pull down to refresh
I will comment on everything else later, but this one is key and I'm dead serious in my response and everyone will hate me for forever if they truly understand my point. (you below is generic, not Scoresby)
Joking aside, do you think such a thing is realistic?
I think that if we're now in the phase where we chastise people for making mistakes in the integration with their software dependencies then we are conveniently working around the fact if you integrate a piece of hardware into your security setup, then:
You only had one fucking job to do, one thing to do right, which is to use the hardware signer/wallet with no bugs. And you couldn't even do that one thing right. In fact, you probably didn't even check and if you did you fucking failed. You criticize your own upstream supplier for not understanding the upstream they were using, while you did exactly the same.
Unfortunately, that goes for every user of single-sig coldcards. Including yours truly.
Roll the dice. Dont trust
Plz stop saying hurtful things.
Joking aside, do you think such a thing is realistic? I'm running Android, Ubuntu, chrome, brave, password manager, 2fa, Bitcoin core, Bitcoin wallet, 3 different lightning wallets, 2 ecash wallets, protonmail app, matrix, couple nostr apps, signal, keet, and a few others daily.
I could ask an llm to audit each one and report back, bit I doubt I could do much with such a report. How do I get to the point where I understand what I'm running in Amy meaningful way?