NEAR - Sponsor Image NEAR - Confidential swaps across 35+ chains Friend & Sponsor Learn more
01:03:26 · 3 years ago
Podcast

Is Ledger Safe? with CTO, Charles Guillemet

Ledger has been the center of attention since the announcement of their new “Recover” feature which has brought into question how secure our Ledger devices actually are.

Up next

All episodes

Inside the episode

Charles joins us to walk through how exactly this recover feature functions, breaking down how a Ledger actually functions, and possible paths moving forward.


TIMESTAMPS

0:00 Intro

6:21 Ledger's Recover Service Overview

18:40 Is Ledger Recover Forced or Opt-In?

23:07 Dissecting a Ledger Device

29:41 Can Firmware Reveal Private Keys?

36:54 A Social Contract With Ledger

42:31 Assurance Of No Back Door

51:16 2-Part Firmware Solution?

57:42 Will Ledger Forget About Us?

1:02:46 Closing and Disclaimers


RESOURCES:

Charles

https://twitter.com/P3b7_

Ledger

https://twitter.com/ledger

Transcript
00:04
Ryan Sean Adams

Bankless Nation, a special bonus episode for you today. And I think an important one we have a ledger on the episode today. The question in our minds are the private keys safe? We have the chief security officer of Ledger, and we ask him that question along with a number of other questions related to this new recovery product that they just launched. David, uh, who's on the episode today?

00:28
David

We have Charles Guillemet, uh, who we've we've actually recently had on the podcast. He taught us how to properly spin up a private key. So Charles does know a thing or two about hardware wallets and and how to secure a private key. Uh, and so today I think we actually learned quite a lot about what is actually under the hood of a hardware wallet and what is the fundamental nature of a hardware wallet. I think this is a conversation that the entire industry is working through right now. And I think this this episode will be very, very useful to understand exactly the topics of discussion that we are having, both in public and on this episode. Before we get there though, we're going to talk about our spot friends and sponsor at

01:04
Ryan Sean Adams

Recording this intro after we've already done the episode with uh Charles from Ledger. And so I think it was a fantastic episode myself. I'm really interested to hear what the community thinks. Um, this is an education episode. We um ask, I think, some difficult questions of Charles at Ledger, and he gives his response.

01:23
David

I feel like we did get down to the bottom of it. Like we got down to the root of the problem. And it's

01:27
Ryan Sean Adams

I personally feel like I have closure in

01:30
David

Yes.

01:30
Ryan Sean Adams

I would say understanding what the security posture of this hardware device that I own called a ledger, understanding what that actually is, I feel like after this episode, I understand it much more. Now it'll be up to bankless listeners to decide whether that is the security posture they uh they want to move forward with and continue using. But um, yeah, this is a successful episode from that perspective to me.

01:54
David

Uh one small disclosure, Ledger is a previous Bankless sponsor. They are not a current bankless sponsor. And with that, let's go ahead and get right into the episode so we can learn exactly how a hardware wallet works with Charles from Ledger. But first, I wanted to talk about these fantastic sponsors that make the show possible, especially Bankless Nation. I'd love to introduce you to Charles Guillaume, who joins Ledger in 2017 as chief security officer after working for 10 years in the world of cryptography and hardware security sector. Charles, welcome back to Bankless.

02:21
Charles Guillemet

Hi David, thanks for having me.

02:23
David

So just want to dive right into the subject at hand here. The context, as I understand it, and we're coming into this episode very, very quickly. So I'm going to give you an opportunity to correct this context if I get this wrong. Yesterday, Ledger launched its recover service that lets users back up their private keys so that it could be recovered if lost. This recover service splits up private keys into three different encrypted shards sent out from the device to be held separately by three different custodians, also perhaps including Ledger. The strategy here is that we know in crypto that private keys are a huge hurdle for adoption, and many people just don't want to manage their own private keys. And Ledger Recover is meant to be a solution. Let the professionals do the professional thing and manage your private keys on your behalf is an opt-in service. But this opt-in service is not exactly the source of the outrage coming from the crypto world. Ledger users previously thought that it was impossible for private keys to ever leave their existing ledger devices, as is this is the point of a hardware wallet after all. So now Ledger has released this firmware update that seems to make this possible, albeit in a highly secure, encrypted, and sharded fashion. The point remains that something that was once thought impossible is now actually learned to be possible and has possibly been possible this entire time. So, Charles, is this an accurate summary summary from your perspective? And what would you add?

03:50
Charles Guillemet

Yeah, I think part of the feedback we uh got from the community were about this this part, but there was also uh like uh some misunderstanding around the feature, what it does, why we uh want to release this and so on, and maybe I can start with that. Like the the intent of um this feature is to bring more people to uh secure self-custody because when you zoom out, we are in in the little bubble, uh like uh tech savvy people, but when you zoom out, uh today most crypto owners are using exchanges uh to custody their assets or are using software wallets. And the reality is that self-custody seems a little bit complex, maybe is a little bit complex for newcomers, and and people can be afraid of it. And for me, there are two major uh friction points in self-kut in the self-custody journey. And I often uh think about my mother, uh it's too complex. Like self-custody is too complex for her because I see two major uh friction points. And the first one is the understanding and management of secret keys, like these things are.

04:53
Charles Guillemet

Quite complex if you are not used to uh to know what is the secret key and so on, it's it's complex. I mean you mean I have to uh write down this 2024 words, what do I do with these words and so on? When you are not tech-savy, this thing uh can be um uh frightening. And the second thing is like understanding what you sign and consent. There are these exagimal addresses, all this stuff when you do smart contract interaction, it can be a little bit complex. So for me, there's two uh major uh friction points need to be addressed by ledger. Um, and we need to find a way for newcomers for for mass adoption in order to uh enable mass adoption. And in cell custody, I think there are different shades of gray, different level of level of trust. At the extreme uh left, you have like a full trustless uh model where you don't trust anyone. You build your own computer, you your own operating system, your own wallet, you and so on. You generate your own secrets, you manage your your backup, you build the tools to synchronize the blockchain and sign.

05:59
Charles Guillemet

This would be the extreme uh trustless model, very difficult to achieve and quite uh it it needs a lot of skills, time, and so on. And the uh at the extreme right, you have like the custodian model where people are completely trusting a third party to manage their assets. And in between, you have like different shades of grey and you have software wallets which are not secured.

06:25
Charles Guillemet

But a little bit more in self-custody. You are in safe custody with software wallets, and you have hardware wallets, which are uh for me the best option so far. But when you use software wallet, there is some level of trust you have to uh put into uh the wallet manufacturer, whether it is called card, treasure, or or ledger, you have to trust a little bit us, you have to trust a little bit our vendor because we also depend on uh different vendors, mostly for um for the hardware itself. We we are buying the circuit. So

06:58
Charles Guillemet

Yes, the intent of this feature is to remove these uh friction hurdles for these people leaving their assets uh on exchanges and get one step closer uh to uh self- self self-custody and self-sovereignty. So when you use this feature, I agree, you are

07:16
Charles Guillemet

Doing a small trade-off where you are saying I'm not completely self-sovereign, I'm not the only one uh able to uh to manage my backup. But the trade-off I think is acceptable because uh the the seed is splitted with uh in into different shards, so there is no one custodian that there's like part of the backup provider providers. They don't custody your seed because cryptographically speaking, they don't have access to uh your seed. Uh, this is a shard, and with a shard, which is encrypted for security reasons, but with a shard, you don't have any information about the secret. You have to uh to have at least two uh out of the three shards in order to be able to be combine a secret and uh and uh know uh the the wallet content and and and use it. So uh this is this is the the trade-off you have. And also, yes, um uh in in this uh in yesterday in this um in this episode, like I noticed that some people, not everyone, but some people were uh a little bit uh starting to understand like how her hardware wallet works, and um and uh they they were a little bit surprised to understand that the the firmware or the software running inside uh the secure element is something that can be changed, uh is something that have an access to uh to the secret.

08:45
Charles Guillemet

But from a security standpoint, like nothing really changes, really. Like the seed is still generated within the secure element. The cryptographic operations are implemented within the secure element, like so that the seed doesn't have to leave the device when you use your crypto. And there is this trusted display allowing you to consent for any uh any operation. And this part is really, really in important. And it never changes. And as soon as the operating system will touch will touch a secret on your device, uh, it will ask you uh for consent, whether it is like for uh signing Bitcoin transaction.

