Conversation

A Trezor is a mini computer keeping access to the seed contained to an isolated component with on-device display / confirmation. It's wrong to expect that an attacker with physical access won't be able to extract the seed. That remains true with an obfuscated secure element too.
4
62
The BIP39 passphrase feature (passphrase appended to the seed phrase before key derivation) is the fundamental defense against an attacker gaining physical access. Trezor Model T has a much better implementation than the original by supporting on-device entry of the passphrase.
1
11
An attacker with physical access can extract data stored on a device. Secure elements can make data extraction more expensive but it's still possible. The benefit of dedicated hardware wallets is isolating access to the seed/passphrase for orders of magnitude less attack surface.
2
8