If I have a blockstream jade and use it as an airgapped wallet, do I run any risks when I connect it to my laptop with a USB to update it? I factory reset before connecting it to my laptop. #privacy #asktr #asknostr
In theory no since you've wiped the device so with the update it's "as new". But if you want to be on the safe side, can you download the update and then run it on the jade on an offline machine? That's probably the approach a paranoid crypto anarchist would take.
Thanks bud!
There is always risk but it’s small. It is not truly airgapped if you have to connect it to your laptop. Coldcard lets you do the update without plugging it into your computer. But you still have to use a microsd card to get the update file or transaction signatures from your computer to the device. I believe you could also use the passport to scan QR codes and never plug it into your computer. But for updates on the passport I think you may have to use Bluetooth. These are all very complicated and sophisticated attacks that are theoretically possible to do but difficult and expensive to pull off.
Looks like a coldcard is a must.
Coldcard and passport are really good. Coldcard is cheaper though and has a long track record. Passport is basically a copy of the coldcard code with some added features like the camera and Bluetooth. If you’re ultra paranoid, you could do a multisig setup with your jade, coldcard, and passport. Your jade could be plugged in, coldcard airgapped with an sd card, and passport uses camera for QR codes.
@Dr. Fernando Morales multisig solves this problem. 2 out of 3 can eliminate any single point of failure, if implemented properly. happy to share more if you’re interested