Foundation is ran by good people but I can’t trust their pro...

semisol
npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj
hex
1531445be6cec1dcdb816aa51f5a91668e1078dce93b143b522caf5ab6af49e2nevent
nevent1qqsp2v2yt0nvaswumwqk4fglt2gkdrss0rwwjwc58dfzet66k6h5ncsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs99d9qw67th0wr5xh05de4s9k0wjvnkxudkgptq8yg83vtulad30gy3aj5lKind-1 (TextNote)
↳ Reply to Hanshan (npub1lxzaxzge0jq9u9cecucctdt5lslwgp7hcxmp2l0wn8r2ecjenwasu6svxa)
woot. finally a hardware wallet! cc nostr:nprofile1qqs99d9qw67th0wr5xh05de4s9k0wjvnkxudkgptq8yg83vtulad30gpz9mhxue69uhkummnw3ezumrpdejz7qg4waehxw309a...
Foundation is ran by good people but I can’t trust their products.
Many of their statements, including:
- calling the SAMA5D2, which lacks security features found on many security-oriented processors, a “security processor”
- using the ATECC secure element, when it is known to be insecure and was designed by a defunct company
- calling smart cards, which are the most secure way to protect your keys and are constantly evolving, “ancient and dated technology”
- forking Xous instead of using a well known kernel like seL4 or Linux or even writing their own (from their marketing, it seems they want to associate with the good reputation of Xous)
make me strongly think that they do not have significant knowledge with security.
As with any HWW company, they have to prove that they can be trusted to make security products. I am not convinced at all.
Raw JSON
{
"kind": 1,
"id": "1531445be6cec1dcdb816aa51f5a91668e1078dce93b143b522caf5ab6af49e2",
"pubkey": "52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd",
"created_at": 1780932701,
"tags": [
[
"e",
"eb8960e092dbd142ec48d7dbd2290003d99dd9b15788237e391823dae1e8e982",
"",
"root"
],
[
"e",
"fe5eff07f7bc3f4e6583026de5231a72a7ba59ee9a94b993b33c96229f367791",
"",
"reply"
],
[
"p",
"a60e79e0edad5100d7543b669e513dbc1c2170e8e9b74fdb8e971afd1e0e6813"
],
[
"p",
"52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd"
],
[
"p",
"f985d309197c805e1719c73185b574fc3ee407d7c1b6157dee99c6ace2599bbb"
],
[
"client",
"Nostur",
"31990:9be0be0fc079548233231614e4e1efc9f28b0db398011efeecf05fe570e5dd33:1685868693432"
]
],
"content": "Foundation is ran by good people but I can’t trust their products.\n\nMany of their statements, including:\n- calling the SAMA5D2, which lacks security features found on many security-oriented processors, a “security processor”\n- using the ATECC secure element, when it is known to be insecure and was designed by a defunct company\n- calling smart cards, which are the most secure way to protect your keys and are constantly evolving, “ancient and dated technology”\n- *forking* Xous instead of using a well known kernel like seL4 or Linux or even writing their own (from their marketing, it seems they want to associate with the good reputation of Xous)\n\nmake me strongly think that they do not have significant knowledge with security.\n\nAs with any HWW company, they have to prove that they can be trusted to make security products. I am not convinced at all.",
"sig": "f04ed655122444145b184234374f96902761a480f233618c51fc90b45ab338574fb1b41354a6e11272f7c2ba644055c4b0f4f025d1d81e9bed99a18a9f2bccc6"
}