Since the release of Secalot, some of our users have been keen to hear more about the deviceβs security. We've published a blog that gives our view on Secalotβs security model.
https://t.co/hSOXnd56d5 #secalot#cryptocurrency#XRP
@nbougalis@xrptoolkit@haydentiff@Dave_Jonez_02 @cryptocatalunya @LeoHadjiloizou@parisbydavid@bob_way@JoelKatz In our solution a PC is only used to relay encrypted/authenticated (TLS 1.2) traffic between Secalot and a mobile phone app. It can be modified by any malicious software using Detours or anything else, but with TLS this is rather useless, as the traffic is integrity protected.
@nbougalis@xrptoolkit@haydentiff@Dave_Jonez_02 @cryptocatalunya @LeoHadjiloizou@parisbydavid@bob_way@JoelKatz Secalot is never relying on a PC not to be compromised. When a Tx is displayed on our mobile phone app, it is read from Secalot over a TLS 1.2 secure channel. Secalot is a TLS server, the mobile app is a TLS client. A PC merely relays the data that is encrypted and authenticated.