At Blockchain Commons @BlockchainComns and at the last two #RebootingWebOfTrust we’ve been working on better standards for social key recovery, one result of which is the Shamir based slip39. But a side consequence is revisiting BIP39. We hope to have compatible alternative soon.

RT @ChristopherA: @VitalikButerin At Blockchain Commons @BlockchainComns and at the last two #RebootingWebOfTrust we’ve been working on bet…

They don’t seem to have announced this yet, but @basecamp added 2FA support without requiring Google accounts for their flagship project management service. A number of software orgs, including my own, chose not to use Basecamp because of concerns regarding SMS-only security.👍😀

RT @socrates1024: All trilemmas can be any two of:

  • well defined
  • insightful
  • true
    but never all three

RT @peterktodd: “Freedom of transaction is a human right that you need to carry out all your other human rights.”

RT @TamasBlummer: UK’s FCA seeks to extend AML regulations to publication of open source software.

RT @kimdhamilton: Thank you for the conversation and thoughtful questions. I appreciate what @Tykn_tech is doing to move forward conversat…

What are the state-of-the-art numbers for brute forcing 8, 9, 10, 11, 12 letter random alpha&number only passwords in late 2019? I have some old figures for Amazon GPU instances, but they feel out of date.

Now that all orders have shipped to my Kickstarter patrons for my “Gate Watch” GMless collaborative storytelling game, sales are open to the public. Just $9.99 for 18 poker-sized cards to hide you through an evening’s entertainment! #BuildWorldsTellStories https://www.drivethrurpg.com/m/product/262972

Replying to @Q_Game_Design

Did you ever finish this? I’m seeking inspiration from a #BelongingOutsideBelonging in a western (or wired west) setting.

A less expensive @htcexodus cryptocurrency cell phone is on its way for around $250, and the option to add storage for a bitcoin full-node. https://www.forbes.com/sites/benjaminpirus/2019/10/19/new-htc-exodus-able-to-run-full-bitcoin-node

RT @Stammy: Just published 15,000+ words on security keys. 🔐📱💻

.@kiarabickers — my former intern then fellow employee at @Blockstream — now has a new book demystifying Bitcoin for a non-technical audience: Bitcoin Clarity. Excellent work! https://getbitcoinclarity.sale/product/book/

Good biometric policy! 👍“beneficiaries may be issued with…a card on which their biometric data is securely stored, but that the ICRC will not collect, retain or further process their biometric data (and will not therefore establish a biometric database)” https://blogs.icrc.org/law-and-policy/2019/10/18/innovation-protection-icrc-biometrics-policy/

The article is interesting. Storage leads to databases which leads to abuse. By storing the info on a card held by the patient the patient controls its use and access to services.

Original BART plan from 1956. Ultimately killed by San Mateo & Marin not wanting to pay in. Bad long-term decision making. https://twitter.com/km/status/1186842858147307520

Not looked at this project, but I’ve been suggesting for years that some older tech, like Chaumian Blinding (used by DigiCash back in 90s), is worthy of reinvestigation as many of their centrality problems can now be solved. Given new BIP-Schnoor code is emerging, worth a look. https://twitter.com/NickSzabo4/status/1187089734910136326

Tails 4.0 is out, which is important for Bitcoin power users because it now supports a current version of the ⁦@ElectrumWallet⁩ when using Tor. I have an interesting #SmartCustody idea for a multisig PSBT scenario using multiple #TailsOS USB keys. https://tails.boum.org/news/version_4.0/index.en.html

There are a number of #SmartCustody cold storage problems where fiduciary responsibility requires separation of duties. With Tails, each manager can generate generate their own keys (save to offline titanium) and then create a multisig address. When you close Tails all is wiped.

Later, they can use their offline key backups to sign a PSBT to recover their funds from cold storage. Advantage of Tails is it is a well known, almost deterministic-built, all in RAM OS that is hard to remote compromise. If @ElectrumWallet supported SLIP39 even better.

That is a legitimate question, but one that can be addressed in the recovery process checklist.

Tails is ephermal by default. No data is saved. All keys are are saved offline.

By default Tails does not have any persistence. It doesn’t, by default, store anything on the USB. Though you can store persistent data in an optional encrypted volume, you don’t need to do so in my process checklist as you enter your offline 12/24 words, erased from RAM after.

Any of your talks on video?

