We all (who have tech skills) are at least a little bit at fault.
We never developed some kind of norm of: how can you assure your users that their private keys are 'proper'?
Were they supposed to look at them? No.
If you grab your randomness from the OS, you can't know, via testing, that the result will be random for a *user*, who is using a different machine than you. But why don't they have a simple push button test to check by sampling?
Obviously it's a bit harder with HWW but same principle.
Actually I'm genuinely curious what people think about that.
We never developed some kind of norm of: how can you assure your users that their private keys are 'proper'?
Were they supposed to look at them? No.
If you grab your randomness from the OS, you can't know, via testing, that the result will be random for a *user*, who is using a different machine than you. But why don't they have a simple push button test to check by sampling?
Obviously it's a bit harder with HWW but same principle.
Actually I'm genuinely curious what people think about that.
223❤️9🤔2❤️1💯1🤙1