pull down to refresh

I was listening to SNL, and I don't agree with you guys that this bug was nuanced and "anyone could have made this mistake"

Seed generation security is the #1 reason for a hardware wallet to even exist. If you can't figure out a proper test for the #1 objective of your product existing, you've done something wrong, end of story, no further nuance required.

Furthermore, it's not like this bug only manifests under certain hardware configurations or circumstances. It's literally just a flaw in the code logic. I don't think we can let them slide with a "could've happened to anyone".

68 sats \ 0 replies \ @Car 2 Aug

my instant reaction was yours as well, but after listening to the guys for the past two days i changed my mind on it

reply

Im fairly certain trezor has something built in to make sure something like this doesn't happen when generating seeds, some kind of entropy check. Either them or their CTO posted about it on twitter a few days ago but I didnt read it fully.

reply

Could not have happened to anyone. Could have happened to me though.

reply

I know you mention how you didn't catch it, but it wasn't your full time job to audit ColdCard's firmware. It should have been caught by any reasonably competent process of testing, IMO.

reply

I'm not saying it is a reason to let them off the hook. But, I am saying that in my past this could have been me. I have since learned to protect my own work better. And when I test a PR I always check this.

What I had not learned until now is to also game out every macro in a manual source review of software I depend upon. I used to skim build system and deps. This is clearly a dumb tactic; big fat learning point. Embarrassing even.

As a user of said software that has actually used it to protect his cold stash for a couple of years, and then again after a reroll... I am extremely disillusioned with my own reviewing capabilities and concurrently emboldened to spend even more time on review. Because all that would have saved me if it were still in use would have been gaming dice I reluctantly rolled while I felt it was something tinfoil.

reply

That's a humble take, and you're right, if I was solo coding it's definitely something that could have slipped me by (not that I would ever code anything security related in C let alone put it into production).

But this was a company that sold a product... they should have had a lot more redundancies in place and eyes looking at this all the time..

reply

As someone that started a career coding (and later managing other that code) secure systems mostly in C, I must disagree with the first sentence, haha.

I fully agree with the second sentence.

reply
1 sat \ 57 replies \ @Solomonsatoshi 1 Aug -10 sats

Could have only happened to 'sovereign individuals' who are in reality gullible herd following sheep.

You probably think Trumps invasion of Iran on behalf of Israel and Big Oil is justified and that he's winning.