Earlier quoted context omitted.
Banks store private keys for their ATMs in hardware security modules (HSM) and there are lots of crypto exchanges that started doing that. One of the features is private keys self destruct when tampering is detected. If you have a backup you’ll be able to recover the private key. While I agree that Trezor wasn’t designed with this in mind, I think it’s a good idea to include this feature. Not sure about the size requ…
At this years RWC someone fuzzed the software on the HSM. Keys came out.
Critical flaw in Trezor hardware wallets
11–20 of 52 posts
Re: Critical flaw in Trezor hardware wallets
#12Re: Critical flaw in Trezor hardware wallets
#13Earlier quoted context omitted.
Banks store private keys for their ATMs in hardware security modules (HSM) and there are lots of crypto exchanges that started doing that. One of the features is private keys self destruct when tampering is detected. If you have a backup you’ll be able to recover the private key. While I agree that Trezor wasn’t designed with this in mind, I think it’s a good idea to include this feature. Not sure about the size requ…
True HSM with active self destruct needs to be constantly powered. On the other hand for many if not most applications, typical secure smart-card is is completely sufficient (and in fact typical POS card terminal stores most of it's long term secrets on SIM-like smart-card).
Had a pair of blown AA battery for self destruction. I never bothered to get it working, but IIRC it was supposed to detect removal from PCI slot(the proper) to self erase. So it’s not rare or difficult.
Re: Critical flaw in Trezor hardware wallets
#14Re: Critical flaw in Trezor hardware wallets
#15Re: Critical flaw in Trezor hardware wallets
#16Earlier quoted context omitted.
With the right systems in place, you can be protected from physical compromise. For example, if my credit card is stolen, I call visa and I'm fine.
And who do you think foots the bill? You might not pay it in one lump sum, but I’m pretty sure you still pay it.
Re: Critical flaw in Trezor hardware wallets
#17Nothing in this flaw is a surprise considering Trezor does not even use a secure element (unlike Ledger).
Re: Critical flaw in Trezor hardware wallets
#18No hardware can protect itself from absolute physical compromise; perhaps a self-fuse burner when somebody tries to open it
Banks store private keys for their ATMs in hardware security modules (HSM) and there are lots of crypto exchanges that started doing that. One of the features is private keys self destruct when tampering is detected. If you have a backup you’ll be able to recover the private key. While I agree that Trezor wasn’t designed with this in mind, I think it’s a good idea to include this feature. Not sure about the size requ…
After all these devices are hard to use in part because if the tiny screens.
Since most of the time you don't carry them in your pocket it does not appear to be a problem if they are bigger.
Re: Critical flaw in Trezor hardware wallets
#19Earlier quoted context omitted.
Banks store private keys for their ATMs in hardware security modules (HSM) and there are lots of crypto exchanges that started doing that. One of the features is private keys self destruct when tampering is detected. If you have a backup you’ll be able to recover the private key. While I agree that Trezor wasn’t designed with this in mind, I think it’s a good idea to include this feature. Not sure about the size requ…
At this years RWC someone fuzzed the software on the HSM. Keys came out.
Which HSM? There are multiple vendors.