Damus

Recent Notes

Derek Ross · 1d
No period https://github.com/Coldcard/firmware/commit/37e4af5451c260c1e7d429fe8972c4cb5e68ee59
Peter K · 3d
Eh, it's possible it really is just like nostr:npub14rg4vrt2v374q95ezeeydu3hkdhmzglcj950mggacap4x0lv0gyq04wun7 said in a different thread, they would have had to set them up to update the firmware. Tamper resistence coming back to bite them.
QnA · 3d
Disclosure - I leaned on Codex's interpretation of our codebase for the answer below, I am not on our developer team. “Fingerprinting” an entropy source is not the same as predicting its previous outputs. A stable device-specific bias might describe the probability distribution of future ANS sa...
Juan Cienfuegos I BITCORNER · 3d
After the Coldcard entropy story, a lot of you asked the obvious follow-up: how does Jade handle this? So we went and read nostr:nprofile1qqsfy229w70e8lgtxavlz9t78k06yrel6fxyhreteafqet8kfxhhwmgpr9mhx...
Emerson profile picture
If you study how entropy works it would actually raise more concerns as the device is effectively fingerprinting. Its like if you generate seed with device, wipe the seed then someone steals the device they can figure out devices bias and generate your key.

The only solution is encapsulated pure randomness paired with destruction of entropy wielding source.

In simple words: this does not mean your seed is safe with Jade its just has different attack vector
❤️1