Oddbean new post about | logout
 It wasn't until March 2024 that the Samourai guys addressed the change of identities in Tor to make the coordinator blind, and only applied on soroban which never went live and also on the desktop client.

And it's one of the worst structured code I've ever seen and people trusted these guys with their privacy....

https://github.com/Archive-Samourai-Wallet/whirlpool-client/commit/fbee9e820f511661c888a53c75a5e5e610b000f5

nostr:note1s8g546a7j2de3ez2x27z8x4gh6qq20qmtfskr930f8wx2t0vysdssc97w9 
 So we can assume coordinator can link input-outputs for all the coinjoin transactions that were done before March 2024? 
 Yes, and I hope they have deleted the logs. 
 you can assume shit It was actually in the whirlpool client all along - it always used a different identity for output registration.  https://github.com/Archive-Samourai-Wallet/whirlpool-client/blob/6eefd5b854110ad5758eb2b34be775ca44d867f5/src/main/java/com/samourai/whirlpool/client/whirlpool/ServerApi.java#L73 
 It is not used in the android app because it is computationally expensive, nor in sparrow.

https://github.com/sparrowwallet/sparrow/issues/1328 
 Crickets 
 Wouldn't it be much fairer to address the devs directly? and it would be interesting to see you discussing your findings with the team. What's all your Samurai bashing about? 
 😂 the cult 
 they are in jail/ House arrest 
 Charge for a privacy service easily doxxed?

I only analyze privacy methods, I don't give a damn who is behind it. 
 The Samourai truthers were really something.  Great marketing, if only JM had marketing like they did. 
 so what do you recommend for privacy in bitcoin? 
 Well, it's honestly a really difficult question and it depends largely on who you are protecting yourself against.

A three-letter agency is not the same as a national government or any user. 
 i mean imo not without flaws (and the one you mentioned is a big one) but by far the best overall privacy solution in the space.  
 Samourai is not one of the best, in fact it is one of the worst. 
 name a better one 
 In order from best to worst:

Joinstr

Joinmarket

Wabisabi

And there are other non-coinjoin solutions such as Lightning that offer great privacy. 
 I can see why you'd rank like that, however if the only criteria would be privacy and nothing else, then the rank order would be reversed, wouldn't it? 
 If we are talking about privacy in chain, wabisabi from my point of view is the one that gives the best privacy, besides solving the problem of toxic change.

It would be great if in the desktop client you could pay through coinjoin without having to depend on BTCPay Server. 
 MIX@meetups  
 It seems they just put that into the RPC yesterday. Although I don't personally think it's a good idea. I think payments in coinjoins will always have bad UX unless a proper P2EP is implemented, and everything that doesn't bring towards making the average Bitcoin user use Bitcoin privately by default is a distraction. But anyway, I'm not there anymore and even when I was I wasn't able to keep the project on track and kill all the advanced feature requests so all I can do now is to bitch about it on nostr😅 

https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.3.0.0 
 Thanks for the info, I saw that it was included in the new version. 
 "don't trust verify" they say & it does pay @ least imho. it's taken sum of my time but glad i did spend. now i read all fine print & try to verify code from know sources. i think anyone can too, cuz, i'm not used to this nuance either & still trying to keep up.   Bless this mess & ours!    pow 866400 
 https://github.com/Archive-Samourai-Wallet/whirlpool-client-cli/blame/91f8609bad8a9d33948b915a01e89aae99c09034/src/main/java/com/samourai/whirlpool/cli/wallet/CliWallet.java#L72

https://image.nostr.build/f235bee06f4f20b0090a9e5109bcedcbcb5c50290f3ced4d7596c5783091729f.jpg
 
 False, the Android app does not manage identities, nor does sparrow. 
 https://x.com/PavelTheCoder/status/1847820728462201333?s=19 
 bad actor Meister
best to move along

he was pushing LN as a privacy solution over Monero until recently 
 I guess I should have known better. those who need to call themselves cypherpunks ... 
 I kept telling him to lose the Guy Fawkes mask... 🤨
I think he muted me 
 For the record, the whirpool-client code does have Tor identity management. The code I showed belongs to the new soroban implementation and I did not review the old client (very badly structured code). However neither the android app nor sparrow manage identities.

The android app because it is computationally expensive, hence one of the reasons why wasabi never had a phone client and sparrow because it was not implemented correctly.

I don't know what percentage of people were using said desktop client, but evidently everyone who has used the android client or sparrow has not been protected.

nostr:note15720avmmchg6fy8rqmwxrxut3cy6kfg297l7scn3gjysemmzrfzsxjva9p  
 Mofos never used the wallet and it shows.

Back when Whirlpool was still spinning, every time you'd submit a UTXO for a premix/remix, your android Samourai client would display a message that a new tor identity has been claimed when submitting that output. 

Stop this unproductive FUD shit show, go touch the grass and enjoy your day.

Support the FOSS devs via p2prights.org

#FREESAMOURAI https://image.nostr.build/227a0d7d82adcca0c889f8935698dd36b05a130e8d3694d86ce82824c78cb6c8.jpg

nostr:nevent1qqsvy6tf55qwz4nm9ds5g7qgqptx8acqu8uturnd6nqcl3zy9wzvdfqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqsrxvn35
nostr:nevent1qqsvy6tf55qwz4nm9ds5g7qgqptx8acqu8uturnd6nqcl3zy9wzvdfqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqsrxvn35
nostr:nevent1qqs20987kdaut5dyjr3sdhrpnw9cuzdty59zl0lgvfc5fzgvaa3p53gpzpmhxue69uhkummnw3ezumt0d5hsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqs06qf6j