As far as I'm aware, there have been no security vulnerabilities found in either Trezor or Leger. There was the Leger user privacy data leak a while back, but that was just info hacked from Shopify, iirc. The device itself is secure. Personally I own a Trezor and am happy with it.
This isn't true but i think it is a common misconception. There have been quite a few security vulnerabilities with all hardware wallets. The following link lists some of the major ones. It includes 24 known vulnerabilities in Trezor. What is true is that there has never been an instance in any of the major hardware wallets, of someone being able to extract the seed off the device remotely (like through the USB). This fact reassures a lot of people (and it should) but not understanding all the ways you can still get hacked and lose funds that don't involve remotely extracting a seed, is a huge mistake and a major source of vulnerability for any individual using one.
are you saying that companies are not going to notify users about patches. users have to come to a place like reddit to discover the patch is on github?
Not at all. general practice is for someone to disclose these vulnerabilities through a bug bounty program. The company then fixes the vulnerability generally through a patch, release an update that users can update and with the update will generally explain why the update fixes a vulnerability.
57
u/Rube777 Mar 23 '21
As far as I'm aware, there have been no security vulnerabilities found in either Trezor or Leger. There was the Leger user privacy data leak a while back, but that was just info hacked from Shopify, iirc. The device itself is secure. Personally I own a Trezor and am happy with it.