Hacker News new | ask | show | jobs
by majormajor 2 hours ago
I guess even when code is public nobody really reads the history very thoroughly. You'd think someone would've made stink about a company willing to show the world how they were fiddling with low-level random generation stuff with commits like `x` and `runs` in the early life of the project, without much discussion of the safety of the crypto code. We hear "don't roll your own crypto!" a lot... but in a world where there are any number of products on the market, with any number of visibility to various people, open source doesn't make all bugs shallow because there aren't anywhere near enough helpful eyeballs for most project. But probably gave some people false sense of confidence.
1 comments

A few people did call out Coinkite for poor engineering at the time but it was either not seen or dismissed as hating in the context of the Coldcard/Passport fight.