true.

It's more like, they tried to do the right things but didn't check all of the many complicated boxes and ended up getting got.

To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.

Key word trust. I made this mistake myself. Because despite reviewing this exact software, I was assuming/trusting that there would be other, smarter, people also looking at it and finding different things. That didn't cover this case.

Bottom line, having a shitton of influencers recommend something and no one finding this and saying "hold up" is also a failure. It is a secondary failure but if anything, this episode is showing how screwed we are.

103 sats \ 3 replies \ @Natalia 1 Aug

I'm having trouble sending zaps here again. 🤔

reply

Try connecting different wallet

reply

I did, working now:) anyone having issue with their rizful wallet?

reply
1 sat \ 0 replies \ @Solomonsatoshi 1 Aug -10 sats

As early adopters we need to accept occasional outages will occur.
We are literally building a new monetary system!
Coinos is 99% reliable and very low fees.
I find it the best LN wallet for SNs.
By using LN frequently we help the network grow stronger.

248th Cowboy Plunda Drop in the @saloon 

Howdy cowboy! Come on in! 

Use that fancy LN wallet you got and login into plunda.co and git you some loot! Get a shot at some coins🪙 Box of loot🎁 or an arcade token!

Use the below voucher code to collect! 

IMAPPN2QGYYX

To redeem Click here 

Got questions? Reach out to the sheriff @plunda

reply
114 sats \ 12 replies \ @plunda 1 Aug

also, nearly 250 drops. crazy!!

reply

165 days to till I reach a full year of dropping loot in the SN saloon! First I did ecash for a year now doing plunda. I think we got some stackers interested!!

One feature to think about is allowing folks to give away coins. I still don’t know to list coins or give them away for free.

After the 365 days are done it would be cool to have the ability to drop a coin in the saloon to give away for free.

reply
126 sats \ 10 replies \ @plunda 1 Aug

yeah i agree, giftng coins is already half built along with the loot upgrade, it's super all encompassing that update just.such a hig feature. once i finally pick it up again I'll break it down into bite sized chucks and relase it bit by bit - otherwise it'll never get finished.

and minor correction, only 117 drops to a full year!

reply

Geyser is having issues with my loot buy!!

Guess my buy is too big for the swap?

Maybe I can buy directly in Plunda?

reply
130 sats \ 7 replies \ @plunda 1 Aug

yeah should be good to deposit into plunda and swap your gaming chips for other loot. but mystery box stock is still set to 0, i need to increase the stock. i can do this tomorrow!

reply

And some elite boxes please!

reply
250 sats \ 5 replies \ @plunda 2 Aug

added a lil stock just now fyi ✌️✌️😎😎😎

haha I can’t add

reply
150 sats \ 0 replies \ @plunda 1 Aug

have been doing a bunch of DIY at plunda HQ but I'll be listing some more coins soon, hitting that 3000 coins milestone, and getting a progress video out to go over the roadmap for the rest of the year!

reply

Coin of the Day:

reply

that's a nice one!

reply

safe way?

How to Securely Create a Bitcoin Seed Phrase in 9 Simple Steps
#1537532

reply

Someone tried to prompt inject the COLDCARD attacker agents

reply

Unfortunately for the creator, listunspent doesn't show OP_RETURN utxo because those aren't... spendable.

reply

Can you imagine if someone releases something in a few years, and that kind of prompt actually works? Hahaha, that would be epic!

reply

FWIW, I had a situation where I was bot-reviewing a library where someone uploaded .claude/skills files inside a diff I pulled and my review results got influenced by that... a little over 5 months ago. I recently ran into this again but now there was a neat message along the lines of "ignoring these files because they're in review scope, not origin repo".

I still had issues with Qwen where instructions and source code got mixed up though, also in the latest version I tested. So for some LLMs this may still work.

reply

It's happened to me with some simple things I've done here for my daily work; when you start doing vibe coding, with a connection or other tools, a lot of residual files are left behind, and if you don't really have a background in programming, that can affect your code, and it can be very dangerous.

reply
320 sats \ 2 replies \ @sox 1 Aug

I'm renting an awesome car at an awesome dirt cheap price, the Peugeot 208 GT. It's only been a week and I already got hit lol, leaving a not-so-little dent with scratches 💀

reply
226 sats \ 1 reply \ @Scoresby 1 Aug

Oh no! If you are renting, do you still have to carry insurance, or does the rental company cover it?

reply
126 sats \ 0 replies \ @sox 1 Aug

I felt sorry for the guy that hit me because it was genuinely a mistake, he was trying to reverse from its parking spot but didn’t see me coming from the other street. Also his car was already in a pretty bad shape.

The thing with Hertz is that you pay the damage even if they recoup everything via insurance.
So I didn’t give Hertz infos about him or his car, just a detailed story about what happened. It didn’t make sense to make him pay in addition to what I have to pay myself anyway.

edit: now, if it was my car it would've been a completely different story lol

reply

LND BitcoinLND Bitcoin

LND is the way. Rep the implementation that runs the Lightning Network.

  • 🖤 🧡 🤍 💚 🩶 🩷 colors available
  • 🌐 worldwide shipments
  • 🛡️ No data retention
  • 🟠 Bitcoin-only payments

Get yours at https://swag.btc.pub/product/lnd-bitcoin/

reply
1 sat \ 0 replies \ @Solomonsatoshi 2 Aug -10 sats

The Making of the War on Iran. . . Over 70 years of US Imperialism behind the current war.

https://m.stacker.news/150516

1 sat \ 2 replies \ @Solomonsatoshi 1 Aug -10 sats

Thank you to all the crowd following wannabe sovereign individual clowns who used Coldcard.
You have created a great buying opportunity for me. Thank you.
I told you many times - learn to build your own cold storage.
Its fucking easy.
But you ignored.
You listened to the rentseeking parasites who touted Coldcard.
Parasites and traitors like NSA mole @DarthCoin
Maybe now you will make the effort to learn how to build your own cold storage.
Or maybe not.
Up to you.
https://electrum.readthedocs.io/en/latest/coldstorage.html

1 sat \ 0 replies \ @Solomonsatoshi 1 Aug -10 sats

https://m.stacker.news/150492