Replies (25)

From the Jade Security Disclosure: The vulnerable code can only be reached on an initialized and unlocked device, where the device was unlocked using the same interface that the RPC is called on. This means a USB-connected device is only vulnerable to USB-RPC calls, and a Bluetooth connected device is only vulnerable to Bluetooth RPC calls. A device that has been temporarily unlocked is only vulnerable on the interface that was chosen when it is unlocked; QR mode is not vulnerable as it does not expose an RPC interface at all.
Motosashi's avatar
Motosashi 2 weeks ago
My Jade was such a liability. Ditched it immediately after I realized I could access my coins WITHOUT the device connected
Oh boy, i am so excited about Blockstream products! So looking forward to using liquid as a scaling solution.
I'm not saying they are, not agreeing or disagreeing. But, a lot of th funding for rhe core Dev team comes from blockstream from what I understand. That alone is suspicious
How long has Bitcoin existed now? You'd think by name someone would have made a user friendly way to spend /store it that doesn't make you vulnerable to thieves or whatever.
By now. I don't understand how I wrote name instead of now. The letters aren't even next to each other
Motosashi's avatar
Motosashi 2 weeks ago
Jade locked up, wasn’t able to enter my passcode into the device. Opened the green software, entered the pin on the laptop, withdrew all my coins. Jade wasn’t even connected to the laptop
because the micro SD Converter/holder broke in half the 2nd time I tried to use it and I could never figure out how to use the micro SD card to do the software updates. I never could update it. It may have been my favorite device, but the user friendly aspect still was not there.
Default avatar
Duvel 1 week ago
Every hardware wallet has this issue at some point. Can your heirs use your hardware wallet in 15 years? They'll need so many firmware updates that the device will probably be unusable. So they'll need to buy a new one, anonymously, if the product still exists or it doesn't have a "feature" that "conveniently" separates your seed into 3 parts and shares it Edith3 different companies, like Ledger did. Seems something like a SeedSigner is much more future proof and doesn't have firmware vulnerabilities issues.
↑