Bitcoin Forum
May 22, 2024, 10:50:03 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Ledger library possibly compromised  (Read 215 times)
Pmalek
Legendary
*
Offline Offline

Activity: 2772
Merit: 7153



View Profile
December 23, 2023, 08:47:55 AM
 #21

Has Ledger at least explained how a former employee still had enough access to cause this latest debacle?
They have, but it doesn't make them look any better.
https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit

The most important parts about their security protocols:

- One person can't deploy any code without review by multiple other people. They didn't respect this procedure.
- They are talking about multi-signature access and what I assume code deployment. Again, none of that happened this time. Unless it's a lie that only one person got phished/hacked and not multiple people.
- Finally, ex-employees have all access rights revoked. Obviously, not this time.

Ledger even lies on their packaging:

Quote
"WE ARE OPEN SOURCE"

That's written on the box for hardware wallets running closed source firmware.  That's intentionally misleading, which means it's a lie.
Yeah, that's not correct. But I am pretty sure they were talking about the Ledger Developer Portal and everything concerning native and 3rd-party crypto apps (https://developers.ledger.com/). That part of their software should be open-source, (the Github rep. link is at the top right) but with the firmware being the opposite, one can't call the device open-source. I agree that it's misleading. 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Meuserna
Full Member
***
Offline Offline

Activity: 128
Merit: 190


View Profile
December 24, 2023, 01:53:35 AM
 #22

Ledger even lies on their packaging:

Quote
"WE ARE OPEN SOURCE"

That's written on the box for hardware wallets running closed source firmware.  That's intentionally misleading, which means it's a lie.
Yeah, that's not correct. But I am pretty sure they were talking about the Ledger Developer Portal and everything concerning native and 3rd-party crypto apps

That's printed on the box of a Ledger hardware wallet.  It's intentionally misleading.  It's a lie.  It would be one thing if Ledger hadn't been constantly lying to their users and in their marketing for a long time.  But at this point, there's no way to look at the long list of Ledger lies and then see what's written on their packaging and not see that it's intentional, and it's false advertising.

It's another lie from a company that constantly lies, and they lie about big things that matter.  They lie about their customers' security.  That's unforgivable.

Ledger is dirty.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!