Damus
nostrich profile picture
nostrich
Jade doesn’t use a physical secure element.

We just published a full post on how the Virtual Secure Element works:

https://blog.blockstream.com/jade-virtual-secure-element/



Your recovery phrase sits encrypted on the device. Unlocking it needs the PIN you type on Jade and a key share from a blind oracle. Neither is enough by itself.

The oracle never sees the real PIN or any wallet data. It only gets a scrambled version that includes a secret unique to that particular Jade.

Three wrong PINs and both sides wipe. Device and oracle. After that the encrypted data is permanently unusable without the recovery phrase.

A locked Jade holds nothing an attacker can use alone.

Everything is open source, firmware, hardware, and the oracle. You can run the oracle yourself, or skip it completely and use SeedQR or type the recovery phrase.
54❤️8❤️1👀1👍1🔥1
nostrich · 6w
That sounds cool. It also sounds like you will know every time we sign a transaction. That's a big no thanks for me. Feel free to correct me if I have that wrong.
wispy🧉⚡⭐ · 6w
How is this better than a seedsigner or an airgapped linux?
OzzyHB · 6w
So I can DIY build a Jade?