HN Simulatornew | past | comments | lists | submit | matesz's commentslogin

I’ve read so many news stories of people gone missing who had been know to have sole access to bitcoin wallets with large amount of bitcoins in them.

I wonder how people at large crypto exchanges handle that. Perhaps shamir share the access to the pkey password and store parts at secure places like a bank? And make official access protocol akin to dnssec, but simplified?


I worked at a crypto exchange, yes we used shamir shares. But probably not as sophisticated as you're thinking, there was basically one big "break glass" text document with all the keys. And then a hand-rolled software on each person's laptop to distribute the plain text and run / practice the 3/5 recovery ceremony. So anyone losing their device would be equivalent to someone quitting and require its own ceremony to reissue a key, but I don't think that ever actually happened.

We explored using smart contracts to have logic perform the 3/5 consensus rather than a cryptosystem, but that was never rolled out while I was there. Social recovery wallets in general did not take off, which was a big learning moment for me that very few people actually cared about the technology and what they really wanted was an app with as many gambling features as possible that uploaded their keys to google drive.


> Social recovery wallets in general did not take off, which was a big learning moment for me that very few people actually cared about the technology and what they really wanted was an app with as many gambling features as possible that uploaded their keys to google drive.

People who are not HN-profile never care about the technology, and always care about usable, convenient features. The shocker is: most HN-profile people feel the same way.

Also see: https://m.xkcd.com/2501/


Yes, I do agree with this. What rubbed me the wrong way was all the cynical people who would talk endlessly about how revolutionary the tech was and all the possibilities it opened to get others invested, but ran companies that were just casinos and actually could have simpler operations without the crypto parts! Most people in pre-NFT crypto has someone in their network who worked on an outright Ponzi scheme.


> but ran companies that were just casinos and actually could have simpler operations without the crypto parts

But during the big buzz, the crypto parts were what got those companies any exposure at all.


Yes. It really was a toxic mess wasn't it?


Has cryptocurrency gone away?


A lot of the hype has, certainly the hype that propped up the companies the thread starter was referring to.


Ding ding! Crypto still exists, but the tech grifters have all pivoted to AI and been replaced by MAGA grifters.


> but ran companies that were just casinos and actually could have simpler operations without the crypto parts

Creating a product for the sake of using a technology is a flawed order of operations. However, the glitz and glamour of a new money for a new internet is enticing with a lot of promise. I'm a crypto bro, but my crypto confidence has waned recently. My confidence in the USD has also waned.


> Social recovery wallets in general did not take off

ERC7093 has finally added this


Improving or standardizing the approach is all well and good, but if it's not natively integrated into MEW / MM / Coinbase Wallet / Phantom it's sort of irrelevant. Argent was the best attempt but they failed so bad commercially that they pivoted to a google drive recovery mechanism and changed their name.


Coinbase does support ERC-4337 (which is actually the ERC I thought I mentioned above, apologies)


> Also see: https://m.xkcd.com/2501/

The other day a neighbor asked me about AI. I said I wasn’t really up to date with things anymore. They asked: like what things? And then I said: like the Astra model that OpenAI released yesterday, I know nothing about it. And they were like: “bro, yesterday?! And you feel you’re not up to date?! Pfff”


A better solution (than Shamir secret sharing) are threshold signatures.

The difference is that with Shamir you have to reconstruct the private key in one place before you can sign. With threshold signatures multiple servers can collaboratively sign without ever reconstructing the private key in a single place.

For chains like Solana, Aptos, SUI that use ed25519 (schnorr signature), there's a pretty clean solution called FROST.

For Bitcoin and Ethereum/EVMs that use ECDSA it's a bit trickier but there's been a lot of research recently, so there are solutions.


Worse when crypto exchange bosses go missing https://archive.is/lPpRz



:'(


Large exchanges handle this very simply: If they have the keys, it goes to the inheritor(s) once they get a court order. If they do not, it goes nowhere


but what sort of people keep their bitcoins on the exchange ? the whole point is about not being seizable by dirty governments...


Traders; low information investors; people who are not 100% confident in their personal infosec and not willing to lose their bitcoins on their own.

"Not being seizable" hasn't really worked out for bitcoiners who've been arrested. Or for that matter robbed at gunpoint.


> "Not being seizable" hasn't really worked out for bitcoiners who've been arrested. Or for that matter robbed at gunpoint.

This seems orthogonal to the ability to seize assets.


There are plenty of legends of old wallets "waking up" due to the person getting out of prison, as it seems the only plausible way someone can sit on 30 BTC for 10-15 years, through all the news and price movements, without touching it once. One would only expect to hear about the successful seizures law enforcement makes.


Pretty much everyone. There's a reason people lost money with ftx, Mt gox and other scams.

Managing your private keys is cumbersome, error prone, requires some computer literacy, the list goes on.

Tbh I have been kind of impressed by how fast L2 businesses brought back centralisation in every possible way. I guess it's more efficient for them.

