trust a hardware wallet?

or verify?

did you verify your coldcard wallet? your blockstream jade wallet?

did you verify every single word of the opensource code of your wallet? did you understand what those words in the code mean? are you a programmer? did you know in what programming language the code is written? from where did you download the code? how did you verify that it is the same code which runs in your device?

how did you verify the hardware components in your device? how many units of hardware storage, memory and how many controllers did you find on your device. how did you verify that every single component was working properly and as intended? even if all components correspond with the image of the manufacturer, how do you know that the manufacturer did not put additional components on all devices in order to take all your coins later when they have reasonable value? how did you verify that no additional code was put into any memory or other storage device ?

did you build another device using similar components running the opensource code with the same results?

congratulations. your device seems to be verified and safe to use.

even if you are a hardware and software engineer graduated as phd from mit you will have a hard time doing all that. it will take days or even weeks to verify everything.

anyone else will have to trust the device maker.

or build his own device with opensource code (same challenge to understand the code and verify)

at the end there is always someone or something you need to trust.

i would never trust anything coming from canada.

in bitcoin i would rather not trust a us company for obvious reasons.

i would rather trust the czech company trezor and the french company ledger. they are the oldest hardware companies and never had any funds stolen out of their devices.

defamation and unfounded attacks do not change a thing

Reply to this note

Please Login to reply.

Discussion

💯💯💯💯

I can’t verify half of that!

This is the concern we should all have!

Never thought about Canada being an issue but it is!

The 👀

Canada 🕵️‍♂️

I agree with you overall but closed source ledger no one can verify the firmware. At least with open source software and hardware there is a more people checking the code and the hardware for potential bugs, backdoors, etc. there is always some level of trust unless you possess the ability to verify everything yourself. But this can be done collectively at least when it’s open source.

the secure component on the ledger is a seperate chip which runs a proprietary software.

for various reasons it is not possible to run opensource software on a secure chip.

there are arguments from highly specialized security software engineers that a security chip running a proprietary security software is safer than a hardware device running opensouce code because opensource code can be analyzed and exploited by attackers.

at the end of the day it comes down to trust.

This is a very poor take. Trusting on the basis of geographical location… Did you read the new MICA regulation that’s coming into effect in Europe? Can you imagine what European signing device companies have to do? ID and monitor every transaction…