Skip to content
Archive

Post

Back to deliverables

𝐓 TheCrypticWolf1
𝐓𝐡𝐞𝐂𝐫𝐲𝐩𝐭𝐢𝐜𝐖𝐨𝐥𝐟
@TheCrypticWolf1

@NeilMoonstrong @DCENTWALLETS The recent coldcard incident involved an open source wallet. Did you trust them because they did so? It goes to show transparency alone doesn't prevent bugs in code. Sure closed source requires more trust in the company and auditors. Each has their trade offs.

· 30 Views

replies reposts likes
1 replies collected
Neil Moonstrong 🌙 💪🏿 @NeilMoonstrong ·

Transparency alone doesn’t prevent bugs nobody said it did. The Coldcard issue was a specific RNG implementation fuck-up that reduced entropy. Open source is what let people actually see and understand what went wrong instead of just taking the company’s word for it after the fact. Closed source doesn’t magically stop the same class of bug. It just means the public never gets to look. You’re still left trusting the company + whatever auditor they paid. With a small closed-source outfit that’s exactly the “trust me bro” situation I’m talking about. That’s why I fuck with Ledger. They keep a lot of the stack open so people can actually review it, while still locking down the Secure Element the part that actually holds the keys. It’s a more balanced approach. And they’re a real company with 700+ employees and serious resources, not a 50-person operation running out of a little building in Gangnam hoping nobody looks too close. Trade-offs exist. I’d still rather deal with the bigger, more established player that at least opens most of the code than put full trust in a tiny closed-source shop and their “trust me bro” audit.