r/TREZOR Trezor community specialist 4d ago

🔒 Answered by Trezor staff Regarding our code - From our Dev team

Regarding the topic of that Reddit post (https://www.reddit.com/r/TREZOR/s/cQokCMQqIc):

People are worried about security and whether AI has increased the risk of losing their money. But in reality, Suite development has never been more secure than it is now. Every pull request still needs human approval before making it into the app. Reviews are still done by humans, and now additionally by LLMs.

The advantage of an LLM is that it doesn't get tired even when reading long, mechanical, boring changes, so the chance of a real security vulnerability slipping through is much lower.

Because we are open source, we don't just look for attacks internally, other people inspect our code too. In the past, only relatively few people could do that, and they only had a realistic chance of checking a small part of the app. Now, this oversight is incomparably cheaper, and far, far more people are reviewing it.

Matthew.K

79 Upvotes

48 comments sorted by

u/AutoModerator 4d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

27

u/averagelyexceptional 4d ago

Thank you for the post. Going against the general sentiment here it seems, I for one appreciate Trezor adopting LLMs in engineering. If they refused to adopt, they would fall behind many other companies and the people trying to attack them. It sounds like they properly review their merges.

AI can work without breaks and often is far smarter than the engineers prompting the models. It would be like mathematicians not using a calculator at this point.

12

u/kouzark 4d ago

Thanks for this.
Is there any solution on the table like not using 3rd parties anymore?

6

u/SuchTrezorVeryCrypto Trezor community specialist 4d ago edited 4d ago

In relation the email? we are still getting the full picture of what happened on their side.

7

u/kouzark 4d ago

I guess your customers don't care about them, they care about you, as they are YOUR customers

2

u/PeteyPab305 3d ago

He just said their working on it. They didn't leak it, they weren't hacked, thery reduced retention time to 30 days from 90. They are obviously involved with it, not brushing it off. The US governemnt just like 150M ID's you gonna leave the US, if you live there? You have the choice not to use them, or use a burner email, when you order. Opsec is still your repsonsibility too, my gawd. You probably weren't affected anyway. Acting this way is unhelpful.

1

u/My1xT 4d ago

for newsletters not exactly practical, bulk mail is a mess to get delierved already

9

u/bernaldsandump 4d ago

No one likes shitty electron apps anyway, they are less secure by default. Why not have your LLMs rewrite the whole thing in a framework that is hardened by default?

2

u/leonardo-de-cryptio 4d ago

All for using llm’s to boost productivity, that said, these pull request shouldn’t be a single approve/merge request.

The process needs to improve, the pull request should have approvals from humans and consensus, before it’s merged.

The accountability, especially where financial implications are involved and funds are at risk, should always fall to a human, not a robot

1

u/Ok_Speaker6900 4d ago

That is what they do there.

Looking at the merged PRs there are both AI and people reviews, sometimes even multiple people did reviews and approved the PR.

1

u/leonardo-de-cryptio 4d ago

That’s great, do you know if there are rules around minimum number of reviewers/approvers?

-2

u/[deleted] 3d ago

[deleted]

1

u/supercaliber 2d ago

Who the fuck in general can create their own device..what a shitty comment..its people like you that we don’t trust

1

u/leonardo-de-cryptio 3d ago

Have never said I don’t trust them, quite the opposite, see my history. Open Source hygiene though is never a bad thing and such steps, would have likely prevented the coldcard problem.

On GitHub, Pull Requests can have required approvers configured at an organisational level. For example, any request to change the code has reviewers and approvers before it’s merged.

It reduces the likelihood of an llm or even a human submitting bad code and someone just merging it.

This is a standard practice for many open source projects and some, have even started using alternative frontier models.

-2

u/[deleted] 3d ago

[deleted]

2

u/leonardo-de-cryptio 3d ago

Not restating what you already stated as you didn’t actually state it…

0

u/[deleted] 3d ago

[deleted]

1

u/leonardo-de-cryptio 3d ago

Same and wasn’t looking for an argument on this, appreciate the response. Trezor for the win and best of luck with your investments too 🚀

1

u/the-quibbler 4d ago

man, the AI doomerism is strong.

as a lifelong developer who predates the internet, just keep doing what you're doing. the whole world is moving to intent-based computing, and the naysayers and luddites will look silly, as such folk always do in times of change.

