[ad_1]

Self-custody is important in crypto, and security is essential to self-custody. Ledger, a notable hardware wallet manufacturer, has built its reputation on the secure storage of users’ private keys. Hardware wallets create a secure offline environment for storing keys and using the keys to execute transactions.
The user’s private keys are generated and stored within the device and are believed to never leave it. This “cold storage” offers an unmatched level of security compared to “hot wallets” or online wallets. The problem is that many people lose their keys.
Ledger this week launched a seed phrase backup product called Ledger Recover. If you give the company your ID and personal information, you can pay for a service that takes your seed phrase inside your device, encrypts it into three “shards” and then sends them to different custodians. shares with.
Introducing a third party inherently centralizes control, creating a single point of failure that can be exploited by hackers or subject to regulatory actions.
Connected: throw your bored apes in the dustbin
I don’t approve of Ledger’s attempt to evolve as a business to reach non-OG and non-cypherpunk-ethos users. Millions of benchmarks, like our skeptical baby boomer in-laws, will only ever be onboarded to crypto via this type of custodial backup approach. It may be faulted for trying to use the same product to appeal to both crypto self-custody OGs and broader future customer criteria.
Ledger’s rollout of its backup product was met with some strong reactions among its community of customers. Many were surprised to learn that Ledger has always had the ability to spoof your secret keys with its hardware updates. Many of us consider our hardware devices sacred. I clearly wasn’t knowledgeable enough about this tool that I trust to protect my crypto assets.
yesterday i got mad about this revelation @Ledger Might spit out your private key with a firmware update.
Yet I noticed that the smartest people weren’t dropping out. Was I missing something?
I spent the evening educating myself, and am now in the “nvm it’s fine” camp.
— Haseeb >|< (@hosseeb) May 17, 2023
Haseeb Qureshi emphasized that although he too reacted negatively at first, he felt this was always true about Ledger. We’ve always trusted it not to put malware in its firmware updates to steal our seed phrases. He’s not wrong, but I wouldn’t say it’s a comforting thought.
Finally, nothing bad can happen to your hardware device until you sign the transaction. Keep you strong. I don’t know about you, but I’m not a coder – I can’t tell a malicious update from a legitimate one, so I’m relying on Ledger on that too. and i have absolutely no choice No To approve the latest firmware update that includes Ledger recovery capability, as Ledger warns that failure to update your firmware is a security risk.
However they do serve to provide trust in the software stack. A better design would include functionality like Certificate Transparency or Key Transparency, so you don’t have to hope they don’t inadvertently send you buggy firmware
— Andrew Miller (@socrates1024) May 17, 2023
I trust Ledger — it’s a great company. It has been the linchpin in the technology stack for crypto self-custody, at least in my own crypto journey.
But a crypto self-custody instrument should aim to minimize trust requirements. And the laser can be improved upon through the open-sourcing of its software and hardware. Ledger’s CTO was asked about this on May 17 unbanked podcast and responded that Ledger has signed non-disclosure agreements that prevent it from doing so and argues that people are unlikely to crowdsource security audits anyway.
I’ll bet security researchers like Andrew Miller, who exposed vulnerabilities in secret networks, will take on that task.
1/ Ledger “recovery,” a thread
Ledger accidentally leaked some information about their new recovery subscription service last night, and today they revealed the details.
Let’s dive into his proposed “solution” to cryptocurrency custody and how dangerous it is. pic.twitter.com/8GnCKv7hTH
— Seth for Privacy (@sethforprivacy) May 16, 2023
While Ledger’s communication regarding the rollout has been a disaster, its crisis communication has been enlightening. I’ve definitely realized that I had an insufficient understanding of how hardware wallets work. But “sorry, we can’t open-source anything because of NDAs” is an inadequate answer for those in the community who worry that a malicious actor may be trying to trick users with fake updates and their seed phrases. Laser recovery can be used to steal . ,
Ledger may also give me the option to continue updating my firmware without adding the Ledger recovery code to my device. But in the absence of open-sourcing its firmware, it won’t do much, as we’ll have no way to verify its claims.
It could be a branding win if Ledger pivots to roll out a “cypherpunk”-branded dimension to its hardware and software that pleases the OG crypto community enough that they’ll be willing to pick it up, and existing hardware owners. Let us choose for this. New updates like their previously purchased hardware are cyberpunk-branded and -approved, as much open source as possible, with crowdsourced security audits – the complete package. All will be forgiven.
For now, it doesn’t look like Ledger plans to do so. Therefore, the alternative is to use open-source hardware wallets, but they do not have the wide interoperability of Ledger with emerging blockchains. Or you can build your own, or use the newly updated Gameboy open source hardware wallet.
For now, and for many coins, the safest option is probably to rely on Ledger while remaining open to competing developers of open-source hardware wallets.
JW Verret George is an associate professor at Mason University’s Antonin Scalia Law School. He is a practicing crypto forensic accountant and also practices securities law at Lawrence Law LLC. He is a member of the Advisory Council of the Financial Accounting Standards Board and a former member of the SEC Investor Advisory Committee. He also leads the Crypto Freedom Lab, a think tank fighting for policy change to preserve freedom and privacy for crypto developers and users.
This article is for general information purposes and is not intended and should not be construed as legal or investment advice. The views, opinions and opinions expressed here are those of the author alone and do not reflect or represent the views and opinions of Cointelegraph.









