Hardware wallet manufacturers need to start publishing third-party test reports on the quality of their internal random number generators.

Replies (7)

Chris's avatar
Chris 3 weeks ago
At the very very least…. And users need to better understand the trade off they are making by not generating their own entropy. The blind assumption that ANY 3rd party device RNGs were impenetrable was softly and implicitly shilled by the industry for far too long. Studying Bitcoin (and security practices) >>> “Buying” Bitcoin 🙏🏻
Yes. Aaaaand. Let’s heal the industry. Follow and work with the guys advocating against hardware wallets and taking flack for years. Open source, non-BTC specific hardware. Seedsigner BtcCuracao JW Weatherman heavilyarmedc BenWestgate Peter Todd Robert Maxwell Robert Spigler LibertyMugs and Epic Curious
Better to sponsor #AI pentest events and fund security researchers using publically marketed security grants. Pay for pentesting, then promote it. Big rewards for findings. Put money where mouth is.
The quality of the internal RNG was fine but it was bypassed. It wasn't used in the ColdCard's case. A quality strong keys are the end result that needs to be proven.
3mily's avatar
3mily 2 weeks ago
Words to the wise…