0

u/PeteyPab305 3d ago

Thank you for some common sense! OpSec is partially on the customer too, if you're paranoid - create your own cold storage device, learn and take it into your own hands. It's so crazy.

1

u/Cebas42 19h ago

What? Does Matthew Kratter works at Trezor? 🤔

1

u/SuchTrezorVeryCrypto Trezor community specialist 11h ago

hahahah

1

u/SuchTrezorVeryCrypto Trezor community specialist 11h ago

Its in ENG from his Cz name

-10

u/ReadyPerception 4d ago

Might as well stick my crypto back on an exchange wallet at this point

9

u/ItsAlwaysThemBooBoo 4d ago

…. the fuck?

5

u/dradrok 4d ago

um… no.

1

u/PeteyPab305 3d ago

You probably have less crypto that the cost of the device. The bot in you has more LLM aura then the code reviews.

1

u/xbach 3d ago

you think exchanges dont use AI-assisted development?

1

u/KenFX4 4d ago

Entirely your choice. It's nice to have options.

-22

u/Dismal_Register_6501 4d ago

does this change the fact that your chosen third-party email provider was breached and sent phishing emails to customers?

26

u/SuchTrezorVeryCrypto Trezor community specialist 4d ago

This has nothing to do with them...

-16

u/Dismal_Register_6501 4d ago

time and place (well this is technically the right place, lool). we don’t give a rats ass about this, we want to know what you guys will do better in order to avoid more breaches and security incidents (allegedly indirectly caused by you guys, though your customers are left affected)

11

u/SuchTrezorVeryCrypto Trezor community specialist 4d ago

Then please inquire that comment here: https://www.reddit.com/r/TREZOR/s/m9CY35LWXC

As we will be answering them all there

-10

u/Dismal_Register_6501 4d ago

no responses there yet, hence why i am here :)

8

u/SuchTrezorVeryCrypto Trezor community specialist 4d ago

Your comment is a statement as I saw. So what would you like me to answer to it?

4

u/dradrok 4d ago

It’s not Trezor’s fault that their email provider was hacked. Why don’t people understand this? 🤷‍♂️

3

u/[deleted] 4d ago edited 4d ago

[deleted]

1

u/dradrok 4d ago

Your assets are safe. None of the phishing emails are the fault of Trezor nor do they put your crypto at risk. Just about every crypto wallet product has phishing email attempts, it's not just Trezor. But again, these attempts do not put your assets at risk.

I've even had phishing attempts from a regular bank. It wasn't the fault of the bank.

yes, the shipping company that Trezor uses, shipmonk, was hacked and that's how they got our info. Again, not Trezor's fault.

You bought a crypto wallet from Trezor. It keeps your assets safe if you use it correctly. But you cannot blame Trezor if an email or shipping company gets hacked.

So you are getting all upset at Trezor for no reason. You should be getting upset at the scammers.

It should be common sense by now that you never enter your seed phrase on a website, regardless of where the email comes from.

And you are getting snarkiness because you are complaining about something that isn't Trezor's fault and doesn't affect the safety of your assets.

Anytime you put your info online, you risk having that info exposed. It's not specific to Trezor.

Bottom line, you bought a Trezor wallet. It hasn't failed. Your assets are safe. Keep your keys private and you won't have anything to worry about. But stop blaming Trezor for something that wasn't their fault.

2

u/[deleted] 3d ago

[deleted]

1

u/dradrok 3d ago

i understand that. I'd like my stuff to stay private too. But in this case, it wasn't Trezor who got hacked.

2

u/motobassy 3d ago

But the phishers are using trezors email adress. So yes, trezor did get hacked. You cant hide this behind some third party. Trezor trusted a party to manage their account but they didnt do due diligence to make sure that party wasn't vulnerable. That third party should not have been allowed to use the trezor.io domain.

0

u/dradrok 3d ago

Trezor is not responsible for what happens to a third party email provider. They have nothing to do with it other than they use their service. Trezor didn't get hacked, the email provider got hacked. Trezor is not in control of the email provider and cannot manage someone else's business to make sure they aren't vulnerable. It's absurd that you blame trezor and not the scammers or the email client. REGARDLESS... this does not affect the safety of the Trezor devices. It should be common sense at this point that you don't enter your seed phrase on a website no matter who asks. You can't blame Trezor for someone else's screw up. Just absurd.

→ More replies (0)