Pages:
Author

Topic: Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities - page 19. (Read 5425 times)

hero member
Activity: 714
Merit: 1298

I suggest sweeping your Ledger HW coins as soon as possible.

I have already did it. Moved the whole of my stash to Passport2 developed by Foundation devices.

After doing that punched both SE and MSU on Ledger board by two strokes of hummer. The final result is simple as that Wink


Quote
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
If you thought the bombshell by the Ledger co-founder wasn't bad enough, wait until you see what he said now!

Ledger co-founder admits that with if you use "Ledger Recover" a government could submit a subpoena and get access to your funds

Éric Larchevêque, a Ledger co-founder, posted in two subs (including here https://np.reddit.com/r/CryptoCurrency/comments/13ldgcl/my_personal_view_on_the_pr_disaster_from_a_ledger/?sort=confidence) trying to do damage control around the Ledger fiasco. In his post he said that he no longer works at Ledger, but in his Linkedin, he lists that he is a board member of Ledger. Apparently, he forgot to disclose that or update his Linkedin.

........

**If Ledger or 2/3 of the companies that handle the data receive a government subpoena, could they get access to your funds?**





Even if you trust Ledger not to change the firmware or add any backdoors to gain access to your private keys, **if you are a Ledger Recover Service user, then your private keys/funds would be accessible by a subpoena.** In the current firmware state, if you are not a Ledger Recover Service user then your private keys would not be accessible with a subpoena.

An update that allows governments to subpoena your private keys and gain access to your crypto is a big deal and likely Ledger is no longer valued at $1.41 billion after this update.


This is damning news and with the trajectory this is going, there is no guarantee that Ledger won't simply force Recover enabled in a future firmware update.

I suggest sweeping your Ledger HW coins as soon as possible.
legendary
Activity: 3150
Merit: 2185
Playgram - The Telegram Casino

[...]

I'm not quite sure I can agree with this conclusion. Having the firmware and applications reside on the same chip as the seed does by itself not necessarily mean that the firmware or applications can access it. You can still have an architecture where part of the flash storage is accessible (ie. for firmware updates and installing apps) and some isn't (ie. for securely storing the seed). Additionally it should also be possible to have some parts of memory be accessible by the firmware, but not by applications.

So it's highly speculative whether the other applications can in theory access the whole seed phrase as well.

However, given what we now know and the closed source nature of the code... it's also highly speculative whether the apps can't.

(but we do know that at least the firmware can access the seed phrase, if only due to them admitting to it)
The function to explicitly export the seed phrase from the monero ledger application has been around for a long time. This means that there are no fundamental restrictions for any ledger application to be able to read the seed phrase.

Looking at the script, I see nothing about it extracting and accessing the seed phrase.

For reference, these are the functions being used when converting the seed phrase directly on the hardware wallet (referred to as "Online" in the Readme):

It is reasonable in my opinion to consider any activated ledger hardware wallet already compromised (and any security model based on a "black box" is inherently weak), in order to avoid unnecessary frustration.
legendary
Activity: 2730
Merit: 7065
The best thing they could do now is to open source their firmware right away, this will at least delay the inevitable collapse and allow them to exit the market with some dignity and fewer lawsuits.
Do you think there are grounds for a lawsuit? What could you sue them for? I am pretty sure their TOS already protects them from any existing or upcoming changes they perform on their software. 

With that said it's very important to stress the fact that what's worse than keeping your BTC on Ledger is panicking to move them elsewhere less secured, or even end up sending them to the wrong address, please folks, don't panic, move your funds out of leger (not to Trezor) without panicking.
That's good advice. I am going to say something not that popular now. Don't be in a hurry to not make a mistake as mikeywith said. Using the same analogy with nudes and passwords, If Ledger has always had a way to extract that data, and they didn't (at least we hope they didn't), what are the chances it's going to happen in the next 10 days while you are panicking and moving your BTC all over the place?

Moving from Ledger to a similar product doesn't solve the underlying problem which is the vulnerabilities that obviously exist in secure element chips these companies use. One company has stepped forward saying what they are planning to do, no one knows what the others will do. Moving to proper cold storage and airgapped devices is now the only security boost left.   
legendary
Activity: 1722
Merit: 2213
Haven't seen this point posted in the thread so thought I'd share...

