Oddbean new post about | logout
 Ledger Live Tracks and Sends ALL User Information to Outsourced Data Harvesting Service

"The tracking code is too structural to be just counting users and downloads, like regular apps do. Ledger Live is doing analytics on everything from screen views, to button clicks, error events, installs, uninstalls, etc. It's basically tracking everything. Anything you do on that app gets tracked."

https://www.nobsbitcoin.com/ledger-live-tracks-and-sends-out-all-user-information-by-default/ 
 No tyvoe ...
nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qpz3mhxue69uhkummnw3ezummcw3ezuer9wcpzpwd9xafrhw30ekhg2lvsmznkphj0yyuun7gdnphhgl886rkq69eaqvzqqqqqqye9kn9a 
 Maybe you would like to change and try @Blockstream or Coinkite or any other things better than Ledger.

nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qpzpmhxue69uhkummnw3ezuamfdejsyg9e55m4ywa69lx6aptajrv2wcx7fusnnj0epkvx7aruulgwcrgh85psgqqqqqqs7q3pl2 
 🤬 Was about to install the damn thing. Would be useful to explain how to opt-out from sharing analytics? Gonna take a look 
 Ledger has admitted they can access your private keys. Don't store anything on there. 
 A Ledger spokesperson refuted that, saying, “Customers can create an encrypted backup of their private keys which is then sharded and encrypted further […] The private key can only be decrypted and reconstituted on a Ledger’s secure element chip, just as it is initially encrypted and fragmented there. Ledger cannot and does not access users’ private keys.” 
 Yes and the CEO said if they receive a government subpoena they can decrypt the shards and hand over your coins.

Also, their software is closed source so there is no way to verify it is doing what they say it is doing. 

Ledger is not cold storage. 
 Glad they don't have such a device at Ledger HQ. /s 
 Glad I stopped using them. Don't know what to do with all my ledger nanos though. 
 Sell them on ebay. People aren't so smart enough to miss this great opportunity.  
 Don't use Ledger if you can avoid it. Every bit of news about these guys is worst than the last. 

If you do own a Ledger or know someone who does, and aren't in a position to get a better device, at least set it up in the best way possible, avoiding Ledger live. 

There is a great article by arman the parman that walks you through this process. You only use Ledger live initially to download the Bitcoin app, then you never touch it again. Then you set up a fresh Bitcoin wallet offline and connect to sparrow wallet.

https://armantheparman.com/ledgersparrow/

nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qpr4mhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet5qgstnffh2gam5t7d46zhmyxc5asdunep88yljrvcda68ee7sasx3w0grqsqqqqqp6zkcwp 
 it's all to improve UI/UX and quality of product 
 What is the best cold wallet? 
 Coldcard  
 Seedsigner. 
 Seedsigner 
 Trezor safe 3 
 SeedSigner 
 Ultimately the best one is for you to decide based on the needs and wants it satisfies. 
 nostr:note146qfrfa5f4np9aepl568uzl7hx5kdjnlufqhq6k7l5ywq86dr42qag7thv 

STOP USING VENDOR CLIENTS IF YOU WANT PRIVACY.

Signer vs Wallet should be separate like Church and State.

Now, imagine even accidentally how the information is stored, who can see it, who can cross reference with the hardware purchase, etc...

GRRRR 
 Big surprise!

The company that admits they can access your private keys also collects sensitive data. 

Who could have guessed! 
 People are taking notice of your post.
Added to the https://nostraco.in/hot feed 
 In other news, you can get 9% off the Coldcard hardware wallet with code BITCOINAUDIBLE.

Throw your ledger in the fucking garbage and get a Coldcard for fuck's sake 😳

nostr:note146qfrfa5f4np9aepl568uzl7hx5kdjnlufqhq6k7l5ywq86dr42qag7thv  
 If you're using a closed source hardware wallet and app to store your Bitcoin, you're doing it wrong 
 Ledger is a TERRIBLE product and company for so many reasons, I've lost count.

Braindead shitcoiners using this piece of 💩 is expected. But Bitcoiners should know better, and need to remember history.

nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qpzpmhxue69uhkummnw3ezuamfdejsyg9e55m4ywa69lx6aptajrv2wcx7fusnnj0epkvx7aruulgwcrgh85psgqqqqqqs7q3pl2 
 nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qppamhxue69uhkummnw3ezumt0d5pzpwd9xafrhw30ekhg2lvsmznkphj0yyuun7gdnphhgl886rkq69eaqvzqqqqqqynuqvcr 
 Not surprising. Here is Envoy for contrast.



nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qppamhxue69uhkummnw3ezumt0d5pzpwd9xafrhw30ekhg2lvsmznkphj0yyuun7gdnphhgl886rkq69eaqvzqqqqqqynuqvcr
https://image.nostr.build/b77aded565f5d38f79e7a6104b8e51c84690f37d7db0fd3fe40084cad39e21d5.jpg 
 How does this effect those using the Ledger Hardware wallet without using Ledger Live?

 
 it doesn't 
 Ledger แอบขโมยข้อมูล

#siamstr
nostr:nevent1qqs2aqy3576y6esj7usl6dr7p0ltn2txefl7ystsdt006z8qrax364qpzpmhxue69uhkummnw3ezuamfdejsyg9e55m4ywa69lx6aptajrv2wcx7fusnnj0epkvx7aruulgwcrgh85psgqqqqqqs7q3pl2 
 Yup. I ditched mine a year ago. 

For those who don't know...Coldcard + Sparrow FTW

After you make that move, improve upon it via:
- Umbrel node (on Raz Pi)
- Bitcoin node on umbrel
- Electrum server on umbrel
- Sparrow gets data from Electrum server

Now you can access the blockchain more privately thru your Sparrow wallet.