<oembed><type>rich</type><version>1.0</version><title>waxwing wrote</title><author_name>waxwing (npub1va…knuu7)</author_name><author_url>https://yabu.me/npub1vadcfln4ugt2h9ruwsuwu5vu5am4xaka7pw6m7axy79aqyhp6u5q9knuu7</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>We all (who have tech skills) are at least a little bit at fault.&#xA;&#xA;We never developed some kind of norm of: how can you assure your users that their private keys are &#39;proper&#39;?&#xA;&#xA;Were they supposed to look at them? No.&#xA;&#xA;If you grab your randomness from the OS, you can&#39;t know, via testing, that the result will be random for a *user*, who is using a different machine than you. But why don&#39;t they have a simple push button test to check by sampling?&#xA;&#xA;Obviously it&#39;s a bit harder with HWW but same principle.&#xA;&#xA;Actually I&#39;m genuinely curious what people think about that.</html></oembed>