09:23
Charles Guillemet

Doing a smart contract interaction, staking on like Cosmos chain or any other chain, doing firmware update, downloading an app, or use a ledger recover service. For all this operation, and there are many other operations, for all these operations, the operating system needs to have an access to the secret, to the seed, in order to do some uh cryptographic operation on it. And as soon as this happens, like the user is prompted and the user has to uh consent for uh the this operation. If the user isn't happy with doing a thermal upgrade, he simply declined, and that's it. There was uh uh nothing happened. Is is the user is not happy with the current Bitcoin transaction.

10:06
Charles Guillemet

he declines and that's it. There is a nothing happens. So we we really must have this part in mind that of of course the operating system has an access to uh the cryptographic uh materials to the secret but as soon as an operation

10:23
Charles Guillemet

uh involved the the secret the user is prompted and the his consent is uh requested so this is this is really the security model and also there was um uh something which was um

10:37
Charles Guillemet

A little bit weird for some people, like this the ability for uh the firmware to be updated. And this part is really important, this is paramount. Well, security is not something static, security is a journey. Like you it's impossible to say, okay, I build a hard wallet, I put uh some like firmware and so on, and that's it. I won't ever be able to change anything. Like everything is uh is engraved in the marble, and I can't change anything. If you do that.

11:06
Charles Guillemet

Your product won't be secure for a long time because, like, as I said, like security is a journey, you always have to improve security to raise the bar for security. So, we are doing quite often uh upgrades in order to add new features because uh as you probably know uh there are there are plenty of new features in the blockchain ecosystem. New blockchain to support means new cryptography to implement. Um new features on Ethereum blockchain uh means like uh a specific support in uh the Ethereum app or in the operating system. Like for instance, we we have to support BLS just uh for the deposit contract for Ethereum in order to uh to interact with uh with the blockchain. And for that, that means we we need to do uh uh a firmware upgrade and upgrade the operating system in order to uh provide this uh this feature. Also, we have we are integrating these days like the ENS integration within the device. That means you will be able to uh send directly Ethereum to uh Vitalik.eth if you want to send uh to send them to send him some uh some Ethereum. And on the device you you will have this resolution, and this requires some like uh uh operating system upgrade, and the operating system uh needs to uh to access to the to the secret key.

12:27
Charles Guillemet

So yeah the the this is uh this was a little bit long but I I want to to give more um uh more kolor uh to all of this and frankly

12:37
Charles Guillemet

I I learned two things yesterday. Uh the the the the first thing is

12:43
Charles Guillemet

Like the community cares a lot about Ledger. Like when you have this kind of reaction, that means like things are important, Ledger is important for the ecosystem, and frankly, this is the this is touching for me, for us at Ledger. And the second thing is like we we could have done a better job at explaining how all of this works because uh that was not completely clear for everyone.

13:05
Ryan Sean Adams

Yeah, I I would deck definitely echo um both of those points that um people care so much about Ledger because this is sort of a I'm we all have one. We've been ledger users forever on the bankless journey. I mean, this is the non custodial hardware wallet that um we recommend that um the you know the community has has largely adopted. So so we we all very much care. And yeah, I would echo that um

13:34
Ryan Sean Adams

Man, the comms around this uh was was real rough. And of course, like Twitter can get into all sorts of um they they can mob attack, they they can pitchfork. Um, and uh yeah, I do think this will be a learning lesson for Ledger moving forward and in how to explain this. But um you've uncovered so many, you've talked about so many things, Charles. I feel like we need to kind of double back and get to get to sort of the first section of this. And I do want in a little bit uh for David and myself to pull up a visual of kind of like the the hardware itself so that people don't leave this podcast episode without understanding the inside of how their ledger device might be working. But before we get there, the main concern on people's minds, you talked about um two different kinds of uh user personas, I think Ledger is maybe appealing to. One is sort of the you know, the crypto OG, the non custodial uh maximalist side. And you know, there are there are a few, very few that you know bought buy a uh brand new hardware laptop from

14:35
Ryan Sean Adams

uh from Best Buy or something and like and like set it up from scratch, right? But there are a lot of people who depend on Ledger to be sort of their

14:43
Ryan Sean Adams

Their non-custodial crypto wallet where the private keys don't leave that particular device. And that's that's a lot of people on the bankless journey right now. And then there is a larger set of users that find it very difficult. My my parents would be one of these for instance. They would find it very difficult to actually set up a you know a hardware uh wallet in Ledger and store those seed that seed phrase in a safe location. And what what Ledger is saying, hey, we want to appeal to that audience too, and we want to have a um a product for them. And so there's this bifurcation, right? And what I think some of the the OG users are worried about is that Ledger has forgotten about them somehow. And so one core question I have for you, and I want to make sure that people are clear on this, this recover service that we talked about, that is, that is more for um people who want to veer on the spectrum more towards a little bit more custody rather than than uh self-custody. Is this opt-in or is this forced? Is this forced on everyone with a ledger device with a firmware update? Or can they say no? Can they, do they have to read and if they can say no, how do they say no? Do they just not download the firmware? Is there a box you can check? Is is are is there a forked version of the software? Let's make sure we understand this first.

