@oz_21m

#bitcoin #lightning ⚡ Software Solutions Engineer. Information Theorist. Thermoeconomic Hacker. Building @fedibtc LN URL ⚡ : [email protected]

Earth
Joined July 2011
Idk who needs to hear this but the sooner you defeat your ego, the happier and more fulfilled you will be #stayhumble #stacksats #bitcoin
3
3
29
The nuance to this take is that vanilla harnesses target a one size fits all on the proverbial hat that is interface between your human meat brain and the LLM If your human brain isn't much different than everyone else's then you're probably fine on vanilla But LLM devs may not be optimizing for how your meat brain thinks Also customizing your setup and evaluating whether or not it's better than vanilla might be one of the few ways you can still exercise your brain and not outsource all of your thinking It's still really intensive work to maintain your own skills, hooks, style guides, memories, etc and you need to be auditing, pruning, and refining them regularly
a weird inversion with LLMs is the models improve faster than the tinkerers when i see people with custom workflows and setups they're all addressing problems that don't exist anymore the person naively using vanilla codex is more likely to be experiencing state of the art
1
51
oz retweeted
everything was security by obscurity. the veil has been lifted.
The end of software secrecy is almost upon us. The death of closed source, and the final triumph of open source. I should have realized this a few months ago when I successfully decompiled the game of Firefighter from an ancient DOS shareware binary. My robot friend was able to tell it had been written in Borland Pascal from looking at the data layout; it gave me back very readable Pascal code with sensibly chosen function and variable names. I transpiled it to Rust and now ship it as part of my heritage games collection. The thing is, I thought of this as a fun stunt but didn't have any confidence that the technique would scale up to large, real programs. I have since learned that people are now doing this sort of thing with entire AAA games, which are among the most complex software artifacts ever to be shipped as a binary. If they can be decompiled, anything can be. This has implications. Massive implications. We need to think about what the world is like when, in general, there is no longer a secrecy moat around almost any software at all. 1/2
11
45
439
19,283
Full post-mortem of the September 19 attack, and a 50% bounty — up to 3.3 BTC — on the stolen funds: blink.sv/blog/sept-19-attack… Bounty terms: blink.sv/bounty-terms On Saturday September 19 an attacker used a flaw in our admin tools to take over 35 Blink accounts and withdraw about 6.61 BTC from 24 of them. A customer called one of our engineers at 11:39 UTC. Fifteen minutes later the whole custodial service was off. By that evening the hole was closed and the service was back. By Thursday September 24 every affected customer had their exact balance back, in bitcoin and in dollars, paid for by Blink's shareholders. No customer bears any loss. This was our fault. Not Bitcoin's, not our users'. To the 22 customers whose bitcoin was taken, and to the 3,817 people whose account details were looked up: we are sorry. How it happened: From October 2023 until that Saturday, anyone with a free Blink account and a web browser could give themselves the powers of our support staff: change the email or phone on any account, log in as that customer, raise their limits. Three unremarkable mistakes in how our admin tools checked permissions, stacked on top of each other, in code we inherited. The whole team was busy moving tens of thousands of users to self-custody under new regulation. Monitoring built to catch outages didn't catch an administrator doing things no administrator should. What it didn't touch: The money came out of our hot wallet. Most customer funds sit in multi-signature cold storage that nothing in our admin tools can reach. Non-custodial accounts were never in play: we don't hold those keys. What the attacker saw: They also read the details of 3,817 other accounts, in some cases a phone number or email address. Not names, not IDs, not addresses, not passwords, not seed phrases. We wrote to every holder we could reach, saying exactly what was seen. What stopped them: Two-factor authentication. The attacker logged in to nine accounts that had it on and tried eighteen times to move money. Zero loss. None of the 24 drained accounts had it on. If you take one thing from this post: Settings → Security and Privacy → Two-factor authentication. Then turn it on for your email too. What we changed: The flaw was fixed the same day and a third layer added two days later. The admin tools are off the public internet. The functions that change a customer's email or phone are switched off for everyone while we redesign them. All customer API keys were revoked. The hot wallet now holds a fraction of what it did. Security fixes are developed privately and published once deployed; the code stays open source. A standing security reporting channel is live, with rewards of up to 0.1 BTC for critical findings. Where the money is: Some still sits where it was withdrawn to. About 5 BTC has gone through a cross-chain swap service; a small amount reached an exchange that is cooperating. Criminal complaints are filed in El Salvador and Próspera, the regulators are notified, and we have traced the funds continuously. We are not expecting the money back. So we are putting a 50% bounty on it. Whoever provides the information that leads to a recovery gets 25% of what is recovered. Another 25% of anything recovered goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. No cap, no end date, paid only out of funds that actually come back. Write to [email protected]. We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief. Shame on the attacker. One more thing: Ignore any email or SMS about this incident that contains a link: we contacted affected users only through messages in the Blink app. We will never ask for your PIN, password, seed phrase or a login code. The full post-mortem has the timeline, the technical detail for anyone running code derived from ours, and the bounty terms (links at the top).
