pull down to refresh

Every time anyone tried to poke at ColdCard or even just ask questions nvk would always dismiss them, call it FUD and attack their character.
Nvm the absolute abysmal attitude he had against competitor, who now still acted like gentlemen despite this generational dunking opportunity.

No one is infallible point blank. Dunk on NVK today trust me a day will come when someone will dunk on you! Way of the universe. We all make mistakes some are more graceful about it than others.

Coinkite still makes cool products some I will continue to use like the block clock and sat cards. Others I was excited about (Arca box) I may fade now. But when when podcasters shill products we still have to take responsibility for using them for better or for worse.

170 sats \ 7 replies \ @kepford 3 Aug

You are correct. The dunking always comes back. NVK has set himself up for this with his whole attitude and persona he puts forward.

NVK's attitude really has nothing to do with this vulnerability. I mean... maybe you could say he's arrogant and should have been more diligent but I would say that this is just a mistake. I don't think NVK is negligent in general. Maybe in this case but not in general. That said, I have never bought any of their products and probably never will.

To me the mistake is mostly not making it very clear that trusting hardware entropy is a major risk. Everyone should be doing dice rolls, 24 seed words, and pass phrases at least. If I had this kind of bitcoin in my stash I'd be doing mulit-sig as well.

None of that is an excuse but the dunking on Coinkite kinda misses the point to me. This will not be the last even like this and other projects/companies will be affected.

reply
398 sats \ 0 replies \ @aljaz 4 Aug

Nvk's attitude has a lot to do with this vulnerability because its a governance fail.

His ego, attitude and cronies doing his bidding are the reason that security researchers and others stayed as far away as possible.

He is a ceo of a company providing most critical services to the user and as such has responsibilities that dont include bullying, alienating and terrorizing everyone else in this space. And using his buddies (who are absolutely to blame for tolerating this fuckery for so long) to influence events, prop him up, give him even more visibility and make the blast radius of this shitshow even bigger.

his behavior is not a shock, the shitshow he was doing for years is not news to people around him yet american bitcoin mafia carried him as the second coming of jesus.

This was a complete failure and exposes the reality of bitcoin ecosystem - it is as rotten as anything else if not worse.

reply

Exactly!

NVK talks a lot about AI one would think an AI system must of reviewed the code but just missed it.

But Coinkite is destroyed now as a company. All the good will and trust they built over the years is all gone in a few days. No one is coming to bail them out and thus the market corrects accordingly. They go bankrupt new companies will come to fill their void and learn from their mistakes.

reply
reply
93 sats \ 3 replies \ @Kruw 3 Aug -125 sats

24 word seeds don't provide extra security over 12 word seeds. No one should use them.

when when podcasters shill products we still have to take responsibility for using them

This is what I'm taking away from it primarily. There was an enormous amount of trusting without verifying, at many levels, and some people are paying a dear price for it.

Yes, it's worth noting where the most egregious breeches of trust occurred. But I think it's more worthwhile to reflect on where we each may have been personally lax and how we each could have done better by one another here.

reply

I agree. I listen to the RHR broadcast today and it’s clear Odell is taking this really hard.

I think I got lucky because I try all sorts of wallets and move things around all the time. But this could have happened with a bitkit or a Trezor.

Fact of the matter is the risk of holding bitcoin is never zero. It’s software! We always should be prepared to lose everything! With no fault of our own.

reply
With no fault of our own.

This is the sentiment that I'm not really comfortable with in this whole discussion. We do choose what to trust and how far to dig. It can't be "no fault of our own" and "bitcoin is the best savings technology".

reply

Sure it can. A zero day bug can wipe us all out! Sometimes things happen that are beyond the control of humans.

This bug with cold card sat in the open for 5 years.

While everyone was dunking on shitcoins and calling out Saylor calling folks who thought they were untouchable ended up getting rekt because everyone trusted NVK and Peter the owners of Coinkite.

A few of us got lucky but things happen that go against your best wishes. And since all of us don’t have time to learn the code base we rely on trust of others to keep us somewhat secure. May it be a false sense of security but it gives people confidence to buy bitcoin and store it off an exchange.

reply

Part of the bitcoin ethos is radical accountability. There have been people voicing concerns about HWW's the whole time and arguing for generating external entropy. Given the availability of that knowledge "no fault of our own" just doesn't resonate with me. That doesn't mean I don't feel a lot of sympathy for the victims of this heist, though.

My model for thinking about this comes from growing up doing dangerous wilderness type stuff. People die climbing mountains and whitewater rafting and the like, sometimes very careful people. Seldom do we say it was to no fault of their own. Rather, we try to understand what lapse in precautions led to their tragic demises, so that the same is less likely to happen to us or someone we care about. That's not the same as blaming them, but it also respects and acknowledges that they made the choices that put them in the position they were in.

All of us are out on a frontier. It has real perils and requires real diligence. I find it both unhelpful and disingenuous to avoid acknowledging that people made mistakes that led to their downfall.

reply
My model for thinking about this comes from growing up doing dangerous wilderness type stuff.

When people buy and store bitcoin we don’t think it’s dangerous nor wild. We are often told it’s a boring dumb protocol that does a few things really well. An oversight of a script of code you don’t have any clue of can absolutely fall into not having fault in your own demise.

Like babies are born through no fault of their own and experience both good and bad things that come with life. Or airplane crashes. It’s the safest way to travel on planet earth and yet every so often one goes down and people die. Are they at fault because they trusted the safest way to travel?

I understand your position of trying to mitigate risk to the lowest possible but I always think risk is unavoidable.

reply

Risk is absolutely unavoidable. That's not my point.

My point is that it's important to respect the choices other people make and not infantilize them by denying their agency. These weren't babies. These were grown ups who decided to trust their savings to a new technology and decided who to listen to about that technology and how much research to do into understanding it.

The whole world, except for a bunch of internet weirdos, was telling them it was risky. If they drew the conclusion that it wasn't, then that was their conclusion and to some degree they have to own it.

reply

I agree. When I say “No fault of their own” I’m not absolving them from of responsibility. No one forced them to listen to podcasts use a single signature cold card and send bitcoin to it that has a weak seed.. They made rational decisions given the best data and information they had access to and their own technical expertise. If something happens that was outside of their purview it is possible fault is not on the victim. But it doesn’t absolve them from responsibility.

No fault accidents are a thing in the insurance industry which tries to mitigate risk.

Saying no fault is not infantilizing them but giving an explanation to a situation that even top security experts have missed.

The more I look into it, the worse it seems.

reply

Into what? Toxicity? nvk challenged me once for agreeing with him.. lol.

What I am extremely worried about are all these other people that are now dancing on the coinkite grave. Each and every one of them is using this as a marketing oppty. But even while they may not have been the lowest hanging fruit, I know teams with higher professional standards than many of these that got rekt.

IRL opti sent out a note with a vuln+PoC to a dev team last month and got a mail back: "thank you, we're already working on it, we'll credit you along with the others". Key thing to note, that s in others. That didn't happen much before. I can't remember ever sending out a dupe on < 1 week old code.

reply

Me too. It’s not fun getting stolen from or having something you worked on your whole life get destroyed because of some low character thief. The person(s) who found this could have easily disclosed this and had coinkite do a patch and save its users from getting rekt.

reply

I am definitely with the crowd that says "this should have been prevented". But I am also part of the (apparently extremely small) crowd that failed to help preventing it - voluntarily, but that does not make it less a bitter, bitter pill to swallow.

However, what I am not cool with is the grave dancing, the offhand comments, the shit slinging that took just a few hours to start and every time I opened yakihonne the past few days it looks like it is still intensifying, so I no longer go there. I wish I could believe in karma but I don't. If I did, I'd sleep better, knowing that all these guys are going to get what they deserve.

reply

I'll say more after doing more research.

reply