Using their command line software I think can at least be do...

npub1lcetwt8hcd9gagdytu4e35ufykxek0elfvx8q3spugmgj9x0ev0q363apw
hex
8c63977c321ef656e95eaaa1e9138c59c466ab8dbf56b2e677771a22eb73b947nevent
nevent1qqsgccuh0sepaajka9024g0fzwx9n3rx4wxm744juemhwx3zademj3cprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs0uv4h9nmuxj5w5xj972uc6wyjtrvm8ul5krrsgcq7yd5fzn8uk8sqvmvpjKind-1 (TextNote)
↳ Reply to CR¥P7ΩWØLF (npub16jknkmh2luflurx2epkj99qyj7v2ut3ew7t2mfd7xxt9jtjku2nsj2gqp0)
this is true, you are right. and if you dont use their software, you have to use their website which is an even worse idea, I agree.
Using their command line software I think can at least be done while airgapped, and is open source.
Like I said, it's usable, I just don't see why I'd buy something where I already know I'm working against their designers.
It's a shame there's no real open hardware options with secure elements at this point. Krux but with a stateful, tamper proof design so that a raw hard copy of your key needn't be kept onsite would be a major step up.
Stateless multisig in multiple locations is probably the best you can get for now.
Or, honestly, just actually generating your keys securely on Coldcards. But I don't blame anyone for not being the most confident in them at the moment. I haven't, however, been able to think up an attack vector for an appropriately airgapped coldcard with really random 256 bits of entropy and the traces for usb, nfc, and bluetooth all destroyed. Aside perhaps from the fact that QR codes need to be audited and sd cards can have poisoned firmware. I think you CAN actually key in a psbt directly but this is admittedly going a little overboard. I almost wish we had floppies back...
If someone knows of another vector though I'd love to know.
Raw JSON
{
"kind": 1,
"id": "8c63977c321ef656e95eaaa1e9138c59c466ab8dbf56b2e677771a22eb73b947",
"pubkey": "fe32b72cf7c34a8ea1a45f2b98d389258d9b3f3f4b0c704601e2368914cfcb1e",
"created_at": 1785562330,
"tags": [
[
"e",
"5ea93d66cd1071f5273aa6961e29901a86b76919bba81f7a88d17d87ce9f23a2",
"wss://relay.ditto.pub/",
"root"
],
[
"p",
"45f195cffcb8c9724efc248f0507a2fb65b579dfabe7cd35398598163cab7627"
],
[
"p",
"fe32b72cf7c34a8ea1a45f2b98d389258d9b3f3f4b0c704601e2368914cfcb1e"
],
[
"e",
"c52715d6b9b8ae883f31298f01e8786136ecd72e74b3933e26e152aa86a54498",
"",
"reply"
],
[
"p",
"d4ad3b6eeaff13fe0ccac86d2294049798ae2e397796ada5be3196592e56e2a7"
]
],
"content": "Using their command line software I think can at least be done while airgapped, and is open source.\n\nLike I said, it's usable, I just don't see why I'd buy something where I already know I'm working against their designers.\n\nIt's a shame there's no real open hardware options with secure elements at this point. Krux but with a stateful, tamper proof design so that a raw hard copy of your key needn't be kept onsite would be a major step up.\n\nStateless multisig in multiple locations is probably the best you can get for now.\n\nOr, honestly, just actually generating your keys securely on Coldcards. But I don't blame anyone for not being the most confident in them at the moment. I haven't, however, been able to think up an attack vector for an appropriately airgapped coldcard with really random 256 bits of entropy and the traces for usb, nfc, and bluetooth all destroyed. Aside perhaps from the fact that QR codes need to be audited and sd cards can have poisoned firmware. I think you CAN actually key in a psbt directly but this is admittedly going a little overboard. I almost wish we had floppies back...\n\nIf someone knows of another vector though I'd love to know.",
"sig": "69ca987a8988e9c6f60823fb7608aebaf48478cdcc74789aa425ca68fdada4c003a6c8c9f1bd9445aca7e3279f0e37430e5ff024c2c5d0ddda19b90d28c80d19"
}