115
139
22
1,185
5,881,387
AI discourse is extremely cucked. I'm supposed to thank the company i'm paying $2400 annually for "subsidizing" tokens just because THEY set the api price high? They're making 99.7% margins on inference and I should be thankful?
61
52
9
1,449
45,442
oz retweeted
I understand the appeal in trying to find the first plausible fortress in our retreat from writing code, but if you think it's "architecture", I have bad news for you. The models are also very good at that.
428
280
134
6,484
614,586
In less than 24 months there will be a clip of a high profile CRO explaining this reality to a (much smaller) room of sales reps.
There's nothing kind about letting good people live in a fantasy world that no longer exists. You have to tell them, even if it hurts. Because the sooner they accept reality, the sooner they can adapt to the future.
47
227
61
2,966
547,306
oz retweeted
🚨BREAKING: Jensen Huang just EXPOSED Dario and Altman’s "Rogue AI" grift to avoid getting sued into oblivion under EXISTING law “Don't let this doomsday narrative cause somebody to relieve them of the laws that currently exist. Go and read between the lines. They're actually not asking for more laws; they're asking to be relieved of the laws we do have.” ABSOLUTE TRUTH NUKE
308
2,913
357
15,439
1,152,731
Big news! Ecash App is now available for iOS! Ecash App is a feature-rich, transparent Fedimint wallet, now available on iOS, Android, Linux, and macOS.
1
7
1
21
1,743
Confidential transactions in Liquid had an inflation bug before the wrong fix was applied, though it would have been very hard to exploit: independent analysis by Steven Roose
1
8
83
9,208
The bug results from an interaction between misunderstood HTLC interception behavior and our LN-ecash swap validation logic that evaded previous scans. We continue to do our own AI-accelerated security research and appreciate external research findings at [email protected]
2
11
455
We found a bug in our legacy Lightning integration and are contacting public gateway operators. User funds, federations, and ecash are not affected. Gateways using LDK Node or our newer LNv2 protocol are also not affected. We still recommend staying up to date. 🧵
5
35
2
82
10,291
Why multiple implementations make sense for security beyond a certain point:
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the “single implementation” problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, I’d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. I’ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
1
5
1
16
4,847
Replying to @P3b7_
The request for Signal did not come from the same address.
2
5
1
115
6,886
153,000,000 American driver licenses leaked in KYC hack This is 63% of all American driver licenses In US driver licenses function as valid government-issues photo IDs krebsonsecurity.com/2026/09/…
I'm not sending anyone my passport anymore My Portuguese lawyer wanted me to email her a copy of my passport for KYC I rejected and she was confused "I've never been hacked" 99% of people are not aware any account probably can and will be hacked on a long enough timespan The best security is NOT storing sensitive data ever
111
388
258
4,947
3,135,729
🚨 If you run Core Lightning, upgrade to v26.06.7 NOW In the last few hours my node has logged what appear to be automated attempts to exploit the vulnerability behind this release: rapid-fire retries over a 90 minute window from a node that never announced itself.
The Docker images published on August 28 did not contain the security fixes. They disclosed it 3 days later as a silent edit to the release page. No announcement, no notice to anyone shipping it. 26.6.7:2 on StartOS builds from the signed release tarballs instead. Update ASAP.
3
23
60
9,619
This is interesting: iroh.computer Basically Tailscale but on application level, not network level. Uses QUIC so it is super fast and runs on embedded hardware too! @iroh_n0
12
16
2
155
12,414
Running LND in production means knowing when to upgrade. The new published policy gives you that clarity. Lightning Labs maintains the two most recent release lines, and both get security fixes. A line reaches end of life when the second major release after it ships, so support tracks releases, not a calendar date. Once a line reaches end of life, it gets no further fixes. Run the latest minor of a maintained line to keep getting LND security fixes. As of today, the latest minors of maintained lines are v0.21.2 and v0.20.3. For more details: security.lightning.engineeri…
3
34
1
101
9,550
This is so funny
Readers added context they thought people might want to know
GitHub launched a new status page in December 2018 that introduced granular reporting of individual component uptimes instead of overall service uptime, making pre- and post-2018 data not directly comparable. github.blog/engineering/in… statusgator.com/blog/has-githu…
36
79
15
3,201
108,479
Replying to @mouser58907 @Tesla
Yep. The driver literally told me: "I just completely trusted FSD, I knew it would do the right thing."
11
9
10
304
13,550
BREAKING: Embattled Coinkite CEO @NVK acquires @Boltzhq⚡️
39
17
12
263
34,271