{"id":24158,"date":"2023-05-16T12:54:11","date_gmt":"2023-05-16T16:54:11","guid":{"rendered":"https:\/\/cryptocornercafe.com\/cafe\/?p=24158"},"modified":"2023-05-16T12:54:11","modified_gmt":"2023-05-16T16:54:11","slug":"is-this-latest-ledger-firmware-update-a-disaster-in-the-making","status":"publish","type":"post","link":"http:\/\/cryptocornercafe.com\/cafe\/2023\/05\/16\/is-this-latest-ledger-firmware-update-a-disaster-in-the-making\/","title":{"rendered":"Is This Latest Ledger Firmware Update A Disaster In The Making?"},"content":{"rendered":"<p>Ledger, the hardware wallet provider, recently upgraded its firmware to version 2.2.1. They introduced an additional safety net called the \u201cLedger Recover\u201d that the crypto community is vehemently rejecting.\n<\/p>\n<p>While upgrades are critical considering the fast-paced nature of cryptocurrencies, Ledger is now being\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/www.reddit.com\/r\/CryptoCurrency\/comments\/13im3bc\/wtf_ledger_this_is_a_disaster_waiting_to_happen\/\" target=\"_blank\" rel=\"noopener\">criticized<\/a> after offering an option for users to store their seed phrases online. The hardware wallet manufacturer said this feature makes it easier for users to quickly recover their seed phrases in case they misplace them.<\/p>\n<h2>The \u201cLedger Recover\u201d Feature Rejected<\/h2>\n<p>The subscription-based service called \u201cLedger Recover\u201d effectively grants the manufacturer access to clients\u2019 seed phrases; defeating the purpose of using a cold wallet in the first place.<\/p>\n<p>Related Reading: <a href=\"https:\/\/www.newsbtc.com\/news\/doj-crypto-task-force-goes-after-hackers\/\" target=\"_blank\" rel=\"noopener\">DOJ Crypto Task Force Goes After DeFi Hackers As Illicit Activity Soars<\/a><\/p>\n<p>The platform says Recover is an \u201cID-based key recovery service that provides backup\u201d for seed phrases for coins like Bitcoin.<\/p>\n<p><a href=\"https:\/\/www.tradingview.com\/x\/Iklm5YRC\/\"><\/a><\/p>\n<p>Earlier, Ledger\u2019s co-founder\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/np.reddit.com\/r\/ledgerwallet\/comments\/13itm7u\/is_there_a_backdoor_yes_or_no\/jkbyyfp\/\" target=\"_blank\" rel=\"noopener\">said<\/a> Recover will split a seed phrase into three shards. A section is distributed to Ledger, Coincover \u2014 a crypto custody firm, and EscrowTech, a company that escrows codes. Therefore, if a user loses access to their cold wallet by misplacing their private key, two of the three custodians can combine their code to recover the wallet\u2019s contents.<\/p>\n<p>While this could help, as it is designed, a cold or hardware wallet is non-custodial. Technically, it should be delinked from the internet. By default, Ledger wallet holders should always be responsible for their seed phrases.<\/p>\n<p>Seed phrases allow users to sign transactions confirming that they are the true owners. Whenever they are misplaced, the token owner losses access to all their coins.\u00a0<\/p>\n<p>Although the \u201cLedger Recover\u201d feature is a precaution, some even claim this move makes Ledger a \u201chot\u201d wallet. A hot wallet is a cryptocurrency wallet connected to the internet and is often the target of nefarious agents. Whenever hackers strike, they aim to wipe clean assets stored in hot wallets like MetaMask or Coinbase Wallet.<\/p>\n<h2>KYC Requirements And Learning From The Past<\/h2>\n<p>Besides Ledger requiring access to private keys, the \u201cRecover\u201d feature demands that users verify their identity as part of the know-your-customer (KYC) rules.\u00a0<\/p>\n<p>As part of this verification and compliance with KYC, users must submit their government-issued cards. Critics say this is against the principles of crypto that work toward preserving privacy and diffusing power from one entity.\u00a0<\/p>\n<p>Trusting private identity documents to a centralized entity can be disastrous. In 2020, Ledger\u2019s database was\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/twitter.com\/_pgauthier\/status\/1341084660953194497\" target=\"_blank\" rel=\"noopener\">compromised<\/a>, and hackers dumped hundreds of thousands of wallet buyers\u2019 confidential information, including physical addresses. <\/p>\n<p>Hackers\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/www.bitdefender.com\/blog\/hotforsecurity\/threat-actors-target-ledger-data-breach-victims-in-new-extortion-campaign\/\" target=\"_blank\" rel=\"noopener\">later<\/a>\u00a0used the same dumped details to target clients in an extortion campaign that affected even some of the top executives of Ledger.<\/p>","protected":false},"excerpt":{"rendered":"<p><!