Absolutely exhausted and don't have the energy to copy paste this from Twitter, but I put together an exhaustive thread on the nightmare fuel that is Ledger Recovery here:

https://twitter.com/sethforprivacy/status/1658544658761277447?s=20

Nitter: https://nitter.sethforprivacy.com/sethforprivacy/status/1658544658761277447

Reply to this note

Please Login to reply.

Discussion

Hey thanks for the nitter link also!

TY + your zapper isn’t receiving

Holy shit that's a train wreck. I simply cannot believe that they "innocently" introduced a code path that excivates private keys.

Zapped you 10,000 nokyc sats for your efforts.

You would think!!! The thing is that NO TRUST security is Ledgers' stock in trade.

The problem is, if their device works as it should, then their business model will run out of steam. Looks like their investors wanted development to keep on rolling.

🔥

Great thread, thanks

Currently have my finger hovering over the “purchase” button for a Foundation Passport

i would not

Why?

Happy to answer any questions you may have!

It's a fantastic device, FOSS and FOSH, privacy-preserving, and tons of integrations.

Plus now Nostr key support and key delegation coming shortly in a beta 😏

I pulled the trigger 🔫

Great thread and well said. What a cluster fuck.

I cannot zap ⚡ you 😒

Payment failed..

It worked finally..

Sorry can be a little buggy with BTCPay!

Thanks for including the Nitter link.

If future updates can extract and export the seed words, encrypted or not, the “secure element” chip does not function as I thought it was supposed to function. 😡

Would be bad even if code was open but the fact it can’t be independently verified makes it even more absurd.

it is an additional service which you do not need to use

if you do not use it, nothing will change

it is the most secure hardware wallet together with trezor

https://stacker.news/items/179501

It seems to me that if it’s possible to do, then it opens Pandora’s box for all users, not just those who opt in.

It’s the same logic behind why back doors for even “good reasons” are a bad idea.

Thx for compiling this thread 🙏🏼

Could you name two or three truly open source hardware wallets, please!?

Very few are actually open-source, only ones I can think of are:

nostr:npub1s0vtkgej33n7ec4d7ycxmwt78up8hpfa30d0yfksrshq7t82mchqynpq6j

Trezor

Shift Crypto BitBox (haven't used myself)

SeedSigner as well!

#[6]​ Jade no?

#[4]

Ledger needs to post a $1M+ bounty on hacking the device with the new firmware.

Thanks for the analysis and summary. I was waiting for more information before judging what was originally put out by Ledger. You have outlined quite a few security concerns. Appreciated.

It’s a good thing that I never used their wallet after purchase. I felt bad about wasting money not anymore! Thanks for the info!

Thanks for the explanation. Clearly internet privacy is becoming a fundamental life skill like looking both ways when you cross the road. And a lot of millennials can't even do that.

Great thread.

If I didn't know better, I'd say that Ledger got requested by the Government to find a way for their costumers to start doing a KYC...