{"id":30086,"date":"2023-05-20T04:36:16","date_gmt":"2023-05-20T11:36:16","guid":{"rendered":"https:\/\/coinnetworknews.com\/ledger-co-founder-clarifies-there-is-no-backdoor-in-recover-firmware-update\/"},"modified":"2023-05-20T04:36:16","modified_gmt":"2023-05-20T11:36:16","slug":"ledger-co-founder-clarifies-there-is-no-backdoor-in-recover-firmware-update","status":"publish","type":"post","link":"https:\/\/coinnetworknews.com\/ledger-co-founder-clarifies-there-is-no-backdoor-in-recover-firmware-update\/","title":{"rendered":"Ledger co-founder clarifies \u2018there is no backdoor\u2019 in \u2018Recover\u2019 firmware update"},"content":{"rendered":"

<\/p>\n

\n

The launch of Ledger Recover \u2014 a\u00a0 new service allowing users of the Ledger hardware wallet to back up their secret recovery phrases \u2014 was met with immense resistance from the crypto community. Ledger co-founder and ex-CEO \u00c9ric Larchev\u00eaque took the criticism against Ledger as \u201ca total PR failure, but absolutely not a technical one.\u201d<\/p>\n

Ledger Recover is an over-the-air firmware update allowing users to back up their seed phrases<\/a> with third-party entities. If a user opts into the new service, the recovery phrase fragments are encrypted and stored by three parties, allowing the user to recover the phrase in the future. However, the seed phrase leaving the hardware wallet did not resonate with users who considered Ledger a trustless service for storing cryptocurrencies.<\/p>\n

Addressing the rising concerns of users worldwide, Larchev\u00eaque posted<\/a> on Reddit clarifying that Ledger was never a trustless solution:<\/p>\n

\u201cSome amount of trust must be placed into Ledger to use their product. If you don\u2019t trust Ledger, meaning you treat your HW manufacturer as an adversary, that can\u2019t work at all.\u201d<\/p><\/blockquote>\n

He argued that the Ledger Recover update does not impact the hardware wallet\u2019s security model, adding:<\/p>\n

\u201cMy mistake as a CEO during my tenure was probably not be relentless enough about explaining the security model, but at some point you just give up as people don\u2019t care at all. Until they care again, like now.\u201d<\/p><\/blockquote>\n

Larchev\u00eaque believes the only thing that changed was the general user\u2019s perspective on trustlessness, and that the Recover code in the firmware was not malicious: <\/p>\n

\u201cLedger is still safe, there is no backdoor, the Ledger Recover is not a conspiracy, no one will ever force anyone to use Recover.\u201d<\/p><\/blockquote>\n

Trusting Ledger with sharding the seed phrase is just like trusting Ledger with signing a transaction, he added. Addressing a user\u2019s recommendation about having two different firmware to eradicate \u201cbackdoor\u201d concerns, Larchev\u00eaque said that \u201cit wouldn\u2019t change anything\u201d and would be saddening for him personally.<\/p>\n

The firmware update in question is not available for the Nano S \u2014 Ledger\u2019s cheapest hardware wallet offering \u2014 as the chipset does not have enough memory to store the new firmware.<\/p>\n

Related: <\/em><\/strong>Crypto community reacts to Ledger wallet\u2019s secret recovery phrase service<\/em><\/strong><\/a><\/p>\n

Amid the rollout of Ledger\u2019s controversial firmware update, competing hardware wallet provider GridPlus decided to open-source its firmware for its users. <\/p>\n

\n

The most trusted name in cryptography, relied upon by the world’s governments for their highest security applications for decades, sold products backdoored by the CIA. How can we ensure this won’t happen again? Open-source software.<\/p>\n

GridPlus will open-source its firmware in Q3. pic.twitter.com\/889OnqXd20<\/a><\/p>\n

\u2014 GridPlus (@gridplus) May 18, 2023<\/a><\/p><\/blockquote>\n

Turning the Ledger controversy into a marketing opportunity, GridPlus announced plans to open source its device firmware in the third quarter of 2023 to deliver greater transparency.<\/p>\n