Avatar
Feels Guy
d5805ae449e108e907091c67cdf49a9835b3cac3dd11489ad215c0ddf7c658fc

I live in my car but not sure I can drive there

I want to respond so bad "happy new year" in odell caps but I'll resist

My gf is on her 6th set of HOKAs and is a full time athlete

Replying to Avatar matata

lol

Responding so u don't respond to ureself a 4th time. Yw fren

Replying to Avatar 7Bluerabbits

Don’t use Ledger Live (the supplied software) with Ledger (use Sparrow or Wasabi)

REKTBuildr 🔺🔺🔺

@rektbuildr

Ledger Live embeds the genuine check into the apps listing procedure. As it is, they always doxx your device when installing or updating apps and firmware. I removed most tracking in Lecce Libre, but they still track you regardless.

For the past couple days I'd been trying to find the genuine check code in Ledger Live

There's "genuine check" labeled code everywhere, but I added tracing prints to it and none of that code was ever run when it checked the device. I thought that was funny so I continued digging.

Looking at the Python code (below) instead of the convoluted Typescript from Ledger Live desktop, I finally understood what's happening

Ledger's genuine device check is embedded with the listApps subroutine. It's kinda hidden there TBH

I tried disabling the remote tracking and it's impossible, it breaks if you do.

Which means Ledger knows it's you every time you plug the device in. During that procedure it lists which apps are installed in your device, so they also know what you're running on your HW.

So right now there's no way to operate Ledger HW's anonymously. They know every time you plug your device in and which apps you have installed. It was even worse before Lecce Libre, it also tracked your crypto balances!

So, the obvious question is why did they glue together apps listing and genuine check? They're not trying to save network calls, that's for sure because their software makes 2 thousand network calls for all sorts of unnecessary stuff (I've removed them from the sources and the system still works).

There were red flags.

#m=image%2Fjpeg&dim=1079x973&blurhash=%3BOI%23x%3A-%3B_NVY%3Fbo%7D-%3Bxat7Rj4.tR%252jr%25ft6xuRj_2RPn%24W%3BM%7CogRPoeoeD*xuR%2Bt7s.RjNGaetQW.aKenNHt7xaozkBs%3AE2t8xaWBR*e.ofR*azt6IUt7xuWBRjWBt7ofD%25RjRjkCt7xaWBkCxu&x=07109d25a4a865177fe8c5a5450ee054305f3af56c70fbba6bc7f5fc12125e3c

Ure use of "more" instead of less makes Mt brain malfunction