As most of you probably know, ledger has introduced a possible backdoor on there device's giving anyone using them a potential risk.
Now some people will tell you that this is fine and others will tell you to switch ASAP. I suggest you do your own research into the matter and decide what you think.
The reason I'm making this post is to remind everyone that black Friday is soon so this would be a great time to pick up an open sourced and air gapped device.
The bottom line is this, if you have spent thousands on bitcoin but your still using ledger why would you want the potential risk? Just spend another 200 max on a more reliable device and make the switch this black Friday for a discount.
Stay safe out there.
A few things to consider:
  1. Hardware wallets fail in tropical weather
  2. Hardware wallets have leaked their customers' physical addresses in the past
  3. Don't take their words, roll your own with diceware/ rolls.py
  4. Consider yeticold or seedsigner or TAILS/Electrum
  5. Avoid having SPOF, unilateral control over your main savings; Create spatial, temporal, social friction
  6. Don't use "duress passwords". They incentivize violent coercion.
reply
Some other useful resources for references.

10x Security Bitcoin Guide

How to store bitcoin without any single point of failure. https://btcguide.github.io

Border wallets

Wallets Recovery

reply
What kind of tools would you use for step 5?
"Avoid having SPOF, unilateral control over your main savings; Create spatial, temporal, social friction"
reply
I think this has more to do with your personal protocol than with tooling. Everyone has differing circumstances and skills. (Spatial/Temporal) Find a way that forces you to travel in order to construct a transaction. Words or Hardware are in multiple geographic locations. (Social) Find a trusted friend or relative or lawyer or third party key custodian to validate your safety and intentions before signing. Make certain all this is documented. Practice.
reply
Don't use yeti cold lol
reply
6 - how do they incentivize violence?
reply
Duress passwords are a known tactic. If an attacker thinks you use them, they have the incentive to beat them out of you. You'll find real world examples of this in Jameson Lopp's Known Physical Bitcoin Attacks Best to not have unilateral control of your funds and be ready to prove this to your attacker.
reply
Lol yeah for sure, if you're holding more coin than a ledger is worth are you really going to take that risk? Everyone has to start somewhere I suppose, I know I started with ledger as many did after I felt my hot wallet wasn't good enough, and then later I felt ledger wasn't good enough.
Pushing people to steps they are not ready for is equally as dangerous, the further you move out into self custody the more complex and the more you can fuck it up to, its not a silver bullet, everything has a trade off and for some ledger is the trade off they are willing to make
reply
I also started on ledger but I'll be buying a coldcard mk4 on black Friday.
Ledger is good for beginners I suppose but once that stack starts to grow I sure hope people learn about better security.
reply
What device are you using?
reply
each wallet has its own trade-off pretty much like open source and closed source.....
reply
Watch latest Chris Bleck pod on wallets ...its informative
reply
is the blockstream jade any more secure than ledger?
reply
BTC Sessions: How to switch hardware wallets
BTC Sessions: Coldcard Bitcoin Hardware wallet - FULL TUTORIAL
reply
deleted by author
reply
This.
reply
Seed signer is a hardware wallet. Do you just hate the companies behind them?
reply
You can make your own seedsigner from off the shelf parts. No need to give your mailing address to a company which can be leaked, exposing you as a hodl'r. This has happened.
reply
I know right. Hardware wallets are more then fine if you know which ones to buy. I just want open source and air gapped.
I'll be getting the coldcard mk4 using it with nunchuk on my phone, using NFC to sign the signatures.
reply
deleted by author
reply
Mk4 is more then ideal for what I need it for, besides I want it this month for the black Friday deal. If the Q is out before the end of the month I probably will get the Q.
reply
deleted by author
reply
Do you know any guides/tutorials for this?
reply