Cryptos and privacy: the Ledger Recover scandal dissected

Over the past two weeks, the firm Ledger, specializing in crypto security, has found itself at the heart of a big controversy. This particularly concerned the new Ledger Recover product. This is an optional update, touted as useful for recovering lost wallet keys. A technical development poorly received by Ledger users. They suspect the company of wanting to violate their most basic right to privacy.

The origins of the Ledger Recover controversy

It all starts on Tuesday, May 16. That day, Charles Guillemet, Ledger’s technical director, posted an update on his Twitter feed. In it, he delivers the ins and outs of Ledger Recover, the new product implemented by the company. And the concept surrounding access to this optional, but billed ($10 per month) service is relatively simple.

Indeed, Ledger wanted to allow its users to recover the keys to their Ledger wallets in the event of loss. In a context where such an option is simply not available, the initiative is ambitious to say the least. Except that making this concept a reality requires a Know Your Costumer (KYC) identity verification process.

This verification procedure is unique in that it involves third-party companies, in this case Tessi and FIDO Alliance. The latter are thus each responsible for carrying out the KYC identification. Approach which, by the way, includes access to facial recognition and the national identity card of users.

In addition, two other companies, namely Coincover and EscrowTech, in addition to Ledger itself, are involved in the process. Each will have a piece of the wallet key whose recovery potentially requested. This, through three end-to-end encrypted channels, thus making the operation independent. Unexpectedly however, the announcement of the project by Guillemet had the effect of a bomb. Users have not failed to express their criticisms and concerns about an initiative deemed risky in many respects.

The virulent criticism of Ledger users

Users were quick to criticize the optional update for operationalizing Ledger Recover. In particular, they raised concerns about the privacy of user data. Well-founded concerns, especially since the platform’s security features provide little reassurance.

In 2020, for example, these were the target of hacking. An attack following which the personal data of thousands of users ended up on the web. Which highlights Ledger’s privacy flaws. This is also the second major concern of users that has generated so much resistance.

Indeed, many are those who fear that hackers succeed in seizing information supposed to be confidential. Not to mention that a secret agreement, detrimental to the interests of users, cannot be excluded. In many cases, these take second place in the face of important issues, as is the case here. These technical concerns raise another, legal one this time: the transferability of user data to the authorities.

What about the transferability of user data to the authorities?

This is one of the strongest criticisms leveled at Ledger Recover. The remark is so relevant thatshe forced the firm’s leaders to respond. This is what the boss of Ledger did, a few days later, on Monday May 22.

In a podcast, Pascal Gauthier, the CEO of Ledger, spoke about the controversy Ledger Recover. With especially little reassuring news for subscribers to this service. According to the official, the information concerning the keys to the wallets of the latter could well be shared with the authorities.

However, he specifies, this eventuality would only be possible in the event of legal proceedings involving a summons to appear. In the case of situations deemed serious, such as crimes related to terrorism, the company would therefore deliver what it knows.

A priori, underlines Paul Gauthier, this possibility could not concern all users. “It is not true that the average person is subpoenaed every day”did he declare.

Ledger reassures its users

As if to qualify his remarks, the manager recalled what a subscription to Ledger Recover implies for a user. “What you create, if you go with Ledger Recover, is an encrypted, chunk-split backup. These fragments are completely useless unless the user restores the backup to a Ledger device, and only to a Ledger device, where multiple parts are needed for decryption. If you don’t want to use Ledger Recover, nothing changes for you”explained the boss of Ledger.

Maybe users are worrying for nothing? Tweeto 0xFoobar doesn’t see it that way. For him, this Ledger update is purely a gross violation of user privacy.

While many users like 0xFoobar take a dim view of this novelty, Ledger wants to be reassuring. Pascal Gauthier took the opportunity to apologize for the ” bad communication “ of the company.

In addition, the leader made an announcement. His firm is committed to making more of its code base available to the public. The initiative aims to improve Ledger’s transparency and user engagement. It concerns, among other things, the basic components of the operating system of Ledger Recover.

In addition, Charles Guillemet, CTO of Ledger, clarified that a white paper on the Recover protocol will be published soon. At the same time, technical blog posts are also planned for “explain the operating principles of Recover”. The big question remains whether all the initiatives planned to rectify the situation will bear fruit. In any case, the issue of confidentiality and the preservation of personal data is a major issue. This is also one of the reasons why the blockchain offers itself as a relevant alternative.

Receive a digest of news in the world of cryptocurrencies by subscribing to our new service of newsletter daily and weekly so you don’t miss any of the essential Tremplin.io!

Similar Posts