Just to clarify, the hack had nothing to do with secure elements; the issue of secure elements is a personal crusade of mine. The hack was a rookie mistake—they failed at the most basic level: the seed entropy.
đź”” This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.
Edit
Just to clarify, the hack had nothing to do with secure elements; the issue of secure elements is a personal crusade of mine. The hack was a rookie mistake—they failed at the most basic level: the seed entropy.
Guys, you need to be prepared for all this crap. Remember, if you use a passphrase, make sure it has at least 128 bits of entropy. Otherwise, use multi-signature. I'm afraid more vulnerabilities will come to light over the next few months.
Today I'll only say one more thing. Satoshi's coins have not been hacked, even though hardware wallets and multisignature didn't exist back then. Think.
The main Bitcoin program/podcast in Spanish has only been recommending failed solutions from the very beginning. They ignored my recommendation not to promote secure-element hardware wallets (HWW), especially ColdCard, which I have been very critical of. They ignored my recommendation not to promote Samourai because it was a flawed solution. They ignored my recommendation not to promote HODLHODL as a non-KYC service. The problem is that the host is an industrial engineer, and his main assistant, who gives opinions on privacy, is not a computer scientist either. They are simply outsiders to a profession they do not practice, and this is the result: they have done a great deal of harm to the community by teaching things incorrectly.
They're a black box that I don't know what it does, and it violates Kerckhoffs' cryptography principle.
Just to clarify, I wouldn't use the Trezor 1 for many reasons. The main one is that you can't enter the passphrase on the device, and it doesn't have MicroSD card encryption for the PIN either.
It has a secure element
Non nobis, Domine, non nobis, sed nomini tuo da gloriam.