16:08
Charles Guillemet

Yeah, uh if you don't like the service, you you don't even have to say no. It's the it's the opposite. If you want the service, you you have to subscribe, you have to create an account, you have to go through uh the identity verification process because this service works with uh identity verification. And if you don't do that, like nothing happens, like you don't subscribe to the service and nothing happened to your seed. Like it stays on your device completely uh secure, and that's it. So of course it's optional, completely optional. If you don't like the this ID, like don't do anything. You can upgrade your firmware, you can upgrade your ledger live, nothing will happen.

16:47
Ryan Sean Adams

So if I upgrade my firmware, this doesn't introduce some sort of difference. This doesn't introduce some sort of backdoor. This doesn't introduce some sort of way for um ledger through a software update to uh you know uh

17:03
Ryan Sean Adams

Extract out my private keys. Is that is what is different about this firmware upgrade versus previous uh firmware upgrade? So anyone who's had a ledger for any number of years has obviously upgraded their their firmware. Why? For security updates. Um because they want additional support, more features, more comp C, right? So like no one has the original version of the, well, very few have the original version of the Ledger software. But what people are worried about is this new firmware update might um degrade the the security posture that Ledger has had on the firmware device so far. Can you can you talk about that?

17:40
Charles Guillemet

No, so in short, no, it doesn't degrade the security posture of ledger of anything in this area. As I mentioned, like it adds a new functionality that you can choose to use or not use. But the operating system, like before this upgrade, the operating system has a full access to your secret.

18:03
Charles Guillemet

And as soon as you want to use this secret, you have to consent.

18:08
Charles Guillemet

After this upgrade, this is the same thing. The operating system has still full access to your seed. And as soon as something touches your secret, you have to consent. There is just a new feature, a new possibility for recover to be activated and to be used. And if you want to use it, you will have to consent on the device. Do you want to initialize a ledger recover backup phase? There is this piece of code inside the operatic system on top of what existing before, what was existing before. But the same way we are adding new applications and new features, you don't have to use them. If you don't like Bitcoin, you just don't uh uh install the Bitcoin application, you don't uh you don't cite transaction, and that's it. In in this case, if you don't like this service, you simply don't have to use it.

19:18
Charles Guillemet

It's the same.

19:20
David

And so I think I think at this point in this conversation, we need to unpack the guts of what makes a ledger a ledger. Uh, and so I think this uh visual uh that I believe Haseeb made from scratch uh is pretty useful here. And so I I think listeners should just view a ledger as two boxes, one box inside of a bigger box. The bigger box is your ledger, the actual device. And inside of that ledger is this secure element, and that is the thing that houses the private key. And so the outside box is like the computer, the device, the chip that manages the secure element, and then the secure element has the private key, and that is like the fort nocks of your ledger. And I think why the the answer to the question, why is everyone so upset right now, is that people previously thought that the secure element, it's impossible for private keys to leave the secure element. That is the purpose of the secure element. Uh, and that is the design that ever that people talk about, the hardware wallets. I say, like, yeah, you get a hardware wallet because humans are messy and hardware wallets have one job, which is to not allow your private keys to leave the hardware wallet. And Charles, what you're saying is that that is still true.

20:30
David

Because you can sign a signature, you can like prove a message on your ledger that requires human input to ever allow for private keys to leave the to for a signature to be signed. But what's different here in this new firmware update is that people are now understanding that that secure element also has software in it, and firmware can update the software of the sick of the secure element. And with this new firmware update, the software inside of the secure element is able to be updated in a way that can allow for the seed, the private keys, to be escaped, to escape from the hardware wallet. If you physically approve the hardware wallet, if it's in your hands and you hit the little checkbox that says approve, but it can now do that. And this product that Ledger is making is the uh as soon as you approve that, it chards it into three different shards, it encrypts each one twice, sends it to different custodians of the world.

21:26
David

probably d uh the most secure way to secure a seed phrase, but people are now understanding that the secure element is actually software, not hardware. And this has caused people's concern. Is it uh is this a good summary?

21:41
Charles Guillemet

I think it's uh it's a good summary of the misunderstanding. What you need to understand like the secure element is is a circuit. It's a circuit with low low capacity processing, but uh this part is true. With some uh crypto accelerator, that means that there are pieces of hardware that can accelerate the cryptographic operation. But when I say when I refer to ledger operating system, like this part is software, it's firmware, and this part is implemented inside the secure element.

22:12
Charles Guillemet

It's possible for the keys to not leave the secure element even if uh even when you are doing uh a signature, because the operating system inside the secure element has access to the keys and can be upgraded.

22:26
Charles Guillemet

Like I mean, when when when we added the when we had the support for uh BLS on um on for ACROM, for instance, that means that we have to add a new feature in the operating system.

22:38
Charles Guillemet

So we are uh writing the code for uh BLS support, and then we are upgrading our operating system so that now it supports BLS and this operating system runs inside the secure element. Uh when when you think um secure element, like secure element is a is a small computer, like there is a small uh MCU, there is a dedicated RAM, there is a dedicated flash, uh, there is um a crypto accelerator, there are different uh peripherals in order to communicate with the rest of the world. This is what a secure element is, and this secure element needs to run some code, like this is not like something magic. Uh and this code is the one we uh we wrote and for years now. Uh this is an operating system. So we load our own operating system, there is an attestation mechanism, uh, there is some uh there are some integrity uh checks in order to make sure that this is our code that runs inside and not another. Um there is um uh there is the the attestation allows to do this firmware upgrade over the air securely because when you do a firmware upgrade, we want to make sure that the firmware comes from us, and then there is the old uh like secure channel attestation. At Ledger, we have uh different checks and controls so that when you when we do uh operating system upgrade, uh we need this upgrade needs to be signed, so we have a multi-signature uh process within Ledger so that to make sure that this new operating system version uh does not introduce uh like uh backdoors or or bugs and so on. But this operating system runs inside the secure element. And this is the same with um your Bitcoin application or Ethereum application. When you load your uh Ethereum application, it's loaded inside the secure element and it runs on top of the operating system. Like if you think like like a computer, like uh the Nano is like the secure element is your computer.

24:34
Charles Guillemet

Uh and the inside the DCQN there is a flash which which would be your hard drive. Uh there is um there is RAM uh exactly as in your computer. There is an operating system like Linux, but it's really small, really smaller and and very few features, it's mostly cryptographic and security oriented. And you can run apps like um uh any app on on Linux, and and there the apps are Bitcoin, uh Ethereum, and others. This is the app that are running inside. So it's like I it's a metaphor, it's a it's a comparison, but I I think it's quite uh it's quite uh a fair one. If because what I realized that was some some people was uh thinking that there was some magic, like the the the seed is inside the secure element and we can add new features uh without uh this feature touching the the secret. No, it it can't it it can't work like that like that. Uh the cryptography um signature, uh encryption, um uh everything related to uh the use of your assets needs to access to your seed. And as soon as we add new features, we upgrade this code so that uh it can do it can it can do new things, but again with your consent, always. This is this thing never changed.

25:53
David

Sure. And so I I would imagine from the ledger perspective, uh, understanding how a ledger works, you this update is released, and then from your from the ledger perspective, everyone is up in arms, is like, oh, you can update the secure enclave, and you guys are like, Yeah, we've been doing that this entire time. That's what that's what that's what firmware updates are. What what you guys think was going on? But then from our perspective, is like it's uh it's specifically the nature of this update that has opened up some doors as to like what could happen in the future. And so, like, there's there's two doors that have opened, which is okay, now Ledger has made a product that opens up access to private keys on an opt-in basis. But what is down, what is down that road? Like, how easy does that get? Like, there's now an API that goes to my private keys that is an opt in basis, but it it raises concerns about like, okay, well, what if a nation state comes and starts to twist Ledger's arm? And what happens if in one or two or five years the doors to accessing my private keys are much larger than they are now? And then also.

