🤓 Our NEW deep dive of the Coldcard disaster is out!
This one covers:
- The ACTUAL entropy level
- The collision risk
- The multiple sources of "entropy", and how each was triggered
It's extremely long, I couldn't review it all yet.
Coldcard MK3, MK4, MK5 and Q are being drained. A bug lets attackers find your seed phrase without any action on your part. Only wallets generated using the dice roll method are safe, assuming you rolled at least 50 dice. If you don’t know, don’t remember, or aren’t sure, move your funds immediately.
With all the talk of supplementing entropy with dice rolls, it's surprising to me that the methodologies I can find don't seem to talk about using randomness extractors to debias the results, with the exception of codex32.
We have become aware of a privacy bug in the -privatebroadcast feature, newly introduced in Bitcoin Core 31.0, that may cause the originator’s IP address to be revealed to the receiving peer under certain network conditions. A fix is forthcoming and will be released with 31.1.
Despite the latest tweet, @glozow is still hacked.
A PGP signed message using the key 6B002C6EA3F91B1B0DF0C9BC8F617F1200A6D25C will be posted if/when she recovers the account.
NOTICE: Wallet Migration bug present in Bitcoin Core wallet 30.0 & 30.1.
Under rare circumstances, migrating a legacy (BDB) wallet can delete all wallet files on the same node. If those wallets aren’t backed up, this can result in a loss of funds.
A fix will become available in Bitcoin Core 30.2. Until that is released, do not migrate legacy wallets using 30.0 or 30.1.
Only the legacy wallet migration process is affected. All other uses are unaffected. You can continue using Bitcoin Core normally, including existing wallets and running a node without wallets.
On Monday's Livestream (May 5 @ 12 PDT) I'll be reviewing OP_RETURN and discussing github moderation
I will:
- Look at the history of OP_RETURN's implementation
- Evaluate the arguments from the ML post and PR for and against the change
(cont'd)
On Monday's Livestream (May 5 @ 12 PDT) I'll be reviewing OP_RETURN and discussing github moderation
I will:
- Look at the history of OP_RETURN's implementation
- Evaluate the arguments from the ML post and PR for and against the change
(cont'd)