ExploreTrendingAnalytics
Nostr Archives
ExploreTrendingAnalytics
semisol147d ago
I have lost all trust in almost everything in the Bitcoin/Nostr space in terms of security. From hardware wallets including the most popular Bitcoin-only ones, to wallet services, to Nostr apps, to LN wallet software… AI slop will only make this worse. This entire ecosystem is built like a house of cards.
💬 34 replies

Replies (34)

The Fishcake (nostr.build)147d ago
House of 💩
0000 sats
semisol147d ago
All HWWs that I have come across are turds.
0000 sats
vinney...axkl147d ago
steel plates, bombproof safes, landmines, walls
0000 sats
semisol147d ago
This problem existed before AI slop
0000 sats
semisol147d ago
3 “do not enter” signs are about as effective as 1 “do not enter” sign. That makes sense when you have good security (3 locks are harder than 1) but if they are flawed in mostly the same ways and are basically a paper tiger then it doesn’t matter.
0000 sats
semisol147d ago
Coldcard is not a solid HWW at all. I work on secure element design and several other people that also do agree. Don’t use an exchange. SeedSigner so far is the best approach though it needs more code auditing.
0000 sats
semisol147d ago
The entire ecosystem is not slop but a majority is, and especially the ones that push marketing hard. What they can’t do with skills they try to do with deception whether it be false marketing or gold-coating a turd.
0000 sats
mIX146d ago
Are there any good write ups on what the concerns are?
0000 sats
BITKARROT147d ago
Slop definitely existed before AI slop. The problem is now everyone is using AI slop, with or without engineering bkgs. I really, seriously am done trying to clean up AI slop. Its like getting a dog to drive, it can push a button to go forward and get from A->B, sorta. But do you really trust it? I can't wait until someone really hits a wall and crashes hard. Then maybe people will wake up.
0000 sats
semisol147d ago
tipping point I reported several security vulnerabilities to LNbits and they took months to fix and ignored it. Alby did not follow basic security practices. many HWWs are weak as shit Nostr apps keep leaking nsecs every few months. The reference Cashu mint is poorly designed and had on one case when I operated it duplicated funds.
0000 sats
semisol147d ago
Well it has already contaminated a monetary system so who knows what’s next. Software development should require a license of competency because it can and will create significant harms. From economic losses to disruption of critical infrastructure.
0000 sats
semisol147d ago
The SeedSigner model intentionally puts firmware verification responsibility on the user. Of course anyone can create a malicious firmware, for any signing device.
0000 sats
semisol147d ago
Some clients were designed without XSS protection. I believe Coracle sent nsecs to an analytics providers for a while by accident. And a lot of other stuff.
0000 sats
The Fishcake (nostr.build)147d ago
Unfortunately that’s true for many, and don’t get me started about random web extensions, that store your nsec in plain text in browser storage
0000 sats
The Fishcake (nostr.build)147d ago
I get 404
0000 sats
The Fishcake (nostr.build)147d ago
I am making a highly secure extension addition for the Nostr Build Shack now, should hit public test release this weekend. https://testflight.apple.com/join/qgkAMPgU Nostr Build Shack
0000 sats
The Fishcake (nostr.build)147d ago
Fair game, but it’ll be tough
0000 sats
The Fishcake (nostr.build)147d ago
Similar but not cross compatible (can be in the future)
0000 sats
The Fishcake (nostr.build)147d ago
🤣
0000 sats
Ava147d ago
Thanks, Love. I'm in. I know Semisol, and I'm with them on this one. Skills matter. AI's a great assistant, but a terrible master.
0000 sats
vinney...axkl147d ago
i stumbled around and eventually landed on and read this post: https://www.vaughnnugent.com/blog/d9ab8a46cfa8d6bd59cf048… 👍👍
0000 sats
The Fishcake (nostr.build)147d ago
Interesting write up
0000 sats
vinney...axkl147d ago
you're thinking of @97c70a44…ad98e322
0000 sats
semisol147d ago
That also is a good option. Smart card as SE works pretty well.
0000 sats
vinney...axkl147d ago
I totally agree with you.
0000 sats
Final146d ago
Many people in the space are far too confident about their competency in cyber security. I've worked in it full time for years, I involve myself in lab training and I am still sure I know very little. Cryptocurrencies being associated with hackers in pop culture is to mostly blame for this. Using a couple apps and a HWW gets people over their heads. Growing anti-intellectualism by influencers (grifters offering to teach you better than a degree or an industry vet), unvetted GenAI content and a purity test mindset harms the movement. People are too confident to go against what every major company security team says. Working in technology doesn't immediately qualify someone as cyber security aware, never mind an expert. People always make basic mistakes. Cryptocurrency companies and people get pwned all the time.
0000 sats
A146d ago
2017 culture with the ICO's was so much worse than it is today. 2013 was where it was at.
0000 sats
semisol146d ago
weak secure elements, bad architecture, UX is suboptimal, the designers of the architecture don’t know much about proper security, and not related but the company behind it has done a lot of shady shit.
0000 sats
semisol146d ago
📝 a391e587…
0000 sats
semisol136d ago
That is just the surface. The SEs they have used are in general insecure, lack any security certifications, and the Coldcards are vulnerable to many supply chain attacks that I have not published yet. Modern attacks with the same method you mentioned btw would cost at most $2K with a DIY setup.
0000 sats
semisol136d ago
Kind of. The developers of Coldcard do not do not have the security experience required to properly maintain a secure codebase.
0000 sats
semisol136d ago
well, an easy example would be NVK squatting domains relating to SeedSigner and lying about it, while also sending a takedown request to @b5127a08…8635c422's FOSS blockclock competitor
0000 sats
vinney...axkl147d ago
Agreed. Though if I'm being perfectly honest, the approach of "everything is insecure, so I should build my own tools - they'll be more secure!" can be an anti-pattern in the wrong hands. I don't know enough about @036533ca…cbaabf58 or his work to say, but it's a very minor alarm bell. Sometimes the whole ecosystem is improved more by talented and motivated individuals contributing to exiting projects that need help in the areas those individuals identify as weak points.
0000 sats
The Fishcake (nostr.build)147d ago
I tried to find clean and compliant libs for swift, just to end up writing my own on top of the standard libsecp256k1 instead of gluing together all the slop
0000 sats