Paranoid cryptoanarchist. #Bitcoin and stuff. Mostly #bitcoin. Sometimes stuff. +youngsun226. Team @FOUNDATIONdvcs. Opinions are my own

Earth, Solar system, Milky way
¡Muchas gracias a @CriptoNoticias y al resto de alumnos que se acercaron el viernes en @Wo_Bitcoin al taller de @FoundationHQ! Ver las caras de ilusión cuando la gente descubre que puede simular Passport Prime en su ordenador y desarrollar las apps que quieran no tiene precio.
1
10
172
Y si no sabes de lo que estoy hablando, apunta tu LLM aquí ;) docs.foundation.xyz/develope…
1
44
Espectacular panel de recopilación de datos excesiva y KYC de la mano de @adsuara, @JavierAMaestre , @patowc, @StarkPrivacy y Eduardo de @policia . Kudos a @Wo_Bitcoin y @FoundationHQ por hacerlo posible!
4
7
28
2,244
FOSS is the way
It's time for a new foundation. Not a new start. Legacy Mode is live on Passport, keep every account you already have, on code anyone can inspect. Switch to open source hardware and software while keeping your existing accounts for supported assets. Here’s how. 🧵
6
202
¡Allí nos vemos!
🛠️ ¡NUEVO TALLER EN WOB26! Foundation Devices (@FoundationHQ) se suma al viernes de talleres de la mano de Jack (@Jacksper13), defensor del software libre y el código abierto. Aprenderemos a sacarle más partido a la Passport Prime y a dar un paso más: pasar de usar tu Passport Prime a crear y ejecutar tus propias aplicaciones sobre ella, con ayuda de IA. Y no, no necesitas saber programar. 📅 Viernes 2 de octubre · Espacio Pablo VI, Madrid 🎟️ El acceso a los talleres está incluido con tu entrada: wobitcoin.org/#entradas #WOB26 #Bitcoin #Madrid #FoundationDevices #Taller #Workshop #Passport #Autocustodia
1
8
314
Jack retweeted
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
44
52
225
102,026
Where FOSS meets FOSH
In case you missed how thoroughly open source Passport Prime is, here's a link to the machining drawing of the chassis for no reason github.com/Foundation-Device…
4
250
Some preliminary results for @FoundationHQ Passport Prime. This thing is a beast!!
Hash-based signatures on hardware wallets are feasible: @blksresearch benchmarks show that SHRINCS & SLH-DSA take less than 2 minutes. Future wallets could be optimized & faster. Code is open-source. Thanks to @BlockstreamJade @Ledger @satoshilabs @BitBoxSwiss for the help!
5
5
85
11,736
Jack retweeted
Replying to @lianabitcoin
15
10
73
19,935
Jack retweeted
Following the recent Coldcard events, we performed an additional review of Passport's entropy architecture – for current and previous Passport models – and want to share more about our existing testing and continued code hardening. Passport contains multiple independent hardware randomness sources. Before releasing each Passport model, we empirically tested each source, as well as the final combined entropy output, and performed statistical analysis on the results. Since January, we’ve also been regularly running frontier AI models against our code alongside human review of every change. This includes GPT trusted cyber access. Going forward, we intend to publish a report alongside each new software release identifying which frontier models were used plus any key findings. We are also: (1) Adding further health monitoring to detect hardware component failures and ensure that an improbable hardware failure never results in a low-entropy seed. (2) Releasing our internal entropy-testing app on Passport Prime so anyone can generate millions or billions of samples, save them to a USB drive, and perform independent statistical analysis. Our additional review found no evidence of an entropy vulnerability in Passport Prime, Passport Core, or Passport Founders Edition devices. No action is needed for Passport-generated seeds. Thank you.
Foundation has confirmed that all Passport models have always correctly generated seeds with 128 bits of entropy (or 256 bits for 24 word seeds). All Passports are safe and secure. If you have questions or if you need help, please do not hesitate to reach out.
34
55
503
97,374
Prioridades...
NVK is currently deleting old posts from 2020 to try to clean up the history. Screenshot them while you can. They will all be gone soon.
