Damus
Foundation · 3w
Offline is the only security model that scales. Updates happen offline. Signing happens offline. Keys never leave the device. Just you and your keys.
JackTheMimic profile picture
Then why is an online connected phone necessary for Passport Prime initialization? Also requiring Bluetooth.
I read that "It was a design feature that was a necessary tradeoff" but why?

Why not initialize, use hash verification for genuine and firmware checks. Then, ask the user if they want to pair with Envoy?

Sure, some features would be limited without Envoy but not the most important ones.
1❤️1
Foundation · 3w
Yes we chose to build our own Bluetooth connection to enable all the other features ie, 2fas etc. Not just for firmware updates. However we do not use a standard Bluetooth connection and built our own QuantumLink, which is a protocol that ensures the data is encrypted before it reaches any chips o...