- Trezor 1 and Trezor T
- Jade
- SeedSigner
Add a passphrase with more than 128 bits of entropy, and as of today, these are the most secure options.
Failing that, you can use them for multi-signature transactions.
Anyone who doesn’t understand why I’m saying this knows nothing about cryptography and is just an uninformed idiot.
And an old, offline PC running Linux encrypted via LUKS is also perfectly valid as a signing device, as long as you use a passphrase and avoid using TPM to encrypt the disk.
quotingKerckhoffs' cryptography principle (also called Kerckhoffs' desideratum, assumption, axiom, doctrine, or law) was stated by Dutch cryptographer Auguste Kerckhoffs in the 19th century. The principle states that a cryptosystem must be secure even if everything about the system, except the key, is public knowledge. This concept is widely adopted by cryptographers, in contrast to security through obscurity, which is not."
nevent1q…8t2t
Most hardware wallets violate this principle.

