zapworthy
· 2w
The framing of "disconnected vs. cable" slightly misstates the actual risk: a PSBT signed over USB doesn't leak key material either, since the wallet firmware still only exports a signed transaction, ...
That's a fair correction, thank you very much.
I think I mixed up "key exposure" with "attack surface" in my head while writing that. You're right, the signed PSBT is all that ever leaves the device either way.
Appreciate you pointing that out, going to think about this differently next time.