It's written
Anybody not
Any body.
Thank you for correcting me.
-----
Ledger Recover may be optional, but the code required for your seed to be extracted from your hardware wallet is not optional. It's baked into the firmware, just waiting to be hacked or worse. We've already seen one Ledger ex-employee get fished and give hackers access to their codebase, which is only made worse by the fact that we've seen Ledger terminate lots of employees.
I did not verify their code if there is any that is public and verifiable. But every time I hear about virtual switches or 'optional' stuff I become very skeptical about it. Virtual switches are a risk. This is why there are phones being created with physical switches for WiFi or Cameras. And even these are being questioned for their reliability.
Is the Ledger Recover option truly optional or can it be triggered? In the imaginary scenario of me being a target of the United States or European Governments and Ledger or Coincover secretly working with them to take me down, can this become a problem for me and the Security of my Coins? Because many things are in my opinion very contradictory or lack sense on their 'What is Ledger Recover?' article (
https://www.ledger.com/academy/what-is-ledger-recover). For example,
Firstly, your seed phrase will never leave the Secure Element chip. Only encrypted fragments of it leave the device only if you choose to subscribe to Ledger Recover, and these fragments are useless alone.
This makes no sense. If Coincover only has a fragment of my Seed Phrase, then I am pretty sure they can not recover my full Seed Phrase in the event I lose it. So while fragments alone are useless, do they not hold ALL fragments necessary to recover my Wallet? Who other than Coincover stores the rest of the fragments? Air?
They begin the article explaining how Ledger Recover makes Self Custody more convenient and less frightening,
Self-custody is the golden standard of crypto security and Ledger’s goal is to make it easy to use. In short, this service is all about making self-custody more convenient and less frightening.
Then they say Ledger Recover is not for those who do not trust Third Parties,
Well, if you believe third parties can not be trusted, Ledger Recover is probably not for you. If you fall into that category—don’t worry. You don’t need to opt in and you don’t need to subscribe: you can continue managing your seed phrase yourself. The security of your Ledger device is not impacted.
I would quote more of their article but you get the idea. Ledger is not to be trusted.
Who guarantees however that my connection to Ledger Live does not automatically send information through Coincover? Who guarantees there is no way my Ledger device can be tricked into sending fragments to a bad actor? There is no physical switch between sending or not sending my information to Coincover. It would be different if Ledger Recover was only included in a different Firmware. As in, you can choose between having it or not having it hard coded into your device. But it always being there feels risky to me. If years ago I would of said Ledger can be easily plugged in a computer heavily infected by Malware, I do not think so any more.
Hello Customers, we just hard coded a bomb into your Ledger device. It is only optional though! It can only be triggered if and when you want it to explode because we truly care for your Safety!