OSs Security: a free toolkit for hardening your devices
The crypto industry has gotten better at auditing code. But the devices the code runs on are still underprotected. A compromised device is the cleanest path to a compromised key. If the device signing transactions or holding seeds hasn't installed its security updates, is sending out data it doesn't need to, has more services running than it actually uses, or was never properly cleaned, none of