-
m-relay
<ofrnxmr:monero.social> Being unrealistic, is carrying on like nothing happened
-
nioc
just imagining how things would go with a idea that was put forward as a solution
-
m-relay
<ofrnxmr:monero.social> I want to lose 3000 xmr and not have to explain anything
-
m-relay
<ofrnxmr:monero.social> Just be handed another 3000
-
nioc
as you have said most of what was in the wallet shouldn't have been there
-
m-relay
<ofrnxmr:monero.social> Or, to explain that my security was bottom tier and still be the front runner
-
m-relay
<ofrnxmr:monero.social> nioc, yep.. and because of were useless, it will accumulate again
-
m-relay
<ofrnxmr:monero.social> Right now, we _should_ have a jet fund.
-
m-relay
<ofrnxmr:monero.social> 240xmr leftover = same amount as overages wallet that should have been in plowsof posession
-
m-relay
<ofrnxmr:monero.social> 2000 xmr = funds being used to pay devs from generalfund right now, but should have been jetfunded
-
m-relay
<ofrnxmr:monero.social> All we did, was lose 3000 xmr and give the jet fund to luigi and bf
-
m-relay
<ofrnxmr:monero.social> Now we have a "protected" and "non protected" group, and 0 authority over how to use thr jet fund
-
nioc
you are of the opinion that luigi doesn't care about what happened which is based on ......
-
m-relay
<ofrnxmr:monero.social> We also went 60 days literally making excuses to devs about where their money was
-
m-relay
<ofrnxmr:monero.social> > <nioc> you are of the opinion that luigi doesn't care about what happened which is based on ......
-
m-relay
<ofrnxmr:monero.social> The fact hes gone til after thanksgivinf
-
m-relay
<ofrnxmr:monero.social> And the funds finak soend was a few days before disclosuren
-
m-relay
<ofrnxmr:monero.social> The active _hackers_ on the payroll werent told anything
-
nioc
!tip ofrn 1 real keyboard
-
m-relay
<ofrnxmr:monero.social> If we wanted to track the funds or find the hole, youd think youd use the devs who want to track the funds and find the hole
-
m-relay
<ofrnxmr:monero.social> Thats what you call having 0 faith in them
-
m-relay
<ofrnxmr:monero.social> You called fluffy? And bf? But not plowsof, kaya, jeffro, berman, koe?
-
m-relay
<ofrnxmr:monero.social> Thats not reality. thats a damn circus
-
m-relay
<ofrnxmr:monero.social> If im holding money for the smaetest hackers i know, im not calling bf and fluffy for backup when i get robbed
-
m-relay
<ofrnxmr:monero.social> Im calling the dangerous men and women who own the stolen funds
-
m-relay
<ofrnxmr:monero.social> Someone wants to rob _us_??
-
m-relay
<ofrnxmr:monero.social> They want to attack the beehive??
-
m-relay
<ofrnxmr:monero.social> Oh. The security guard didnt wake the bees.
-
m-relay
<ofrnxmr:monero.social> I'd take it personally if someone targeted _me_ to get one over on with the monero project.
-
m-relay
<ofrnxmr:monero.social> imagine your the hacker
-
m-relay
<ofrnxmr:monero.social> wouldnt you think these monero geniuses were hot on your trail from 5 seconds after you got out?