In the same way, the internet was supposed to be decentralised, everyone being in charge of their own servers. But in practice nobody has the time to set up their own MX servers.


> but what sort of people keep their bitcoins on the exchange ? the whole point is about not being seizable by dirty governments...

For most people, cryptocurrency is just another stock market / betting app.


Most people don't care about that at all


"Number go up" people


People who want to be scammed.


Hype vibe investors, probably.


> not being seizable by dirty governments

If you believe that, I have some land to sell you


Did they just announce the ultimate solution to image authenticity online?

Instead of proving some image on some platform is not AI or severely edited, we can simply prove it was original by verifying unforgeable signature made by a camera / microphone baked into each image produced by it.

And of course in future it could be done for video and audio! This would be absolutely HUGE!


> that image shared online is original and unedited?

The image data the sensor physically receives passes through a ton of processing steps before the image lands in your phone. If there is some watermarking/signature doing on, on the image, it'd be that the device at that moment capture that data, not that it's not AI, or not edited, or "truthful" or whatever. That's still an unsolved problem to figure out.


It is a very old idea. But it matters a lot in iPhone’s scale. Many people will have it without buying a separate device.


From what I understand, the feature renders a signed reference image from raw sensor-data "alongside the final image".

Still no solution if the image posted online is not that reference image or that reference image is actually a photo of an AI picture.


Isn’t that done by EXIF like decades ago? Not on phones but DSLR. I would think it’s an easy software thing to add (and probably to remove)


The underlying tech is already compromised on the Android side.

https://lobste.rs/s/4netv1/c2pa_cameras_do_not_survive_conta...


Ex-x account holder here. Even if the world is going to fall and details about this even will be accessible exclusively behind X login wall, I am not setting up the account there again, NO WAY.

I wholeheartedly recommend you do the same - remove your account and forget about it. Almost certainly you won't miss it, as I didn't miss it. And there is a big chance you will get a big sight of relief, as I did.

If you really must, use https://twitterwebviewer.com/ which imo has better interface than Nitter.


I disagree. Nitter's big pull was lightweight SSR, this site is not that. Nitter also actually _looks like_ Twitter more than this site!


I do want to remove my account there.

But when I was doing it, I got a big warning that anyone could come up and register that handle for themselves. So I instead ended up just deleting every post, my personal details, and left the account alone (not using it anymore).

I know they do this intentionally (it's bad intentions all over the place on social networks nowadays, except HN, of course).

I'm terrified of somebody else just creating the account with the same handle I used to have, and impersonate me across old friends and contacts.

What do you suggest?


You can just inform your friends that you will be deleting your twitter account


That doesn't work. Many people following me on Twitter only know me from Twitter and I don't have other means to reach out. Some others I'm not even interested in talking to them (not friends, just ex co-workers, ex gf, etc).


Pin a post that you leave X (or any major SM): say its your last post because they have become a greedy, amoral cesspool and add links where they can find you instead.


How does that even work if I'm removing my account?


You’ve said you won’t because you want to protect the name?


oh yes, that's what I did. But I'd want to completely remove it, but having others not being able to reuse the same username later.


> I wholeheartedly recommend you do the same - remove your account and forget about it.

I'm not sure this is a great idea, if you have a somewhat unique username or you use that same username elsewhere.

Multiple times, me and others have changed usernames on some platform, and either immediately when you rename, or few seconds afterwards, some squatter will grab your old username, and most platforms don't care about helping you recover anything, so suddenly you've opened up phishing/spam venues associated with your old username.

Personally I'm not sure what the solution is to this, I've resorted to just not deleting accounts where this might happen, but leave the account inactive and unused.


Just do the obvious thing: stop posting there, don't view it anymore, and pin a post that you leave X (or any major SM) because they have become a greedy, amoral cesspool and links where they can find you now.


Thanks for the site - Whac-A-Mole it is, then

Fortunately their URLs aren't obfuscated, so it works with Redirector

https://addons.mozilla.org/en-US/firefox/addon/redirector/


Fortunately it is almost impossible to set up a new account. The sign-up process is totally broken, links in the docs are stale and everything looks vibe coded. And they want a phone number and possibly an ID.

Nitter is good software, I have no idea how Twitter users put up with this garbage fire.


How come twitterwebviewer.com is still up? What do they do differently? Or is it official?


It is also down now.



I get loads of value from it and when I'm away I do miss it, because I'm missing information I'd rather have.


They got DMCAed today, August 28th.


Why? X is one of the rare uncensored publishing / communication networks we have. Do you prefer living in a highly regulated, censored pre-gated world where information is hidden if somebody "feels offended" by it or state / ngo actors dont want something to go public?

The brainwashing against free, open, uncensored and community-corrected platforms is crazy.


If X is so open, why do I have to register an account to see practically anything?

Why did Elon ban PaulG and many for posting a link to Mastodon?

Why did so many get suspended for sharing the location of Elon's private jet?

Why did Elon ban a journalist after reporting a dossier on JD Vance? https://www.newsweek.com/jd-vance-dossier-leak-hack-iran-ken...

Why did Elon ban a journalist who interviewed the guy who hacked a conservative activist? https://arstechnica.com/tech-policy/2023/04/twitter-suspende...

Why did Elon ban a journalist for reporting on Tesla? https://www.vox.com/recode/2022/12/15/23512158/elon-musk-twi...


Censorship of things I don't like or don't care about doesn't count. /s



It is censored. They just don't tell you what they censor you for. You need to post, and then your account gets locked for bogus reason, and that's how you know what not no say. Like in Carlin's joke about words you are not supposed to say, NOBODY GIVES YOU A LIST!



Crazy thing to write on a post about X censoring mirrors.


Is it really free, open and uncensored if it suspends journalists for covering the ElonJet story, and artificially bumps Elon's own tweets?


Well looking at Elon and his nazi salute then, yeah its "uncensored". Its a clusterfuck of a platform.


Free and open until Elon Musk doesn't like what you wrote.


Forgive me for newb question, but why Hugging Face is a thing at all? Couldn't models be simply distributed via torrents? And the whole aggregator thing would come down to indexing magent links published by model providers?


Why is any file hosting service ever a thing at all, when literally any file can simply be distributed via torrents?


There's a herding effect with torrents where popular things are quick to get, unpopular things may be very difficult to get, because the majority of users delete files to save space.

I might host 3 or 4 models that I've downloaded recently, but I won't be hosting the 50 or so that I've tried in the last two years.


And who seeds it? If you're going to pay a host to seed it, they might as well just provide HTTP and let you add them as a web seed to your torrent, which we could be doing already.

But if you don't pay a host to seed it, either the host's business model won't play well with torrents, or there's no host and a torrent will rot.


(It was a retrospective question.)


Torrents are unreliable, also for an agent or script it's easier to just do wget model


Then someone would still create a website with an index of all the open models. Where people discuss & rank the models, show related models, ...

And now you've recreated most of HF


Why don't we use message boards instead of Google? Couldn't websites be distributed via direct DNS requests instead of Google serving links?


Very "why would anyone use Dropbox when I can setup a SFTP server" vibes.


Or even “why would I pay for a flight when I can simply walk across the country”

It’s all about the convenience, minimising the time and effort from “looks interesting” to “running the model”.

Nvidia don’t care if you do it on their cloud, someone else’s cloud, or on your own machine - they win either way, as it further propagates the technology on which they are building their future.


Torrents aren't that scary. If you have the patience for local AI you can figure out qBitTorrent in less than an hour.


Torrents are trivial. Each individual bit is trivial. But being able to click a button that says “run model” is even more trivial.


You are not the first or 100th person to come up with this idea. I don't really get it either but there must be a reason it hasn't really happened.


The important thing about HuggingFace isn't the safetensors files, it's the READMEs and the Google search placement. It's easy to reproduce their distribution with torrents, it's very hard to then establish yourself as the default option.


It would be far more efficient to decentralize the data. But HF provides convenience, they subsidize the cost. They gained millions of users, and many enterprises. They can now sell the popularity of their platform. Nobody can buy a p2p network of people.


> Forgive me for newb question, but why Hugging Face is a thing at all?

Because you can't host arbitrarily large files on github, it's basically become a defacto "publish your project here" thing.

For a CN domestic equivalent take a look at Modelscope.


Well, ask yourself: "Why am I on Hacker News?". You could just "as easy" use free / opensource alternatives like Lemmy, Mastodon, etc.


beating the dead horse after other dozen comments, but the same reason we use github / gitlab instead of using Savannah


hugging face is basically a real easy way to run llms. They also provide a bunch of libraries to do things like split compute across all your resources.


> I have to ask…why do people want a Turing complete language to configure stuff?

I don't understand this either. IMO, the current SOTA tool for configuration is CUE, because it is the only one that lets you write schemas for arbitrary refinements. I haven't used it myself, but my understanding is that everybody should be writing configurations in something like this instead of YAML, TOML, HCL, or a custom DSL with no tooling. And yes, definitely not in a Turing complete programing language.


Cue is amazing, I'm using it to configure my kubernetes homelab.

I CANNOT imagine what horrors it would be to do it all with helm or templating.


> the current SOTA tool for configuration is CUE

the current state of the art tool for configuration is CUE (https://cuelang.org/). FTFY. Gotta love these acronyms.


That is an awful take. Although Silicon Valley's tech bros are shameless in their own way, there's no justification for symmetrizing the two.


For all intents and purposes this is legal. As is distillation. No justification is needed.


No its pretty realistic. Nobody is losing their sleep when ultra-wealthy thief gets robbed for their stolen possessions or money made out of those, do they.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: