Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Monero Community Workgroup Meeting: Saturday 25th November / 2nd / 9th December 2023 @ 15:00 UTC #934

plowsof opened this issue Nov 25, 2023 · 5 comments


Copy link

plowsof commented Nov 25, 2023

Location:, #monero-community | Matrix

Instructions for joining the Matrix server.

15:00 UTC Check your timezone

Moderator: plowsof

Please reach out in advance of the meeting if you would like to propose an agenda item.

Proposed Meeting Items:

  1. Introduction
  2. Greetings
  3. Community highlights
  4. CCS updates
  5. Workgroup reports
    a. Dev workgroup
    b. Localization workgroup
    c. Outreach workgroup
    d. Events workgroup - MoneroKon 2023
    e. Website workgroup
    f. Policy workgroup
    g. Research workgroup
    h. Seraphis Migration workgroup
  6. Open ideas time
  7. Confirm next meeting date/time

Previous meeting including logs

Meeting logs will be posted here afterwards.

@plowsof plowsof changed the title Monero Community Workgroup Meeting: Saturday 25th November 2023 @ 15:00 UTC Monero Community Workgroup Meeting: Saturday 25th November / 2nd December 2023 @ 15:00 UTC Dec 2, 2023
Copy link

plowsof commented Dec 2, 2023

2nd Dec: (todo: add logs)

Copy link

plowsof commented Dec 3, 2023

Logs 25th November

< p​ > Greetings, hello

< t​ > Bro's/bitches - What's up. Are we doing this shit, or are you moving off-line?

< p​ > thanks for the funding link reminder msvb. monerokon call for presenatations is also open: , volunteers please apply here

< s​ > hey

< midipoet > hello

< o​ > Gm

< r​ > Lurking

< msvb-lab > Hello.

< p​ > what would be the purpose of this meeting? an end/round up of the proposals for "fixing" or "evolving" the CCS?

< o​ > pay plowsof and kaybanerve from generalfund

< o​ > meeting over?

< p​ > a reminder of where we are at currently: the WIP list have funding secured from the General Fund, sent to luigi who then makes payments. The Ideas are divided into 2 distinct groups, the Protected Group (PG) - who are core developers / researchers that generally get auto-merged, and the None Protect

< p​ > ed Group (NPG) which would be everything else. PG's have funding secured by either retro funding on the CCS or direct funding from the GF or a combination of the above. NPG's have no such guarantee and must wait until the CCS wallet situation is "fixed".

< p​ > luigi1111 can better clarify if there are errors

< o​ > These groups dont really exist

< o​ > I just added plowsof and kaybanerve to "protected"

< o​ > (that is, if they do exist)

< h​ > hello

< p​ > Pro-Escrow (PE) and None-Pro-Escrow (NPE). an example of PE from midpoet: "I think we could establish a list of people willing to be escrow provider...." cont and an NPE idea can be found at: Rethinking Monero CCS - escapethe3ra

< o​ > Im not here because i have an hour to talk bullshit

< o​ > I do that outside of meetings, in my spare time.

< o​ > Please stop posting non-solutions

< p​ > further discussion on this happened yesterday here

< p​ > nowww

< o​ > Now, either ccs wallet is uo and running? (i assume its not), or generalfund can start paying out merge queue

< o​ > Our

< o​ > everybody is orot

< o​ > Protected*

< p​ > is there anything missing? a new idea/proposal that hasnt been discussed already? Core shuld have enough to act upon?

< midipoet > We need an escrow step/process of some sort, imo. The question is how many escrowers we should have, and whether they should use multisig or not.

< p​ > i dont even want to be involved in a PG / NPG situation, i'd rather doordash

< o​ > multisig, yes, but not yet.

< o​ > escrow, of course.

< o​ > no multisig = 1

< o​ > multisig = 3/4 and 2/3 donation ans payout

< t​ > At this point, we should ignore what have already been settled, and move to secure a future solution. The CCS have a long record of success, getting fucked up by human (error/malice). The CCS didn't fail, someone else failed.

< p​ > the 'ccs coordinator' loses 25% of his role and then gets to shoulder his way into the PG. no way lol

< p​ > or 85% , a large chunk anyway

< o​ > The ccs coordinator worked for 12+ months and was paid for 6

< o​ > While being kept out if the loop and made to look like a fool

< o​ > For 60/90days of most recent term

< o​ > "90" (which was really 180)

< p​ > ofrnxmr raised a good point about kayabanerves proposal being granted 2 months on the CCS page -now- in a Post Hack environment. Pre Hack , 2 months would have been plenty of time i think to achieve most if not all reauested funding. but now, in a post hack time, his proposal may suffer because of the CCS' problems,, which is uncalled for

< o​ > Not just this proposal, but continued work on fcmp can come to a halt haveno style..

< o​ > there are definitely follow up prooosals

< o​ > Were 1/4 of a year wasted.

< o​ > lets just keep pretending the world will wait for us

< o​ > Fcmp is essential

< midipoet > can we not use kayaba's and plowsof's proposals to test out new setup? GF can donate a chunk to them if required

< o​ > Articmine and fluffy have posted sentiments to that nature, thats 2/7 signers

< o​ > Lololol

< p​ > we must wait for Cores input on all the ideas/proposals for fixing the CCS as we havn't received any since the last meeting

< o​ > > <m​idipoet> can we not use kayaba's and plowsof's proposals to test out new setup? GF can donate a chunk to them if required

< o​ > Midi, im actually suggesting the matter for those 2

< p​ > just that monerokon being linked on the funding required page is seems to be a good idea

< o​ > Latter*

< t​ > I should look up on twitter, how to spell "sksualllt".

< o​ > > just that monerokon being linked on the funding required page is seems to be a good idea

< o​ > Its a terrible idea

< o​ > Its not monerokon, its paying to form a legal entity

< o​ > Monerokon ccs will come when it comes

< p​ > ccs coordinator that reads emails being boosted to funding required paid while actual devs in the NPG look on and starve

< o​ > Actual devs should be boosted too

< o​ > I dont know abiut you, but i see 2500xmr jet fund sitting in generalfund, LITERALLY for occasions like this

< o​ > Use kt

< o​ > It

< p​ > kayabas was voted for merge a long time before i even posted my proposal

< p​ > technically monero now has a dev fund

< o​ > Or.. quit the excuses about not raising money

< p​ > general fund == our dev fund, and we only have 9000 xmr

< o​ > No they dont

< midipoet > ofrnxmr: who are you talking to?

< o​ > Plowsof

< o​ > The generalfund is not our dev fund

< o​ > Its bareky an emergency fund

< midipoet > I don't understand why we can't stay on topic

< midipoet > which is what is the next step for CCS?

< o​ > theres nothing to talk about

< midipoet > Then why are you talking?

< o​ > there are actions that need ti happen

< o​ > And nobody willing to do anything

< t​ > the idea of promoting legal entities (what the actual fuck) seriously?

< o​ > If i say "give luigi a new wallet"

< o​ > We will move forward

< o​ > which is fuckin retarded

< p​ > it rests with Core to decide who would qualify for the escrow positions to begin with. at the moment, bF is still happy for luigi to continue the role which is why he asked what community felt @

< o​ > No it doesnt

< o​ > if it does, fine

< p​ > we can suggest names all we want but they're the ones who have to sign off on it in reality... otherwise we are talking about a ccs dot monero dot com fork

< o​ > Your funeral

< o​ > No it isnt

< o​ > They can either okay ball or have a boating accident

< h​ > everyone proposes their magical idea that fixes everything -> no-one will actually work to implement it and/or it assumes other people will -> luigi ends up with ccs wallet duties again

< h​ > we can just skip to the end

< midipoet > So we have a first vote then? Luigi to escrow CCS wallet.

< p​ > perfect

< midipoet > 1 is Yes. 2 is No.

< midipoet > 2

< o​ > Clownshow

< o​ > 2

< msvb-lab > 1.

< o​ > Sneedlewoods, you can vote yknow

< o​ > > <m​svb-lab> 1.

< o​ > 🤣

< o​ > k im out

< o​ > the beatings only get worse - you get to be luigis shield again

< midipoet > Anybody else voting?

< o​ > thats 2 and 2

< o​ > Stalemate

< s​ > I would say no, at least as long as it's not disclosed how it happened

< o​ > Yet we want a 2/7 multisig

< o​ > Cant even get 7 votes

< o​ > Fkn c l o w n s h o w

< midipoet > so 3 no. And 2 yes.

< o​ > Im going to talk to fluffy 🤬

< p​ > nioc voted 1 last meeting

< o​ > N stop wasting my time

< o​ > core runs this bitch? So what am i talking to you ppl for

< p​ > luigi is escrowing the ccs funds already for the PG

< o​ > > nioc voted 1 last meeting

< o​ > Speak for yourself

< o​ > Ceetee dan and all my 5000 alts voted no

< o​ > So fk u we win

< msvb-lab > Do you midipoet have a fast explanation why you vote against the luigi escrow option?

< p​ > then the beatings shall continue , just trying to be realistic

< midipoet > Because it is proven to be the source of a vulnerability/threat/attack vector that may surface again.

< o​ > S l a p

< o​ > +1 midi

< o​ > And luigi didnt give 2 fucks

< o​ > Casually like "oh well"

< midipoet > I would also vote no if fluffy was the escrow provider

< o​ > Fuck all that bullshit

< o​ > fluffy wont be escrow

< o​ > But if core is pkowsofs boss

< p​ > midpoet didnt you type shouldn't be then should be the other day when asked about luigi

< o​ > than plowsof can stfu and do as hes told

< msvb-lab > That's understandable midipoet.

< midipoet > plowsof: i don't understand the question

< o​ > One way or another, ccs is movijg forwaed

< o​ > Plowsof and some others say "core will do it"

< midipoet > we should leave the vote open for a few more days. Maybe 48 hours

< midipoet > And then move on with the outcome.

< msvb-lab > So a person like dsc or geonic would be better for the role, because they are less well known. Is that approximately why you vote 2 midipoet?

< t​ > It's not that hard. We need wallets for active development, dormant development(jet fund) and a hot thingy to make the actual payouts.

< t​ > In a community of developers, it shouldn't be that hard.

< o​ > Msvb is HILARIOUS

< o​ > Hahahahahahahahaggahaggagagagad

< midipoet > msvb-lab: i think we should have a few CCS wallets, and escrow providers unknown and rotated

< msvb-lab > I remember partially the discussion now, okay midipoet.

< o​ > Geonic is less well known. Lol.

< o​ > to who??

< msvb-lab > I still vote 1 for the strong preference to the kiss factor and historical value.

< o​ > Hes trying to win a fkn oscar

< o​ > Historical value = balance says 0

< o​ > Men lie, women lie, numbers dont lie

< p​ > the beatings shall continue until the public outcry reaches a boiling point (could take another month or 2.. or 6)

< o​ > Luigi and his "i wont be able to do forensics for 2 more weeks" maid attacks are ideal

< midipoet > Can we move on to next topic please?

< midipoet > Vote stays open for 48 hours, i think that's fair.

< o​ > No

< o​ > Monero development will just die

< o​ > 6 months of starvation is a clown suggest bud

< o​ > There are no topics for discussion, afaik.

< midipoet > ofrnxmr: what are you on about?

< t​ > I like this one "strong preference to the kiss factor "

< t​ > Kissing who's ass ?

< o​ > Its "soo...."

< o​ > "have we.. no? Not yet?"

< o​ > We cant merge anything

< o​ > This protected and non orotected shit is bullshit

< t​ > What are we voting about?

< o​ > If plowsof would rather doordash than coordinate, so be it

< p​ > the next topic should the the CCS ideas list / merges but....

< o​ > Ill deal with core directly

< o​ > And by next week, we'll have a wallet

< p​ > there would be hardly anything to coordinate .. the PG are self functioning .. monthly updates, guaranteed progress

< o​ > whatever circus games ppl want to think up, can be done while were paying devs and raising money

< o​ > The wallet

< o​ > You had 60 days of coordinating payments

< o​ > Where you didnt know there was no damn money!

< p​ > the monero core / seraphis devs / researchers have funding secured

< p​ > they wont starve

< o​ > Because i made a comment out of the side of my mouth about selsta working for free

< o​ > Thats notna solution, jackass

< o​ > The jetfund is supposed to cover this

< o​ > Generalfund has the jetfund

< o​ > Its not a "let them do what they want"

< o​ > We are supposed to be able to look at prooosaks


< t​ > Fucking bitches. Focus on the problem at hand.

< c​ > Join us at 11am est (in 20mims)) for this weeks MoneroTopia show. We will have Recanman on to discuss Monerokon and the fundraiser for it.

< c​ >

< o​ > Problem: no donation wallet

< o​ > solution: make one

< o​ > Problem: who makes it?

< o​ > solution: not the person who got robbed blind and didnt bother to tell the coordinator

< t​ > chowbungaman: Cool spam, mf'er.

< o​ > Thats doug haha

< o​ > chowbungaman: what time is guest on stage

< p​ > there is one topic in AOB to touch on. any closing words on the entire situation?

< p​ > a vote of luigi being the CCS escrow is open for 48 hours

< o​ > thats hilarious

< o​ > I wonder if we'll get memed for that

< p​ > not sure about the 48 hours time constraint

< o​ > He wont be back til after thanksgiving

< o​ > So.. if we can vote in his absense

< p​ > god forbid luigi uses a trezor and never gets hacked again

< midipoet > plowsof: then change it

< o​ > > god forbid luigi uses a trezor and never gets hacked again

< o​ > Just what we need. Luigi losing the trazor

< s​ > I'm tempted to vote yes, just to get this moving forward, but on the other hand I'm afraid what another ccs incident would do to moneros reputation

< o​ > at least a few devs dont want luigi or bf holding their funds anymore.

< p​ > imagine if he learned a lesson from this whole thing

< midipoet > sneedlewoods: your indecisiveness isn't helpful

< p​ > the horror

< selsta > fwiw I trust luigi

< msvb-lab > midipoet trusts luigi just like we all do selsta, but I think the point is to redistribute risk.

< selsta > he has done a lot of underappreciated work since the beginning of monero's existence

< o​ > i know

< midipoet > selsta: it's not just trust, imo. If there is a vulnerability then it may get exploited again

< o​ > But these days hes on vacation with his computer unattended

< o​ > And doesnt give a shit

< t​ > I have never made it through the initial blabla niceties, to actual get some substance. It's too boring for my limited attention span. I need action.

< msvb-lab > The question for me is if we should try for a more complex arrangement to improve security or assume the same thing won't happen a second time (while reducing complexity.)

< p​ > "if there is a vulnerability" with a HOT wallet that had the seed shared on all kinds of platforms/computers

< o​ > Why would luigi get off his boat for that??

< selsta > midipoet: well yes he wouldn't use the same setup again

< o​ > Hes been using the same windows 11 setup, ssh passwords instead if keys and everything for years

< selsta > without luigi doing maintainer work who knows where the project would be now

< o​ > The vulnerability is the person

< msvb-lab > I think any changes we make, whether assigning a new person or having a multi person pool, would maybe be less secure than giving the role to luigi.

< t​ > Did I see pictures from Bahamas?

< msvb-lab > Also, I think luigi has offered to do the escrow which is very generous of him.

< selsta > and he is only backup maintainer but we haven't found a replacement in multiple years

< o​ > If he was committed, maybe he wouldn't he vulnerablen

< midipoet > selsta: he can remain a maintainer

< o​ > Generous.. lol

< o​ > yeah, no issues with him being maintainer

< p​ > he had a wallet containing 244 xmr that was perfectly fine

< o​ > That was the overages wallet

< p​ > why didnt the 1337 hackers take it

< o​ > Cuz it has "ofrnxmr jet fund" written on it

< selsta > so far I haven't seen a realistic solution other than luigi

< o​ > They knew better

< midipoet > plowsof: knowing the answer to that question doesn't help in anyway

< midipoet > selsta: that's fine. So you vote 1.

< o​ > Selsta is a better solution, but selsta is already overworked and underpaid with a shitload of things to pay close attn to

< midipoet > can we at least agree on how long the vote stays open?

< midipoet > And then move on

< selsta > I don't want to deal with any wallets

< o​ > (raise rates plz)

< msvb-lab > 48 hours, is that okay midipoet?

< midipoet > i think it's fine, plowsof isn't sure

< o​ > 7 days

< msvb-lab > We can check the log in about two days.

< o​ > Meeting in 1 week

< p​ > only if the result is the one i want :D

< o​ > Vote on meta issue

< midipoet > ofrnxmr: agree.

< p​ > ok next saturday sounds good. enough time for core to respond to all this

< o​ > 400 comments later

< midipoet > Plowsof: can you make the meta issue?

< p​ > now with 5 minutes left i would like to give msvb the floor to advertise CCC

< midipoet > please clarify its a simple yes, no vote.

< p​ > yes i can make the meta issue , any suggestion for the title?

< h​ > +1 meta issue

< p​ > Luigi to continue as CCS escrow?

< midipoet > plowsof: if the outcome is no, we'll figure out the next required vote.

< o​ > Nominations for ccs wallet excrow

< p​ > msvb-lab

< msvb-lab > It's my turn now plowsof?

< p​ > yes !

< msvb-lab > Whoever wants to help organise a Cryptocurrency Hackers assembly at the forthcoming CCC Congress in Hamburg, please send me a DM so I can help you get a ticket.

< msvb-lab > If we have no staff in about a week, I'll cancel our participation.

< msvb-lab > ...assuming it's a vote with our feet against introducing Monero and Crypto at the event.

< m​ > Best to send the direct message here to my Matrix account, if you want to help. Thanks!

< m​ > That's all plowsoft, next topic.

< o​ > Vote

< o​ > yes luigi

< o​ > or no (optionally nominate someone else)

< o​ > And monerotopia wants some ppl to come on the show (now, i guess)

< p​ > Vote: Luigi to continue as CCS escrow #935

< t​ > Gentlemen, and bitches - I don't have a problem with Luigi managing the hot wallet.

< t​ > We should, however think about some kind of management of secondary mallets. Like sponsors sending to a cold wallet, only releasing funds to hot wallet on majority votes.

< t​ > I know, it's weird.

< h​ > plowsof: maybe add some info supporting both yes/no sides

< p​ > thank you for the vote idea, i should have made that issue after the last meeting, my apologies - it will help clear things up

< p​ > for now i just added "Further details/caveats to your answer is much appreciated."

< p​ > i would be biased in my answers telling people why yes is amazing and no is yucky BAH!

< p​ > i will think/collect the reasons for yes / no later though

< p​ > my answer is something like Yes : but make luigi agree to terms and conditions that remove ALL plausible deniability so that if any such hack happens in the future , there is only 1 conclusion

< midipoet > context is less important, imo, given the amount of unknowns on the matter.

< p​ > a hot wallet , with the seed shared on the internets / multiple devices is a gaping hole that can easily be fixed

< midipoet > It's either we continue as before (assuming Luigi improves/adjusts his setup to account for the issue) or change something. If it's change something we can then concentrate on what we change to, after this vote is concluded.

< p​ > ok i understand

< p​ > so this vote is 'do yo utrust luigi didnt steal yes/no?'

< p​ > if the outcome is that people think he didnt steal then we can discuss how he can custody the wallet more securely?

< midipoet > plowsof: no it's not

< t​ > Also, they checked some of the alts 😎

< midipoet > And that's unhelpful

< p​ > i think this vote is a combination of those 2

< p​ > ok define the vote exactly

< midipoet > we can also believe that Luigi has been a target. And if he maintains the wallet again, whatever vulnerability has been exposed may still be there - especially as we have no forensics (as i understand it)

< p​ > true

< midipoet > Could even be his partner or son/daughter for all we know

< midipoet > Could be his best mate

< midipoet > Could be state attacker

< midipoet > Could be anything

< p​ > (has luigi even raised his hand publicly to be willing to custody the ccs moving forward, should people want that, i guess we can find that out eventually)

< midipoet > The fact we don't know is why removing Luigi is the best short term mitigation (imo)

< p​ > alright, this is all good context to help people decide

< o​ > Just

< o​ > yes

< o​ > no

< o​ > explain

< h​ > ^

< midipoet > There doesn't need to be an explanation, imo. There are too many unknowns

< h​ > luigi will continue to hold funds - yes or no

< p​ > i am not giving enough credit to the "being targetted" line of thought, i must admit

< p​ > we have no idea

< midipoet > plowsof: exactly.

< o​ > > <m​idipoet> There doesn't need to be an explanation, imo. There are too many unknowns

< o​ > Yes and no are too binary.

< o​ > if everyone says yes, what if luigi just uses the old wallet and seed?

< midipoet > ofrnxmr: yes, let's give people the "maybe" option

< o​ > Yes

< o​ > explain: im ok, but not on the same setup

< midipoet > Just for clarity

< p​ > alright, everyone give yourselves a pat on the back, lets meet next week

< p​ > ok "maybe" if / pending this/that

< midipoet > jesus, we can presume the setup will change

< midipoet > If it doesn't there is no way Yes should even be an option

< o​ > No

< midipoet > i was joking about the maybe

< o​ > Id assume he wouldnt keep leaving it unattended, but cest la vie

< o​ > Hes not able to access the machine right til after thanksgiving

< p​ > i am thankful that thanksgiving is over

< o​ > Evil maids are better than wrenches

< p​ > lets call this meeting it and gather next Saturday .. ideally with some input from Core

< t​ > Ah. yes. One for the future ...

< msvb-lab > Good meeting, dankon everyone.

< h​ > ty plowsof

< p​ > thank all for attending, apologies to all waiting for a solution :(

Automated by this

Copy link

plowsof commented Dec 3, 2023

Logs 2nd December

< plowsof > Meeting time #934 (comment)

< plowsof > greetings!

< b​ > Hi everyone

< o​ > Good evening

< plowsof > last week we put up a vote, how's it going? #935

< t​ > 👍️

< m​ > Hello.

< o​ > looks sad af

< plowsof > :(

< 0​ > Hi everyone

< o​ > Took a month to.. do nothing

< r​ > Hi

< o​ > Fix nothing

< o​ > Investigate nothing

< o​ > Just YOLO into repeating the same mistake

< o​ > Trusting someone who didnt care

< plowsof > Rucknium just left a comment, great, i suppose anyone who hasn't voted on the matter can also share their opinion now if they feel like it

< plowsof > yes we still don't know how anything happened, thats the only thing which the yes/maybe voters are feeling conflicted about

< dsc >_ i do not feel conflicted at all, it's just 'yes' for me

< o​ > thats the elephant in the room, and its pink, and blows bubbles

< plowsof > ah thanks dsc_ , i enjoyed the accurate performance review

< o​ > Do i think the new wallet will be drained right away? No.

< o​ > thats just too obvious.

< dsc >_ plowsof: thanks ;P

< o​ > for me its simply no.

< h​ > hi

< o​ > Im not blocking fundraising.

< o​ > do whatever you want, asap

< plowsof > what if we just pretend like luigi is temporary, and then tell yo uthat the eventual multisig group can 'oust him' as being the escrow due to bad performance and such?

< o​ > Last meeting i said "merge evrrything, fund with generalfund"

< o​ > Luigi isnt temporary

< o​ > Just like bf and generalfund isnt

< plowsof > if we have a multisig group - they can effectively fire him from handling the payouts

< r​ > IMHO, even if luigi's management had nothing to do with the theft, he had poor judgement in: 1) Having an online wallet, 2) keeping funds in wallet that fluffy had access to after fluffy's other Core access privileges were stripped, 3) being physically away from the hot wallet for long periods (months?).

< o​ > Its just us ignoring our problems again

< plowsof > the ONLY safe wallet in luigis custody was hte hot wallet on his windows machine lol

< b​ > I don't vote yet... But the thing are clear, there were many mistakes... I like Luigi but...

< o​ > correction

< plowsof > which only he had the seed for

< luigi1111 > Well lots of other wallets but yeah not XMR project ones

< o​ > the only safe wallet was ofrnxmrs overage jetfund

< 0​ > As a newcomer, selsta opinion is very rational IMHO #935 (comment) We should not have a single point of failure. IMHO. Although the points Rucknium mentioned are extremely concerning.

< plowsof > we will always have single points of failure

< plowsof > lol

< o​ > > <l​uigi1111> Well lots of other wallets but yeah not XMR project ones

< o​ > On the same system?

< luigi1111 > If ArticMine wants to do it I'm more than happy with that. If some multisig participants want to go ahead in the current state I'm also ok with that

< o​ > This guy drunk?

< o​ > You have shitcoins on the ccs machine?

< luigi1111 > No ofc not

< b​ > I could be in favor of Luigi if the setup is good and safe

< plowsof > the guy who has access to the infrastructure 'can turn everything off' - so reducing single points of failure where possible seems sane

< o​ > luigi csnt to forensics til after thanksgiving

< plowsof > a human(s) has to be trusted at some point

< luigi1111 > Yeah that's now

< o​ > Aka no setup is safe - he leaves em unattended

< plowsof > multisig is .. im going to guess and say 12 months away

< o​ > > <p​lowsof> a human(s) has to be trusted at some point

< o​ > Luigi has to trust his maids

< h​ > lol @ "Monero Employee Performance Review"

< luigi1111 > I don't have maids

< plowsof > the eventual scope of audit / funding / audit complete / reviewed

< o​ > > <p​lowsof> multisig is .. im going to guess and say 12 months away

< o​ > Less if we have money lololololo

< luigi1111 > But they can't get in anyway

< o​ > Cant get int the wallet? someone did

< luigi1111 > We don't know that really

< luigi1111 > Hopefully forensics will tell us

< plowsof > the only safe machine is the windows one , that'll be the answer

< o​ > You think someone Cracked the private key?

< luigi1111 > No

< o​ > And not simply stole it?

< o​ > Well then, they got into the wallet.

< luigi1111 > Two parties had the seed. I don't really know what happened on fp's end following arrest

< o​ > Safe = full > safe = empty

< o​ > = somebody got into it

< luigi1111 > Ruckniums #2 above is important

< o​ > Who put the ccs funds on a shared fluffy sees?

< o​ > you

< o​ > Lol

< plowsof > Ruckniums 2) is why we have GF2 (we can't even trust our GF1, kinda sad)

< luigi1111 > Did I deny that?

< o​ > Nope. You didnt deny.

< o​ > So its fluffy's fault that you moved the money to a fed wallet?

< luigi1111 > That was a big mistake esp given this result and no obvious entry point.

< o​ > Yep

< o​ > Red herring too

< o​ > Easy scapegoat

< o​ > Lets wait 90days for forensics too

< luigi1111 > 60 but yeah

< o​ > 90 now

< dsc >_ like that will yield anything

< dsc >_ elite haxors go in/out without logs

< luigi1111 > Yeah might as well count days before it was discovered

< o​ > Exactly

< plowsof > luigi1111: If ArticMine wants to do it I'm more than happy with that. If some multisig participants want to go ahead in the current state I'm also ok with that => ArticMine to do what? lol there is no way you are passing on the baggage of saying hello and being greeted by "you merged the oscars proposal" to ArticMine :D

< o​ > Lets just keep playing hot potato

< luigi1111 > Not to run CCS, to escrow the big wallet

< plowsof > ah i see

< o​ > Sorry guys. Ill stfu now. My 0.5c has been left

< dsc >_ you could actually make the point its in the interest of Monero's foes to adopt some complicated CCS setup going forward, anything that slows down our innovation is a win in their book

< o​ > (fwiw, i still have luigi as a signer on a multisig scheme. But not as a sole signer for ccs funds)

< dsc >_ that means getting rid of those that previously managed the fund, as well as contributed

< plowsof > luigi cant be in the multisig group because we have to oust him if he goes rogue!

< o​ > @dsc right?:

< o​ > 1/4 of the fucking year with no fundscoming in

< h​ > 1) would ArticMine be okay with custody? 2) he seems... unavailable - hot wallet top ups could take a while

< o​ > This is cucked as fuck

< dsc >_ no ofrnxmr I mean that any type of drama is a win for them, including this. While I am advocating to just go the pragmatic route.

< o​ > Those who can fix are scared, those who will, shouldnt be allowed near the money

< dsc >_ the pragmatic route = some Core member manages the fund

< o​ > > <d​sc_> no ofrnxmr I mean that any type of drama is a win for them, including this. While I am advocating to just go the pragmatic route.

< o​ > And im agreeing with you

< luigi1111 > Actually 60 days again but w/e

< dsc >_ ah ok

< s​ > the biggest issue is the lack of transparency and personality cults of the people connected to the core team

< o​ > sept 1 > dec 1

< luigi1111 > Funds were raised in September

< plowsof > spirobel is anti core anti ccs !!! disregard everything he says!!

< o​ > = 60 days. Gotcha

< o​ > Loll

< r​ > A second theft would be an even bigger victory for Monero adversaries.

< s​ > say all the people with the hands in the cookie jar lol

< s​ > its all about politics

< plowsof > :$

< s​ > politics truth vs real truth

< s​ > political truth vs real truth

< plowsof > spirobel is also anti 'community meeting every other week' so please throw stones at us in a decentralised manner

< dsc >_ my hand has not been in the cookie jar for 3 years actually

< s​ > we have a 24/7 community meeting anyway

< dsc >_ (please pay me)

< o​ > Im eating cookies rn

< s​ > these stupid rituals are just super inefficient

< dsc >_ nice, which?

< o​ > No popcorn left

< plowsof > dsc_ you are talented so no

< dsc >_ ty sir

< o​ > Regular chocolate chip

< plowsof > you deserve funding = sorry !

< o​ > Hypocrite plowsof

< o​ > Mr 3 months is 6

< o​ > Working for free rn

< s​ > but if there is no meeting there is no need to manage it. So the person with this job now is obviously against making this more efficient

< o​ > Not in the ProtectedGroup

< plowsof > this meeting was brought to you by DoorDash

< s​ > it all comes down to politics

< o​ > Neither is Kaya afaik

< s​ > people dont care about the thing as whole

< s​ > people dont care about the thing as a whole

< o​ > Foes love this filibuster though

< s​ > they just care about getting their tiny hands in the cookie jar and that is all that matters

< plowsof > spirobel finally gets it , now

< s​ > When do I get my cookies???????

< luigi1111 > Spirobel thrust forth thine hand

< o​ > Cookie jar = fame for some people.

< o​ > > <l​uigi1111> Spirobel thrust forth thine hand

< o​ > Luigi giving away our lunch again

< luigi1111 > Too many cookies isn't good for you

< plowsof > we could even spend weeks/months voting on the multisig persons.. size of the group

< luigi1111 > How did the vote go

< plowsof > ok the vote

< 0​ > I don't understand why we should not have multisig wallet for managing these funds, instead of relying to single person. There are many people that I believe community trusts, plowsof, ofrnxmr and many others. (and I am not saying luigi should not one of the signature holders)

< luigi1111 > I can nominate some community members and enslave them into service

< o​ > The governance says who givrs a fuck

< o​ > Governance says "core decides"

< o​ > I already drafted our leaders

< o​ > But they dont want to lead

< r​ > 0xffc: Monero multisig is still experiential. We do not know if it is secure.

< r​ > experimental*

< luigi1111 > Ok so wat do

< 0​ > Any timeframe about when it will get more robust? Months? Years?

< r​ > Uh, multisig is also an "experience" with more than 3 signers. So it is experiential, too.

< luigi1111 > Yeah not bullish on high signer count

< o​ > > > <> 0xffc: Monero multisig is still experiential. We do not know if it is secure.

< o​ > > Any timeframe about when it will get more robust? Months? Years?

< o​ > Its in use by at least 1 active exchange, 1 in development, and 1 enterprise wallet (RINO)

< 0​ > 3 is enough IMHO. We want to prevent similiar issues. We don't want 4000 signer for each transaction.

< r​ > 0xffc: At fastest pace, 6 months to one year IMHO. The pace is zero now because no one is working on it. Check recent MRL meeting logs.

< plowsof > rough numbers from that GH issue 9 ish yes/maybes , 6 ish no

< o​ > @luigi my suggestions are 3/4 and 2/3 for donation and payout, respectively

< 0​ > thanks. sure.

< plowsof > multisig just doesnt exist, we need a solution now

< o​ > > @luigi my suggestions are 3/4 and 2/3 for donation and payout, respectively

< o​ > This is after UX improvements

< plowsof > we needed a solution the day of the hack

< luigi1111 > My suggestion for payout is 1 unless something online

< o​ > > <p​lowsof> multisig just doesnt exist, we need a solution now

< o​ > Have one now

< o​ > Had one weeks before the hack

< o​ > Months before

< o​ > > <l​uigi1111> My suggestion for payout is 1 unless something online

< o​ > 2/3 bcuz ppl afraid of wrenches. lolz

< plowsof > the payout wallet will be escrowed by luigi as per for "Vote"(tm) if he wants to

< a​ > I would vote no, pending the forensic investigation. luigi was a target once and we dont know how the funds were lost, it would be idiotic to try the same thing again and just hope the threat actor goes away.

< o​ > But im fine with 1 for payout, if the signer is

< o​ > Im not ok with luigi being the sole signer :)

< a​ > If we discover how the funds were stolen, I am fine with luigi being the custodian

< plowsof > just restating that a multisig group is used - for the big wallet - will have the opportunity to say "hey luigi.. we dont like yo uanymore. we're not sending you funds to payout anymore'

< r​ > For people who have posted CCS ideas, why not apply to MAGIC? Is it the KYC? Give hints about how MAGIC could improve worker experience please :)

< plowsof > please keep this in mind for da future

< h​ > hardware/cold wallet for the next few months (custodian pending), fast-track multisig development and move onto that eventually?

< b​ > Agree

< plowsof > Rucknium: im unemployable, theres my reason

< h​ > unless taking the risk on multisig is worth it in this case

< o​ > > hardware/cold wallet for the next few months (custodian pending), fast-track multisig development and move onto that eventually?

< o​ > Agreed. But not luigi.

< o​ > likely to lose the hw device

< h​ > multisig isn't that far off - the current deadlock is whether it should continue to be within monero-project/monero or not

< luigi1111 > Hasn't happened yet. But it could

< plowsof > we must not forget the work tobtot has done (before this even happened.. for working on QR code transfers in feather AND recently on multisig UX with jeffro256)

< h​ > kayaba already has a working impl, a review is all that is needed - although it is not controlled by core

< plowsof > tobtoht*

< o​ > > <p​lowsof> we must not forget the work tobtot has done (before this even happened.. for working on QR code transfers in feather AND recently on multisig UX with jeffro256)

< o​ > This is what im alluding to

< o​ > Working without real assurances

< o​ > On hero missions

< b​ > Yep this is important point

< o​ > When we could use this opportunity to BRING IN mkre dev power

< h​ > if the current core were to be used, it would just take a couple of the current devs to shift focus on it

< o​ > Gives us a reason to MOVE FASTER

< plowsof > the multisig group will lead the coup

< o​ > Instead we stall for an entire quarter and come out with "we got no ideas"

< o​ > Plowsof is afraid of money corrupting him

< o​ > But he knows hes not built like that 😂

< plowsof > next month, luigi will more than likely be sent funds from the general fund to payout some work in progress porposals (the same will be done for the rest of them)

< plowsof > we wont lose any sleep over that

< o​ > Yes we will

< o​ > Where tf is fcmp ?

< o​ > i havent slept in a month

< o​ > Where tf is the friggen coordinator?

< o​ > Starving?

< h​ > Rucknium: it's the KYC

< o​ > applying for part time jobs?

< o​ > we have billlions that we secure for people

< plowsof > DoorDash app is always available (can go online at any moment! and cash out daily)

< o​ > TIL

< o​ > Pays bettet than monero too, i bet 😆

< o​ > Wait. You dont have to request pay, ans be met with silence?

< plowsof > in the winter, (bad weather/rain - it's hard to compete with the earnings possible delivering food)

< o​ > Doordash actually has your money?

< o​ > They didnt lose it, and let you continue working without telling you?

< plowsof > DD sponsored me to infiltrate the Monero community and recruit delivery riders, this is why i targetted the CCS

< plowsof > we have KYC like Magic, but you can begin work /getting paid even before your proposal is merged (or not) lol ok ill stap

< 0​ > KYC is dealbreaker for some of us.

< o​ > Too bad we dont have any proposals for a monero doordash - oh yeah, we cant merge anything.

< o​ > K. So plowsof, can we agree were doing plan a or b, and we can do it today? Proposals can go up for monday etc?

< o​ > "what is plan a or b"

< o​ > Plan a: fix it

< o​ > plan b: fix it harder

< o​ > No vote, just a yes or no

< plowsof > luigi1111 has won the vote, by a huge majority, i know an acceptance speech on short notice is a bit rude but do you have anything to say?

< o​ >

< o​ > EOD

< b​ > We cannot delay the proposals any longer

< plowsof > EODecember lmao

< o​ > :D

< luigi1111 > Um.

< 0​ > Great speech!

< plowsof > luigi everyone... thank you. so luigi is escrowing everything , right

< plowsof > ArticMine thoughts on escrowing a big wallet and sending luigi CCS funds every x month(s)?

< o​ > Sure, if thats what people are to believe

< o​ > I say "its fixed" and we can disclose how in 60days

< plowsof > the eventual multisig group for the big wallet will "oust" any bad performing escrow holders

< o​ > Thats not possible

< o​ > You cant "oust" the supreme leader who controls everything

< o​ > Anyway

< o​ > Fixed today

< o​ > ccs proposaks can go up soon

< plowsof > luigi shouldnt be in the Msig group of the large wallet

< o​ > Who needs to be merged

< o​ > Plowsof, kaya

< o​ > who else

< plowsof > xmrscott has just shared their opinion on the GH issue also, thanks

< o​ > Erc, observer

< o​ > Jeffro and selsta are covered by GF (right)

< plowsof > the animated explainer video proposal that would need just ONE xmr (plus the stolen funds reimbursed from the general fund)

< o​ > Any objections to merging

< o​ > plowsof - coordinator

< o​ > kaya - FCMP

< o​ > Erc - monero-site

< o​ > observer - continued work

< m​ > Congratulations luigi1111 and dankon very much for the hard work.

< o​ > > Jeffro and selsta are covered by GF (right)

< o​ > Dangerousfreedom is as well?

< plowsof > hooray luigi1111

< o​ > > Congratulations luigi1111 and dankon very much for the hard work.

< o​ > What are we celebrating

< o​ > Merge some damn proposals

< plowsof > XD

< o​ > Fkn circlejerk shit

< o​ > Were here, not for us, but for the proposers

< o​ > > Any objections to merging

< o​ > > plowsof - coordinator

< o​ > kaya - FCMP

< plowsof > pipes need unclogging

< o​ > Erc - monero-site

< o​ > observer - continued work

< o​ > ^

< o​ > Don't threaten me with a good time

< o​ > So.. nobody is going to vote?

< o​ > > Any objections to merging

< o​ > > plowsof - coordinator

< o​ > kaya - FCMP

< o​ > Erc - monero-site

< o​ > observer - continued work

< o​ > ^

< plowsof > hearing ArticMines opinion on the offer to escrow a big ccs wallet sounds great tho NGL + EODecember acceptance speach from luigi1111 with proposals merged and being funded

< o​ > fuck that

< plowsof > i have zero objections ofrnxmr

< luigi1111 > Can't merge until there's a new wallet address up

< o​ > Thats for after the meeting

< o​ > > <p​lowsof> i have zero objections ofrnxmr

< o​ > Thank you

< o​ > > <l​uigi1111> Can't merge until there's a new wallet address up

< o​ > I said that.

< h​ > note that the agreed upon condition was for luigi1111 to create a more secure wallet

< plowsof > the latest version of Windows this time

< h​ > and yeah there's still website plumbing to fix

< plowsof > not the standard edition either (cheap skate volunteer) .. professional or nothing

< plowsof > Core is a tool for the community to use woohoo

< o​ > Meet back here in 1 week to discuss more proposals?

< s​ > if you dont have a license key i can send you a crack no problem

< plowsof > thank you spirobel

< o​ > Such has hintos and v1docq47

< o​ > Such as*

< r​ > hinto: Would you consider working on Seraphis instead of cuprate? There is already a dev working on cuprate. About 2.5 devs working on Seraphis now I think.

< plowsof > lets end the meeting here then, wen can the one whale start donating to proposals luigi1111? stay tuned. thanks all for joining x

< m​ > Dankon everyone for a good meeting.

< r​ > I know Monero has no bosses, but having two people on cuprate and 2.5 on Seraphis does not seem like a good allocation of resources.

< plowsof > oh , ideas list suggestions

< plowsof > there have been no cuprate proposals merged onto the ccs for funding

< plowsof > boog's one had direct benefits to monero-core (and we are reaping the rewards already)

< o​ > > <p​lowsof> lets end the meeting here then, wen can the one whale start donating to proposals luigi1111? stay tuned. thanks all for joining x

< o​ > I will let you know 😂

< r​ >

< plowsof > else we have to re-hash all of the same arguments for putting forward a monerod rust implementation to funding

< h​ > Rucknium: depends what else is left to be implemented in Seraphis

< h​ > i might just be stepping on toes joining this late - not to mention the c++ landmines

< o​ > never too late with seraphis

< plowsof > anyone on the twitters want to talk about Monero with "Privacy Guardians spaces invite" have an open invite

< plowsof > +1 for never too late

< plowsof > im head of audits

< plowsof > lmao

< o​ > haha. yep. "how did i end up here"

< plowsof > ZKsecurity wishes us a quick recovery BTW

< o​ > 😭😭

< o​ > how much did they want again?..

< o​ > 10k/week?

< a​ >_ dm me if anyone is available to chat about Monero with Privacy Guardians on twitter spaces

< plowsof > yes

< plowsof > thanks ajs_ , i almost forgot

< o​ > (im not saying price is bad. Im saying - we HAVE MONEY TO RAISE. Not time to fk around)

< plowsof > 100%.. we have to raise funds to formalise seraphis AND then fund ZKsecurity who so far are the best candidates to look at the paper

< plowsof > jberman has took over the 'get seraphis formalised part' now thankfully because >plowsof

< o​ > And cz left binance. Who knows if he'll keep donating

< nioc > as to the 2 of 3 multisig, what are the odds that something happens to 2 of them and the wallet is therefore lost?

< nioc > sorry missed the meeting, was out shopping for Cat

< o​ > Cat won the election

< nioc > \o/

< o​ > > <n​ioc> as to the 2 of 3 multisig, what are the odds that something happens to 2 of them and the wallet is therefore lost?

< o​ > Depending on who the 3 are, i say 0..

< o​ > if one disappears, the other 2 can move funds

< nioc > whoops, the other got hit by that damn bus

< nioc > it cannot be zero

< o​ > Same day, same time?

< o​ > Feds raiding everybody = possible

< nioc > you think between it being known and action being taken no time has passed?

< o​ > if plowsof disappears for 24hrs, we can assume hes dead

< o​ > If cat disappears for 6 hrs, same thing

< nioc > 24 of 25 multisig

< nioc > lololol

< plowsof > <3

Automated by this

@plowsof plowsof changed the title Monero Community Workgroup Meeting: Saturday 25th November / 2nd December 2023 @ 15:00 UTC Monero Community Workgroup Meeting: Saturday 25th November / 2nd / 9th December 2023 @ 15:00 UTC Dec 8, 2023
Copy link

plowsof commented Dec 8, 2023

9th December:

Copy link

plowsof commented Dec 18, 2023


< p​ > i hear a new version of feather has been released 👀

< dsc >_ (c)(tm)

< p​ > how do i pronounce guix? cus i did a guix for feather yesterday, its like gitian for monero but it worked first time

< t​ > geeks

< p​ > so not goo-eee-EX , ok lol

< Lyza > I like gwiks

< p​ > Monero GUI is Monero Goo-EEE right???

< Lyza > that's how I say it

< t​ > yes haha

< p​ > loll

< Lyza > fucking terrible name btw most people don't know what the fuck a GUI is

< o​ > Should name it "wallet of vitalik"

< Lyza > won't matter when we finally make feather the official =P

< p​ > is it meeting time? #934 (comment) part 3

< p​ > greetings!

< t​ > hi

< Lyza > hey dude

< r​ > Please apply to the MAGIC Monero Fund to get funding for your projects to improve Monero: . We're lonely over here 🥲

< r​ > Hello

< p​ > right, this was kind of impromptu .. with luigis proposal only a few days ago to temporarily kick start the CCS

< p​ > #935 (comment)

< p​ > what do we think about it? can feather wallet be used for offline transactions?

< o​ > We dont know what is used for GF

< o​ > Who cares

< o​ > Yolo, lets get merging..

< h​ > hi

< r​ > afaik we don't know "how" it got hacked

< p​ > GF2 balance is somewhere around 11k xmr now , im not sure exactly but its not far off

< o​ > on a cake wallet somewhere, maybe (im joking. Bf isnt crazy)

< p​ > we don't know how it got hacked, but i know that the only machine/wallet that didnt get hacked was luigis windows one, that only he had access to

< r​ > Luigi is very helpful, but I naturally wouldn't put him back into escrow position

< r​ > But who else?

< o​ > Voldemort

< o​ > Just say "luigi has the money" and not worry about who actually does

< o​ > Let the hacker go hack the decoy wallet

< r​ > That isn't a bit odd that no one knows?

< o​ > Most people still have no idea how general fund is managed

< Lyza > If I were soley in charge of that much money I wouldn't want to dfescribe how I stored it either

< o​ > Transparency is nice, when it can be secure

< p​ > luigis proposal only has support (with some suggestions for tweaks) so its time to get merging after luigi1111 creates an offline wallet. will featherwallet version 2.6.0 help him with offline tx's?

< o​ > Can make merge queue now

< p​ > when tobtoht closes his eyes he see's QR codes (so many hours he's been starring at them)

< t​ > yes, so new Feather Wallet release is out:

< r​ > Why feather wallet?

< r​ > Why feather wallet? (instead of gui or cli)

< t​ > airgapped signing with animated QR code, generate additional seed entropy from dice rolls, plugin system, receive tab improvements and fixes

< r​ > Ah ok, I didn't see this

< o​ > Community news!

< Lyza > Imo it will but as much as I love tobt he's basically the sole dev on feather so like, would be good to have more eyes on the project in general if we're going to be using it like this

< t​ > can't disagree with that

< r​ > That is what I think. Also, "official" monero fund, not using "official" monero wallet. Feather wallet is still really cool

< p​ > make a few more aliases for decentralisation

< Lyza > r​ecanman I can think of a fix for that :D

< Lyza > new official wallet wet

< Lyza > wen*

< dsc >_ Would like to raise the complaint that thotbot got angry at me in private because of a picture I posted here yesterday: <dsc_> here is a pic of feather running on a $15 computer

< dsc >_ He does not like me mentioning Feather, even though it is indeed running Feather on a 15$ SBC - as it may confuse people in thinking this project is related to Feather desktop.

< o​ > Why feather?

< dsc >_ I think thotbot needs to check his ego, it is FOSS software, I forked the project (that I once started may I remind him) and made it run on a low-powered device, and already made it clear 1 week ago I would not release under that name.

< p​ > luigis plan is to be the sole escrow holder of ccs funds for 3~ months

< dsc >_ Publicly stating this so people know he takes himself too serious.

< o​ > feather will support multisig UI/UX first

< h​ > tobtoht: how are you generating + adding entropy from dice rolls? some library or did you write this?

< t​ > i wrote this

< p​ > see you in intellectual property court dsc_ !

< g​ > What if he get hit by an Airbus?

< h​ > could i get a link to the file?

< t​ > yes, one sec

< o​ > > <d​sc_> Publicly stating this so people know he takes himself too serious.

< o​ > Tobtoht needs a snickers

< o​ > been a long months

< p​ > Feather desktop is a work in progress thing from dsc_ (is this the bespoke OS/thing to run on a specific hardware?)

< o​ > Whether peoplenare confused or not.. we arent big enough to care. All newcomers are welcome

< Lyza > If we're doing this then I will say that I saw when dsc_ posted that picture and him saying this was feather running actually confused me because... what

< o​ > Just call it "wallet of satoshi v2"

< dsc >_ plowsof: I forked it and replaced the GUI code with something that would work for a touchscreen

< Lyza > I don't know, this shit seems dumb, I've only ever seen tob be super chill, and what you are doing rn dsc does not seem chill

< t​ > hinto:

< o​ > Lyza, dsc and tobby have a personal relationship

< p​ > sounds awesome dsc_

< o​ > So its "deeper" than that

< Lyza > that's what I'm saying, it seems likle they have personal disagreements that aren't really relevant here

< o​ > Basically, we shouldnt get in the middle of this brotherly spat

< Lyza > so Idk why dsc is bringing it up like it matters

< p​ > can we fund a ccs to force teamwork?

< o​ > We love both of you

< o​ > Slap slap

< o​ > Dont worry.

< dsc >_ Lyza: I'm bringing it up because I feel wrongfully accused of doing something wrong

< p​ > dsc is the original creator of the featherwallet

< Lyza > maybe dsc would feel better if we used wowlet?

< dsc >_ Tob is doing great work on feather, that is out of the question

< o​ > Anyway

< o​ > - new feather released 🥳

< o​ > - dsc forked feather and changrd ui for $15 sbc support 🥳

< o​ > - cake / monerocom polyseed support 🥳

< o​ > - mysu polyseed support 🥳

< r​ > > dsc is the original creator of the featherwallet

< r​ > Good to know

< t​ > we co-created

< r​ > If the license was fine and tobtoht forked it, then I do not see a problem

< r​ > Oh

< o​ > procreated

< luigi1111 > There's a joke there somewhere

< Lyza > <dsc_> you were "accused" in private from what you said, why make it publioc in a damn meeting



< dsc >_ to let people know he is a over-protective drama queen and needs his ego checked

< Lyza > I just don't see the issue

< Lyza > you are the one starting drama though, how do you not see that

< o​ > This years monerokon will be WILD

< Lyza > whole meeting has been derailed over your personal grievance

< Lyza > so you can "ego check" somebody, get real my dude\

< o​ > dsc Vs tobby

< o​ > ofrnalts vs geonic

< o​ > pP vs their ceo as a special attraction

< luigi1111 > Can we discuss what OS should be used instead. Everyone has a different idea

< Lyza > yes thank you luigi

< t​ > just go with debian

< o​ > Luigi

< p​ > is there a write up somewhere of Feather desktop(c)(tm)s features/goals?

< o​ > Hyc and others told you on the thread

< r​ > OS for new CCS?

< Lyza > Debian / Ubuntu is my vote, good mix of security and widespread use and supported by Monero

< o​ > not qubes

< o​ > use debian or bsd

< p​ > OS for the offline laptop

< o​ > Dont use ububtu.

< p​ > what does hintos guide suggest (luigi1111 do yo ufeel confident enough to attack the laptop with a screwdriver to remove the wifi chip?)

< r​ > If you use ubuntu I will laugh

< Lyza > we do the official builds on Ubuntu

< o​ > crazy talk

< r​ > Don't

< Lyza > so using Ubuntu in some way minimizes attack surface

< Lyza > building and running on same OS

< o​ > Lyza, we do them on 18.04

< Lyza > fair point

< Lyza > maybe we should move up

< r​ > with openrc

< o​ > Probably should switch to debian for our builds

< c​ > Jump on folks! 11am est live. We got Abdullah giving us the update on reporting From China where he traveled to finalize Nodo production! As always all are welcome to jump on stage to give us your weekly Monero takes:

< c​ >

< Lyza > switching to debian seems more work but Idk that's above my paygrade so to speak

< r​ > If migrating commands are an issue, it is pretty simple

< luigi1111 > Someone suggested Debian minimal I think

< Lyza > Debian Minimal ships with no GUI but yeah

< luigi1111 > Oh great

< r​ > For the offline laptop, you need to use an operating system with very low attack surface:

< r​ > Alpine linux with hardened kernel or parabola gnu/linux-libre with openrc

< o​ > Ok, luigi this is cringe

< o​ > Please stop lol. Ill ask plowsof, hyc or similar to send instructions

< r​ > You'll need to go through a specific process for kernel hardening

< r​ > This has some good stuff, but there should be more:

< luigi1111 > Lel they all have different ideas

< o​ > hand holding out in public lol 🥶

< Lyza > Y'all it's an offline machine, the protection is the encryption, you can't count on it to be actually secure from a local attacker if running

< o​ > Its not rocket science

< p​ > full disk encryption ye,, and its never going to be updated so it doesnt matter

< o​ > and its not a billion dollars

< luigi1111 > Then why are the talk

< o​ > But everyday we DONT merge, the balance will be higher

< r​ > You should use libreboot and anti-tampering measures in order to minimize physical attack surface

< r​ > libreboot will allow for encrypted /boot and grub password

< p​ > 5$ wrench , anyway

< p​ > minimal de.. deihen? +1 great idea

< o​ > $5 wrenches dont work on decoys

< r​ > You can use multiple luks keyslots

< h​ > tobtoht: (kinda offtopic at this point lol) the mapping of dice rolls <-> entropy is each die number concatted as a string, e.g 1626, then system entropy appended on-top of that?

< r​ > You could also use dm-crypt directly, but that is harder

< p​ > we need luigi1111 to try out the setup first, if its viable as is written in the proposal, then go ahead with it + debian minimal , sane

< t​ > hinto: yes, with a space in between rolls, and then ran through pbkdf2

< o​ > im crying. 29more mins ofrn, just 29 more mins

< luigi1111 > Ok next topic

< o​ > Just do it

< p​ > ok

< r​ > full-disk-encryption is useless without /boot encrypted IMO

< r​ > There should be a separate discussion on this

< o​ > community highlights.

< o​ > i mentioned during the noise but polyseed wallet support has been rolled out be a few wallets and we have good support now

< r​ > Any good explanation of polyseed?

< o​ > Feather first

< o​ > anonero

< o​ > cake / monerocom

< o​ > mysu

< r​ >

< r​ > Has a good explanation in readme

< o​ > Did you reply to yourself 👀

< r​ > I did

< r​ > "Due dilligence"

< p​ > if/when luigis new wallet/setup is finished, the CCS will have a working wallet, and need things on the funding required page

< Lyza > one thing I've been wondering about the recent donation, is if Moonstone Research or anyone would be interested in doing some research into it. There's a non-zero chance it could be connected to the transactions that have been pointed out by Moonstone's research on the hack

< o​ > that was fast

< t​ > if you need a device that can authenticate itself to the user: I think this is overkill if luigi only custodies the funds for the next ~3 months

< r​ > Looked it up right after asking

< r​ > Was first result

< t​ > debian + disk encryption + transfer over official binaries

< o​ > For that, they need to be in a merge queue

< Lyza > +1 tobtoht

< p​ >

< o​ > #1 the PG

< p​ > ajs_ is perhaps going to wait a bit to see how the first initial proposals are put forward / funded

< o​ > Generalfund can cover them this time

< r​ > Has to include /boot or useless

< r​ > Align payload to a number and use separate device for storing LUKS header

< r​ > Then create another one with decoy

< o​ > using my jet fund

< r​ > No systemd

< a​ >_ hey chowbungaman bumping monerokon funding campaign would be much appreciated

< r​ > L​yza: Moonstone Research is already aware of the big donation. SGP runs Moonstone.

< p​ > so other than monerokon funding proposal, the rest can be dealt with immediately ish

< o​ > selsta

< o​ > jeffro

< o​ > Dangerous freedom

< o​ > Go to funding, funded from GF

< Lyza > copy that rucknium

< p​ > more likely merged onto the ccs and will be funded too quickly before GF can make a donation .. oops :P :P

< o​ > Also erc for PG

< o​ > And plowsof. These people never stopped working

< p​ > (erc may have downed tools during the social experiment)

< o​ > I really feel like FCMP is core r&d and shouldn't have the 8 week limit

< r​ > Agreed

< o​ > I also feel like its the exact tye of work that generalfund should be interested in

< p​ > the luigi temp solution limit of 3 months~?

< o​ > Yeah

< o​ > Backwards. Youd think general fund was there to MAKE SURE we fould complete essential work

< o​ > but 1. Instead of donating, core gave conditions that can lead to ubderfunding

< o​ > So, what is general fund for? Million dollars needed for "hosting"?

< o​ > ~2m

< o​ > Should be 8 week, and we'll cover the shortfall

< p​ > i'd say the proposal in need of community feedback/votes would be hintos , the rest have been discussed at length in meetings afaict

< o​ > So before discussing

< o​ > lets confirm the others quickly

< p​ > and recanman shared an update on his own proposal :) (an example of the community re purposing funds) .... and so to will the Core monero concepts animated videos - to be put forward for 1 XMR of funding after absorbing the savandras proposal funds

< p​ > a. Add retroactive funding proposal for FCMPs

< p​ > merge

< p​ > b. dangerousfreedom - wallet work

< p​ > merge

< p​ > c. Core Monero Concepts

< p​ > do we need an update from the team as to where they're at?