-
m-relay
<ofrnxmr:monero.social> Nope. They were able to taje their sweet ass time and do whatever they wanted with the money for 60 damn days
-
selsta
the wallet itself gets only opened once every 4 months or so
-
selsta
once he saw the funds are gone 30 days had already passed, the funds were long gone
-
m-relay
<123bob123:matrix.org> could of had SIEM solution setup
-
plowsof
midipoet: context for my should/shouldn't be comment - the award for the most unclear "No" goes to
libera.monerologs.net/monero-community/20231120#c305322
-
m-relay
<123bob123:matrix.org> ```
-
m-relay
<123bob123:matrix.org> 14:16
-
m-relay
<123bob123:matrix.org> midipoet
-
m-relay
<123bob123:matrix.org> Unfortunately, i don't think it should not be luigi
-
m-relay
<123bob123:matrix.org> 14:16
-
m-relay
<123bob123:matrix.org> midipoet
-
m-relay
<123bob123:matrix.org> *should be
-
m-relay
<123bob123:matrix.org> ```
-
m-relay
<123bob123:matrix.org> ```
-
m-relay
<123bob123:matrix.org> 14:16 midipoet: Unfortunately, i don't think it should not be luigi
-
m-relay
<123bob123:matrix.org> 14:16 midipoet: *should be
-
m-relay
<123bob123:matrix.org> ```
-
m-relay
<rucknium:monero.social> Anyone have a public statement by luigi saying he is willing to be CCS escrow agent again?
-
dukenukem
luigi1111: ^
-
luigi1111
No we don't.
-
m-relay
<rbrunner7:monero.social> So we've got that settled ...
-
plowsof
xD
-
m-relay
<rucknium:monero.social> Is luigi an option or not? A plain reading is that he is not available. So the "vote" should be closed.
-
msvb-lab
I think some of us assumed that he had offered to continue his escrow work as before, and maybe our assumption was wrong.
-
msvb-lab
A really good alternative in case luigi1111 declines, is midipoet's multiple members idea.
-
msvb-lab
I'm against this very mildly for only one reason, that it is more complex than a single person approach.
-
msvb-lab
But if it seems that three or more members in good standing could easily be convinced to do the work, it might be our best option. What do you think rucknium?
-
msvb-lab
And rbrunner7, would either of you want to be in the multimember escrow group?
-
m-relay
<rucknium:monero.social> Is the idea to have a single multisig wallet or having multiple single-signer wallets held by multiple people, taking turns for which proposals they escrow? I doubt Monero's current multisig has enough confidence to do CCS multisig now.
-
msvb-lab
rucknium: midipoet's idea does not require multisig. Rather, a one time pad style iteration among a group of escrow providers with a level of randomness.
-
luigi1111
I'm not strictly against it. I just am not sure
-
msvb-lab
Okay luigi1111, just know that you have some very grateful fans in the audience.
-
msvb-lab
I think we should continue plowsof's weeklong survey 'Luigi yes or no' and then deliver the results to luigi1111 can decide if he wants the role.
-
msvb-lab
Would that be okay with you luigi1111?
-
msvb-lab
Even if the community votes no, it's up to luigi1111 to decide if he's the new escrow boss. That's a privilege he (and core colleagues) have.
-
plowsof
I plan to ping all contributors that have been through the CCS system to vote if they wish to
-
m-relay
<rucknium:monero.social> Anyone have a link to midipoet's idea?
-
m-relay
-
plowsof
Does this link in the meeting notes take you there (my phone doesnt want to cooperate)
libera.monerologs.net/monero-community/20231124 RTFMeering issue!
-
plowsof
Meeting*
-
plowsof
Rucknium i just rtfmeering notes and the link was wrong , here
libera.monerologs.net/monero-community/20231124#c306628
-
m-relay
<rucknium:monero.social> I don't know if the idea reduces the total attack surface. Maybe it does. (But IMHO we should not refer to it as one time pad style iteration since that's just confusing.)
-
m-relay
<rucknium:monero.social> I may ask the MAGIC Monero Fund committee if they would be willing to fund a bounty to improve multisig. Probably there would be no takers for the bounty, but we could get lucky.
-
msvb-lab
Sorry rucknium, that's mixing concepts and I'll avoid the term again.
-
m-relay
<rucknium:monero.social> Thanks :)
-
msvb-lab
I think midipoet has stated several times their idea, so it's a stable one not under development.
-
msvb-lab
If we ask him (because we consider it an important option) then he would probably be convinced to create a document like a whitepaper or RFC.
-
msvb-lab
BIP.
-
m-relay
<rbrunner7:monero.social> Well, the good thing for me with multisig would be that I would not carry responsibility *alone* and would *never* have power to spend alone, hence much lower chance to get into the crosshairs of somebody. That's not given with some one time pad scheme where at random times I would have power alone.
-
m-relay
<rbrunner7:monero.social> Because, as I speculate personally, may that was indeed the case with Luigi: That somebody, or some gang, made them their target and just dug long enough until they got the jackpot. I really would not want that for me ...
-
m-relay
<rbrunner7:monero.social> As for trust in multisig, being un-proofed and "experimental" and all: For me a question of the lesser evil. Single persons with full power over single wallets are an almost guaranteed week point, whereas the weak points with Monero multisig seem to be more on the theoretical side.
-
m-relay
<rbrunner7:monero.social> IMHO, of course.
-
m-relay
<rbrunner7:monero.social> But yeah, of course it would be somehow unsatisfying having to resort to that.
-
m-relay
<rbrunner7:monero.social> And, hardly anybody more aware about that, lol, Monero multisig is damned complicated as-is.
-
m-relay
<rbrunner7:monero.social> Which is itself again a possible source of weak points. I am just a bit uneasy already e.g. with 3/4. If more than 1 person loses their keys, gone are the funds.
-
m-relay
<rbrunner7:monero.social> Can't we just set up a clever Ethereum smart contract and let people donate ETH? (ducks and covers)
-
m-relay
<rbrunner7:monero.social> > if they would be willing to fund a bounty to improve multisig
-
m-relay
<spaceguide:matrix.org> and make a well planned rugpull , normal in the eth world
-
m-relay
<rbrunner7:monero.social> I see it as a grave chicken-and-egg problem: I stopped to work on the MMS because almost nobody used the poor thing ...
-
m-relay
<rbrunner7:monero.social> With a lot of people using multisig motivation would have been there ...
-
m-relay
<rucknium:monero.social> Is money a good motivator?
-
m-relay
<spaceguide:matrix.org> imo, multisig is still meh
-
m-relay
<rucknium:monero.social> We need better theoretical basis for the multisig implementation. We need better MMS, but also the theoretical work.
-
m-relay
<rbrunner7:monero.social> I would say it depends. For me personally, not so much, I have a full dayjob that already pays reasonably ..
-
m-relay
<rbrunner7:monero.social> For me, the MRL meeting about multisig made clear how hard it would be to get full, 100% trustworthy multisig just on the side of math and crypto. It's almost too easy to despair.
-
m-relay
<spaceguide:matrix.org> do we 100 percent sure know what / how exactly this happened, and are there ways, to clean up, secure against what happened ?
-
m-relay
<rbrunner7:monero.social> As far as I learned so far, no, it's not yet known what happened, and IMHO that's a point against Luigi doing duty again until it's known. Not a statemeent about them, but a statement about the unknowns in the situation.
-
m-relay
<rbrunner7:monero.social> I would give the theory "Luigi just took it" a quite low probability.
-
m-relay
<rbrunner7:monero.social> But there are many things that could have happened that would not have been possible if more than 1 person was needed to spend, if you ask me.
-
m-relay
<spaceguide:matrix.org> is this wallet moved from one person, to another person, then the leak could have been happened, on another place too
-
m-relay
<spaceguide:matrix.org> it does not make sense, going put from 'luigi just took it'
-
m-relay
<rbrunner7:monero.social> "going put"?
-
m-relay
<spaceguide:matrix.org> 'stating' would be better
-
m-relay
<spaceguide:matrix.org> working on different platforms, seems there are some pool problems
-
m-relay
<rbrunner7:monero.social> I just brainstormed that the Monero project could sponsor the Python3 port of PyBitmessage, which is maybe half completed, make it happen *somehow*. As a messaging app PyBitmessage has some, let's say, retro charm, but for shuttling around Monero multisig related data packets it does the job. If only it could leave out-of-life Python2 behind already ...
