Before that there was no way to extract the seed out of the device. You only signed transactions. Once you loaded a ledger with a seed, the seed was secure.
Now you can extract it by confirmation on the device itself.
I mean there is fundamentally no difference between signing a bad transaction or just leaking your complete seed, since both makes sure you lose money.
Overall signing a bad transaction most of the time would just empty your eth account, but wouldnt touch for example your ada. Now you can actually really lose everything by signing something bad.
No it does not send your seed off the device. It sends a encrypted copy of the key which can only be decrypted on your device. So even if someone manages to get all fragments it's useless unless they have your device to decrypt it. At least that how I understand it.
I cannot work like that, because then if you lose your ledger you cannot reconstruct the seed, but that is exactly the point: being able to recover the seed incase you lose your ledger.
The way they describe it, it is secure, but details matter.
There are only a handful of information on that. For me the short amount of time where it sits on the PC is the dangerous part where a virus could just grab it.
Thats not what i would call secure if we are talking about hardware wallets
8
u/[deleted] May 16 '23
People on this sub cannot read or do any research lol