I don't understand bitkey. There's no screen on it to see what you're confirming. If your phone is compromised and showing you a different address than where you'll really be sending the btc, what protection does the bitkey give you?

#btc #bitcoin #bitkey #security

Reply to this note

Please Login to reply.

Discussion

Quite the if.

If you take for granted that your phone is not compromised, you don't even need bitkey.

I don't understand this section of that webpage "Receiving Money: Screens Help, But Aren’t the Only Option"

That's not how Jade works. Your Green app (companion app) gives you an address and you can click a button on the app to "verify" that the address does belong to your Jade. You then click confirm on your Jade.

I don’t think the article claims every HWW with a screen behaves like that

> I don’t think the article claims every HWW with a screen behaves like that

They're explaining the problems with screens. In the case of Jade, what they're explaining doesn't apply, as far as I know.

The article is from two years ago and also talks about what they *might* do (like using the servers to do another verification). Do you know of a more recent article that talks about what they actually settled on and what they're doing now?

Fair point about Jade.

I do not have familiarity with a more recent article on this context. Their blog page is https://bitkey.build

Obviously their X account would include more recent things too

I'm not sure I would even be comfortable using an app and a signing device built by the same vendor (with or without a screen). If the vendor happened to be malicious then it would be trivial for the signing device to just show you the same wrong address as the app.

Many wallet are compatible with Jade (notably sparrow), from different projects.