In case there was any doubt about whether third parties could get legal access to your seed phrase:



Source: https://twitter.com/0xfoobar/status/1659765939225735169 (Can't find reddit source though)

Maybe this was an obvious one, given that companies are required to hand over data when legally requested...

Is the next step simply pushing firmware to extract seed phrase to specific users after a government request maybe?

This story get's worse day by day.
copper member
Activity: 2254
Merit: 915
White Russian

It seems like the MCU does nothing but connect the screen/buttons to the secure elements, and the applications are actually installed ON the secure element itself where the firmware resids.

This means the claim that " you will have to physically press a button to sign a transaction" which they have always promoted is also a lie.

It's also mentioned on their website

Quote
In order to accomplish this, we attached an additional STM32 microcontroller (the MCU) to the Secure Element (the SE) which acts as a “dumb router” between the Secure Element and the peripherals. The microcontroller doesn’t perform any application logic and it doesn’t store any of the cryptographic secrets used by BOLOS, it simply manages the peripherals and notifies the Secure Element whenever new data is ready to be received. BOLOS applications are executed entirely on the Secure Element. In this section, we’ll take a look at the hardware architecture to better embrace the hardware related constraints before analyzing their software implications.

So this means, funds were always "movable" without having to physically initiate an order from buttons that control only the MCU, so not only the firmware had access to the private keys, even the various applications including all of those shitcoins applications that were available to download from Ledger had access to your funds, so for all we know, you could install a shitcoin application on the secure element, which could have access to your BTC private keys or the whole seed phrase.

I'm not quite sure I can agree with this conclusion. Having the firmware and applications reside on the same chip as the seed does by itself not necessarily mean that the firmware or applications can access it. You can still have an architecture where part of the flash storage is accessible (ie. for firmware updates and installing apps) and some isn't (ie. for securely storing the seed). Additionally it should also be possible to have some parts of memory be accessible by the firmware, but not by applications.

So it's highly speculative whether the other applications can in theory access the whole seed phrase as well.

However, given what we now know and the closed source nature of the code... it's also highly speculative whether the apps can't.

(but we do know that at least the firmware can access the seed phrase, if only due to them admitting to it)
The function to explicitly export the seed phrase from the monero ledger application has been around for a long time. This means that there are no fundamental restrictions for any ledger application to be able to read the seed phrase.

It is reasonable in my opinion to consider any activated ledger hardware wallet already compromised (and any security model based on a "black box" is inherently weak), in order to avoid unnecessary frustration.
legendary
Activity: 3304
Merit: 8633
icarus-cards.eu
since some are now looking for an alternative, many other hardware wallet providers are now taking advantage of the situation and want to win over 'old' Ledger customers, for whom seed security is still one of the top criteria.
now Trezor offers a 15% discount on all orders of the two models (model one and model t) that are received until may 21...
for me Trezor has always been worth considering when i had to decide between Ledger and Trezor...


https://trezor.io/
legendary
Activity: 3150
Merit: 2185
Playgram - The Telegram Casino
There are concerns that the recovery feature in the latest firmware has a backdoor. If there is a backdoor, it's already a problem, what if Ledger instead adds this feature to all of its hardware wallet products.
Within the sea of comments in the Reddit post shared by NotATether, both the co-founders (/u/murzika[1] and /u/btchip[2]) say that the reason this feature won't reach Nano S is due to memory limits:
Quote from: /u/murzika
I don't have the details, but I think it's related to the SE chip not enough memory to store the new firmware (this will require a confirmation as I'm not sure).
Quote from: /u/btchip
The firmware is the OS, so you need to be using one (same thing on your computer). We just won't port the Recover functionality to the SE because there isn't enough space to put it there.

That's good, as there apparently really is a technical limitation that prevents the Nano S to be affected by this update.

That's bad, as this confirms that the only thing preventing someone from writing barebones seed extracting firmware is security by obscurity (ie. fact that parts of the code are closed source).


Quote from: u/murzika
If you are a Recover user and have your shard into safeguarded by third parties, then yes, a government could subpoeana them and get access to your funds.

Using Recover gives you an easy recovery option and mitigates backup loss, but your assets could get frozen by the government (in theory, I'm not a lawyer and I didn't see any legal opinon on the subject).

2 sats say that they only admit that now, so that once this case inevitably happens they can say "hey we've always said this could happen, look at how honest and trustworthy we are!"


