I’ve read so many news stories of people gone missing who had been know to have sole access to bitcoin wallets with large amount of bitcoins in them.
I wonder how people at large crypto exchanges handle that. Perhaps shamir share the access to the pkey password and store parts at secure places like a bank? And make official access protocol akin to dnssec, but simplified?
I worked at a crypto exchange, yes we used shamir shares. But probably not as sophisticated as you're thinking, there was basically one big "break glass" text document with all the keys. And then a hand-rolled software on each person's laptop to distribute the plain text and run / practice the 3/5 recovery ceremony. So anyone losing their device would be equivalent to someone quitting and require its own ceremony to reissue a key, but I don't think that ever actually happened.
We explored using smart contracts to have logic perform the 3/5 consensus rather than a cryptosystem, but that was never rolled out while I was there. Social recovery wallets in general did not take off, which was a big learning moment for me that very few people actually cared about the technology and what they really wanted was an app with as many gambling features as possible that uploaded their keys to google drive.
> Social recovery wallets in general did not take off, which was a big learning moment for me that very few people actually cared about the technology and what they really wanted was an app with as many gambling features as possible that uploaded their keys to google drive.
People who are not HN-profile never care about the technology, and always care about usable, convenient features. The shocker is: most HN-profile people feel the same way.
Yes, I do agree with this. What rubbed me the wrong way was all the cynical people who would talk endlessly about how revolutionary the tech was and all the possibilities it opened to get others invested, but ran companies that were just casinos and actually could have simpler operations without the crypto parts! Most people in pre-NFT crypto has someone in their network who worked on an outright Ponzi scheme.
> but ran companies that were just casinos and actually could have simpler operations without the crypto parts
Creating a product for the sake of using a technology is a flawed order of operations. However, the glitz and glamour of a new money for a new internet is enticing with a lot of promise. I'm a crypto bro, but my crypto confidence has waned recently. My confidence in the USD has also waned.
Improving or standardizing the approach is all well and good, but if it's not natively integrated into MEW / MM / Coinbase Wallet / Phantom it's sort of irrelevant. Argent was the best attempt but they failed so bad commercially that they pivoted to a google drive recovery mechanism and changed their name.
The other day a neighbor asked me about AI. I said I wasn’t really up to date with things anymore. They asked: like what things? And then I said: like the Astra model that OpenAI released yesterday, I know nothing about it. And they were like: “bro, yesterday?! And you feel you’re not up to date?! Pfff”
A better solution (than Shamir secret sharing) are threshold signatures.
The difference is that with Shamir you have to reconstruct the private key in one place before you can sign. With threshold signatures multiple servers can collaboratively sign without ever reconstructing the private key in a single place.
For chains like Solana, Aptos, SUI that use ed25519 (schnorr signature), there's a pretty clean solution called FROST.
For Bitcoin and Ethereum/EVMs that use ECDSA it's a bit trickier but there's been a lot of research recently, so there are solutions.
Large exchanges handle this very simply: If they have the keys, it goes to the inheritor(s) once they get a court order. If they do not, it goes nowhere
There are plenty of legends of old wallets "waking up" due to the person getting out of prison, as it seems the only plausible way someone can sit on 30 BTC for 10-15 years, through all the news and price movements, without touching it once. One would only expect to hear about the successful seizures law enforcement makes.
Pretty much everyone. There's a reason people lost money with ftx, Mt gox and other scams.
Managing your private keys is cumbersome, error prone, requires some computer literacy, the list goes on.
Tbh I have been kind of impressed by how fast L2 businesses brought back centralisation in every possible way. I guess it's more efficient for them.
In the same way, the internet was supposed to be decentralised, everyone being in charge of their own servers. But in practice nobody has the time to set up their own MX servers.
Did they just announce the ultimate solution to image authenticity online?
Instead of proving some image on some platform is not AI or severely edited, we can simply prove it was original by verifying unforgeable signature made by a camera / microphone baked into each image produced by it.
And of course in future it could be done for video and audio! This would be absolutely HUGE!
> that image shared online is original and unedited?
The image data the sensor physically receives passes through a ton of processing steps before the image lands in your phone. If there is some watermarking/signature doing on, on the image, it'd be that the device at that moment capture that data, not that it's not AI, or not edited, or "truthful" or whatever. That's still an unsolved problem to figure out.
Ex-x account holder here. Even if the world is going to fall and details about this even will be accessible exclusively behind X login wall, I am not setting up the account there again, NO WAY.
I wholeheartedly recommend you do the same - remove your account and forget about it. Almost certainly you won't miss it, as I didn't miss it. And there is a big chance you will get a big sight of relief, as I did.
But when I was doing it, I got a big warning that anyone could come up and register that handle for themselves. So I instead ended up just deleting every post, my personal details, and left the account alone (not using it anymore).
I know they do this intentionally (it's bad intentions all over the place on social networks nowadays, except HN, of course).
I'm terrified of somebody else just creating the account with the same handle I used to have, and impersonate me across old friends and contacts.
That doesn't work. Many people following me on Twitter only know me from Twitter and I don't have other means to reach out. Some others I'm not even interested in talking to them (not friends, just ex co-workers, ex gf, etc).
Pin a post that you leave X (or any major SM): say its your last post because they have become a greedy, amoral cesspool and add links where they can find you instead.
> I wholeheartedly recommend you do the same - remove your account and forget about it.
I'm not sure this is a great idea, if you have a somewhat unique username or you use that same username elsewhere.
Multiple times, me and others have changed usernames on some platform, and either immediately when you rename, or few seconds afterwards, some squatter will grab your old username, and most platforms don't care about helping you recover anything, so suddenly you've opened up phishing/spam venues associated with your old username.
Personally I'm not sure what the solution is to this, I've resorted to just not deleting accounts where this might happen, but leave the account inactive and unused.
Just do the obvious thing: stop posting there, don't view it anymore, and pin a post that you leave X (or any major SM) because they have become a greedy, amoral cesspool and links where they can find you now.
Fortunately it is almost impossible to set up a new account. The sign-up process is totally broken, links in the docs are stale and everything looks vibe coded. And they want a phone number and possibly an ID.
Nitter is good software, I have no idea how Twitter users put up with this garbage fire.
Why? X is one of the rare uncensored publishing / communication networks we have. Do you prefer living in a highly regulated, censored pre-gated world where information is hidden if somebody "feels offended" by it or state / ngo actors dont want something to go public?
The brainwashing against free, open, uncensored and community-corrected platforms is crazy.
It is censored. They just don't tell you what they censor you for. You need to post, and then your account gets locked for bogus reason, and that's how you know what not no say. Like in Carlin's joke about words you are not supposed to say, NOBODY GIVES YOU A LIST!
Forgive me for newb question, but why Hugging Face is a thing at all? Couldn't models be simply distributed via torrents? And the whole aggregator thing would come down to indexing magent links published by model providers?
There's a herding effect with torrents where popular things are quick to get, unpopular things may be very difficult to get, because the majority of users delete files to save space.
I might host 3 or 4 models that I've downloaded recently, but I won't be hosting the 50 or so that I've tried in the last two years.
And who seeds it? If you're going to pay a host to seed it, they might as well just provide HTTP and let you add them as a web seed to your torrent, which we could be doing already.
But if you don't pay a host to seed it, either the host's business model won't play well with torrents, or there's no host and a torrent will rot.
Or even “why would I pay for a flight when I can simply walk across the country”
It’s all about the convenience, minimising the time and effort from “looks interesting” to “running the model”.
Nvidia don’t care if you do it on their cloud, someone else’s cloud, or on your own machine - they win either way, as it further propagates the technology on which they are building their future.
The important thing about HuggingFace isn't the safetensors files, it's the READMEs and the Google search placement. It's easy to reproduce their distribution with torrents, it's very hard to then establish yourself as the default option.
It would be far more efficient to decentralize the data. But HF provides convenience, they subsidize the cost. They gained millions of users, and many enterprises. They can now sell the popularity of their platform. Nobody can buy a p2p network of people.
hugging face is basically a real easy way to run llms. They also provide a bunch of libraries to do things like split compute across all your resources.
> I have to ask…why do people want a Turing complete language to configure stuff?
I don't understand this either. IMO, the current SOTA tool for configuration is CUE, because it is the only one that lets you write schemas for arbitrary refinements. I haven't used it myself, but my understanding is that everybody should be writing configurations in something like this instead of YAML, TOML, HCL, or a custom DSL with no tooling. And yes, definitely not in a Turing complete programing language.
No its pretty realistic. Nobody is losing their sleep when ultra-wealthy thief gets robbed for their stolen possessions or money made out of those, do they.
I wonder how people at large crypto exchanges handle that. Perhaps shamir share the access to the pkey password and store parts at secure places like a bank? And make official access protocol akin to dnssec, but simplified?