5
1,154
Yesterday, a serious flaw was disclosed in Coldcard’s seed-generation process. Funds linked to affected seeds are already being stolen. We know Passport owners will have one immediate question: is my seed affected? If your seed was generated on Passport Prime or Passport Core, the answer is no. Both devices use entirely different seed-generation code, and neither has ever contained this bug. If you own a Coldcard, please read Coinkite's advisory immediately. It is time-sensitive. Please read the section on scams at the end before you take any action. Losses that follow an incident like this often come from the scams around it rather than the original problem. What happened Every Bitcoin wallet starts with a seed, and its security depends completely on that seed being random. If the randomness behind it is weak, everything built on top of it is weak too. In March 2021, Coldcard changed the code behind its seed generation. A check that was meant to guarantee the device's hardware randomness was being utilized did not work as intended, and the firmware was instead built to use ordinary software randomness, calculated from predictable values like part of the chip's fixed identifier and timing registers. The hardware randomness was still there on the chip. That code path simply stopped using it. The result is that the range of seeds a Coldcard could produce was drastically narrower than it should have been. How much narrower depends on the model and firmware, but all Coinkite devices are at risk. The two accounts worth reading: - Coinkite's advisory, which is the manufacturer's own and is being updated as they learn more - blog.coinkite.com/coldcard-m… - Block's technical analysis, which is the most thorough public write-up so far. - engineering.block.xyz/blog/p… Coinkite's advisory currently covers Mk3 from firmware 4.0.1, Mk4 and Mk5 before 5.6.0, and Q1 before 1.5.0Q. Block additionally identifies affected Mk2 firmware. Check the advisory directly rather than relying on this summary, since the scope has already widened once. Two things are worth understanding if you own a Coldcard: 1) What matters is the firmware that was running when the seed was created, not when you bought the device, and not which wallet holds it today. 2) Updating your firmware does not fix an existing seed. Recovering from this means generating a new seed and moving your funds to it. Coinkite also has guidance on where dice rolls or a strong passphrase change the picture. Read it there rather than taking a rule of thumb from us. Why Passport-generated seeds are not affected Both Passport Core and Passport Prime generate seeds by combining multiple independent hardware sources, including our avalanche noise circuit, a physical component on the board built specifically to produce randomness. The published seed generation code on both devices uses those hardware sources. It does not fall back to a serial number, a device identifier, a timer or a clock. CHECKING RATHER THAN TRUSTING You do not have to take the above on our word, and we would rather you did not. Our firmware is open source, so you can read the code that creates your seed yourself. Both devices also have a documented reproducible build process, so you can build a release from source and confirm it matches the binary we published. Independent security audits of both Passport Core and Passport Prime are published in full, along with our responses to them, foundation.xyz/security. PLEASE BE CAREFUL OF SCAMMERS This is the part we would most like you to take away. Scammers are always circling, but when something high profile happens, they go into overdrive, because they know a lot of people are suddenly worried, confused and in a hurry. Assume anyone who contacts you out of the blue about your wallet is a scammer until proven otherwise. To be completely clear about how we operate: Foundation will never ask for your seed words, recovery phrase, private keys, passphrase or PIN. Not by email, not on the forum, not in a support ticket, not on a call. There is no situation in which we need them. We will never ask you to type your recovery phrase into a website, a form, an app or a support tool. We will never contact you unexpectedly about your wallet, and we will never ask you to move your funds. We will never ask you to share your screen or install remote access software. If someone is pressuring you to act quickly, telling you your funds are at risk and they can help, offering a "recovery service", or asking you to verify your seed somewhere, stop and do nothing. That is the scam. Be especially wary of direct messages, of people claiming to be Foundation or Coinkite staff, and of search results and sponsored links for wallet software, and only download software from the official source. QUESTIONS If you have questions about how your Passport creates and protects your seed, reach us through our official support channels or our community forum. Forum: community.foundation.xyz Email: hello@foundation.xyz
6
34
144
9,299
La revolución será FOSS o no será
Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened. It's a disastrous situation and our heart goes out to all the Bitcoiners affected. Here's a timeline of events: On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license). On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.lingyaoai.com/nvk/status/12888603458… On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmware… On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS. On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license. On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.… github.com/Coldcard/firmware… Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase. To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds. But the timeline establishes two things: (1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and (2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite. We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.
7
712
A wallet built from @tether's own Android app, with no seed phrase on the phone. It keeps the full Tether Wallet experience: the same screens, the Wallet Development Kit's own wallet libraries, live balances, and direct network broadcast. The difference is where the key lives. When you send, the phone builds the transaction. Passport Prime independently decodes it, checks the network, recipient, value, and fees, then signs only after physical approval. The phone verifies the signature before it broadcasts. The phone remains the wallet. Passport Prime becomes the authority. A proof of concept, working today: USD₮ transfers on Ethereum Sepolia and Bitcoin transactions on Bitcoin Testnet. Built with @WDK_tether. CC: @paoloardoino
4
5
49
4,357
freedom.tech is officially back! @sethforprivacy built it a few years ago as a home for freedom tech writing. When he moved on from the @FoundationHQ team it sat dormant and never got the love it deserved. It's running again now, as something completely different.
7
15
55
13,954
Ahora empieza lo divertido
The most interesting apps of the next decade won't run on your phone. They'll run on hardware. Today we're launching the Passport Prime App Showcase: a preview of the proof-of-concept apps already being built ahead of the full SDK and app store. 👇🧵
4
267
oh boy, i can’t wait to use fable 5 for non-coding non-biological non-cybersecurity tasks for up to 50% of my usage limits for about a week
195
349
9,126
196,910
Some of our team out at @bcc8333 in Spain this weekend. Presenting Passport Prime. Proud to be sponsoring the event 🧡
Sobres gordianos por @Jacksper13 en la @bcc8333
1
1
19
1,363
Jack retweeted
Sobres gordianos: un salto en la implementación de bluetooth —> @Jacksper13 on stage en la #BCC8333 #BCC26 #cypherpunk #Barcelona
1
18
454