-
m-relay
<rucknium:monero.social> rbrunner7: Will PyBitmessage or something with similar features be necessary for Seraphis multisig? Wondering about obsolescence when/if Seraphis arrives on mainnet.
-
m-relay
<rbrunner7:monero.social> I think the problem is smaller in Seraphis, because after wallets are established much less data must be sent around after transacting. But of course it still would be comfortable to be able to pass partially signed transactions to the next signer with some simple command, and also safer.
-
m-relay
<4rkal:monero.social> How can I get the average transaction fee?
-
m-relay
<4rkal:monero.social> Via api or something
-
m-relay
<rucknium:monero.social> 4rkal: The empirical average tx fee or the fee that you should be using in your txs?
-
m-relay
<4rkal:monero.social> Both would be optimal
-
m-relay
<rucknium:monero.social> An RPC call to `monerod` gets you the fee you should use for your txs if you are building a custom wallet implementation:
getmonero.org/resources/developer-g…es/daemon-rpc.html#get_fee_estimate
-
m-relay
<rucknium:monero.social> A chart for the daily mean tx fee in USD is
bitinfocharts.com/comparison/monero-transactionfees.html
-
m-relay
<rucknium:monero.social> The median is much lower. The mean is pulled up by a few txs that use a high nonstandard fee.
-
m-relay
<4rkal:monero.social> Cool thanks alot
-
m-relay
-
m-relay
<snjay:mozilla.org> Does anybody here have a link /room-name for policy working group?
-
m-relay
<snjay:mozilla.org> I remember joining it long time ago but must have removed myself from the group.
-
m-relay
<snjay:mozilla.org> I remember joining it long time ago but must have removed myself from the group.
-
m-relay
<ofrnxmr:monero.social> Monero Policy
-
m-relay
<snjay:mozilla.org> Thanks.
-
m-relay
<ajs_:matrix.org> MoneroKon 2024 Call for Presentations now open
apply.monerokon.org
-
m-relay
<ajs_:matrix.org> please share with people you think would be interested in doing a talk or workshop at monerokon
-
m-relay
<123bob123:matrix.org> Hows the progress on multi sig development ?
-
m-relay
<rbrunner7:monero.social> Nonexistent? :) No, maybe tobtoht may tell us what they are up to, and how far along they are.
-
m-relay
<123bob123:matrix.org> One would think after the jetfund flew away that it might become a priority ?
-
m-relay
<tobtoht:monero.social> rbrunner7: Currently finishing up a big Feather release that should be out some time next week. After which I will focus on adding practical multisig support. Shared some ideas with jeffro re: self-hostable message daemon / UX. Keep an eye on #feather:monero.social for updates.
-
m-relay
<123bob123:matrix.org> What about monero gui/cli “ No wallet left behind”!!!
-
m-relay
<rucknium:monero.social> Dan r/dark (Is not the man & Braxman Tomsparks Advocate ): Multisig was discussed two MRL meetings ago:
libera.monerologs.net/monero-research-lab/20231115#c303794
-
m-relay
<rucknium:monero.social> My conclusion: "If anyone really wants to work on multisig, especially in the direction of kayabanerve 's proposal, please speak up. IMHO, this was a productive conversation, but I don't expect any action to be taken unless more labor [is] put toward the problem."
-
m-relay
<rucknium:monero.social> Proposal is: "What'd likely be easiest, in a pure-C++ way, is to explicitly intended Monero's DKG to match MRL-0009 (if not already) and have it audited to line up. Then, a Musig2-esque CLSAG should be formalized (likely a modification of MRL-0009's Musig-DN-esque CLSAG?) and Monero should explicitly intended to match it. The fact it lines up should be audited."
-
m-relay
<ofrnxmr:monero.social> Very much appreciated, tobtoht @tobtoht:monero.social: and jeffro256: