Skip to main content

DON'T enable this feature on Ledger Nano X

 

‘There Is No Backdoor,’ Ledger Says in Response to Recover Reactions


Ledger’s newest Nano X update allows users to subscribe to a recovery tool that encrypts the users’ seed phrase and sends it to different custodians to reconstruct the seed after going through ID verification.

However, Ledger customers are less than pleased by the news.

Mudit Gupta, Polygon Labs’ chief information security officer, warned users not to enable the feature, calling it a “horrendous idea.”

Though Gupta did not take issue with the breakup of the key — he praised it, stating that “I may or may not be doing that personally as well.”

Gupta’s concern stems from the ID verification and the key access given to the contacts who are chosen by a user to store key parts, as it could open a door for identity theft.

Ledger just released a new update for Nano X that allows social recovery of your seed phrase.

It encrypts your seed in 3 shards and sends it to different entities that can then reconstruct the seed for you post ID verification.


It's a horrendous idea, DON'T enable this feature. 

— Mudit Gupta (@Mudit__Gupta) May 16, 2023

Gupta wasn’t the only person concerned about the update.

So the seed can leave the device now?

Sounds like a different direction than "your keys never leave the device". 🤷‍♂️

— CZ 🔶 Binance (@cz_binance) May 16, 2023

Stop using Ledger hardware wallets. Migrate away from them immediately. They’ve shown nothing but gross incompetence and wild misunderstanding of their own purpose. And now they’ve publicly admitted to intentionally backdooring their own proprietary hardware. Stop using Ledger pic.twitter.com/LLFFUsOW4y

— foobar (@0xfoobar) May 16, 2023

In a video on Twitter, Ledger Chief Technology Officer Charles Guillemet said that “there is no backdoor for anyone, neither us, a provider or even a very gifted hacker to access it.”

“Back door would mean that we control all ledger devices and could run automated updates for example…That’s not the case. Will never be the case. Only you can use functions on your Ledger. No one else can enter your pin code and press those buttons,” CEO Paul Gauthier also said.

The Recover feature is an opt-in feature.

“Ledger Recover is an optional subscription for users who want a backup of their Secret Recovery Phrase. You don’t have to use it, and can continue managing your recovery phrase yourself if that’s why you bought a Ledger,” Ledger tweeted.

Ledger Recover is an optional subscription for users who want a backup of their Secret Recovery Phrase. You don’t have to use it, and can continue managing your recovery phrase yourself if that’s why you bought a Ledger.

— Ledger (@Ledger) May 16, 2023

“The device sends encrypted shards of your seed to different companies if you decide to use the service. You can of course still choose to [back it up] yourself,” Ledger’s co-founder said on Reddit.

Ledger claims that “self-custody remains and will always be at the core principle of Ledger.”

Self-custody remains and will always be the core principle of Ledger. The ethos of self-custody is that it’s your choice – you can choose to manage all your assets yourself, or you can have a backup with Ledger Recover.

It’s up to you – and that won’t change.

— Ledger (@Ledger) May 16, 2023

Wired, in February, clarified that the three recovery custodians would be Ledger, Coincover – a crypto custody firm – and EscrowTech – a code escrow company.

The concern around Ledger’s update comes a few years after the company was targeted by a cyberattack in the summer of 2020 which led to personal information of 270,000 customers being leaked.

In response to the announcement, some Twitter users suggested that Ledger make Ledger Recover a totally separate product.

Ledger did not immediately respond to a request for comment.

Comments

Contact us

Name

Email *

Message *

Popular posts from this blog

Cryptocurrencies Adding to the Safety and Security in the UK Gambling Industry

These are exciting times for the UK gambling industry. The impact of internet technology is now being felt with online gambling now controlling the industry.  The adoption of cutting-edge technology is reasonable for the boom in the industry. From live casinos, mobile apps to artificial intelligence, incredible trends continue shaping the gambling industry. However, it is the rise of cryptocurrency casinos that seeks to redefine UK gambling.  Many operators now include crypto coins such as bitcoin, Ethereum and Litecoin as part of their banking methods. Others offer exclusive bitcoin payments and promotions based on digital tokens. This revolutionary trend has a huge impact due to enhanced safety and security on these platforms. Players looking for peace of mind when playing online now opt to use cryptocurrencies. This post looks at how cryptos guarantee the safety and security of players at online casinos. How Cryptocurrency Gambling Works There’s a lot of talk about cryptocurrency,

Will Solana (SOL) Be the Shining Star of the Bull Market?

About 250,000 to 700,000 SOL have been sold daily by FTX for the last three weeks. SOL’s price jumped above $60, as GSOL’s premium also increased. While the price may retrace, it may not take long before SOL hits $70. Despite being a notable casualty of the FTX contagion in 2022, Solana (SOL) has defied all odds in 2023, as the price continues to outshine its peers. In the last 30 days, the value of SOL has increased by 180%, rising as high as $62 on November 11. However, the rising price of SOL is not the only interesting thing the token has shown by the token. For a token that was once described as dead, it has shown tremendous strength. Coin Edition came to this conclusion because of a post by trader Bluntz Capital. The Big Players Are Here According to Bluntz, FTX, after getting the go-ahead to liquidate its assets, has been selling around 250,000 to 700,000 daily for the last three weeks. Regardless of the sales, SOL has failed to nosedive. Rather, the price has chosen the upside

Terra Classic Community Passes Major Constructive Proposal, LUNC And USTC To $1?

  The Terra Luna Classic community has passed another key proposal as they prepare for a revival of Terra Luna Classic (LUNC) and repeg USTC stablecoin to $1.  The proposal aimed at having a guideline for a pay-per-job approach on the Terra Classic chain as core developer L1TF goes into maintenance mode for Q4. Meanwhile, the community is also collaborating on other fronts to keep LUNC and USTC above key support levels as traders started booking profits amid the latest pullback in the crypto market. Terra Luna Classic Passes Pay Per Job Proposal Proposal 11889 “Pay-per-job and governance-ruled Job List” has passed successfully. The proposal deemed the monthly model of roadmap and payment planning as suboptimal and plans to switch to a pay-per-job model. The proposal has received 91.99% “Yes” votes, with others mostly voting “Abstain”. The community believes it will optimize compensation structure, provide flexibility and transparency, boost community engagement, and risk mitigation. A