people are making false presumptions? For me it’s clear. No hardware should be able to extract the private key
I think, I will continue using mine. Don't know if I will update firmware. Will definitely not use this Recover functionality ever. And will definitely not recommend Ledger as wholeheartedly as before. It *is* disappointing that key extraction is not prevented as fundamentally as previously thought. The communication of the Ledger team *is* totally disappointing (e.g., claiming that the keys never leave the secure module, while *obviously* enough information to recover them *does* leave the secure module is so far beyond …). To be honest, I thought that the secure module was safer, but could have known that that is not the case before that. This tweet somehow summarises my position: https://twitter.com/roinevirta/status/1658525016550416384 And the discussion below shows that it's clear for a long time that apps *can* get private keys from the secure enclave. On the other hand, Trezor as far as I know does not even *have* a secure enclave. If the argumentation is that a rogue firmware can get keys, that is very much also true for Trezor.
So, our current only option is paper wallet?
With a huge difference. Trezor is open source.
Paper wallet cannot interact with smart contracts :(
Обсуждают сегодня