That company is so compromised and/or inept. From another tweet:
  1. They are loading Javascript from a CDN (Content Delivery Network).
  2. They are not version-locking loaded Javascript.
  3. They had their CDN compromised.
ELI5 version:
reply
"The @ledgerhq/connect-kit-loader allows dApps to load Connect Kit at runtime from a CDN so that we can improve the logic and UI without users having to wait for wallet libraries and dApps updating package versions and releasing new builds."
This looks like an extremely dangerous approach now. Connect-kit-loader trusts whatever the CDN throws at your dApps. So when connect-kit is comprised, all downstream dApps are automatically exposed.
Many familiar names there and I stopped scrolling after seeing wagmi and MetaMask SDK.
Also, revoke.cash is compromised.
reply
deleted by author
reply
The maxis were right again.
reply
deleted by author
reply
need to look into this when i have time but
Connect-kit-loader trusts whatever the CDN throws at your dApps.
sounds like this doesn't affect us? since we're not a dApp?
reply
deleted by author
reply
oh sorry, thought you are someone else, lol
similar nym
reply
reply
deleted by author
reply
reply
mh, interesting, you posted this at 2023-12-14T13:42:43.847Z and this here was posted at 2023-12-14T13:43:01.081Z so only a few seconds apart.
i wonder why this got a lot more sats than yours.
maybe because you only posted a (twitter, not even nitter) link and "some" people complain here they don't want to see links, they want to see original content where the OP provided some context?
so I wonder if @IgnaciobTato just gamed this sentiment since they created a "discussion post" but basically just posted links, lol
but you even posted this in the right territory (at least the one in which i would have posted this): ~bitcoin instead of ~privacy
so really not sure what happened here, maybe others can add their thoughts on this :)
reply
Regarding the flags, what happens with the votes on Meme Monday and Fun Facts?
reply
wdym?
reply
downvotes on meme monday and fun fact shouldn't be possible. I haven't tried it, but it must affect the voting.
reply
downvotes on meme monday and fun fact shouldn't be possible
why not?
reply
The way I see it, it doesn't make sense, because it's a vote for the better. It's the same as voting for the best footballer, it doesn't make sense to give downvotes to a certain player. Besides, this possibility could be used to manipulate the results.
reply
your reasoning makes sense but there might still be comments that aren't even related to Meme Monday in Meme Monday so i think flagging should still be supported there
to implement your request, we would need to be able to detect if something is related or not so people can't just post anything since they know they can't get flagged.
but that is an unsolvable problem since if we could do that, we could basically automatically flag stuff, so no need for any flagging at all
makes sense?
At the end of the day, it's the people who decide whom to reward. I'm okay with it. By the way, it would be cool if it were possible to remove the flag :)
reply
which flag? your post isn't flagged as outlawed
reply
After downvoting, it's not possible to revert
stackers have outlawed this. turn on wild west mode in your /settings to see outlawed content.
Dapps? Dude, get off that crap. Bitcoin only
reply
The alleged drainer address:
Looks like it's slurped up +$200k so far.
reply
So today Tether freezed the account as it was a hacker account, tomorrow a country or someone that says something they don't like.
reply
deleted by author
reply
👀👀👀 could....of...sworn...this....was... Foreseen
reply
Lol who uses dapps and why would they think a tethered signing device is going to make it better than a browser, you were already cooked to begin with, ledger is doing these people a favour by allowing them to get rugged
reply
Stuff like this will drive pre-coiners to BlackRock and Fidelity, unfortunately.
reply
Many people are gonna go with the ETFs. They will have to learn their lessons.
reply
Can you be more specific about which lessons these types of investors will learn?
reply
When the rug pullings start.
reply
How many rug pulls have happened with the GLD etf?
reply
They don't care about people holding an ETF, they care about people using bitcoin as money. No one will be avoiding sanctions with their Blackrock Bitcoin ETF shares. They will be safely controlled by a fully compliant and regulated entity. No worries there. That's why Lizard Warren has her panties in a knot about self-custody. So you're right, gold and bitcoin ETFs are probably safe for the foreseeable future, because that's exactly what they want: everyone owning a derivative instead of the real thing. The fight is over self-sovereignty, and ETFs are a win for them in that respect.
reply
reply
I'm not trying to dodge the question. I don't know actually. Do you know? Is it more than zero?
reply
To my knowledge, it's 0.
reply
I think you misunderstand what I'm saying. The US gov controls the system which you would be trusting. That's what I'm saying. When it gets bad, you will not be able to access your bitcoin.
reply
And they will learn the same lessons
reply
Which same lesson? ETF investors won't have to worry about these custodial issues. They'll just hold shares in a brokerage account.
reply
ETFs don't hold funds, its just a claim of a third party to another third party, lots of fingers in that pie on the back end and loads of room to stuff up key management, then what?
reply
The ledger issue is now fixed.
To make sure you don't have the malicious library cached, go to https://cdn.jsdelivr.net/npm/@ledgerhq/connect-kit@1 and ensure the version is 1.1.8.
If it's not, clear your cache. chrome- F12> Chrome Developer Tools > Application tab > Storage in left tree> Clear site data.
reply
ACINQ uses Ledger for their lightning multi-sig