It seems like the MCU does nothing but connect the screen/buttons to the secure elements, and the applications are actually installed ON the secure element itself where the firmware resids.

This means the claim that " you will have to physically press a button to sign a transaction" which they have always promoted is also a lie.

It's also mentioned on their website

Quote
In order to accomplish this, we attached an additional STM32 microcontroller (the MCU) to the Secure Element (the SE) which acts as a “dumb router” between the Secure Element and the peripherals. The microcontroller doesn’t perform any application logic and it doesn’t store any of the cryptographic secrets used by BOLOS, it simply manages the peripherals and notifies the Secure Element whenever new data is ready to be received. BOLOS applications are executed entirely on the Secure Element. In this section, we’ll take a look at the hardware architecture to better embrace the hardware related constraints before analyzing their software implications.

So this means, funds were always "movable" without having to physically initiate an order from buttons that control only the MCU, so not only the firmware had access to the private keys, even the various applications including all of those shitcoins applications that were available to download from Ledger had access to your funds, so for all we know, you could install a shitcoin application on the secure element, which could have access to your BTC private keys or the whole seed phrase.

I'm not quite sure I can agree with this conclusion. Having the firmware and applications reside on the same chip as the seed does by itself not necessarily mean that the firmware or applications can access it. You can still have an architecture where part of the flash storage is accessible (ie. for firmware updates and installing apps) and some isn't (ie. for securely storing the seed). Additionally it should also be possible to have some parts of memory be accessible by the firmware, but not by applications.

So it's highly speculative whether the other applications can in theory access the whole seed phrase as well.

However, given what we now know and the closed source nature of the code... it's also highly speculative whether the apps can't.

(but we do know that at least the firmware can access the seed phrase, if only due to them admitting to it)
legendary
Activity: 2464
Merit: 6687
be constructive or S.T.F.U
We all know Ledger is done, but the real concern for me now is "what is the current firmware", and wether people's funds are even remotely safe.

Their claim is that their firmware is audited by a 3rd party to make the users feel comfortable that their funds are safe and the firmware won't be able to steal their funds.

According to their Co-Founder who goes by the name btchip on reddit

Quote
The latest firmware received a certification from ANSSI as you mentioned.

Someone on their subreddit searched for the latest certificate they had and it was done for V1.2.5

I managed to find the ANSSI certificate for the nano-s version 1.5.1.

That seems to be the latest certificate they had there, so any firmware past that version could have anything in it.

What I found intersting in that report is the architecture of the wallet



It seems like the MCU does nothing but connect the screen/buttons to the secure elements, and the applications are actually installed ON the secure element itself where the firmware resids.

This means the claim that " you will have to physically press a button to sign a transaction" which they have always promoted is also a lie.

It's also mentioned on their website

Quote
In order to accomplish this, we attached an additional STM32 microcontroller (the MCU) to the Secure Element (the SE) which acts as a “dumb router” between the Secure Element and the peripherals. The microcontroller doesn’t perform any application logic and it doesn’t store any of the cryptographic secrets used by BOLOS, it simply manages the peripherals and notifies the Secure Element whenever new data is ready to be received. BOLOS applications are executed entirely on the Secure Element. In this section, we’ll take a look at the hardware architecture to better embrace the hardware related constraints before analyzing their software implications.

So this means, funds were always "movable" without having to physically initiate an order from buttons that control only the MCU, so not only the firmware had access to the private keys, even the various applications including all of those shitcoins applications that were available to download from Ledger had access to your funds, so for all we know, you could install a shitcoin application on the secure element, which could have access to your BTC private keys or the whole seed phrase.

I think the former CEO really meant it when he said

Quote
Trying to explain the security model to customers with a less and less knowledgable user base became more and more difficult, and it looks like in 2022 a marketing executive tweeted "A firmware update cannot extract the seed from the Secure Element". It's not a lie, but it's missing "as long as you are trusting Ledger".

