pull down to refresh

Thanks Sessions.
reply
What happens if the blockstream website to "unlock the pin" goes away?
reply
35 sats \ 10 replies \ @k00b 22 Jan
IIRC you can run your own pin server
reply
reply
0 sats \ 8 replies \ @nym 23 Jan
What does it do? Verify the integrity of the device?
reply
Jades don't have "secure element" chips in them. This was a design choice since 90% of all "cracks" of hardware wallets involve disrupting the secure element to gain control.
As a result of no secure element, the way the device encrypts the data on it (your seed) is by using the pin you enter. Obviously a 5 digit pin is a very small keyspace (which would be trivial to crack), so what happens is that pin is itself key-stretched to become a much larger encryption/decryption key off-device by using the website.
So the back-and-forth scanning of QR codes does that, essentially the "secure element" is the website / blind oracle which transforms your 5 digit pin into a proper encryption/decryption key.
reply
27 sats \ 6 replies \ @nym 23 Jan
Thank you. That comforts me a little. So the exchange has nothing to do with your seed (since you have to enter the pin before the seed anyway) and after it gets the pin and before it gets the seed it has no outside connection to the world again?
I have mine. The log in via website url QR thing is weird. They should also move it to the unlock Jade section and out of the QR section.
Bought it to play with and replace a Nano S. Prefer Seedsigner overall but its a decent unit.
reply
66 sats \ 0 replies \ @nym 22 Jan
A neat feature of the Jade Plus is that it can be used as a stateless signing device like the SeedSigner.
reply