The logic doesn’t hold. If reproducing the theft would “help...

CR¥P7ΩWØLF
npub16jknkmh2luflurx2epkj99qyj7v2ut3ew7t2mfd7xxt9jtjku2nsj2gqp0
hex
2c02ae555dcad27b89640c985bfc22704e3c833d47035241bfc3e0defb2a2a36nevent
nevent1qqszcq4w24wu45nm39jqexzmls38qn3usv75wq6jgxlu8cx7lv4z5dsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsdftfmdm407yl7pn9vsmfzjszf0x9w9cuh094d5klrr9je9etw9fc8fqtcfKind-1 (TextNote)
↳ 回复 Matt Corallo (npub185h9z5yxn8uc7retm0n6gkm88358lejzparxms5kmy9epr236k2qcswrdp)
I mean look at coldcard’s blog too…
The logic doesn’t hold. If reproducing the theft would “help attackers,” then we’re being asked to trust claims we can’t verify, which is the opposite of how Bitcoin security works. Engineers can disclose a vulnerability without publishing an exploit path, and they can demonstrate failure conditions without enabling theft.
Right now we have assertions, not evidence. “Trust but don’t verify” isn’t a security model — it’s a social request.
原始 JSON
{
"kind": 1,
"id": "2c02ae555dcad27b89640c985bfc22704e3c833d47035241bfc3e0defb2a2a36",
"pubkey": "d4ad3b6eeaff13fe0ccac86d2294049798ae2e397796ada5be3196592e56e2a7",
"created_at": 1785515682,
"tags": [
[
"e",
"fa37a2400b5688ef67bfb64c19b9ab2ddd582a6b2bda0ab92b0e137758f34166",
"wss://nostr.bitcoiner.social/",
"root",
"3d2e51508699f98f0f2bdbe7a45b673c687fe6420f466dc296d90b908d51d594"
],
[
"e",
"2ceb1f059d0e0933eb04a279fa77537b2c970389769fe96cd05f61e2aae6eb92",
"wss://relay.ditto.pub/",
"reply",
"3d2e51508699f98f0f2bdbe7a45b673c687fe6420f466dc296d90b908d51d594"
],
[
"p",
"3d2e51508699f98f0f2bdbe7a45b673c687fe6420f466dc296d90b908d51d594"
],
[
"p",
"3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24"
],
[
"p",
"5a288f11c00b37df47c3bfe95e5397288d99951fe8100c228399cf2ab8c4517e"
],
[
"client",
"Ditto",
"31990:781a1527055f74c1f70230f10384609b34548f8ab6a0a6caa74025827f9fdae5:ditto"
]
],
"content": "The logic doesn’t hold. If reproducing the theft would “help attackers,” then we’re being asked to trust claims we can’t verify, which is the opposite of how Bitcoin security works. Engineers can disclose a vulnerability without publishing an exploit path, and they can demonstrate failure conditions without enabling theft.\n\nRight now we have assertions, not evidence. “Trust but don’t verify” isn’t a security model — it’s a social request.",
"sig": "2c6cc24a968237ba8815c8f65126313782082ba268c4230a8941e4e5da0bb5179bfbc9ecead3e946b99ab2a6e2fa04d022662f4c361b12c6d12fb12beea8e657"
}