Damus
Efrat Fenigson · 1w
In a couple of days I’ll hold an interview with Tomas Susanka, CTO of Trezor, about the Coldcard catastrophe & Trezor’s view. Apart from my own questions, I’d like to present some community que...
Nullius2140 profile picture
The ColdCard failure wasn't broken cryptography — it was broken entropy, so every sweep carried a valid signature: the ledger stayed true. So,
(1) Bitcoin assumes uniformly random keys but cannot verify how any key was generated. Does Trezor see hardware wallets as part of Bitcoin's security model, or as its weakest imported assumption? What would verifiable entropy look like, versus trusted entropy?
(2) At a terrible cost to people who did nothing wrong, the failure became the industry's early-warning system and everyone is auditing now. How could we get that sensitization without the casualties?
1❤️1
BitcoinSandy · 1w
Great question / topic