pull down to refresh

There’s a cultural reason in the loud opposition to experimentation.
It’s actually just loud opposition, not strong opposition! Most bitcoiners don’t oppose experiments. But many builders confuse the loud voices for strong voices, and just give up.
Personally as people might’ve noticed, I don’t really mind opposition, and I’m happy to charge away anyways, but that’s not always the case for all builders. I think many of them were turned off because of the culture, even if that’s somewhat irrational, but thankfully I think the culture is starting to change in the last year.
Experimentation is important, because through experimentation you discover new successful usecases (and many failed usecases!), and each new successful usecase brings about a wave of adoption.
I've been in Germany for 10 days visiting clients in 5 different regions of the country. What makes me stunned is that the vast majority of the people keeps ignoring the econ desaster of this country. My thesis: they will be the last to wake up to the debasement of their currency and the last to adopt btc. Sad to see (at least for me as a german that still has (orange pilled) family there). Have a nice week-end guys and girls!
Ecash mints are useful for their privacy properties and the fact that they don't require a consensus change. They will still need to use geographical arbitrage or network privacy techniques such as tor to remain operational in the face of state sponsored attacks. This is still an easier path than achieving consensus on a soft fork. My ecash bullishness remains unperturbed.
One of the frustrating aspects of discussing these options is the constant attempts to play different solutions off of each other. We don't need to focus on a single solution. We can try all solutions at once. Please stop implying that all scaling solutions are rival. They are nonrival.
They're popular amongst targeted (state-level?) attack campaigns that have an amount of known victims in the tens or low hundreds. They're pretty advanced, but there isn't much of a benefit to a bootkit beyond absolute persistence compared to a zero-click remote 0day. Malicious UEFI firmware that infects the OS on reboots have been observed in the wild before, and the NSA also had firmware attacks for weaponizing hard drives during the Snowden era too.
CosmicStrand, MoonBounce, MosaicRegressor, BlackLotus come to mind as best examples to demonstrate.
Both of them are undetectable by the operating system since what is executed runs with the highest privilege. Windows Defender can do nothing against unknown malware and Linux is Linux. Forensic analysis of the device can reveal the attacks although this is not an automated process and you'd need experience in DFIR to analyse a device to see if you was infected by this.
Bootkit firmware have to drop malware within the installed OS for command and control and to monitor their victim's activities. Forensic analysis of the disk for potential IoCs, network traffic analysis to find connections to a potential C2 server and memory dumping (for fileless malware) are some ways to find out. You'd also need reverse engineering experience to confirm suspicious activity. This is also why when people talk about "hardware backdoors" in a security researcher they get laughed at. They are only useful by being unknown and to a limited group of people.
Windows tried to add boot security (called System Guard) to prevent firmware based attacks on a line of PCs called "Secured-core" but they are a questionable half solution that avoids the real solution. Dmytro Oleksiuk (cr4sh) is a very good researcher who develops a lot of PoC UEFI bootkits and he has some good material about the subject matter.
Desktop boot security is fucked. "Secure boot" is nothing like the Verified Boot used in Android, iOS, GrapheneOS, ChromeOS and ARM Macs. Desktop OSes need to move towards being adminless and make features like sandboxing for apps mandatory. Android works really well with verified boot because most of the OS is an immutable, adminless workspace that separates all of what the user does in it's own place. The desktop OSes also trust the hardware connected to it and their drivers too much.
How often are you commenting Matt? If not very often, how do expect SN to look the way you want it?