Post
Topic
Board Hardware wallets
Merits 5 from 2 users
Re: Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities
by
RickDeckard
on 23/05/2023, 19:13:16 UTC
⭐ Merited by o_e_l_e_o (4) ,vapourminer (1)
To be honest, here 'open source' is thrown around wildly (blog posts and whitepapers are no 'source' of anything).. Grin

They are taking credit for their '+150 applications' being open source, meanwhile are not writing those themselves, right? The individual coins' developers make them, don't they?

The SDK pretty much has to be open-source if they want altcoin developers to make the accompanying Ledger app for them (for free?); so nothing to take much credit for there, either.

A whitepaper cannot be 'open / closed source' since (1) it's not a source of anything (neither software, nor hardware), (2) you don't write a whitepaper if you don't intend to publish it.

All these blogposts, little tools and whatever they want to provide are just fillers for the big void on the infographic: the firmware remains closed.
As long as that doesn't change, their ability to include backdoors doesn't change. No matter how many blogposts they publish, whether they open-source some dashboard or individual apps. We need the firmware source code; anything else is pointless.

Well said. Lots of fluff, nothing that actually changes anything. Just a continuation of bullshittery, and not a good one at that.

I mean let's look at that step for step.
(...)
I agree. To me it looks like they are just throwing sand into people's eyes and aren't addressing the issue directly (and considering the reputation damage that they got, this current issue isn't their only problem). Their last phrase on the tweet[1] is loaded with irony - "We believe open source brings openness, transparency, audibility, and trust" - mostly due to the fact that they didn't never cared about going OS as far as I'm aware, they are just trying to shed a very limited light within their code due to this horrible PR mess and hoping that people get satisfied by their "open source plan".

For the few people that still believe in Ledger, do note that I am also unsure whenever you'll see this full plan being implemented as their CTO also admitted[2] that "The other parts will take a little more time since it needs to be refactored to abstract the chip-specific characteristics under NDA from our OS.", meaning that this will be a long(tm) journey before getting everything ironed out within their NDA...

[1]https://nitter.it/pic/orig/enc/bWVkaWEvRncwWDRscGFBQVlqX0JwLmpwZw==
[2]https://nitter.it/P3b7_/status/1661012225073745929