pull down to refresh
0 sats \ 0 replies \ @final 8 Jul 2023 \ parent \ on: Trezor developer confirms private keys can be extracted if firmware is corrupt tech
No. Because then it wouldn't be a wallet/signing device. The private key is needed for core functions like transactions after all. The best you can do currently is hardware security that prevents extraction capabilities of that information which Coldcard and another certain specific controversial wallet by secure elements.
Trezor doesn't do it because secure elements arent open hardware and there isn't a production one available. Trezor has a lot of hardware vulnerabilities, such as being able to brute force the PIN without any protective measure or rate limit.
Blockstream Jade doesn't either but uses an Oracle functionality or SeedQR to use the private key without actually storing/knowing it. That doesn't fix the issue, only circumvents it by making another device or object be part of trusting that instead.