Bitcoin Forum
December 25, 2025, 10:14:49 AM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 [13]  All
  Print  
Author Topic: Show off your hardware wallet  (Read 3541 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
LoyceV
Legendary
*
Offline Offline

Activity: 3906
Merit: 20747


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
November 18, 2025, 08:53:42 AM
 #241

If the issue for you is about the Ledger being closed source
I'm pretty sure the issue is Ledger's lying about "the seed can't leave the secure element":
the future firmware releases will add the ability to unsubscribe from this service
So they went from "the seed can never leave the secure element" to "don't worry, our software broadcasts your seed to our servers" to "trust me, we won't do that again if you don't want to"? Lol.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 8876



View Profile
November 18, 2025, 04:34:45 PM
Merited by LoyceV (6), NeuroticFish (5)
 #242

If the issue for you is about the Ledger being closed source, I believe the Trezor Safe 3 has the same issue? The firmware of the chip is closed source, like the Ledger and the SafePal.
The secure element on the Trezor Safe 3, like all other secure elements, is closed source. So Ledger and Trezor are similar in that regard. One difference is that Ledger's SE manufacturer required the signing of an NDA. The company can't disclose findings and vulnerabilities of the chip. Trezor's Optiga Trust SE doesn't need a signed NDA.
Besides that, other areas of Ledger's ecosystem are closed-source, which isn't the case with Trezor. The firmware on your device for example.   

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Wind_FURY
Legendary
*
Offline Offline

Activity: 3514
Merit: 2121



View Profile
November 19, 2025, 06:00:24 AM
 #243

If the issue for you is about the Ledger being closed source


I'm pretty sure the issue is Ledger's lying about "the seed can't leave the secure element":



the future firmware releases will add the ability to unsubscribe from this service

So they went from "the seed can never leave the secure element" to "don't worry, our software broadcasts your seed to our servers" to "trust me, we won't do that again if you don't want to"? Lol.



I'm confused. Is that when you have their "Ledger Seed Recovery" service on? OR the seed could still be broadcasted to Ledger's servers even if the service is OFF?

That's a serious issue.

But OK, the closed source firmware could also a real issue because we're also merely trusting the company that the device is secure.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
LoyceV
Legendary
*
Offline Offline

Activity: 3906
Merit: 20747


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
November 19, 2025, 06:19:54 AM
Merited by Pmalek (3)
 #244

I'm pretty sure the issue is Ledger's lying about "the seed can't leave the secure element":
I'm confused. Is that when you have their "Ledger Seed Recovery" service on? OR the seed could still be broadcasted to Ledger's servers even if the service is OFF?
It's impossible for us to know whether or not they still broadcast the seed phrase, but I'm sure as hell not going to trust a company that has lied before. Besides, if a firmware update can gain access to the seed phrases, a hacked firmware can do the same.

Quote
That's a serious issue.
That's an understatement Wink

Quote
we're also merely trusting the company that the device is secure.
They've shown they can't be trusted, so I'm not trusting them. If I wanted to trust companies, I'd use banks instead of Bitcoin.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 8876



View Profile
November 19, 2025, 08:18:26 AM
Merited by NeuroticFish (3)
 #245

I'm confused. Is that when you have their "Ledger Seed Recovery" service on? OR the seed could still be broadcasted to Ledger's servers even if the service is OFF?

That's a serious issue.
That's just the thing, we don't know. What we do know is that they have said things that have turned out to be false before. Seed extraction code is embedded in all firmware on their new devices. No one can check how long it's been there because the code is not public. You can only choose to trust what they say is true. And let me remind you that Ledger has been saying that your keys can never leave the secure element. Turns out that they can easily be extracted with a few lines of code.

They have talked about making Ledger Recover or some parts of it open-source. That hasn't happened. Instead, they have released a second backup system, but this time as a physical card.

The entire idea behind Ledger Recover is for law enforcement to have a backdoor to your wallet. Shards of your seed are in the hands of different companies. If law enforcement needs Ledger to freeze your crypto, all they have to do is ask. Since everything is closed-source, there is no way of knowing if this freezing feature is possible against everyone running the latest Ledger firmware or if it's exclusive to those who have signed up and paid for Ledger Recover.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
NeuroticFish
Legendary
*
Offline Offline

Activity: 4256
Merit: 6970


Looking for campaign manager? Contact icopress!


View Profile
November 19, 2025, 07:18:29 PM
Merited by Pmalek (3)
 #246

I'm confused. Is that when you have their "Ledger Seed Recovery" service on? OR the seed could still be broadcasted to Ledger's servers even if the service is OFF?

That's a serious issue.
That's just the thing, we don't know. What we do know is that they have said things that have turned out to be false before

It's not just that. It's also that we cannot know what surprises will "the next" firmware update come with. Maybe something is not enabled or broadcasted... now. But tomorrow?
And why take any risks if you can just get another HW at under 50$ for Black Friday?

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 [13]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!