Josh
· 2w
Complementary is exactly how I see it too. favillakey.io/security is best read for now. Would genuinely value your read on it. The site is a bit simplified, I will add the technical document and firmw...
I looked at the site overall. I can't really comment on the hardware tooling since I don't know much about that topic, but the amount of detail that's included plus the effort to not over-promise make it seem conscientious and to some extent trustworthy. I guess "trustworthy" may not be the best word because there's an emphasis on auditability, verification, and disclosure, so in a way you're not asking for people's trust, which seems like the right posture.
The combination of secure boot + source code for the firmware + reproducible builds is maybe enough to make the device auditable, at least to the extent to which that's possible at all? Not an expert, but I guess the residual trust is that these things are actually implemented correctly and as promised at the hardware level?
One thing that wasn't completely clear to me from a quick look is what *types* of things can be signed by the device. It seems like it's "Bitcoin transactions" and "Nostr events", and I guess any type of event? Can anything else be signed?