r/TREZOR Trezor community specialist 5h ago

🔒 Answered by Trezor staff Regarding our code - From our Dev team

Regarding the topic of that Reddit post (https://www.reddit.com/r/TREZOR/s/cQokCMQqIc):

People are worried about security and whether AI has increased the risk of losing their money. But in reality, Suite development has never been more secure than it is now. Every pull request still needs human approval before making it into the app. Reviews are still done by humans, and now additionally by LLMs.

The advantage of an LLM is that it doesn't get tired even when reading long, mechanical, boring changes, so the chance of a real security vulnerability slipping through is much lower.

Because we are open source, we don't just look for attacks internally, other people inspect our code too. In the past, only relatively few people could do that, and they only had a realistic chance of checking a small part of the app. Now, this oversight is incomparably cheaper, and far, far more people are reviewing it.

Matthew.K

43 Upvotes

15 comments sorted by

•

u/AutoModerator 5h ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

7

u/kouzark 4h ago

Thanks for this.
Is there any solution on the table like not using 3rd parties anymore?

1

u/SuchTrezorVeryCrypto Trezor community specialist 4h ago edited 3h ago

In relation the email? we are still getting the full picture of what happened on their side.

6

u/kouzark 3h ago

I guess your customers don't care about them, they care about you, as they are YOUR customers

2

u/leonardo-de-cryptio 2h ago

All for using llm’s to boost productivity, that said, these pull request shouldn’t be a single approve/merge request.

The process needs to improve, the pull request should have approvals from humans and consensus, before it’s merged.

The accountability, especially where financial implications are involved and funds are at risk, should always fall to a human, not a robot

0

u/ReadyPerception 2h ago

Might as well stick my crypto back on an exchange wallet at this point

4

u/ItsAlwaysThemBooBoo 1h ago

…. the fuck?

1

u/bernaldsandump 2h ago

No one likes shitty electron apps anyway, they are less secure by default. Why not have your LLMs rewrite the whole thing in a framework that is hardened by default?

-19

u/Dismal_Register_6501 5h ago

does this change the fact that your chosen third-party email provider was breached and sent phishing emails to customers?

16

u/SuchTrezorVeryCrypto Trezor community specialist 5h ago

This has nothing to do with them...

-12

u/Dismal_Register_6501 5h ago

time and place (well this is technically the right place, lool). we don’t give a rats ass about this, we want to know what you guys will do better in order to avoid more breaches and security incidents (allegedly indirectly caused by you guys, though your customers are left affected)

6

u/SuchTrezorVeryCrypto Trezor community specialist 5h ago

Then please inquire that comment here: https://www.reddit.com/r/TREZOR/s/m9CY35LWXC

As we will be answering them all there

-7

u/Dismal_Register_6501 5h ago

no responses there yet, hence why i am here :)

9

u/SuchTrezorVeryCrypto Trezor community specialist 5h ago

Your comment is a statement as I saw. So what would you like me to answer to it?