...
But best thing you could do is to stop using devices from anti-open source creators, and switch to better open source alternatives.
Correct me if I'm wrong, but coldcard has a type of license where the code is
source-available, meaning its firmware is publicly accessible for review, study, audits and security checks. However, it's proprietary code, not closed, which means redistributing Coinkite's code or using it to create competing products isn't allowed.
This is why coldcard's firmware is not considered open source, yet it remains available to the public. This allows technically skilled individuals to verify whether the code does exactly what it claims or if it hides any secrets.
I just can’t recall the name of the license Coinkite started using for the code. I believe this change happened because Passport copied part of coldcard's code (please correct me if I’m wrong).