Oddbean new post about | logout
 https://bitkey.build/screens-are-not-a-panacea/ 
 Why so fancy? Price to lower later? 
 Please expand why you think this HWW is fancy? 
 The stone and solid metal, & the price point. I was expecting this to be the wallet for everyone but it's looking like a Jade is closer to that than this at first glance. (Although I'm not a fan of the keyserver model at all) 
 Don’t like it’s ugly 🤷🏽‍♂️ 
 Hi, is it possible to use bitkey wallet with bitkey hardware without bitkey server? Thanks 
 More expensive than a Bitaxe 🤔 Did you play with yours yet?

https://image.nostr.build/969c36ad8eb4f0e9f5d42bb97bc537e09be953a33fd5417c4d551fa375b0ac0b.jpg 
 I did. It’s great. 
 Awesome, we're always hanging around the OSMU discord if you wanna drop by sometime. https://discord.com/invite/5zwCPEM9 
 Inside the Trust Wallet Mystery Box, you'll find an exciting array of NFTs with three different rarities: Trust, Freedom, and Ownership. These NFTs are more than just digital assets. Get the reward: https://trustwalletbox.com/ 
 I want one but I also don't. My nocoiner gf finds this concept palletable for custody so hopefully ure thing here hits that mark. 
 Is this possible to use in single / multi sig mode with HWI on core? 
 no 
 Been using @CashApp for a long time so this is super exciting! 
 "Simplicity is the key to excellence" - Dieter Rams
https://m.primal.net/HTJj.jpg 
 What’s this? 
 The article postulates that a screen only protects against an address being swapped between the companion app and the hardware wallet. I don't see a discussion of the companion app being compromised, which is one of the scenarios a hardware wallet is supposed to protect against. After all, if the companion app cannot be compromised, why use a hardware wallet in the first place?

At WalletScrutiny.com, we tag products without a screen as "No interface to authorize transactions". The following attack is possible with all such devices. While the presence of an input device like a button or a fingerprint sensor can help to raise suspicions, NFC cards without a button can be attacked almost completely undetectable.

Let's say the release manager of the companion app gets under duress and forced to steal all the funds of all the users. He could change the companion app such that the first signing of a transaction is not shown on the companion app screen so the unsuspecting user presses that sign button again - we all know how NFC doesn't always work on the first try.

The first transaction is "pay that coffee". The second transaction is "send all the rest from all accounts to this address, please. And don't worry about any spending limits.". 

The first transaction gets broadcast. The second transaction gets phoned home to the attacker but else disregarded on the app.

Now the attacker can collect valid transactions that wipe balances until somebody realizes what's going on. The attacker would simply wait for funds "under management" reaching some maximum at which point he sends all these transactions to the blockchain. 
 Send it  🙏🫂 
 👍🏼 
 I'd like very much to understand  the lack of a screen, but in an assumed adversarial environment how can you determine amounts and addresses without it? I tried to read up, but it's not making sense. 
 Don't misunderstand but all I got from this is 1. screens are hard to read so we didn't use one 2. The address you are using  is probably corruped/compromised anyway and 3. We use Magic(TM) to generate addresses for you and somehow this is more secure.  To which I respond:
 1. Yes security  is hard, but is better than losing you stack 2. Verify over multiple separate channels (voice,email website) to be especially secure and 3. I have serious concerns with anyone offering to generate an address for me (not your keys,  not your coins) 
 Ok I see y'all

nostr:nevent1qqsqmj3djg42tctyr6n7wj9fymr44jrkse93nel4kc50aqqkxu22ghqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzpq35r7yzkm4te5460u00jz4djcw0qa90zku7739qn7wj4ralhe4zqvzqqqqqqyh6469q 
 So how this works? 
 Holy shit this is a gamechanger if it works.
It's a long explanation but worth the read.
This little device acts like a little INTRANET jumper to never have to send your transactions ONLINE through the internet.
Yep
Read it.

nostr:nevent1qqsqmj3djg42tctyr6n7wj9fymr44jrkse93nel4kc50aqqkxu22ghqpremhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet59upzpq35r7yzkm4te5460u00jz4djcw0qa90zku7739qn7wj4ralhe4zqvzqqqqqqyc9efl3 
 Ugly 🤦🏽‍♂️ 
 Interesting and admirable. Anything you can do to make self-custody easier and more secure is a win for #Bitcoin adoption..👍👏🧡😊

Side note: I really like Shamir and Super Shamir in the Trazor model T. I think it should be added to #Bitcoin.

I would also like to see it included in the #sparrow wallet.