I wouldn't trust it to generate a key, but I didn't trust it...

npub1lcetwt8hcd9gagdytu4e35ufykxek0elfvx8q3spugmgj9x0ev0q363apw
hex
2bd48e085b7b723acb016071e43ffc318a99a92e1b3c7f9e295390b547479183nevent
nevent1qqszh4ywppdhku36evqkqu0y8l7rrz5e4yhpk0rlnc548y94garerqcprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs0uv4h9nmuxj5w5xj972uc6wyjtrvm8ul5krrsgcq7yd5fzn8uk8st4sz4yKind-1 (TextNote)
↳ 回复 CR¥P7ΩWØLF (npub16jknkmh2luflurx2epkj99qyj7v2ut3ew7t2mfd7xxt9jtjku2nsj2gqp0)
yes there is. Should we trust it?
I wouldn't trust it to generate a key, but I didn't trust it before to generate a key. And thus, my key is actually safe.
I see nothing that changes my opinion about the device otherwise. If it's airgapped, and your seed is secure, the only real angles to really reinforce I can think of are the SD card firmware and double checking your psbt's and maybe auditing the QR codes.
Better though would be not trusting any one device and doing multivendor multisig. A seedsigner and a coldcard are still my go to approach, with the coldcard providing a good stateful option so an attacker would have to convince me to turn over my key rather than knock me out and take it, and the seedsigner providing me a more easily auditable design with a simplicity that doesn't ask me to trust as much. Generate your keys separately for each key. Maybe even tie in some timelocks -- Liana makes all of this easy.
原始 JSON
{
"kind": 1,
"id": "2bd48e085b7b723acb016071e43ffc318a99a92e1b3c7f9e295390b547479183",
"pubkey": "fe32b72cf7c34a8ea1a45f2b98d389258d9b3f3f4b0c704601e2368914cfcb1e",
"created_at": 1785562547,
"tags": [
[
"e",
"5ea93d66cd1071f5273aa6961e29901a86b76919bba81f7a88d17d87ce9f23a2",
"wss://relay.ditto.pub/",
"root"
],
[
"p",
"45f195cffcb8c9724efc248f0507a2fb65b579dfabe7cd35398598163cab7627"
],
[
"p",
"fe32b72cf7c34a8ea1a45f2b98d389258d9b3f3f4b0c704601e2368914cfcb1e"
],
[
"e",
"a00b415be40f90451727749213950c94c32ef4ac3dac08e06988cbf0166a6f54",
"",
"reply"
],
[
"p",
"d4ad3b6eeaff13fe0ccac86d2294049798ae2e397796ada5be3196592e56e2a7"
]
],
"content": "I wouldn't trust it to generate a key, but I didn't trust it before to generate a key. And thus, my key is actually safe.\n\nI see nothing that changes my opinion about the device otherwise. If it's airgapped, and your seed is secure, the only real angles to really reinforce I can think of are the SD card firmware and double checking your psbt's and maybe auditing the QR codes. \n\nBetter though would be not trusting any one device and doing multivendor multisig. A seedsigner and a coldcard are still my go to approach, with the coldcard providing a good stateful option so an attacker would have to convince me to turn over my key rather than knock me out and take it, and the seedsigner providing me a more easily auditable design with a simplicity that doesn't ask me to trust as much. Generate your keys separately for each key. Maybe even tie in some timelocks -- Liana makes all of this easy.",
"sig": "8e5974a7c56ab0313cbd1ad6031102f5f9b27aac077d006107ed282d2daecb33f97c2611b9ec6329c107e7b86cb5fa59ae1571b788a0906ce4a49c7c38e626e4"
}