There is this one quote about betrayal thatâs been stuck at the back of my mind for a while now: âthatâs the thing about betrayal. It never comes from the enemy.â
Thatâs why it hurts so much. If you donât trust someone, if he (or she) is your enemy, betrayal doesnât happen. Trust has to come first, and after that betrayal can happen.
The world runs on trust, and to a large degree it has to. You have to trust the people you interact with, you have to trust that the water is drinkable, that the food you eat isnât poisoned, that the chair youâre going to sit down in is not made of paper, and so on. Going through the world relies on a million different trust assumptions, whether youâre conscious of them or not.
Magicians use these trust assumptions to fool you. When you see someone who is wearing glasses, for example, you trust that there are actual glasses in the frame. Itâs a fine assumption to make. A magician will use this assumption to play a trick on you, and suddenly you realize that your assumption was wrong all along. Youâve been fooled. You feel surprised, and if itâs innocent enough, delighted. But you might feel stupid too, and if the magician is not a magician but a scammer, you feel stupid and angry.
Anger. Thatâs probably the main emotion that a lot of bitcoiners have felt in the last two weeks. Confusion and anger. And disbelief.
âDonât trust, verify.â Thatâs how the slogan goes. And thatâs part of the issue: it became a slogan, not a practice. (Oh my god, Iâm sounding like ChatGPT now, fuck me. Maybe hodlbod was right after all.)
But hereâs the issue: itâs an impossible problem. How paranoid should you be? What should you trust, and what might be compromised? The reality is that everything and everyone might be compromised. Your spouse might be an agent, your compiler might have an undetectable backdoor, someone might listen to your every conversation by measuring the vibrations of your window with a laser. There is no end to it. Your skepticism has to bottom out somewhere. If it doesnât, your life will be indistinguishable from the life of the psychotic.
How paranoid should you be? If you get rekt, you havenât been paranoid enough. But still, if youâve been fine until now, itâs no guarantee that youâve been paranoid enough, since you might get rekt at any moment.
On the other side: how trusting should you be? If you are generally trusting, you will get hurt. Betrayal, exploitation, and other ills along these lines will befall you. However, if weâre not trusting anyone or anything at all ever, weâre back at paranoid schizophrenia, which isnât a good way to live life either.
People often ask me what wallet they should use, or similar questions of that sort. I never give a direct answer, because it always depends. What is your situation? What are you worried about? How much do you know about the thing youâre getting yourself into? Are we talking chump change, or generational wealth? Where do you live? Are you a person of interest? Are you worried about kidnapping, extortion, theft? How often do you need to access it? Are you in my position, where you need to part with your sats to eat food? Or are you just dabbling and looking for exposure?
There is no blanket answer, just like there isnât a blanket answer for what car to get, or what house to live in, or what country to move to, or what kitchen knife to get (or what kind of gun, for that matter). It all depends.
That said, if you finally make a choice and get the thing, there are certain trust assumptions that the thing will work as advertised. You trust the manufacturer to do their job. To run certain tests, have a certain level of quality assurance, and so on.
I think thatâs what a large (small?) part of the Bitcoin community is wrestling with right now. Certain trust assumptions turned out to be wrong, on multiple levels. There is a feeling of betrayal. And it hurts so much because betrayal never comes from the outside, never from the enemy. Always from within. Always from people you thought could be trusted.
It might have been a stupid mistake, but itâs a mistake that shouldâve been caught, that shouldâve been fixed, that shouldâve never ended up in production.
It shouldâve never ended up in production because entropy generation is the most critical part of any hardware wallet. Users trust that this part works, no matter how often you encourage them to roll the dice. Low entropy should be treated as a catastrophic failure mode because it is impossible to patch after the fact.
Impossible. Thatâs the right word to use. People were put into impossible situations because of that failure. People thought that they could sleep soundly, having all their funds in airgapped cold storage. You did everything right, so waking up one day to see that your wallet is suddenly empty is literally something that should be impossible. And yet it happened. The impossible happened.
âDonât trust, verify.â Someone shouldâve verified that the hardware RNG is used. Yes, hindsight is 20/20, but for such a critical piece of equipment⌠Iâm flabbergasted that it wasnât tested properly.
Where do we go from here?
I canât help but think about the gun community, and all the lessons that had to be learned along the way. âHandle every gun as if it were loaded.â (Even though you know that it isnât, even if you just unloaded it yourself.) âTreat every RNG as if it were compromised.â Maybe thatâs the lesson. (But then, why build and use RNGs in the first place?)
And I canât help but notice that following age-old wisdom wouldâve helped to avoid catastrophic loss too: âNever put all your eggs in one basket,â and so on. âMeasure twice, cut once.â
Itâs been two weeks now. The adrenaline is slowly but surely leaving my body. The damage is done. (Psychological damage; I am aware that the financial damage is ongoing.)
I keep wondering what weâll learn from this. I donât think that the lesson should be âdonât trust anyone or anything ever again,â although I think it will be something close to that.
Thereâs a rule in the backup world thatâs called â3-2-1.â It means that you keep three copies of your data on two different types of storage, with one copy stored off-site. There is a lot of experience (a lot of wisdom) embedded in this rule. Lots of lessons learned the hard way. Itâs a good rule, because it is not overly paranoid. It is paranoid enough. Itâs â3-2-1â not â7-6-5-4-3-2-1â.
I guess weâll land on something similar. Secure enough. Paranoid enough. Trusting some things, like our own two eyes, looking at the dice we rolled or the coins we flipped. The paper we just wrote on, or the steel we just stamped. What can fail us, and what shouldnât? What is trustworthy? Who or what can betray us?
Thatâs the question, isnât it. Who can betray us. Who or what can rug-pull us? Itâs everyone and everything, including ourselves.
Trade-offs. All the way down.
đ§Ą
Found this valuable? Don't have sats to spare? Consider sharing it, translating it, or remixing it.Confused? Learn more about the V4V concept.
