pull down to refresh

How would you verify a software wallet? Input the seed phrase into iancoleman.io and see what analysis it spits out?

Of course you would never use that particular seed, but after testing numerous times you might come to trust that the seed you generate is safe.

I do not recommend inputting anything ever into a website, but yeah, you can compare outputs from completely different software as a test.

Testing (with your own test cases, not some CI fixture suite you run) is verifying. Trusting is not testing. Like: you say you tested it then I don't do it because I trust you. Of course, you'll always have < 100% certainty because you'll have assumptions. But it would be good to minimize these, and track those that you cannot get rid of.

reply
126 sats \ 5 replies \ @OT 4 Aug

This might be off topic but we kinda need 12 word software wallets to just work if we want to grow the community.

It was a critical error and we're all shaken and emotional at the moment. But let's not forget that under a year ago someone moved 80k Bitcoin that was sitting in legacy wallets for 15 years.

reply

I think that we miss the process maturity. The only processes we have is BIPs and some bespoke ones inside software repositories. Some institutionalized processes too, like the fuzzing efforts and maybe signet, that helped catching bugs early or ensuring functional improvement.

Let's not forget that BIP-39 was for a decade flagged as recommended against, but this has been removed (commit) a few weeks ago.

Like I said elsewhere, I think the best way to look at what is happening right now is that debt is being discovered. This is long-term good because don't want it simmering. Some debt will be defaulted on in the form of funds loss, this is bad, very bad. That per calle there are critical vulns found every hour now in their little kimi rush, means that hidden debt is a lot more common than anyone cared to imagine and/or admit.

I do think that we need good software solutions. But you cannot prove that something is without errors. You cannot guarantee it. You at most can rigorously test it and insure against any liability. But most of this is MIT licensed software where literally in the 2nd paragraph all liabilities are waved. So there is no incentive for any software developer to invest a couple of million into some scheme if you can just publish with a waiver.

I don't see it happening. Not now. And the tradeoffs I foresee in it potentially happening (imagine: certification mafia) are not something I'd expect anyone with a mg/L of cypherpunk in their blood to be really open to.

reply

80k Bitcoin. Did I miss something?