26:58
David

Now there's an additional attack vector, which technically has always existed, but now we are more aware of it. Is there's just one rogue firmware update away from uh a rogue firmware update that would make accessing private keys uh trivial? And so now we are all understanding that uh if ledger is compromised or some firmware update is compromised, that that could be a black swan event, if you will, because everyone's ledger is compromised if we all download this new rogue firmware. So that's a new security vector, which I'm guessing, again, it's already has always been there, but now we're aware of it. Um do you have any thoughts or reflections on these concerns?

27:37
Charles Guillemet

Yeah, you're completely true. And it's it's true for every wallet, whether they are software or hardware. When they are harder, it's a little bit more complex because you have to upgrade the firmware and then you need some collaboration between like Ledger Live or the software uh interfacing with the hardware. But yeah, you you're totally true. Uh and this is the level of trust that I were I was mentioning before. When you use Ledger, there was there was some level of trust that you need to put into Ledger so that we don't do uh a very nasty thing. And if you don't want to uh to have any trust, as I as I said, it's it's really really complex. There is it's always a trade-off between like trust, security, and self-sovereignty. And uh it's yeah, it's it's it's impossible to be completely trustless. You would need you would need to be uh to build your own computer because uh if you want to be trustless, you can you can trust your own computer. And then you would need to build the software running on top of it. But when we're building software, you need a compiler. So how do you trust the compiler? You you're going to you you would need to build the entire stack that the the overall electronic and software industry uh have been built during 50 years. So, what I want to say it's impossible uh for one human to be completely trustless in this process. And then the the it's a matter of trade-off, like where do you put the cursor or of I trust this guy for uh managing uh and providing me uh the right tools, and I'm completely self-sovereign. And these cursors are plenty of different shades of grey. And as you as you mentioned, I think like some people realize that there was there were they were trusting ledger a little bit more than they thought. And I think this is this is what happened yesterday.

29:29
David

I'm reminded of a metaphor that was used when uh I actually remember this pretty clearly. Vitalik was on the Eric Weinstein's podcast, and they were talking about the 2016 Ethereum DAO hack. And the social contract of Ethereum at the time was completely autonomous, robots only, don't trust the humans. And then the DAO hack happened. And then it was like this it was a robot, and you rip the mask off the robot and there's a human there. And I think this is the same thing that's currently happening with Ledger. Is everyone thought it's like, oh, it's completely hardware. You don't have to trust humans. Uh, the hardware's got you. That's the whole point of the hardware wallet. And now with this understanding about like what a firmware update means and how deep a firmware update goes, people are now realizing that, oh, it's a human there. It's Ledger, which is a company of people that is uh incorporated in France that uh has founders and leadership. And so now I think the crypto world is now coming to terms with that and is now going to ask Ledger, the company, to make a very strong social contract to the crypto industry, to the crypto believers, the the crypto hardliners, if you will, which are causing this uproar. About you with now that this new attack vector is opened up, this can the genie's out of the bottle, how are you guys going to sign a social contract on our behalf? And is that even possible? I think that is kind of the question that everyone's learning how to ask right now, including myself.

30:49
Charles Guillemet

Yeah, it's it's a good one. I I think like the the social contract uh is is what I said before, as soon as like the software, the firmware is touching your secret.

31:00
Charles Guillemet

Like it's up to your consent. There is a always you need to authenticate yourself. Always the everything starts with the PIN. And after the PIN, like as soon as something touch your secret to do like sensitive operation, I'm not saying generating a public key. But for everything related to using private keys and so on, you are always prompted and you you need to uh consent for that. And this contract never changed.

31:34
Charles Guillemet

At some point you you need to trust us d for not putting back doors. And for this there is there is no real choice and it's always the case for every uh single wallet uh vendors w whether it is uh it is uh hardware or or even software.

31:49
Ryan Sean Adams

Well it's interesting. So I okay, so I I'm hearing this loud and clear. There's really like two levels of consent on the device but before you know allowing this, and that's just on the device, allowing this kind of recover service. One is you update the firmware, right? So there there could be a swath of people listening to this saying, I, you know, am not going to update the firmware, and that if so, that's your choice. You you you bought the hardware device, you don't have to update the firmware if you don't want to. But

32:14
Charles Guillemet

It's a bad idea. It's a bad idea.

