You don't think Coldcard was incompetence?
Login to reply
Replies (4)
It was definitely incompetence and hubris.
Mechanic just needs a rallying cry.
Ah yeah, how could I forget the hubris. Seems like a good example of Hanlon's razor.
I wouldn't think so. security of keys has always been the most vital aspect of self storage, so you're suggesting Coldcard just accidentally fucked up the most fundamental principle to their entire business? yeah.....nah.
It's very similar to the [2008 Debian weak SSH key generation bug](https://www.cve.org/CVERecord?id=CVE-2008-0166). In both cases keys were created with insufficient entropy because the developers got error messages they didn't understand and ended up trying to "fix" these errors.