<oembed><type>rich</type><version>1.0</version><author_name>semisol (npub122…cgrkj)</author_name><author_url>https://nostr.ae/npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>Good morning Nostr&#xA;&#xA;It is good to see that many people’s efforts have helped people move their coins into safety.&#xA;&#xA;While I hope that the hardware wallet industry and developers will learn a lesson from this, I think that many will have the wrong takeaways, or none at all.&#xA;&#xA;This is not the first time that such things have happened, as seen with the Blockchain.info wallet, and I don’t think it will be the last.&#xA;&#xA;It is embarrassing that the same mistakes happen over and over again.&#xA;&#xA;These companies are often managed by people with little understanding of cryptography and security. A flawed leadership then leads to flawed products.&#xA;&#xA;While open source, AI security audits, etc., are nice, they are not going to solve the problem at all.&#xA;&#xA;I would recommend anyone who wants to make a signing device first study the history of cryptography, hardware security, and related topics. Then decide whether you want to take the risk.</html></oembed>