How were you on the board of Opensats this long and never su...

Jay

npub10mtatsat7ph6rsq0w8u8npt8d86x4jfr2nqjnvld2439q6f8ugqq0x27hf

hex

ba7ec4068a58719bf3f0fb33e96acd96f56129c5b568e2a1fd6d85189c91815f

nevent

nevent1qqst5lkyq699suvm70c0kvlfdtxedatp98zm268z587kmpgcnjgczhcprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs8a474cw4lqmapcq8hr7res4nknar2ey34fsffk0k42cjsdyn7yqqtwat5w

Kind-1 (TextNote)

2026-08-03T09:15:09Z

↳ 回复 Gigi (npub1dergggklka99wwrs92yz8wdjs952h2ux2ha2ed598ngwu9w7a6fsh9xzpc)

Yes, things fucking suck right now. Something that should've never happened has happened, and is still happening as I'm typing these lines. The conseq...

How were you on the board of Opensats this long and never suspected that Coinkite's blatant contempt for open source development wasn't a clear red flag that their products may also be affected by such a stance, that NVK's own judgement as a board member would be affected?

Open source code is not secure because more people read it, it's secure because more people use it and exercise it. No one sits and reads code unless they have a worthwhile reason to do so. And with no one able to actually use Coldcard code in their own work, no one had any incentive to externally review the code.

A hasty migration between cryptography libraries introduced this zero day bug 5 years ago that could have been caught if people were building on Coldcard's code. That's just in one part of the codebase. Who knows what other zero days are lurking in any Coinkite product because of their stance on so-called "cloners?"

I'm glad to see NVK stepping down from Opensats board. But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. It's crucial to continue educating users about safe practices. But I believe it's equally crucial that you educate people about how this bug really came to be, from more than a technical standpoint. So that a disaster like this can be prevented in the future.

原始 JSON

{
  "kind": 1,
  "id": "ba7ec4068a58719bf3f0fb33e96acd96f56129c5b568e2a1fd6d85189c91815f",
  "pubkey": "7ed7d5c3abf06fa1c00f71f879856769f46ac92354c129b3ed5562506927e200",
  "created_at": 1785748509,
  "tags": [
    [
      "e",
      "82995cd710ba73d4dd4be830ef8224c097d9ec5b9ae55eacc13a0f57685835ee",
      "",
      "root"
    ],
    [
      "p",
      "6e468422dfb74a5738702a8823b9b28168abab8655faacb6853cd0ee15deee93"
    ]
  ],
  "content": "How were you on the board of Opensats this long and never suspected that Coinkite's blatant contempt for open source development wasn't a clear red flag that their products may also be affected by such a stance, that NVK's own judgement as a board member would be affected?\n\nOpen source code is not secure because more people read it, it's secure because more people use it and exercise it. No one sits and reads code unless they have a worthwhile reason to do so. And with no one able to actually use Coldcard code in their own work, no one had any incentive to externally review the code.\n\nA hasty migration between cryptography libraries introduced this zero day bug 5 years ago that could have been caught if people were building on Coldcard's code. That's just in one part of the codebase. Who knows what other zero days are lurking in any Coinkite product because of their stance on so-called \"cloners?\"\n\nI'm glad to see NVK stepping down from Opensats board. But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. It's crucial to continue educating users about safe practices. But I believe it's equally crucial that you educate people about how this bug really came to be, from more than a technical standpoint. So that a disaster like this can be prevented in the future.",
  "sig": "cd17d89e1301fded9dfa4cb8b5ec6bcf99a6ac9635a9fc363c59c5ba181f641e5da1c5721d6a5c17f93c7bad935664a7e9eaee3e8e977c694c2b25535a953c87"
}