< p​ > xenu and vostoemisio

< r​ > I think it is going well

< r​ > I don't see a need for an update

< o​ > PG > full ccs funded out of jet fund

< o​ > - selsts

< o​ > - jeffro

< o​ > - erc* (maybe regular)

< o​ > - plowsof

< o​ > - dangerousfreedom

< o​ > - bp++ update

< o​ > regular ccs merge:

< o​ > - kaya

< o​ > - v1d

< o​ > - Observer

< o​ > close

< o​ > - Self hosted

< o​ > - form nonorofit monerokon

< o​ > discuss the rest

< p​ > looks sane

< p​ > pasting links for logs

< p​ > d. escapethe3RA Monero Observer maintenance (2023 Q4)

< p​ > merge

< p​ > e. [External] Form Nonprofit Assocation for MoneroKon

< p​ > ajs_ marked this as not ready for merge anyway as they wanna see how things turn out for the first proposal

< p​ > and would require changes to the ccs backend (if external is required)

< p​ > f. erc: ccs for getmonero and weblate

< o​ > Merge

< r​ > I think there was an issue with this

< p​ > there is some back story to moneroguides downvote on this proposal, who had some redesign / shuffling choices for getmonero that he felt was ignored

< r​ > I forgot

< o​ > Erc isnt a 1 man horse

< r​ > I forgot to say that you can submit yourself as MAGIC Monero Fund committee member or as a voter for the committee: . Nominations close on December 31st.

< p​ > erc has my +1 for merge

< o​ > Hinto, plowsof and hardenedsteel help out over there. But could use more eyes

< o​ > Over there = monero-site

< r​ > You don't have to KYC to be a candidate for the committee nor a voter.

< o​ > s/eyes/hands and eyes

< p​ > g. Monero Selfhosted View-only Web Wallet (with received transaction Telegram/Email/SMS/Discord/Webhook alerts)

< p​ > lol^

< r​ > That is just to receive compensation I think

< r​ > Close

< o​ > Close

< r​ > That is just to receive compensation I think (MAGIC monero fund committee)

< p​ > moving through them quickly, if anyone wants to vote on an earlier one, please do so

< p​ > h. CCS Coordinator

< t​ > merge

< r​ > Merge

< o​ > Merge

< p​ > thnx ❤️

< p​ > i. v1docq47 - monerotopia 2023 (part 2) and monerokon 2023 voiceovers and working on

< o​ > Merge

< r​ > merge

< p​ > merge, long history , and quick funding

< p​ > j. jeffro256 full-time dev 2023Q4

< r​ > merge

< t​ > merge

< o​ > Merge

< p​ > merge

< r​ > merge

< a​ >_ merge

< p​ > k. hinto-janai - full-time work on Cuprate (3 months)

< p​ > needs discussion

< p​ > which will be possible now that the ccs has survived , between now and the next meeting(s)

< o​ > I think we need -dev to comment (unbiased)

< p​ > on the hour

< p​ > l. selsta part-time monero development (3 months)

< o​ > Cuprate docs alone are worth money

< t​ > merge

< p​ > merge selsta

< r​ > merge

< o​ > Merge

< r​ > merge

< h​ > +1

< o​ > boog900: wink wink

< p​ > so we need to somehow get the cuprate proposal to benefit monero core and/or seraphis to make it more appealing

< a​ >_ it would spread limited resources unnecessarily

< o​ > During reimplementations of pruning, cuprate found and documented a bug

< b​ > it's not really a bug more of a typo ...

< o​ > one thing is like to ensure with funding cuprate, is that issues and fixes are relayed to minero-project

< a​ >_ indefinite long term maintenance

< o​ > What if they were able to do seraphis before us?

< a​ >_ merge for selsta

< p​ > i think i can say thanks to all for attending the meeting here

< p​ > and continue discussions

< msvb-lab > Dankon everyone for the good meeting.

< b​ > I do understand this and my next proposal will be to work on Cuprates p2p code and document Moneros p2p protocol but with a database im unsure what we can document ... synthetic has already documented monerods schema

< p​ > msvb-lab do events have a meeting today?

< msvb-lab > Yes, in one hour on #monero-events.

< o​ > uh we forgot the biggest news

< msvb-lab > Our new moderator Comradeblin is going to run the meeting.

< o​ > We had a small donation to generalfund

< p​ > oh thanks msvb-lab comradeblin

< r​ > Lol

< plowsof > a small donation hm let me check

< plowsof > 21 hours ago it received 💝 +0.00001 #xmr 💝 $0.00 🐋 🚨

< p​ > (my matrix screen filled with hearts because of that)

< r​ > Moonstone/sgp is trying for something?

< r​ > Mine did as well

< p​ > XD

< o​ > 💝 +2696.73 #xmr 💝 $464889.28 😉

< p​ > - 💝 +2696.73 #xmr 💝 $464889.28 😉 nitter / X

< p​ > so many hearts

< h​ > not again

< o​ > #wereback

< h​ > this is an attack on slow machines lol

< p​ > laptop crashing

< p​ > haha

< r​ > Why are you running something as heavy as element on a slow machine?

< r​ > Use a simpler one

< o​ > Good meeting.

< o​ > thanks everyone

< r​ > Goodbye, thank you

< p​ > missed an events summary from msvb-lab but i assume this will happen at the events meeting

< r​ > Pretty much just looking at forming association and getting ready to sell tickets

< p​ > i think we can pencil a meeting in 2 weeks (23rd?)

< r​ > The channel right now has a summary of TODOs

< msvb-lab > It's fine plowsof, as I only wanted to give the events summary after you added the request in the agenda.

< plowsof > ah ok

< p​ > dsc_ dare i ask for a roadmap of feather desktop?

Automated by this


16:20:24 <m-relay> <h​> boog900: re: db documentation - the code/design itself
16:20:58 <m-relay> <h​> try replacing any subsystem in `monerod` - "just read all the code"
16:21:42 <m-relay> <h​> i'll be making this thing such that i can die in 3 months and someone can come along and read easy english on how to pickup exactly where i left off
16:32:21 <m-relay> <b​> yes but my point was that there isn't a lot we can do to benefit monero core right now so although we can (and will) document how Cuprate is doing things, which when Cuprate is up and running will help maintainers we can't really document how monerod is doing the database without going out our way to do more work which will `spread limited resources unnecessarily`.
16:32:22 <m-relay> <b​> With the p2p and consensus code I already have to look at how monerod is doing things.
16:33:18 <m-relay> <e​> ah yeah, the guy who wanted me to redesign the entire website and that disappeared when i asked them to provide more details. A solid contributor whose opinion is very important, clearly.
16:34:16 <m-relay> <e​>
16:36:14 <m-relay> <b​> IMO cuprate will help (and already has helped) core-monero anyway so it shouldn't matter that this proposal doesn't have a direct benefit, it allows more work which will have a direct benefit
16:45:57 <m-relay> <c​> plowsof: sorry i dint reply. Yes meetinf in 15mins
16:46:06 <m-relay> <c​> Meeting*
16:47:49 <m-relay> <h​> maybe someday cuprate will stop being... "the alternative", so it's a (in hindsight) direct benefit :)
16:48:22 <m-relay> <h​> i worry for the future poor soul who will read my code not knowing what the hell is going on
16:59:09 <dsc_> <p​> dsc_ dare i ask for a roadmap of feather desktop? <== The device doesnt have a name yet. Ill post a devlog on, to follow progress for those interested
17:00:16 <m-relay> <b​> We will have docs so it should be easier to understand than monerod :)
17:01:13 <m-relay> <o​> Boog, are you guys doing seraphis in parallel
17:01:26 <m-relay> <o​> Or rather, would it be a good idea to?
17:01:57 <m-relay> <s​> Hey everyone, PLEASE do this! Thank you!
17:02:00 <m-relay> <o​> "cuprate releases the First testnet daemon for seraphis"
17:04:48 <m-relay> <b​> AFAIK some important things are still in discussion? so I would say now is not the right time for us to start this, monero-serai would need to be updated first
17:07:59 <m-relay> <o​> Seraphis, i think, should be your focus (unless were _not_ doing seraphis, it doesnt make sense to implement an EOL protocol)
17:09:57 <m-relay> <r​> Good point
17:10:18 <m-relay> <o​> and as far as in discussion - this is your chance to help decide how things are going to be implemented, and to do it first
17:10:36 <m-relay> <r​> cuprate has to implement all the EOL protocols because it has to sync from genesis.
17:11:03 <m-relay> <r​> Most of Seraphis code work is in the wallet, not the daemon AFAIK.
17:11:50 <m-relay> <o​> But who's working on thr daemon..
17:12:31 <plowsof> no daemon left behind
17:13:15 <m-relay> <o​> And yeah, i dont mean "you can skip the whole blockchain and just do seraphis" i obviously meant "dont recreate stuff we arent going to be using down the road"
17:13:52 <m-relay> <o​> Like, if wallet 3 is replacing wallet 2, dont bother rewriting wallet 2. Just go straight to wallet 3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
None yet
None yet

No branches or pull requests

3 participants
@selsta @plowsof and others