āāš§ [Long Research] Topic: Ledger, HW and Security
Ohayo, have you heard of the Ledge⦠- OMG STFU š¤¬
Hold on; we wonāt bore you with just an annoying recap. This post is more of a quick thought-piece for you to consider and maybe calm your nerves. Scroll to āWhat now?ā if you are up-to-date.
Ledger fiasco 1-2-3 š¤¦āāļø
A few days ago, Ledger announced the launch of Recover. It allows users who opt-in and subscribe to use it as a backup for their private keys. The service splits the userās seed phrase into three encrypted shards and sends them to third-party companies⦠smth like that. Ledger, especially, made statements about their use of the secure element, and 6 months ago they published a post where they said: "A firmware update cannot extract the private keys from the Secure Element".
They pretty much lied to our face again. Morons, truly.
The trouble lies somewhere else - any HWW can have firmware written to extract the seed, as it seems after this charade. The problem is that Ledger is a closed source, so no one can verify that it isn't happening, no matter how much they promise there is no backdoor.
- Trezor is able to do the same thing, but itās open-source, so you can kinda check it;
- GridPlus is the same as Ledger in this case, but they promised to open-source soon.
It all depends on your threat model. But if we decide to trust our information to Ledger, then it's worth remembering a story about the Ledger data leak that exposed usersā information in 2020 & moreā¦
You already knew they could do it; you just didnāt THINK!
Remember when you were happily downloading new chainsā integrations on Ledger? But some of those previously have not been a part of the old encryption list. So, it was new-new. Well, this wouldnāt have been possible unless this ābackdoorā existed. Basically, every developer around the world happily continued installing those updates and didnāt think twice.
What now, any alternatives? š¤
Donāt update the firmware for as long as you can. When Metamask stops functioning with the older versions⦠well, seek another extension like Frame and the likes. Thatās an option. Here, you kind of have to assume that ledger devs havenāt fucked us yet and didnāt backdoor a firmware before.
Alternatives: Lattice1 and AirGap. Just google them and read more.
TINFOIL ON, THE GOVERNMENT IS WATCHING ME šŖ£
Welcome, Gnosis Safe. If you want the ultimate security, go make a safe. Make it 3/5 in case you are afraid to lose the 2/3 keys. You have to believe contracts are safe, but with the amounts they are holding today⦠we all pray they are. Itās like Saylor, if hacked, itās all pretty bad from there.
Be careful not fucking yourself, unless you genuinely like DPā¦
You can go very far with upgrading your security, so my question to you would be - are you sure that you are worth it and that you know what you are doing? If you are not a developer, there is a high chance of you facking yourself over with wrong moves. Are your $$ even large enough?
- If you use a VPN like NordVPN, itās dumber than no VPN
- If you double-encrypt something, itās dumb as hell
- If you use your real name in apps, itās also unsafe
How safe can you go, anon? Well, you arenāt anon after all. Donāt go too tinfoil; it never ends well. But if you must⦠CIA writes about these things (not the agent, lol) - you can check it out.
More threads š¦
- https://twitter.com/Mudit__Gupta/status/1659071865762230274
- https://twitter.com/notsofast/status/1658538053219016707
- https://twitter.com/PixSorcerer/status/1658511668853501952
- https://twitter.com/hosseeb/status/1658740433361702913
- https://twitter.com/web3_Phil/status/1658525128928395269
Post #929
6.68K