32:16
Ryan Sean Adams

It's a bad idea. Well I let me get back to that. But it's like the so that that is a first thing you have to do. A second thing is um

32:22
Ryan Sean Adams

Uh there's actual physical approval from uh ledger if you want to, if anytime it's going to act uh touch your secret, and so opt you, like get you into the recovery service. There's something you have to actually click approve on your ledger device. So there's kind of two layers here. Now, getting back to it's a bad idea, right? To not update your firmware, that this is kind of the the trade-off spectrum I I think people had. Like, how uh to Bankless System, I guess, and to myself, I'm asking you this question: how certain am I that the existing firmware version on my ledger device uh doesn't have a security flaw in it? Like, I don't know. I mean, this is part of what um a company like Ledger, I imagine, provides is when you identify any sort of security flaw or some sort of issue, um, you kind of patch that. You you fix the bug and you require or you ask for a firmware update from all of your users, right? So that's kind of an unknown for me, in addition to like the whole world of all of the features that um I might want in the future for my ledger device. So that's kind of a choice you have to make. It's like how secure is your existing, the existing version of your firmware? You really don't know. And what if a flaw is uncovered? Who who do you kind of trust to um you to patch that up? Uh so that that is kind of the trade off, but you wanted to say something here, Charles.

33:48
Charles Guillemet

Yeah, what I wanted to say is it's a bad idea to uh not update your your firmware because uh in firmware update there are there are always security improvements, some sometimes it's it's even a vulnerability fix. There was and we are completely transparent about that. You can go on dungeon.ledger.com slash lsb for ledger security built-in. And every every time we we uncover a new vulnerability, whether it is our teams or external teams, we are first fixing them and then we are uh we are uh publishing the ledger security built-in. And and to be completely transparent, like a few days, weeks ago, we we have we have found something quite interesting on the implementation of mini script. We are uh we are among the the only one supporting well miniscript, and there was a team um uh integrating like this miniscript implementation and they found uh something uh uh something quite interesting, a vulnerability. So we worked with them, we fixed the vulnerability. And if your Bitcoin app is up to date, you uh you this vulnerability is fixed. Uh if you're not now uh the attacker knows the vulnerability because now it's public and you are vulnerable. So that's why it's really important to uh to always uh update your firmware and and the application.

35:04
Ryan Sean Adams

This is such a hard situation for for I think users who who want to be completely bankless and and uh self-sovereign to to be in because we have to sort of make a choice. We have to and I I guess maybe the question goes to like David is pointing to sort of the social contract that Ledger can make um to say we believe in self-custody. Um you know we we can uh we believe in uh you know kind of transparency. We um are going to do our best to kind of protect your device at all times and keep your private keys in the secure uh enclave and only ask your your permission if if you know something changes. But um I I'm wondering if we can even get stronger on because crypto is very much an industry of like don't trust but verify, right? And so like, is there a way that

35:54
Ryan Sean Adams

Crypto, a listener, can have assurances that Ledger hasn't introduced some sort of backdoor. Like, can we open source this? Is that not a pavu? Is there is there some way to guarantee this? I mean, I don't even want to rely on like third-party auditors here, but you you see what I'm saying? It's just like, um,

36:14
Ryan Sean Adams

how can we be sure that a future ledger firmware update does not introduce some sort of uh backdoor, right? Because you know, ledger's now a large company. I'm I'm sure there are author authorities. I'm sure there are nation states who uh somewhere on the planet would like to introduce some sort of backdoor into a future uh firmware update. And um yeah, how how can we verify that this indeed hasn't happened? Do we just have to basically trust at the social contract layer that you haven't done that?

36:48
Charles Guillemet

So first first I'm gonna uh start with the social contract. And again, we we are pro self-custody. Like this is this is the purpose of Ledger. We would like everyone to be completely uh self-sovereign and completely in self-custody. And I as I mentioned, like in this self-custody journey, there are different shades of grey, and and there are the reality is that today we are very few in self-custody. Okay, I'm it's important for me, it's important for you. But at the end, this what's what is this part of the crypto ecosystem? Most of people are using Robinhood to buy uh Bitcoin or are leaving their Bitcoin on an exchange. This is the situation, the situation right now. So, how can we make sure that these people come a little bit closer to self-custody? And I think this kind of feature goes in that direction. I would love that everyone understands very well that self-custody is the purpose of blockchain revolution. This is something I say like every time I can speak. But the reality is that's not the case right now. Most people are using Bitcoin as it's as it as they were speculating on stocks. This is not the purpose of like crypto, Ethereum, or Bitcoin.

Ryan Sean Adams

1115 posts

Crypto investor going bankless.

A huge thanks to our Friends & Sponsors
No Responses