I think it's time to stop recommending Ledger as a hardware wallet.
After reading approximately the 700ths post of some poor chap being phished, because of the negligence and incompetence of this company, I will never recommend anybody to buy a Ledger product again. I hope you agree and strike them from all your guides, how-tos and recommendations.
Imagine paying $70 for a shitty little hardware wallet, but to these greedy fucks, that's not enough. They HAVE to have your identifying personal information FOREVER, including your name and physical home address, just to squeeze out a few more Euros of bottom line per customer by marketing or probably outright selling the data. And YOU pay for that by being exposed and phished. Ledger sacrifices YOU for a few Euros.
Edit 2:
BTW, if any representative of Ledger, Trezor or ColdCard wants to correct anything I said here, please DM me. I'll gladly correct the post and apologize for errors.
I would very much appreciate clear and certain language around who retains what data for how long, in which way and why.
- Statement by u/rnvk: https://www.reddit.com/r/Bitcoin/comments/k9qj81/i_think_its_time_to_stop_recommending_ledger_as_a/gf653ys/
Edit 3:
I want to highlight this response: https://www.reddit.com/r/Bitcoin/comments/k9qj81/i_think_its_time_to_stop_recommending_ledger_as_a/gf67b75/?utm_source=reddit&utm_medium=usertext&utm_name=Bitcoin&utm_content=t1_gf67ys2
Ledger could have used the user data they had and are now used by scammer to attack their customers, to warn their users. They didn't.
Ledger knows, that almost all of their users, most certainly the most vulnerable to attacks, are using their inhouse software Ledger Live.
How many lives were financially devastated, because Ledger Inc. didn't find it necessary, to send out ONE FUCKING E-MAIL at the day of the breach saying something like this:
Attention: There was a data breach with the Ledger user database. From now on forward, all communication between Ledger Inc. and its customers will be done through Ledger Live. You can verify the authenticity of all our messages using Ledger Live in this way:
Edit 4:
Look at this shitshow: https://twitter.com/ndeet/status/1320307663427768320
I'm not a lawyer, but if that shit isn't a violation of the GDPR, I don't know what is.
Edit:
If you already bought from Ledger, demand erasure of your personal data immediately. Here is an example E-Mail:
Subject: Demand of erasure of personal data subject to Art. 17 GDPR.
Good day,
hereby I demand the immediate erasure of my personal data subject to Art. 17 GDPR.
Art. 17: (1) The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
Complete text of the law: https://gdpr-info.eu/art-17-gdpr/
Please inform me of the erasure as soon as it is done.
[link] [comments]