
A fresh firmware version 1.5.1Q was released for the Q device, significantly enhancing security features and altering entropy generation methods. This update has stirred mixed responses within the community, revealing ongoing concerns and requests for clarification.
The new firmware introduces vital changes, including:
Entropy Generation Revamp: Combines new master seeds from STM32 hardware RNG and secure elements, using SHA-256 Hash_DRBG to enhance randomness.
User-Supplied Entropy Required: Users must now incorporate their own entropy via keyboard mashing, dice rolls, or coin flips, mixed with hardware sources.
Enhanced Security Fixes:
USB Transaction Tampering: Now re-verifies transaction bytes before signing, alerting users if modifications occur.
USB Information Leakage: Requires encrypted sessions for downloads, preventing unauthorized access.
SIGHASH_SINGLE Protections: Blocks certain SIGHASH_SINGLE transactions by default to reduce risk.
General Improvements: Tightened firmware parsing, improved backup features, and better validations.
Forum discussions reflect a polarized atmosphere. Some users hailed the update for patching previous RNG vulnerabilities, stating, "Now the RNG bug has been patched, and many eyes are on the code; it's secure." Others showed skepticism, questioning the companyβs reliability after past issues, with one user bluntly asking, "Why anyone would trust this company now is beyond me."
There's also an emerging concern regarding the update's effectiveness in addressing specific device problems that arose from earlier firmware versions, like the "bricking" issue and boot hang scenarios. A community member commented, "Does this release address the boot hang that occurred with some devices?" Reports suggest that the recent update aims to fix those infamous bugs, although not all users have found reassurance.
Interestingly, many users remain hopeful about the device's newfound resilience, with one stating, "Iβm quite sure that the ColdCard is now the most secure hardware wallet out there."
The dialogues sparked by the firmware update extend beyond mere technical fixes. Users are calling for greater transparency surrounding the RNG changes and more straightforward communication from the developers.
"They said this version fixed the weak entropy issue and this version improves upon it by requiring additional entropy," shared a commenter, clearly eager for clarity in the wake of the shift.
π¬ Many users express concerns about trusting the company post-update.
π Calls for transparency suggest a need for improved communication on security matters.
β Some users believe the latest firmware has strengthened device security substantially.
As user engagement intensifies, it'll be noteworthy to see how developers respond and whether future updates will incorporate community feedback. Meanwhile, the emphasis on user-supplied entropy marks a shift toward more personalized security practicesβputting more control in the hands of users while also inviting scrutiny.
Curiously, the response to these changes reflects a burgeoning trend toward self-managed security in the crypto community, echoing sentiments from the early days of personal computing.
Community members remain eager for clarity and assurance as they navigate this evolving landscape. Only time will tell if the confidence in device security can fully restore user trust.