Replying to Avatar Cyph3rp9nk

anti-exfil protocol by Blockstream.

https://github.com/BlockstreamResearch/secp256k1-zkp/blob/d22774e248c703a191049b78f8d04f37d6fcfa05/include/secp256k1_ecdsa_s2c.h

Everything Blockstream does is opensource, I have never understood the hatred of the community towards blockstream, I guess ignorance is very bold.

As notes:

- Jade is fully opensource, both hardware, software and firmware.

- Because of this you can build your own Jade (DIY) avoiding supply chain issues.

- It solves the problem of secure elements through a multi-signature pin system.

- If you don't understand how such a multi-signature pin system works and you are fucking paranoid, you can build your own oracle server. This doesn't really make any sense if you understand how blockstream's oracle server works, other than blockstream may stop providing service.

- Jade is really inexpensive compared to other competitors.

- You can do air-gapped transactions.

- For those who criticize Bluetooth you can disable it through firmware so that it is totally inoperative due to the lack of low level driver.

Honestly, Jade is a HWW made for the community and by cryptographers and not for profit (in my opinion), blockstream does crazy things that don't exactly benefit their pockets (also in my opinion), that's why I don't understand many times the hate that is poured against them.

Here you have the instructions to make your own Jade:

https://github.com/Blockstream/Jade/tree/master/diy

Talking about anti-exfil, what opinion do you have about the Keystone 3 Pro (only bitcoin firmware)?

Reply to this note

Please Login to reply.

Discussion

It uses secure element (I don't like it) although they have followed the trezor safe model and use secure element with open firmware, so, in theory, you could test the specification and check all the inputs and outputs generated by the chip.

From my point of view, I rule out any HWW that uses secure element, except for what trezor is building with Tropic.

Secure Element are black boxes, by contract you can't even disclose the vulnerabilities found.

In cryptography there should be no trust.

the masses?

I was thinking something similar, I like the HWW but use secure element, when they advocate open source (software and hardware), it's not very congruent, IMO.

Still, I'm trying to get their point of view.

Thanks!