Earlier quoted context omitted.
Crypto is digital cash, not digital credit. If someone steals your physical wallet, you generally aren’t getting that cash back. Can we please dispense with this kind of hyperbolic nonsense?
You wouldn't carry large sums of cash on your person, so why are people considering large piles of cryptocurrency?
Critical flaw in Trezor hardware wallets
41–50 of 52 posts
Re: Critical flaw in Trezor hardware wallets
#42Earlier quoted context omitted.
As most on HN know, if anyone has physical access it's game over - so when I read "critical flaw" in the title to me that meant remote key extraction (or similar remote flaw), and since there's nothing remote about this I consider it a clickbait article. No, what has been written up is not "critical". physical in-person key extraction after literally opening up a piece of hardware and glitching its exposed innards is…
IMO there's a huge difference between invasive and non-invasive attacks. I would expect something that bills itself as "The safe place for your coins" to require a bit more effort, know-how, and tools to read out my keys than "a couple hundred dollars of equipment" and a python program. > if anyone has physical access it's game over It's actually not when you use a series of common defenses that wipe the chip when ta…
Have a look at this: https://saleemrashid.com/2018/03/20/breaking-ledger-security...
Re: Critical flaw in Trezor hardware wallets
#43Earlier quoted context omitted.
To me, this is full admission of a complete lack of security competency. Building a hardware wallet without using a smart card or some other secure element that at least has mitigation’s against voltage/clock glitching, detects light, reduces the ability to measure power consumption, etc is negligent. Either they don’t know how to design secure solutions or they wanted to use cheaper chips since tamper resistant chip…
As most on HN know, if anyone has physical access it's game over - so when I read "critical flaw" in the title to me that meant remote key extraction (or similar remote flaw), and since there's nothing remote about this I consider it a clickbait article. No, what has been written up is not "critical". physical in-person key extraction after literally opening up a piece of hardware and glitching its exposed innards is…
That's true but for only for threat models that assume decapping and other extreme efforts.
Re: Critical flaw in Trezor hardware wallets
#44Earlier quoted context omitted.
As most on HN know, if anyone has physical access it's game over - so when I read "critical flaw" in the title to me that meant remote key extraction (or similar remote flaw), and since there's nothing remote about this I consider it a clickbait article. No, what has been written up is not "critical". physical in-person key extraction after literally opening up a piece of hardware and glitching its exposed innards is…
> if anyone has physical access it's game over That's true but for only for threat models that assume decapping and other extreme efforts. https://en.wikipedia.org/wiki/Secure_cryptoprocessor
While we're at it, for the last question, tamper evidence, how good are tamper evidence seals - for example would a tamper evident seal on the enclosure show visually whether it has been opened (for example to exploit the flaw this article is about), or are tamper evident seals easy to get around or re-apply undetected?
Re: Critical flaw in Trezor hardware wallets
#45Earlier quoted context omitted.
As most on HN know, if anyone has physical access it's game over - so when I read "critical flaw" in the title to me that meant remote key extraction (or similar remote flaw), and since there's nothing remote about this I consider it a clickbait article. No, what has been written up is not "critical". physical in-person key extraction after literally opening up a piece of hardware and glitching its exposed innards is…
IMO there's a huge difference between invasive and non-invasive attacks. I would expect something that bills itself as "The safe place for your coins" to require a bit more effort, know-how, and tools to read out my keys than "a couple hundred dollars of equipment" and a python program. > if anyone has physical access it's game over It's actually not when you use a series of common defenses that wipe the chip when ta…
Re: Critical flaw in Trezor hardware wallets
#46Earlier quoted context omitted.
> if anyone has physical access it's game over That's true but for only for threat models that assume decapping and other extreme efforts. https://en.wikipedia.org/wiki/Secure_cryptoprocessor
How extreme is decapping? How much equipment and how much time does it require? How often does it destroy the chip or cause damage? How obvious is it that it occurred? While we're at it, for the last question, tamper evidence, how good are tamper evidence seals - for example would a tamper evident seal on the enclosure show visually whether it has been opened (for example to exploit the flaw this article is about), o…
Tamper evident seals can often be defeated with nothing more than a PTFE (Teflon) knife made from shim stock.
Re: Critical flaw in Trezor hardware wallets
#47Earlier quoted context omitted.
IMO there's a huge difference between invasive and non-invasive attacks. I would expect something that bills itself as "The safe place for your coins" to require a bit more effort, know-how, and tools to read out my keys than "a couple hundred dollars of equipment" and a python program. > if anyone has physical access it's game over It's actually not when you use a series of common defenses that wipe the chip when ta…
Interesting comment, thanks. What would you say about my other question: how good are tamper evident seals - for example would a tamper evident seal on the enclosure show visually whether it has been opened (for example to exploit the flaw this article is about), or are tamper evident seals easy to get around or re-apply undetected?
Re: Critical flaw in Trezor hardware wallets
#48Earlier quoted context omitted.
I think people in practice buy these and use them thinking that they are secure against physical theft because of “encryption” and requiring a pin. This shows that assumption to be totally false.
The attack doesn't work if you are using a passphrase. I'm not sure why they let people use a PIN in the first place, but you should never be using PIN instead of a passphrase.
Re: Critical flaw in Trezor hardware wallets
#49Re: Critical flaw in Trezor hardware wallets
#50Earlier quoted context omitted.
How extreme is decapping? How much equipment and how much time does it require? How often does it destroy the chip or cause damage? How obvious is it that it occurred? While we're at it, for the last question, tamper evidence, how good are tamper evidence seals - for example would a tamper evident seal on the enclosure show visually whether it has been opened (for example to exploit the flaw this article is about), o…
Decapping requires dissolving the plastic with acid. Attacking the chip from there is typically done in a Focused Ion Beam workstation (about $500k), and the risk of destroying the chip depends on too many factors. Some chips have photosensitive elements that generate just enough voltage to wipe their memory if they're exposed to light via decapping. Tamper evident seals can often be defeated with nothing more than a…