pull down to refresh

go ask the onceler, he knows! I agree with you, but to challenge it anyway:

what if a person knows that they won't be able to get rid of trusted single points of failure? For instance, they may know that they are not going to be able to do a good job of auditing hardware signer code and they may also know that they aren't going to be able to do a good job of evaluating the financial wherewithal of a given custodian (eg Prime Trust was a shit show). But they may still one over the other because they think they will be slightly better at the one than the other.

The real question though: did the custodian review the code to their HSM?

reply