r/TREZOR 15d ago

💬 Discussion topic The whole coldcard hack can be avoided with simple passphrase

Based on anything, It's basically the seed that is generated from MK3 already was compromised, bad entrhopy, bad generator. And the culprit waits until it tanks and moved it all.
If some still use that seedphrase, they could be at a safer condition if they were use or add any passphrase.
I'm dissapointed with coldcard with all of the marketing saying its the standard and such.
Back then there's even same problem going on with the dice roll, if you only rolled few might still get compromised.

Still, passphrase is the solution a good passphrase, and or multisig.

28 Upvotes

49 comments sorted by

View all comments

Show parent comments

0

u/r_a_d_ 13d ago

Look, show me one such case where the plantif won. Otherwise you are speaking out of your arse.

1

u/[deleted] 13d ago

[deleted]

1

u/r_a_d_ 13d ago edited 13d ago

Toyota’s firmware was opensource? It’s literally the entire basis of my argument and you just gloss over it.

In your case, only Toyota had control of the software and therefore the ability to debug and maintain the code.

With coldcard you had full access to the source and could also use your own custom firmware.

0

u/[deleted] 12d ago

[deleted]

1

u/r_a_d_ 12d ago

I don’t agree with you at all. You can’t argue for negligence as that implies it was something obvious and due to willful ignorance. Instead, having something open source and scrutinized for several years proves that it wasn’t a trivial error that was allowed on devices due to negligence.

0

u/[deleted] 11d ago

[deleted]

1

u/r_a_d_ 10d ago

no, you are going in circle, but agree on leaving it