This article is not an attack on Ledger. It is based on this article from the Ledger Official Blog, written by Ledger itself.

 

Before reading the Ledger article, let's understand what Open Source means. What is Open Source?

 

Open Source refers to the disclosure of the Source Code that developed the Hardware Wallet, meaning whether it is made accessible to the public, to demonstrate transparency and allow everyone to jointly review the Source Code of that Hardware Wallet. 

 

Currently, Ledger only has 95% Open Source. The part that is not currently disclosed is the Firmware. There is also an issue regarding Ledger Recover where Ledger stores our Seed with Ledger  and Ledger's Partner. You can find more details about Ledger's Open Source here.

 

Back to the issue of why Ledger is not 100% Open Source.

From parts of this article and on X (Twitter), Ledger stated that they have a legal agreement with STMicroelectronics, the manufacturer of the Secure Element Chip, not to disclose the low-level code of the Secure Element Chip.

 

The reason STMicroelectronics does not want to open source the Secure Element Chip is because they have invested billions of dollars and many years in its development. This is why STMicroelectronics prevents firmware developers from disclosing parts of the code related to the circuit.

 

The Secure Element chip is considered the most secure chip among all chips. It is the same type of chip used in passports and credit cards, offering strong protection against various attacks such as side-channel attacks, etc.

 

Ledger also states that Hardware wallet developers must choose between the most secure Chip on the market, used billions of times, without disclosing a small amount of code within the Chip, or disclosing the Chip's code with reduced security. Of course, Ledger chooses security.

 

Does Ledger plan to be 100% Open Source?

Ledger plans to be 100% Open Source, but it may take time as it is a difficult task. However, they will try to follow the roadmap they have set.

 

The following message is the author's personal opinion.

At first, I wondered if Ledger couldn't disclose the source code of the Secure Element chip, could Trezor? It turns out Trezor can, by finding a Secure Element chip manufacturer that can disclose 100% of the source code. 

Ref: https://trezor.io/learn/a/secure-element-in-trezor-safe-3

 

Reference

Ledger's X post about Open Source: https://x.com/Ledger/status/1814247133517627545

Blog LEDGER IS 95% OPENSOURCE, WHY NOT 100%: https://www.ledger.com/blog-ledger-is-95-opensource-why-not-100

Trezor that can disclose 100% source code: https://trezor.io/learn/a/secure-element-in-trezor-safe-3

Leave a comment

Please note, comments need to be approved before they are published.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.