pull down to refresh
reply
Most of them. A physical attack doesn't need your device to be online.
If you're a nobody and/or you're protecting a small amount of coin, fine. If one day your stack becomes significant (from your subjective pov) or you grow up to be on anyone's radar, you need to reassess every choice you made based on available tech rather than based on protocol. But if you can't afford a $5000 laptop and need to get a $50 one, then that says something about your stack size already, so no worries, I guess.
We often use to model our security around available/known tooling, so this is not criticism of you or your solution per se; hobby security is the norm anyway in this space. It's fine if nothing is truly at stake.
reply
Security is a process. Not a set of tools. So take away all the tools at first, don't build around them. Make a great process. Then, find the tools that will (provably...) make the process more bearable and check the tradeoffs.
What you just did here is to avoid a hardware wallet, let's trust cheap and definitely bugged hardware and install the software with the most exploits that ever existed: the linux kernel. Have you done a kernel review lately? It's really complex and it's rather hard to actually spot weak points and patch or work around these. Not to mention you didn't explain how you're going to patch your installed kernel in the first place. Easier to maintain reviews of an ESP32 firmware, because it is less complex.