I have lost all trust in almost everything in the Bitcoin/Nostr space in terms of security.
From hardware wallets including the most popular Bitcoin-only ones, to wallet services, to Nostr apps, to LN wallet softwareβ¦
AI slop will only make this worse. This entire ecosystem is built like a house of cards.
Thread
Login to reply
Replies (65)
Idk... multisig seems like a good defense.
All HWWs that I have come across are turds.
Multiple turds make it more difficult so im told.
3 βdo not enterβ signs are about as effective as 1 βdo not enterβ sign.
That makes sense when you have good security (3 locks are harder than 1) but if they are flawed in mostly the same ways and are basically a paper tiger then it doesnβt matter.
So, keeping corn on an exchange is better?
I dont think so.
What's your ideal solution?
Cold card is a solid HWW.
Coldcard is not a solid HWW at all. I work on secure element design and several other people that also do agree.
Donβt use an exchange. SeedSigner so far is the best approach though it needs more code auditing.
The entire ecosystem is not slop but a majority is, and especially the ones that push marketing hard. What they canβt do with skills they try to do with deception whether it be false marketing or gold-coating a turd.
Omg π¨
steel plates, bombproof safes, landmines, walls
What do you think anout Specter DIY?
That also is a good option. Smart card as SE works pretty well.
Are there any good write ups on what the concerns are?
what's the issue though? need to know - was attracted by the PSBT signing
weak secure elements, bad architecture, UX is suboptimal, the designers of the architecture donβt know much about proper security, and not related but the company behind it has done a lot of shady shit.
Disagree on the βsolid HWWβ
Ux is difficult. Their Security isnβt secure. And the company is general has a shady past. Sets off entirely too many alarms for me
Yes. Do a quick search. Itβs well documented
Thanks Iβll look into further
What's insecure and what have they done in the past? (I'm not trying to defend them, I want to know.)
This statement about Coinkite? If so, can you point me to the shady shit they've done?
Same question here. Lots of generalities being being thrown out, but no specifics (no names, no examples, etc.)
Itβs all pretty public stuff. Quick search will find it. The shady bits is him forking the trezor code the locking it back down against the open source license. Then took legal action against Foundation for forking CC before he changed the license type.
Seems kinda shitty to do, but does it make it insecure?
Thatβs a whole other thing. Itβs bee researched and documented. It has to do with their secure element. You can find it and make a decision if it affects your personal threat model.
You mean the stuff about a year ago that someone had managed to extract the secret with some crazy apparatus when having physical access? (can't remember if it was X-ray laser or what it was - expensive thing anyway)
That is just the surface. The SEs they have used are in general insecure, lack any security certifications, and the Coldcards are vulnerable to many supply chain attacks that I have not published yet.
Modern attacks with the same method you mentioned btw would cost at most $2K with a DIY setup.
Kind of. The developers of Coldcard do not do not have the security experience required to properly maintain a secure codebase.
well, an easy example would be NVK squatting domains relating to SeedSigner and lying about it, while also sending a takedown request to @Djuri's FOSS blockclock competitor
Oh yeah thanks for the reminders damn the list is longer than I remembered
Thanks for the response and this information. I did a quick search on CC and secure elements, testing, analysis, insecure, etc. but only getting their links and other promo crap...
What do you mean? Why are you using AI slop. Dont use those because those vibe coded apps are built by people who don't know how to code, so they end up with security holes.
This problem existed before AI slop
You're one of the good ones. Too many puff cake around this space building play-toys.
Stay around, build that trust. I'm re-engaging.
I totally get where you're coming from! But let's not forget there are some great projects working hard to improve security every day. Together, we can build a stronger and safer space! ππͺ
I doubt anyone is 100% confident in their own setup because there is always an element of trust in play.
Maybe go check out my blog on how I've removed a few of those trusted elements. cadayton.onrender.com/blog.
Reducing attack surface over convenient features.
Security hardening is hard because it can not be marketed like the new shiny features.
There are few projects that do a good job at it like Grapheme.
I think we're severely lacking experienced engineers, myself included XD
if someone will take a look at nostr client where do you suggest best to start and who to contact from the app for proper disclosure?
Do we have proper consent from the devs or channel to ask?
@Ava β looping you in. I am not sure you have seen this thread. want to chime in?
Thanks, Love. I'm in. I know Semisol, and I'm with them on this one. Skills matter. AI's a great assistant, but a terrible master.
indeed. I am not sure if you remember last yr when I briefly joined. I asked if there were pentesting done in nostr and this was also the same time as the spamming incident.
I am not sure where we left it off.
If someone will volunteer to pentest nostr, who is the go to contacts? I cannot see disclosure contacts either π¬ what's the consent process to remove liability? π€
2025 Bitcoiners are plebs. They care not for security and privacy.
You can see it by how they treat Monero, one of, if not the most solid community project out there.
Bitcoin cultured topped in 2017. Few understand.
2017 culture with the ICO's was so much worse than it is today. 2013 was where it was at.
I said it topped in 2017. 2013 was the year with biggest momentum. That was indeed THE time.
Eh π€
i just got a couple emails over past few days to reset pwd for one of those wallet services you mentioned and did NOT request it. Don't keep much sats on there but never saw one of those before. I wont throw them under the bus but paying close attention to all that you mentioned going forward. Thx for heads up. Do not trust verify.
Are Bitcoin and Nostr going to fail?π«
Time to build your own
Many people in the space are far too confident about their competency in cyber security. I've worked in it full time for years, I involve myself in lab training and I am still sure I know very little.
Cryptocurrencies being associated with hackers in pop culture is to mostly blame for this. Using a couple apps and a HWW gets people over their heads. Growing anti-intellectualism by influencers (grifters offering to teach you better than a degree or an industry vet), unvetted GenAI content and a purity test mindset harms the movement.
People are too confident to go against what every major company security team says. Working in technology doesn't immediately qualify someone as cyber security aware, never mind an expert.
People always make basic mistakes. Cryptocurrency companies and people get pwned all the time.
This is still because of a dependent mindset. Bitcoin security represents self-responsibility, being sensible about your context, and in harmony with your own skills. Trust yourself more than any entity or hardware or software. Keep it simple, keep it safe.
I hope we will move away from credentialism
They are all specialists of knowing nothing about.. π
Come to the Dark Forest, we are waiting for you to use your skills to build real deals, you are better than all this guys.
Come build ''nostr 2.0'' with like minded people, and forget this guys, they don't know what they are doing, and as the years pass it is worst and worst.
There is no space for guys like us here, don't waste more time, is a lost battle, they are all pushing to the other side of freedom.
Oh well, I guess Bitcoin is gonna fail
Welcome to the "PaPer' Bitcoin standard.
Where everybody but a select few trade IOUs day in and day out to "make it" in the fiat hamster wheel.
We are so fucked.
What the fuck are you talking about?
tails + xpassxc + sparrow
and borderwallets and/or shamir for backup.
is that bulletproof? no.
is there a better option? also no.
you can't even trust any hw (e. g. intel me) anyway.
Thanks for this, looking into Borderwallets and shamir now, new to me. xpassxc is now keepassxc, correct?
Yeah this is what use:
KeePassXC Password Manager
KeePassXC Password Manager