به Nostr بپیوندید
2026-08-02 20:11:04 UTC

Dr. Hax on Nostr: I feel for these folks who bought coldcards. Trust in that company has been ...

I feel for these folks who bought coldcards.

Trust in that company has been completely shattered. People expected that buying a closed source hardware product would be run by people who would invest in audits of their firmware and the libraries on which they depend. That's a reasonable expectation, even if it is based on trust instead of verification.

On the flip side, there's open hardware projects like seedsigner and trezor, where it's well known that they're not raking in the money needed to fund a serious audit. Because they are expensive. There aren't a lot of people who can say "yeah, the code looks good" and have that be taken as evidence that the code is vulnerability-free. Their time is valuable.

There aren't any magic answers here. Sure, it's easy for armchair analysts with the benefit of hindsight to say now what people could have done differently. It's a different thing entirely to put in the work to change the game.