-- wp:html --><\/p>\n<p>Ledger, the hardware wallet provider, recently upgraded its firmware to version 2.2.1. They introduced an additional safety net called the \u201cLedger Recover\u201d that the crypto community is vehemently rejecting.\n<\/p>\n<p>While upgrades are critical considering the fast-paced nature of cryptocurrencies, Ledger is now being\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/www.reddit.com\/r\/CryptoCurrency\/comments\/13im3bc\/wtf_ledger_this_is_a_disaster_waiting_to_happen\/\" target=\"_blank\" rel=\"noopener\">criticized<\/a> after offering an option for users to store their seed phrases online. The hardware wallet manufacturer said this feature makes it easier for users to quickly recover their seed phrases in case they misplace them.<\/p>\n<h2>The \u201cLedger Recover\u201d Feature Rejected<\/h2>\n<p>The subscription-based service called \u201cLedger Recover\u201d effectively grants the manufacturer access to clients\u2019 seed phrases; defeating the purpose of using a cold wallet in the first place.<\/p>\n<p>Related Reading: <a href=\"https:\/\/www.newsbtc.com\/news\/doj-crypto-task-force-goes-after-hackers\/\" target=\"_blank\" rel=\"noopener\">DOJ Crypto Task Force Goes After DeFi Hackers As Illicit Activity Soars<\/a><\/p>\n<p>The platform says Recover is an \u201cID-based key recovery service that provides backup\u201d for seed phrases for coins like Bitcoin.<\/p>\n<p><a href=\"https:\/\/www.tradingview.com\/x\/Iklm5YRC\/\"><\/a><\/p>\n<p>Earlier, Ledger\u2019s co-founder\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/np.reddit.com\/r\/ledgerwallet\/comments\/13itm7u\/is_there_a_backdoor_yes_or_no\/jkbyyfp\/\" target=\"_blank\" rel=\"noopener\">said<\/a> Recover will split a seed phrase into three shards. A section is distributed to Ledger, Coincover \u2014 a crypto custody firm, and EscrowTech, a company that escrows codes. Therefore, if a user loses access to their cold wallet by misplacing their private key, two of the three custodians can combine their code to recover the wallet\u2019s contents.<\/p>\n<p>While this could help, as it is designed, a cold or hardware wallet is non-custodial. Technically, it should be delinked from the internet. By default, Ledger wallet holders should always be responsible for their seed phrases.<\/p>\n<p>Seed phrases allow users to sign transactions confirming that they are the true owners. Whenever they are misplaced, the token owner losses access to all their coins.\u00a0<\/p>\n<p>Although the \u201cLedger Recover\u201d feature is a precaution, some even claim this move makes Ledger a \u201chot\u201d wallet. A hot wallet is a cryptocurrency wallet connected to the internet and is often the target of nefarious agents. Whenever hackers strike, they aim to wipe clean assets stored in hot wallets like MetaMask or Coinbase Wallet.<\/p>\n<h2>KYC Requirements And Learning From The Past<\/h2>\n<p>Besides Ledger requiring access to private keys, the \u201cRecover\u201d feature demands that users verify their identity as part of the know-your-customer (KYC) rules.\u00a0<\/p>\n<p>As part of this verification and compliance with KYC, users must submit their government-issued cards. Critics say this is against the principles of crypto that work toward preserving privacy and diffusing power from one entity.\u00a0<\/p>\n<p>Trusting private identity documents to a centralized entity can be disastrous. In 2020, Ledger\u2019s database was\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/twitter.com\/_pgauthier\/status\/1341084660953194497\" target=\"_blank\" rel=\"noopener\">compromised<\/a>, and hackers dumped hundreds of thousands of wallet buyers\u2019 confidential information, including physical addresses. <\/p>\n<p>Hackers\u00a0<a class=\"editor-rtfLink\" href=\"https:\/\/www.bitdefender.com\/blog\/hotforsecurity\/threat-actors-target-ledger-data-breach-victims-in-new-extortion-campaign\/\" target=\"_blank\" rel=\"noopener\">later<\/a>\u00a0used the same dumped details to target clients in an extortion campaign that affected even some of the top executives of Ledger.<\/p>\n<p><!-- \/wp:html --><\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[82],"tags":[],"class_list":["post-24158","post","type-post","status-publish","format-standard","hentry","category-blockchain"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/posts\/24158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/comments?post=24158"}],"version-history":[{"count":0,"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/posts\/24158\/revisions"}],"wp:attachment":[{"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/media?parent=24158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/categories?post=24158"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/cryptocornercafe.com\/cafe\/wp-json\/wp\/v2\/tags?post=24158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}