Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This sounds a lot like a sales pitch by Ledger, is the next service you are going to sell me involving me sending my seed, online, to Ledger so it can be sent to 3 third parties... because that is what made so many people laugh at them last year. They can add as many layers of cryptographic schemes on this, it so antithetical to what you should do with a seed you want to secure that it ruined their reputation for a lot of people. If you have missed this episode or prefer to forget about it, it doesn't make it less real.

I'll add that even if that didn't make them a joke to you, I am just as concerned by their customer data leak (similar to what I've mentioned above for Trezor) and that alone makes me not want to recommend them, I just didn't mention it as the other point is egregious enough on its own.



I'm not familiar with the seed uploading incident. I'm just evaluating the device on how easy it is to compromise vs Trezor and competitors.


Do you HAVE TO send your seed for backup? Do they use dark patterns to force you to upload your seed?

Do you realize some people value (probably wrongly in this case) convenience over absolute security?

There’s nothing wrong with offering additional options.


>value (probably wrongly in this case) convenience over absolute security?

I'm guessing there has been far more crypto lost through people forgetting/losing their keys than by having been hacked. Though personally I prefer to lose it speculating on the futures markets. People are idiots a lot of the time.


It's simple, the surface of attack of their system is much larger with the mere existence of this backup scheme, even if none of their customer used it...for the convenience of a fringe of their customers (the real reason is to widen their userbase to less security conscious customers and make more money this way). They also have proven to be poor deciders in the past when it comes to protecting their customers' data. The two combined make me want to never purchase a device again from them, and made me demand that they delete all my PII from a former purchase.

If these red flags are not red enough for you, go on, use them, I refuse to recommend them anymore for the stated reasons, especially when there are alternatives with better security/track records.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: