I could make the counterargument that the usb cable providing host entropy adds complexity to the RNG code, more places for bugs. And now we have to worry the software on host is sending good entropy, and that same untrusted host is not sending /malicious entropy/.
Complexity is the worst enemy of security.
While I agree that more entropy is better, in this case we add an attack surface and code complexity for something that can be handled entirely on device. Have the device use sufficient entropy, and use cryptographically secure algorithms.
This device sw is open, and could have been discovered any time. Finally someone found it. Because the 1st batch went to a single wallet I hope the situation ends up being whitehat rescue, and people get refunded.
Weak key generation in Bitcoin wallets is an evergreen problem. Analyze your favorite wallet today!
I could make the counterargument that the usb cable providing host entropy adds complexity to the RNG code, more places for bugs. And now we have to worry the software on host is sending good entropy, and that same untrusted host is not sending /malicious entropy/.
Complexity is the worst enemy of security.
While I agree that more entropy is better, in this case we add an attack surface and code complexity for something that can be handled entirely on device. Have the device use sufficient entropy, and use cryptographically secure algorithms.
This device sw is open, and could have been discovered any time. Finally someone found it. Because the 1st batch went to a single wallet I hope the situation ends up being whitehat rescue, and people get refunded.
Weak key generation in Bitcoin wallets is an evergreen problem. Analyze your favorite wallet today!