pull down to refresh
Meh. They've been attacking this with words forever. Are they going to withstand a targeted attack? Time will tell.
The real question is why didn't we find a truly critical error that existed for 7 ish years?
I know why I didn't find it - I didn't review all the code back when I manually reviewed and didn't notice it. I stopped using my coldcard by the time my bot-aided review set-up was productive. I never ran it on the improved system.
I wonder why Ledger's lab didn't find it. Why in one evening we find not one but 2 critical issues. It means that my surprise at Evan being surprised someone is reviewing his code, was me living in opti dream space. No one is doing shit, we're all yolobois.
On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license
So this was the precise moment of the vulnerability?
Zach Herbert, CEO of Foundation Devices (a ColdCard competitor) put this out a few hours ago, alleging that this problem has its roots in CC's attempt to avoid an open source license: