Post
Topic
Board Hardware wallets
Re: Thoughts about Passport hardware wallet
by
n0nce
on 27/07/2022, 16:03:19 UTC
As wallet software, I use Bitcoin Core and Sparrow.
What Bitcoin and LN wallets are you using and recommending for smartphones?
As of right now, honestly nothing. I will look into something simple, without tons of bloat introduced by suspicious (read: Google et. al) frameworks that I can compile myself, in the future.

Maybe also just going to make my own. I don't need lots of fancy features; just creating a PSBT from a Bitcoin address, a selected UTXO, an amount and a fee can't be that hard, right. Not even any USB protocol is needed; just QR code generation, reading the signed QR from a camera image and sending it to an Electrum node. Honestly that would be one of the simplest software programs I've ever written so I don't get why all these mobile apps overcomplicate it so much so that they need to resort to frameworks (yeah I'm not a fan of frameworks especially if they might phone home.. Roll Eyes)

While we're waiting for n0nce's review, I'd like to complain about their packaging:
  • On their "unboxing video [part one]", I noticed only the outer box comes with a tamper-evident seal and the inner/main box is only bubble & shrink wrapped! I do know there's a way to check and verify if you've got the correct product, but this way of packaging still gives certain users a chance to figure out a non-detectable way to bypass such things in the future.
I'm not sure how I feel about 'tamper evident packaging'. It can give a false sense of security, especially since such stickers can be got anywhere very cheaply; I believe even fake Ledger devices come with tamper evident seals. So I wouldn't put too much trust in solely such stickers; on the other hand, they cost nothing so adding one more may give a little extra protection for barely any cost at all.

Edit: It uses Google Firebase. If I don't absolutely have to, I'd prefer to skip Envoy for now.
I guess that confirms I was wrong [they "didn't" alter the foundation letters' color into black], but while we're waiting for n0nce's review, I'd like to complain about their packaging:
  • On their "unboxing video [part one]", I noticed only the outer box comes with a tamper-evident seal and the inner/main box is only bubble & shrink wrapped! I do know there's a way to check and verify if you've got the correct product, but this way of packaging still gives certain users a chance to figure out a non-detectable way to bypass such things in the future.
Unfortunately some custom offices open the sealed package. The device comes with or without firmware?
Passport v1 came with firmware and I'm sure that v2 comes like that, too. But you can always go in and immediately flash a fresh image from Foundation's webpage or GitHub when you receive it. Mind you, the device only installs firmware signed by Foundation, so it's going to be pretty hard (read: almost impossible) for someone to casually replace the firmware on your Passport at the customs office.
Realistically, worst thing that can happen is that they open it, boot it, configure it, and write down (steal) your seed. However you would notice since after turning on you wouldn't see the usual setup. In such case you could trash it, or just format it and re-configure (getting a new seed).