Agree.
Although I don't think people should have audited ColdCard necessarily. It's the job of the company behind it, they are selling a security product. Not auditing and not having a bug bounty program is a much bigger failure than having the bug itself. Bugs happen, but a security company yoloing it is a borderline scam.
I'm happy I've never used it and never recommended it (open source Trezor is a much better deal).
Otherwise very good post and I agree it was not a conspiracy. Very few things are. Conspiracies are hard to coordinate, harder to keep secret and even harder to have intended effects.
View quoted note →
Login to reply
Replies (1)
I never was so deep in this project to know about this points, because I had a bad feeling about their moral integrity.
Happy to see my intuitive bullshit detector worked again.
And sad so many people don’t have such detector, even they seems much less autistic.