If the code is open, bad actors will read it and exploit it

SatsAndSports

npub1zthq85gksjsjthv8h6rec2qeqs2mu0emrm9xknkhgw7hfl7csrnq6wxm56

hex

1dfde1d6d3c43c31829ade6ad044aca612048a9637ea563e9fa2876ac976925b

nevent

nevent1qqspml0p6mfug0p3s2ddu6ksgjk2vysy32tr06jk86069pm2e9mfykcprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsp9msr6ytgfgf9mkrmapuu9qvsg9d78ua3ajntfmt580t5llvgpesx5npqp

Kind-1 (TextNote)

2026-08-01T08:40:32Z

If the code is open, bad actors will read it and exploit it

If you want to motivate people to review and help you to improve the code, actively encourage them to use it and encourage them to depend on it in their products

Make it truly open source (MIT, GPL, BSD).

Be flattered, not angry, when people incorporate the code in their products. They are now motivated to help find and fix problems

Don't arrogantly try to say that it's "your code", as if you are perfect

I.e. don't be like ColdCard. Don't do a dumb rewrite, against the loud advice at the time, to switch all the code to a fake-open license which allows bad actors to read the code and doesn't incentivize good actors to do the same

More examples are being (re-)surfaced of Coinkite/nvk being assholes. Their anti-open attitude appears to be deeply embedded in their DNA. I say this because they can't recover from this; the root cause of this isn't just "aww shucks, this one line was unfortunate". They were mismanaged by an egomaniac who hated openness


Just one example

https://thecharlatan.ch/COLDCARD-Supply-Chain/

I guess I'm lucky that I had a slightly "icky" feeling about Coldcard. Their device looked really cool, and they had some good marketing, but that all felt kinda sus to me. So I don't think I really considered it

原始 JSON

{
  "kind": 1,
  "id": "1dfde1d6d3c43c31829ade6ad044aca612048a9637ea563e9fa2876ac976925b",
  "pubkey": "12ee03d11684a125dd87be879c28190415be3f3b1eca6b4ed743bd74ffd880e6",
  "created_at": 1785573632,
  "tags": [
    [
      "alt",
      "A short note: If the code is open, bad actors will read it and e..."
    ],
    [
      "r",
      "https://thecharlatan.ch/COLDCARD-Supply-Chain/"
    ],
    [
      "client",
      "Amethyst"
    ]
  ],
  "content": "If the code is open, bad actors will read it and exploit it\n\nIf you want to motivate people to review and help you to improve the code, actively encourage them to use it and encourage them to depend on it in their products\n\nMake it truly open source (MIT, GPL, BSD).\n\nBe flattered, not angry, when people incorporate the code in their products. They are now motivated to help find and fix problems\n\nDon't arrogantly try to say that it's \"your code\", as if you are perfect\n\nI.e. don't be like ColdCard. Don't do a dumb rewrite, against the loud advice at the time, to switch all the code to a fake-open license which allows bad actors to read the code and doesn't incentivize good actors to do the same\n\nMore examples are being (re-)surfaced of Coinkite/nvk being assholes. Their anti-open attitude appears to be deeply embedded in their DNA. I say this because they can't recover from this; the root cause of this isn't just \"aww shucks, this one line was unfortunate\". They were mismanaged by an egomaniac who hated openness\n\n----\n\nJust one example\n\nhttps://thecharlatan.ch/COLDCARD-Supply-Chain/\n\n I guess I'm lucky that I had a slightly \"icky\" feeling about Coldcard. Their device looked really cool, and they had some good marketing, but that all felt kinda sus to me. So I don't think I really considered it",
  "sig": "d0865c4793801abe33c0fa612e081d1dd84aa13c6c4a34e87ef144e2b19fda411fec2ab0f828aa5a4cb37c72f2b6d1a9816d166ef280216bdb3536b8fef18d0b"
}