bitpunkfm on Nostr: So basically all of them do the thing they claim which is, they separate the key from ...
So basically all of them do the thing they claim which is, they separate the key from your main computer/tablet/phone. Most of them are pretty good we've only found minor issues since we gave that talk.
In that sense, I'd like to think the industry learned a bit from us. With the exception of tamper stickers. They are worthless.
But none of them solve the really hard problems of can I truly verify and trust this hardware. And some of them do shady things with licenses and cloud servers and what not.
So in conclusion, despite me earning money from the industry, I think people don't need a hww. I think a laptop running tails with persistent is fine for most people. Boot into tails, do your thing and disappear. Tails has had more eyes on that software than any hww code base. But nothings perfect.
Honestly, this is where
SeedSigner (nprofile…kjg2) kinda wins. I don't use it personally but it's the embedded version of what I just described. And it's an actual open source project, not a product.
I could audit it but it's like, it doesn't store anything. So I could verify it does that but at worst case it is a malicious signer. But that's the same threat to all hww, every vendor could push a (unintentional) malicious update.
Some hww vendors also just shit on each other all the time. It's honestly a bit exhausting.
I get a bit sad tbh because I'm in all these chats about how to do self custody and it's all these cults of people saying Coke is better than pepsi.
So I'm a bit disillusioned with bitcoin hardware at the moment. I'm hoping to make some actually fun electronic project instead of watching people cheer for their favorite vendor.
Anyway, long rant. But this is kinda why I'm doing bitpunk.fm at the moment to find my spark again ⚡️
Published at
2024-07-23 20:20:31Event JSON
{
"id": "a05da96636a54c34f035c02bd93677b746eb33f46d0ac4801f9378bf3947d0bf",
"pubkey": "4d4ab737e2fbb5af0fd590b4b7e8c6fe76d3a02a9791ef7fdacf601f9e50fad8",
"created_at": 1721766031,
"kind": 1,
"tags": [
[
"e",
"dbdee7267665865f1f79a0f861459ee6eee132e782c58fb1334e9391aa1b88aa",
"",
"root"
],
[
"e",
"58617f860e29cec39229d7d4bff1aa4527f2420611defba962e7807751e7318f"
],
[
"e",
"ebc278323c3abef1ca318309a011cb72dc96901ea832a3b73a6203565cd4a1ec",
"",
"reply"
],
[
"p",
"4d4ab737e2fbb5af0fd590b4b7e8c6fe76d3a02a9791ef7fdacf601f9e50fad8"
],
[
"p",
"98f818e72348b604077ae049a838c7e66fd01e2e3f68c5e02f11258a2704ff04"
],
[
"p",
"f2c96c97f6419a538f84cf3fa72e2194605e1848096e6e5170cce5b76799d400",
"",
"mention"
],
[
"r",
"bitpunk.fm"
]
],
"content": "So basically all of them do the thing they claim which is, they separate the key from your main computer/tablet/phone. Most of them are pretty good we've only found minor issues since we gave that talk.\n\nIn that sense, I'd like to think the industry learned a bit from us. With the exception of tamper stickers. They are worthless.\n\nBut none of them solve the really hard problems of can I truly verify and trust this hardware. And some of them do shady things with licenses and cloud servers and what not.\n\nSo in conclusion, despite me earning money from the industry, I think people don't need a hww. I think a laptop running tails with persistent is fine for most people. Boot into tails, do your thing and disappear. Tails has had more eyes on that software than any hww code base. But nothings perfect.\n\nHonestly, this is where nostr:nprofile1qqs09jtvjlmyrxjn37zv70a89csegcz7rpyqjmnw29cveedhv7vagqqpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0xmkjg2 kinda wins. I don't use it personally but it's the embedded version of what I just described. And it's an actual open source project, not a product.\n\nI could audit it but it's like, it doesn't store anything. So I could verify it does that but at worst case it is a malicious signer. But that's the same threat to all hww, every vendor could push a (unintentional) malicious update.\n\nSome hww vendors also just shit on each other all the time. It's honestly a bit exhausting.\n\nI get a bit sad tbh because I'm in all these chats about how to do self custody and it's all these cults of people saying Coke is better than pepsi.\n\nSo I'm a bit disillusioned with bitcoin hardware at the moment. I'm hoping to make some actually fun electronic project instead of watching people cheer for their favorite vendor.\n\nAnyway, long rant. But this is kinda why I'm doing bitpunk.fm at the moment to find my spark again ⚡️",
"sig": "5be1e56a63895bd5ede65a5e07ee9967e810478a7b1ec1f8502c30cdc4eda10a050cf6d377f3fbd3a7d904efceb5d698d765d49202d83c38f3105d72b6e63012"
}