Why Nostr? What is Njump?
2024-08-06 10:58:17
in reply to

Cyph3rp9nk on Nostr: No, the seed is encrypted with PIN (Local) + secret (Blockstream Server). The seed is ...

No, the seed is encrypted with PIN (Local) + secret (Blockstream Server).

The seed is stored locally on the Jade.

What does this do? If you extract the seed from the chip and try to brute force attack it, it will be useless, because apart from the pin, you need the secret (256 bits) stored in the blockstream server.

So they would have to hack also the Blockstream server and have your jade and also know the pin.

On the other hand the blockstream server can not do anything, it is only a shared secret, the blockstream server at no time access to the Jade.

https://help.blockstream.com/hc/en-us/articles/9639949755673-How-does-Blockstream-Jade-s-oracle-enforced-PIN-protection-work
Author Public Key
npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt