To me, there’s no big difference between stateless and stateful, because the purpose of a signing device is to protect the keys from leaks during use. In between uses, other key security measures apply (physical security, operational security).

I would not reuse a signing device for multiple seeds though. Especially seeds that make up a wallet quorum. One hopes that each device’s erase function works, but it’s safer to assume that they’re each forever stateful.

Reply to this note

Please Login to reply.

Discussion

No replies yet.