pull down to refresh
I read some posts that keep saying those using cold cards are doing everything right, yet the coins are still being drained. To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.
I feel many people are in panic mode now and not sure whether they should still self-custody their coins.
To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.
Key word trust. I made this mistake myself. Because despite reviewing this exact software, I was assuming/trusting that there would be other, smarter, people also looking at it and finding different things. That didn't cover this case.
Bottom line, having a shitton of influencers recommend something and no one finding this and saying "hold up" is also a failure. It is a secondary failure but if anything, this episode is showing how screwed we are.
It is pretty rough that none of us managed to spot this before it was exploited.
I like to think that if I had really serious amounts of Bitcoin to secure, I'd pay some auditor to examine all the pieces of my stack. The reality seems to be as you say that we were all content to trust that someone else was doing that checking. That's bad.
For myself, I am realizing I need to get much more serious about using the tools to check on the tools I use.
multisig only buys time
...if you only used one hardware vendor...which, to be fair, most of us do.
Sure dice rolls, but aren't I still trusting the hardware wallet not to screw up turning my dice roll entries into a key?
Maybe instead of adding layers, I should have said spread out your trust.
Go through your setup and ask: if this part is pwnd what happens? Hopefully the answer is: you have time to get to safety.
but aren't I still trusting the hardware wallet not to screw up turning my dice roll entries into a key?
No you're not because you don't trust, you verify. Thursday night when someone here asked me about that I opened the code and ran through it (as in besides code glaring, stub it and execute) end-to-end, to be absolutely sure I wouldn't give the wrong answer. That was for someone else. They should have done that themselves imho, but I try to be nice and do the effort, even for a stacker that I extremely dislike, which was the case.
Go through your setup and ask: if this part is pwnd what happens?
That is the way. Also: what do I do when unlikely event xyz happens anyway. Like... some crazy RNG integration error.
ok what if you did the dice rolls to the keys in the multisig?
Good practice!
I generally am not even exposed to these except for what stackers link and I take the time for, but I think that there was a huge podcast/influencer driven inflow of new Bitcoiners since.. I'd guess covid?
Kinda sad if you got sequentially rekt through ftx, then one of the lenders and now coldcard. Every time you "did everything right" according to the most authoritative source you've got. If you can't review code, you get rekt easily. If you can, you must do it to at least make informed-ish decisions and even then, you still may not escape.
I wish I wasn't an anon and that making podcasts would make me happy, because there is so much to discuss.
I agree. I think it's just uncomfortable to say the victims did something wrong, even though that's obviously true.
It's more like, they tried to do the right things but didn't check all of the many complicated boxes and ended up getting got.
It's a false dichotomy to think either coinkite or the user must be entirely responsible.
It's possible for both to have not done everything they should have. Listing the dice rolls as an option still gave users an opportunity to look into why they might want to do that and they either chose not to look into the option or decided it wasn't worthwhile.
I'm not blaming people for not doing the dice rolls. Most likely, I wouldn't have either. I'm certainly not blaming you for not catching the mistake, although I get why that might be weighing on you.
My point is pretty straightforward: it's not correct to say they did everything right. There were choices made during setup of their devices that both were the wrong choices and could be reasoned to be the wrong choices before hand.
I agree with your point. The problem is that people in influencial positions are saying they're doing everything right! I personally did the roll on my first initialization (and also the later ones) when I was just testing, despite it being optional.
But I seem to remember that at the time I wasn't a fan of it. It felt like a chore that, when taken into the perspective of the literal words "we're taking seeds from each secure element" when in reality that is not the case - goalpost shifting on what is and isn't a secure element, but that is the narrative all around bitcoin ever since block 2 - felt a bit like a tinfoil feature.
In retrospect, it was literally the most important feature. So I this is why I say that we are having a mindset issue. I too bought the bullshit. Fell for it. Didn't even spot a stupid vuln (that arguably is hard to detect, but still.) So when everyone is worried about normies being on bitcoin - something I personally don't even believe they should do unless they have a proper reason to use it as an MoE - then we have a real problem that I do not know how to address.
Yes to all of that
yes, we're quick to fall back into familiar patterns of bullshit while for others their world is smoldering, we didn't address any root causes and we have no plan for the future.