I don't even know what to think about Coinkite as a company anymore. I really liked my ColdCard and was convinced Novak was the most paranoid person on the planet about security. I don't think that company survives this.
As of last night I don't use ColdCards and will never recommend them to anyone ever again.
Nothing about this is right. Lives were destroyed and all Novak did was essentially say, "I'm sorry".
Login to reply
Replies (9)
what else can he say, though?
Yeah, this is a nightmare scenario for them. As I have said elsewhere, and maintain, the hardware wallet has one job: to protect your seed material during use.
It is not your hardware wallet’s job to generate entropy. It is not your hardware wallet’s job to resist an attacker long-term with physical access.
But, I accept that my stance is unconventional.
People get into this field with the “don’t trust, verify“ mentality, but then they place all their trust in the single most important thing that must not fail. The generation of their seed.
Sorry is an obvious one, followed by some sort of step to try and make things right- probably impossible though. Would have been better if his first response hadn't been to dismiss it.
He didn't even do that.
They're also downplaying/misstating the threat.
I stopped recommending ColdCards a little while ago. Something irked me about NVK's reliance on IP. That's bad philosophy. That's evil.
A rare post that actually says what I've been saying. I still think the need to sell hardware wallets has caused of what a hardware wallet is supposed to be and how useful it is and is not supposed to be all in the name of sales.
In hindsight, we should push for it to be common practice for devices to warn users that generating keys on device is not guaranteed to be 100% secure and to propose rolling your own entropy.
By the way, even supplying dice rolls to a device is not good enough. If you can take that entropy and turn it into 11 words yourself then when the device gives you your 12 seed words, at least you can compare notes and know that the computer is using the entropy you provided.
Or back up even further if they had left seed signer alone. Karma is a btch they say.
Is activity on nostr tracks with the downfall.