pull down to refresh

I think that we miss the process maturity. The only processes we have is BIPs and some bespoke ones inside software repositories. Some institutionalized processes too, like the fuzzing efforts and maybe signet, that helped catching bugs early or ensuring functional improvement.

Let's not forget that BIP-39 was for a decade flagged as recommended against, but this has been removed (commit) a few weeks ago.

Like I said elsewhere, I think the best way to look at what is happening right now is that debt is being discovered. This is long-term good because don't want it simmering. Some debt will be defaulted on in the form of funds loss, this is bad, very bad. That per calle there are critical vulns found every hour now in their little kimi rush, means that hidden debt is a lot more common than anyone cared to imagine and/or admit.

I do think that we need good software solutions. But you cannot prove that something is without errors. You cannot guarantee it. You at most can rigorously test it and insure against any liability. But most of this is MIT licensed software where literally in the 2nd paragraph all liabilities are waved. So there is no incentive for any software developer to invest a couple of million into some scheme if you can just publish with a waiver.

I don't see it happening. Not now. And the tradeoffs I foresee in it potentially happening (imagine: certification mafia) are not something I'd expect anyone with a mg/L of cypherpunk in their blood to be really open to.