Skip to content
Archive

Post

Back to deliverables

L ledger_business
Ledger Enterprise
@ledger_business

Ledger Enterprise is not affected by the recent Coldcard incident. According to Coinkite's own advisory, the issue traces back to firmware released in March 2021, affecting multiple Coldcard models through their recently fixed versions. Seeds generated on the affected firmware carry significantly reduced entropy. Fixed firmware is now available for every affected model, and Coinkite has published migration guidance for impacted users. We'd point readers to their advisory directly for the confirmed technical detail (link in comments). At Ledger Enterprise, Shared Owner seeds are generated by Personal Security Devices (PSDs) using the hardware True Random Number Generator within the Secure Element. The relevant production see generation path has been reviewed and does not provide any fallback to a software based or otherwise non-secure RNG - as was the case for Coldcard. The TRNG is evaluated under AIS-31 and certified at PTG.2. The Secure element carries Common Criteria certification at EAL5+ or EAL6+, depending on the signer. LedgerOS, the Ledger Enterprise platform and PSDs are reviewed regularly by our internal security team, the Donjon, learn more in the comments. Ledger Enterprise's Personal Security Devices and Secure Element architecture are not exposed to the RNG issue affecting Coldcard Mk3 devices.

· 2.5K Views

3 Reposts 1 Quotes 16 Likes 2 Bookmarks
replies reposts likes
2 replies collected
Ledger Enterprise @ledger_business ·
1
H.O.P.C🐈 @hopcofficial ·

@ledger_business This is exactly why a Secure Element with a real hardware TRNG is different from a software fallback. Thanks for the clear explanation.