You really have to trust Ledger both on the firmware and the application level, trusting someone with the physical chip design, firmware, and application is too much, you still to have to somehow trust all those open-source software hardware wallets since you don't know what's inside the chip, but that risk is minimal and there is nothing you can do about it, but having to trust the wallet maker with everything is stupid, even if they were dead honest, there are probably tens of devs maintaining those different apps and firmware versions, it's impossible to control the outcome even for Ledger folks themselves.
legendary
Activity: 1148
Merit: 3117
(...)
This was a willful lie, and one which Ledger were quite happy to not correct because it made them profit.
And yet with just this move all of their reputation was lost. Even for the users that don't think that this is an attack to one's sovergiyn, I wonder what they have to say about this[1]?:
Quote from: u/murzika
If you are a Recover user and have your shard into safeguarded by third parties, then yes, a government could subpoeana them and get access to your funds.

Using Recover gives you an easy recovery option and mitigates backup loss, but your assets could get frozen by the government (in theory, I'm not a lawyer and I didn't see any legal opinon on the subject).
Now that's a steal! For just $9.99 per month, not only do you spread your a copy of your SRP with 3 entities but you also enjoy the benefit of being an easy target for subpoenas, who can say no to that?  Cheesy

[1]https://safereddit.com/r/CryptoCurrency/comments/13ldgcl/my_personal_view_on_the_pr_disaster_from_a_ledger/jkpnvnl/
legendary
Activity: 2268
Merit: 18775
Quote
Trying to explain the security model to customers with a less and less knowledgable user base became more and more difficult, and it looks like in 2022 a marketing executive tweeted "A firmware update cannot extract the seed from the Secure Element". It's not a lie, but it's missing "as long as you are trusting Ledger".
So it's a lie then.

You cannot say that 2+2=5 is not a lie but simply missing the phrase "as long as you add one more". If you miss out a piece of information that fundamentally changes the entire concept of what you are saying, then you are lying. What next? We claim that all hot wallets are safe (as long as you never connect to the internet)?

This was a willful lie, and one which Ledger were quite happy to not correct because it made them profit.
legendary
Activity: 1148
Merit: 3117
There are concerns that the recovery feature in the latest firmware has a backdoor. If there is a backdoor, it's already a problem, what if Ledger instead adds this feature to all of its hardware wallet products.
Within the sea of comments in the Reddit post shared by NotATether, both the co-founders (/u/murzika[1] and /u/btchip[2]) say that the reason this feature won't reach Nano S is due to memory limits:
Quote from: /u/murzika
I don't have the details, but I think it's related to the SE chip not enough memory to store the new firmware (this will require a confirmation as I'm not sure).
Quote from: /u/btchip
The firmware is the OS, so you need to be using one (same thing on your computer). We just won't port the Recover functionality to the SE because there isn't enough space to put it there.
All their marketing during these 8 years was aimed at passing the idea that it would be impossible to remove the SRP from the SE but recently they've started to push the narrative "oh no, in these past 8 years you had to trust Ledger to not implement such mechanisms". Talk about misguiding their audience.

[1]https://safereddit.com/r/ledgerwallet/comments/13layt7/comment/jkp9xq2/
[2]https://safereddit.com/r/ledgerwallet/comments/13layt7/my_personal_view_on_the_pr_disaster_from_a_ledger/jkpttz0/
sr. member
Activity: 616
Merit: 317
Vave.com - Crypto Casino
This really shocks me with the latest ledger firmware update. Yup, seed phrases are safe as long as they don't join the recovery program, but with an update to the recovery feature, it means that there is software to support this feature. And what the crypto community is afraid of is that the software could become a backdoor for hackers to take seed phrases surreptitiously.

Key points from this case:
- Temporary recovery feature is only available on Nano X (in the latest firmware version in May).
- Recovery feature for new comer / newbie / senile old people.
- The recovery feature is optional... you can use it or not.

There are concerns that the recovery feature in the latest firmware has a backdoor. If there is a backdoor, it's already a problem, what if Ledger instead adds this feature to all of its hardware wallet products.
legendary
Activity: 2464
Merit: 6687
be constructive or S.T.F.U
~snip~
The best thing they could do now is to open source their firmware right away, this will at least delay the inevitable collapse and allow them to exit the market with some dignity and fewer lawsuits.

I think there is less than a 1% chance of that, because all these years they have not shown their intention to be completely transparent, so I don't see why they would do it now. In addition, they believe that the future 100 million users will support them in what they do, and in addition, they will have the gratitude of all the mothers of the world (read previous posts for reference), so I believe that they are not worried about their business, and even less about possible lawsuits. Nothing major happened after the database leak, right?

