Post
Topic
Board Hardware wallets
Merits 3 from 2 users
Re: Ledger Recovery Key: Ledger Recover 2.0?!
by
satscraper
on 12/07/2025, 07:15:22 UTC
⭐ Merited by Pmalek (2) ,Cricktor (1)
And yes, what Pmalek mentions and what I tried to highlight as a quite despicable part of firmware is code that's there to have the main secret leave the hardware device completely. Oh boy, this is a can of worms and we kicked it. Yes, I'm aware, my BitBox02 allows a backup on a microSD card. Is this equally wrong as Ledger's Recovery service crap? You judge!

Displaying the wallet's recovery words again on demand feels kind of wrong to me, too.
As long as it's an optional feature that is not forced on you,

@Pmalek, whether this feature is optional or not is beside the point. The reality is that its presence introduces a potential vulnerability i.e. essentially the "door" for the SEED phrase to leak from the SE and display in this case. In my opinion, this compromises the security, as the truly secure environment must ensure that SEED phrase is 100% sealed and inaccessible at all times after it was generated by wallet and saved by user.