They call it 'responsible disclosure'
Laughable. Trezor
claims that Ledger asked them not to publish this issue.
That being said, we were surprised by Ledger’s announcement of this issue, especially after being explicitly asked by Ledger not to publicize the issue, due to possible implications for the whole microchip industry, beyond hardware wallets, such as the medical and automotive industries.
They also posted The Workaround
By the way, there is another workaround for Trezor T users. Since the latest update, SD cards can be used to store a secret which along with the PIN can be used to encrypt/decrypt the data stored on the device. So, without the SD card inserted, the attack is not valid anymore.
Why Ledger is posting this now on all their social media and website? Am I missing something?
I believe it is Ledger's answer to Trezor's recent announcement of
Tropic Square.