They had no real reason to open source their firmware code, they sold the most hardware wallet without doing so, people trusted them and thus everything was fine, the customer data leak is pretty minor compared to this issue, besides, it is not like opening the source code would undo the leak.

This time however, people are now doubting the fact that current and old firmware can't export seed phrase, by releasing the code people can somehow be sure that as long as they don't update to the latest version -- thier funds are safe, and that ledger did not lie to them about their keys never leaving the secure element.
legendary
Activity: 3150
Merit: 2185
Playgram - The Telegram Casino
Even the co-founder and former CEO of ledger says this is a disaster (but but *everything will be fine, as long as you trust Ledger   Roll Eyes)

https://www.reddit.com/r/CryptoCurrency/comments/13ldgcl/my_personal_view_on_the_pr_disaster_from_a_ledger/

Thing is, he's not wrong. We should have never trusted Ledger to begin with. We, as a community, have failed, to properly communicate the technical implications of some elements of the code being closed source to those that are less tech savvy. We accepted a compromise out of convenience and now look at where it got us.

Also I have to cringe at how in his eyes (and apparently many other folks too) the "here are the facts" thread he's linked is making things better. Their main arguments being (1) you didn't seem to mind when you weren't aware of the problem and (2) other hardware wallets have problems too. Fuck me. And to top it all off, the gall to try to spin this as a communication problem rather than a technical one. Fuck.
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
Even the co-founder and former CEO of ledger says this is a disaster (but but *everything will be fine, as long as you trust Ledger   Roll Eyes)

https://www.reddit.com/r/CryptoCurrency/comments/13ldgcl/my_personal_view_on_the_pr_disaster_from_a_ledger/
Quote
My personal view on the PR disaster, from a Ledger co-founder and ex CEO

 I'm Éric Larchevêque, Ledger co-founder an CEO of the company from 2014 to 2019. My flair here says "Ledger CEO" but I'm not anymore. I'm only a shareholder of the company, not an executive, and all views are personal. My views are not representative at all of Ledger, its management or its board.

What an horrible mess.

I'm devastated to come on this subreddit, that I created nine years ago, to see images of Ledger devices burning, insults and lot and lot of anger. I'm honestly to the verge of tears.

I've given so much to this company, that it's impossible for me not to be highly emotional in this moment.

So much anger, so much hate, and also so much insanity.

My first step is to apologize as a co-founder about how this launch have been handled. I can't help but to wish this had been done differently. I don't have all details, but for sure something went wrong and the Ledger Recover service was put in your face in the worst way possible.

This is obviously a sensitive subject and would have needed a much more prepared communication.

To me, all this meltdown is a total PR failure, but absolutely not a technical one.

Please read this post which is a very good factual take on he (sic) situation : (https://www.reddit.com/r/CryptoCurrency/comments/13kdusd/hardware_wallets_here_are_the_facts/)

Since 2014 I have been explaining the security model of Ledger and the implications of using a Secure Element (good : very secure, bad : closed source). The security model of any Ledger device relies on the fact that you need to trust Ledger to provide with a firmware doing exactly what it is supposed to be doing.

In the early days, people just had to trust us. The more the company grew, raised money, got customers, the more the incentive to make sure the firmware is sound grew. Hence audits, governance control on the firmware release, the Donjon, etc. The more Ledger had something to lose by doing a mistake, the more things were put in place to prevent this.

Trying to explain the security model to customers with a less and less knowledgable user base became more and more difficult, and it looks like in 2022 a marketing executive tweeted "A firmware update cannot extract the seed from the Secure Element". It's not a lie, but it's missing "as long as you are trusting Ledger".

So people started to think Ledger was a trustless solution, which is not the case. Some amount of trust must be placed into Ledger to use their product. If you don't trust Ledger, meaning you treat your HW manufacturer as an adversary, that can't work at all.

When Recover was abruptly launched, this false sense of trustlessness went into pieces and people started to actually understand how a HW works. At least, that's a positive note.

My mistake as a CEO during my tenure was probably not be relentless enough about explaining the security model, but at some point you just give up as people don't care at all. Until they care again, like now.

The mistake of some of the "power user" community (reddit, twitter...) is to become batshit crazy and start writing stuff like "there is a backdoor from day one" or "the governement has taken over Ledger".

