Cassie Heart pfp
Cassie Heart
@cassie
Hearing this Ledger news makes me chuckle a little, because I have maintained a distrust of vendors hawking “HSMs fix security” consistently.
2 replies
1 recast
7 reactions

Cassie Heart pfp
Cassie Heart
@cassie
I think the thing that’s ruffled so many feathers about it is that people felt like there was an implicit contract that Ledger couldn’t export your key and this update gives the device the ability, which is a double-whammy of “actually, they always could” & “just trust that we won’t do it unless you ask”
2 replies
0 recast
5 reactions

timbeiko.eth pfp
timbeiko.eth
@tim
yeah, latter bit is by far the worse IMO. big difference between "if I install untrusted firmware, I'm screwed" and "if the new feature doesn't quite work like it's supposed to, I'm screwed"
0 reply
0 recast
3 reactions

Daniel Lombraña  pfp
Daniel Lombraña
@teleyinex.eth
This is why we need open source solutions, so we could fork it and run it without this feature. Moreover, to audit the firmware.
0 reply
0 recast
2 reactions