I played Street Magic at @bigbadcon last week. Good Microscope-like game but space rather than time. May substitute it for Kingdoms in my 9-hour Cooperative Trilogy games I have run at @DunDraCon (Microscope->Kingdoms->my instant Fiasco playbook).

I did some work on turning bip39 random seeds into iambic pentameter poetry. “the hazards of bliss are pleasing the lounge
unfair was cinnamon to search and scrounge
the stained vibrant lasers give us lectures
prayer saves the valley from conjectures” See: https://github.com/ChristopherA/iambic-mnemonic/blob/master/README.md

Some of the code we used to create our dictionaries are at at https://github.com/ChristopherA/password_poem - some of this data was used to inform word selection of SLIP39. Hope to return to this side project soon.

Yes. Of if Electrum eventually supports SLIP39 then write down al least 60 and restore 40. But there are some advantages to this depending on your attack scenario.

I talk about Titanium offline key backups in #SmartCustody Book v1.01 2019-09-16 http://bit.ly/SmartCustodyBookV101

😡 Censorship of free speech & protests by shutting down tools: “the charge of “terrorism” is clearly overblown. Unless your definition of terrorism extends to harnessing the power of peaceful civil resistance to generate momentum for political change” https://techcrunch.com/2019/10/30/github-removes-tsunami-democratics-apk-after-a-takedown-order-from-spain/

I’m not sure that always bowing down to the demands of “best for shareholders” without consideration of the whole system, or at least other stakeholders like customers, is warranted. I agree there is a line — but I don’t believe this app crossed it.

Wish I could be there, but needed more notice (and a sponsor since #RWOT is a non-profit & Blockchain Commons is a benefit corp.

RT @grittygrease: We deployed two post-quantum (aka quantum-resistant as far as we know) key agreement algorithms in TLS 1.3: one fast with…

Sorry, you a wrong. That decision only applies to when a company is for sale. It unfortunately, however, has become an accepted cultural excuse for executives to ignore the larger picture for short term reasons. https://www.washingtonpost.com/opinions/harold-meyerson-the-myth-of-maximizing-shareholder-value/2014/02/11/00cdfb14-9336-11e3-84e1-27626c5ef5fb_story.html

As far as argument, devs are moving off of GitHub because Microsoft is proving that they don’t understand the underpinnings of why people contribute to open source. Apple has shown that at trying to stick to your principles can gain you good will. It should have gone to court.

I was nice running into you, and thanks for supporting the #SmartCustody book! Let’s find a way to do more educational workshops based on it.

#SmartCustody v1.01 2019-09-16 Free PDF: http://bit.ly/SmartCustodyBookV101

At-cost POD (print-on-demand) $13.50 from Lulu #SmartCustody by Christopher Allen (Paperback) - Lulu: http://bit.ly/SmartCustodyBookViaLulu

Financially support updates to the next edition: #SmartCustody! http://bit.ly/SupportSmartCustody

I liked the start on termless glossary from #RWOT9 https://github.com/WebOfTrustInfo/rwot9-prague/blob/master/topics-and-advance-readings/Terminology%20for%20Agent_Hub-Related%20Identity%20Concepts.pdf — capture than from all the communities, then choose terms appropriate for each.

Another resource is the RWOT glossary primer at https://github.com/WebOfTrustInfo/rwot9-prague/blob/master/topics-and-advance-readings/glossary-primer.md

RT @JournoJoshua: Microsoft researchers suggest ‘data dignity’—tech companies like Facebook paying people to use their data—will create a b…

You can now support my open source efforts such as my #SmartCustody book, my Bitcoin Command Line Course, etc. & my advocacy of decentralized identify& privacy through the new @github sponsors functionality. And the first $5000 they they will match! https://github.com/sponsors/ChristopherA

Free PDF of my #SmartCustody book: http://bit.ly/SmartCustodyBookV101

Epic Halloween Night ending tonight for @mattleacock & @robdaviau’s cooperative board game #PandamicLegacyS2, by the Thursday night @MeeplesTogether gang. We won! 🥳 After 21 (of max 25) games we had a final score of 581. Great game! 👍 https://www.zmangames.com/en/products/pandemic-legacy-season-2/

Decentralization isn’t a spectrum (i.e. a line) but a continuum of multidimensional space. There are at least three axis, maybe 4 or more, and the area is not convex but concave, such that there are gaps where increasing in one dimension decreases another.

There also is a hole in the center of the continuum, as there can be no perfect decentralization. Like Arrow’s Theoem for voting system design, as some criteria of decentralization are mutually exclusive of others.

