pull down to refresh

I maintain that this is an utter failure. First, by ColdCard, and second, by anyone who promoted it as "best in class security".

Usually, when I hear about some major security breach and try to read up on what happened, I can't really understand it because it's exploiting some weird interaction in the internal memory of the computer or somesuch. (Or just plain and simple social engineering, which is a different beast)

But when I read about this vuln, I understood immediately. The fact that it was so simple and that no testing process caught it... it's just a bit crazy to me to even imagine that. Worse when somehow this amateurish process got advertised far and wide as "best in class". How....?

I think it does kinda expose how much of the bitcoin world is really just LARPing (#1537803). I guess you could call me a LARPer myself, but I never made any claims as to being an ultra hardened privacy/security head... just a pleb.

For the record, I didn't use ColdCard and my coins are safe. So my negative reaction is not personal. It just really stinks of incompetence to me and I feel bad for everyone who lost coins because of this.

Not proven, but could be more than just incompetence. Shutting off HW RNG is too much of a rookie move. No seasoned dev does that by accident.

reply

Plausible. We'll see what shakes out of all this.

reply

Feel bad for whoever got rekt, but bottom line: this ain't a Bitcoin issue, it's on the HW vendor. And second, don't trust, roll the dice!

reply