| |
A critical security vulnerability in Coldcard firmware was introduced through two poorly documented code commits with extremely low comment-to-code ratios (0.003 and 0.001), which disabled the hardware random number generator and forced the system to rely on a weaker alternative entropy source instead. The commits, titled merely "runs" and "x," made massive changes (1534 and ~1000 lines respectively) to security-critical code with minimal explanation, violating basic software development best practices that require thorough documentation when modifying security-sensitive functions.
Read Full Article →
← More Tech news