The hard truth, which has been confirmed by many experts who took the time to actually deep dive on the subject, is that nothing changed. Absolutely nothing happened. The security model is the same than before you knew Ledger Recover existed.

What changed is the perspective some of you had on the trustlessness, which appeared to be much more nuanced than you thought, and as this is a very sensible subject, many became extremely angered because they felt lied to.

I understand this point of view, but it's important also to be reasonable, take a deep breath and actually think about the facts.

If you think that Ledger did a terrible thing by not being relentless enough on the security model, and took shortcut when expressing it, if you think that at the time you bought the device, you would never have bought it if you had known this wasn't a fully trustless solution, then yes I get your point of view.

But if your only take is to jump on the hate bandwagon and yell "there is a backdoor" when you don't have any understanding of what you are saying, then it's a free country, but at the end the real victims will be the noobs who in panic will try to offload their crypto from Ledger, make stupid mistakes and lose it all.

Ledger is still safe, there is no backdoor, the Ledger Recover is not a conspiracy, no one will ever force anyone to use Recover.

The Recover code in the firmware is not a malicious code nor does it open a way to arbitrary extract the seed.

If you trust the device to sign a transaction only when you press a button, then you can trust the device to compute a SSS (a shard of the seed) only if you press a button.

I'll now answer questions to the best of my abilities.

(I have posted the same thing in the Ledger subreddit and already answered a lot of questions there

https://www.reddit.com/r/ledgerwallet/comments/13layt7/my_personal_view_on_the_pr_disaster_from_a_ledger/ )

Thank you.

Éric

PS : again, this is a personal post, personal views, and I'm not representing the views of Ledger or its management.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
~snip~
The best thing they could do now is to open source their firmware right away, this will at least delay the inevitable collapse and allow them to exit the market with some dignity and fewer lawsuits.

I think there is less than a 1% chance of that, because all these years they have not shown their intention to be completely transparent, so I don't see why they would do it now. In addition, they believe that the future 100 million users will support them in what they do, and in addition, they will have the gratitude of all the mothers of the world (read previous posts for reference), so I believe that they are not worried about their business, and even less about possible lawsuits. Nothing major happened after the database leak, right?
legendary
Activity: 2464
Merit: 6687
be constructive or S.T.F.U
In theory, unless you update to the newest firmware that unlocks seed-share and approve it physically by pressing the buttons on your Nano, the feature won't work.

What's even worse is "How do we know the current firmware isn't capable of doing the same thing"?.

I see most of these videos on youtube telling people not to worry, and that their funds are safe as far as they don't update to the latest firmware, as if they reviewed the current/previous firmware versions and made sure that there was nothing in the code that could send the seed phrase over to someone else.

I think Ledger shot themselves in the foot, there is no Control Z in this, it's like telling your friend that you always knew their phone's password -- but you never checked their nudes, and that you never will as long as they tell you not to, it's wishful thinking to believe that person is ever going to trust you ever again even if you were completely honest, you had to keep your mouth shut, you can't unspeak something.

The best thing they could do now is to open source their firmware right away, this will at least delay the inevitable collapse and allow them to exit the market with some dignity and fewer lawsuits.

With that said it's very important to stress the fact that what's worse than keeping your BTC on Ledger is panicking to move them elsewhere less secured, or even end up sending them to the wrong address, please folks, don't panic, move your funds out of leger (not to Trezor) without panicking.



hero member
Activity: 770
Merit: 538
Leading Crypto Sports Betting & Casino Platform


This image really explains what the situation is with the new concept ledger wallet is trying to be launch, and it is quite beyond stupidity that this company has to even come up with an idea like that, despite all the attacks that Bitcoin is facing, but they seem to have ignored them. Let's look at how the US government is even treating the adoption of Bitcoin recently and all the attacks and hacks that have been happening. I know a lot of Bitcoiners are not that stupid to start backing up their seed phrases to the cloud.
legendary
Activity: 2212
Merit: 7064


another proof of the whole thing is that Ledger has now deleted this tweet, which RickDeckard has already posted earlier
Oh they are deleting a lot more than that, people caught them deleting a bunch of things recently, someone was working real hard to read their entire twitter (reddit history  Roll Eyes

Misleading advertisement... class action lawsuit might be landing soon in France...









Pages:
Jump to: