bitcoin & BGP

Joined May 2024
5 Photos and videos
Pinned Tweet
The bitcoin network needs a lot more nodes to be IPv4 reachable/listening, but many of the nodes are run in homes and there are legitimate security concerns with opening up an inbound port forward to a node sitting on a home network. One crude but easy way to increase listening nodes at home is to inject a second small home router to create a pseudo-DMZ, where the bitcoin node can live and accept connections, while still protecting the rest of the home network. Here's a terrible diagram depicting this.
1
6
56,355
bitprojects retweeted
Intellectual dishonesty is Shinobi’s bread and butter
4
11
130
2,490
bitprojects retweeted
If bitcoiners don't get their act together & don't fully support BIP-110/RDTS to wipe out Core & their Corecoin version of Bitcoin, Bitcoin WILL NOT survive in the long term, at least as a sovereign/decentralized/P2P money/network. Make no mistake. It's almost too late already.
CAPTURE An investigation across four articles into how informal power over Bitcoin Core was assembled, exercised, and defended. Article Three: The Merge citadel21.com/the-merge
4
26
77
2,653
bitprojects retweeted
Core v.30 = Negative Peer Pressure on Bitcoin Knots BIP-110 = Positive Peer Pressure on Bitcoin Hold yourself and your fellow Bitcoiners to high monetary standards. If you know, you Knots BIP-110 Filters up!
4
24
230
bitprojects retweeted
Article 2: The Lever citadel21.com/the-lever
1
8
74
2,196
It is highly possible and probable that failure of #bip110 (and continuation of allowing 100k op_return) will end #bitcoin as a truly decentralized store of value. Bitcoin would continue to run but with a tiny fraction of the current node counts, making it a pointless centralized blockchain like most of crypto. No other chain has anywhere near the decentralized and distributed node count as bitcoin, not even close. That is why this attack vector via storage of large contiguous extra data was created - to break down the decentralization of bitcoin.
Replying to @BitcoinBombadil
All bip110 nodes will turn off if bip-110 doesn't activate. Other suckers can be tricked into storing pornographic jpegs but not us. Bitcoin is dead if the miners tell us what changes we can and can't implement.
14
12
44
5,697
bitprojects retweeted
Article 1: The Network citadel21.com/the-network
1
8
78
2,527
bitprojects retweeted
CAPTURE An investigation across four articles into how informal power over Bitcoin Core was assembled, exercised, and defended. Article Three: The Merge citadel21.com/the-merge
44
196
469
62,013
bitprojects retweeted
As a #BIP110 supporter I have zero tolerance for changes in #Bitcoin that were (at all) discussed in back rooms, with underhanded deals. Zero tolerance. #Liars hide behind a veil of trickery. Don't be #duped. Run #Knots
2
23
135
5,911
bitprojects retweeted
Bitcoin Core is Malware.
Bitcoin Core is Malware.
8
49
633
retard
"Hey guys, I know how we'll defend Bitcoin! Us, the broke plebs with no serious capital whatsoever, will band together online and yell loudly at all the people with real money and capital to do what we want, just like political activists on the left! How can we lose?"
31
THE SOVEREIGN COMPUTE MANIFESTO By @HodlTarantula I did not come this far to rent permission from some weak ass corporate cloud priest in a glass tower. I did not crawl through oilfield dust, generator heat, broken regulators, dead ASICs, blown hoses, gas lines, mud, diesel smoke, wire burns, bad sleep, bad deals, and the endless bitch slap of entropy just to hand my digital life over to a cloud cartel that can shut me off with a policy update and a mouse click. Fuck that. I came here to build rails. Real rails. Sovereign rails. Steel in the dirt, Bitcoin in the veins, no permission needed digital territory for people who still remember what freedom smells like before the compliance department pissed all over it. That is Sovereign Hybrid Compute. Sovereignhybridcompute.com @SHCompute SHC is not another cute little hosting company. It is not some fake revolutionary SaaS toy dressed up in black and orange branding while quietly suckling from AWS like a newborn cuck calf. It is not cloud cartel theater. It is not reseller cosplay. It is not digital landlord bullshit with a privacy sticker slapped on the hood. Sovereign Hybrid Compute is compute in the form of a sword. A fuckin sword. Not a leash. Not a cage. Not a velvet-lined prison with a monthly invoice. A sword. A weapon for builders. A shield for sovereign individuals. A workshop for men who still know how to create without asking some platform overlord if their thoughts are allowed to exist. Bitcoin gave us money without masters. But most people stopped there. They got their hardware wallet, memorized their seed phrase, screamed “not your keys, not your coins,” then turned around and hosted their business, their data, their apps, their files, their servers, their AI tools, their websites, and half their digital soul on infrastructure owned by the same surveillance soaked assholes they claim to be escaping. That is not sovereignty. That is self custody with a cloud collar. That is freedom wearing a shock chain. That is a man locking his gold in a vault, then giving his house keys, diary, business plans, and rifle safe to a smiling corporate whore with terms of service. No. Sovereignty does not end at the wallet. It begins there. A sovereign individual needs sovereign money. Sovereign energy. Sovereign communication. Sovereign compute. Sovereign storage. Sovereign network access. Sovereign digital shelter. Because in the world that is coming, compute is not optional. Compute is speech. Compute is business. Compute is memory. Compute is AI. Compute is markets. Compute is coordination. Compute is war. Compute is the nervous system of civilization. And the weak, obedient little herd is sleepwalking into a future where every thought, file, prompt, server, wallet, app, website, and transaction lives inside someone else’s permission stack. A compliance stack. A surveillance stack. A cloud plantation with clean fonts, soft colors, and a knife behind its back. They call it convenience. I call it digital serfdom with better marketing. The cloud cartel does not want sovereign individuals. It wants managed livestock. It wants profiles. It wants KYC. It wants metadata. It wants control. It wants every builder plugged into a system where one payment processor, one vendor, one regulator, one policy goblin, one risk committee, one frightened middle-manager asshole can press a button and turn your entire operation into a smoking crater. That is not infrastructure. That is a hostage situation with an API. I reject it. I reject the idea that a man has to identify himself, beg permission, lick corporate boots, and pray to the gods of account approval just to host code, run a server, protect his traffic, deploy tools, store files, or build a business.
27
23
144
15,126
bitprojects retweeted
Our statement on the UK government’s demand that all content on all devices sold or used in the country be scanned, on the presumption of nudity, using a dystopian combination of age verification and content scanning. This proposal will not safeguard children. It endangers us all. signal.org/blog/pdfs/2026-06…

745
8,570
41,385
2,751,187
bitprojects retweeted
Javier Milei: “I thought being on the left was a mental problem. The empirical evidence is so overwhelming that it never worked anywhere, and they refused to accept it.” “But what I discovered is that being on the left is a disease of the soul. The left is built on envy, hatred, resentment, and unequal treatment under the law. They are very violent, and since they have no way or arguments to answer, they go for physical violence.”
501
12,227
48,330
768,309
bitprojects retweeted
Replying to @Leishman
You mean Knots. Core is dead.
5
33
294
4,250
bitprojects retweeted
22 Oct 2025
Arbitrary content on blockchains makes them far more risky, legally and morally, to operate, than with blockchains confined to financial transactions. Running a node where one cannot selectively delete unacceptable content without wider functional disruption is also far riskier than running data services where one can selectively delete unacceptable content without causing wider functional disruption. There are a wide variety of moral and legal categories of arbitrary content, and many of them are radically different from each other. CSAM/CP, other kinds of obscenity, copyrighted material, censored political content, trade secrets, classified material, and many other such categories are treated in extremely different ways from each other by morality and by law. What's more, each of the 100s of jurisdictions over which a blockchain runs has its own wide variations. Some legal prohibitions, such as those against CSAM/CP, have extremely high popularity and involve highly motivated enforcement. Government response to one kind of content is an extremely poor predictor of its response to another kind of content. The response of one government to a kind of content is often a poor predictor of a response to another government to the same content. Nodes on blockchains that, through means such as escalating fee schedules, byte limits, format enforcement, etc., discourage arbitrary content, are far less risky to run than nodes on blockchains that encourage arbitrary content.
106
270
1,270
92,704
bitprojects retweeted
BIP-110: Reddit mods hate it. This should be enough to extinguish any remaining opposition.
If Reddit moderators hate it, you know you’re doing it right.
9
35
223
4,217
bitprojects retweeted
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too. Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition. The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it. Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web. Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems: support.google.com/recaptcha… Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web. Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more. Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive. Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out. Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it. It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source. Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them. Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security. reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that. This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere. Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.

167
2,349
9,149
367,944
bitprojects retweeted
Whats happening in #bitcoin right now has all the tell tale signs of "the powers that be" not listening to the user/fanbase of the protocol. This rarely if ever ends well. Something needs to change.
3
5
21
366
bitprojects retweeted
Hugely disappointed by virtually all the bitcoin influencers not supporting BIP-110 vociferously.
3
6
35
471
this is really fucking important. if contiguous CSAM data makes it into a block, bitcoin is over.
No, it only takes one malicious miner (ie, running Core 30 ) to force Bitcoin nodes of ANY type from now until the end of time, to actively participate in CSAM distribution.
3
3
30
102,929