Live data from Hacker News

Funds of every Trust Wallet browser extension could have been stolen

blog.ledger.com

141–150 of 186 posts

Re: Funds of every Trust Wallet browser extension could have been stolen

#141
post #32

Earlier quoted context omitted.

> Browsers just aren't intended for doing things that require the generation and safe storage of private keys. This sounds like webcrypto and it’s interface which is designed to make some data unexportable.

Last time I used WebCrypto the implementation in Safari was buggy in subtle ways. It was possible to work around it. I filed bugs against Apple so maybe it's fixed now. These days you can argue that a browser is intended to do anything, as there seems to be no scope limit to what goes into HTML5. But it's not what they're really about. Why did this exploit occur, well, WebCrypto apparently isn't directly exposed to W…

> Last time I used WebCrypto the implementation in Safari was buggy in subtle ways.

Oh hell yes. I used maintain webcrypto code for a different job and yes Safari was broken forever. I don't have the codebase anymore (I sold the company in 2020) but we disabled keypair crypto features in Safari and told people to use a different browser. I believe it's since been fixed.

Re: Funds of every Trust Wallet browser extension could have been stolen

#142
post #135

Earlier quoted context omitted.

Can we conclude that gold is similar to cryptocurrency because of this?

As a store of work, sure, The difference being the currency in this case has no inherent value to fall back upon.

Why do precious metals have inherent value?

Re: Funds of every Trust Wallet browser extension could have been stolen

#143

Earlier quoted context omitted.

Those 100 are worth less, not because it was stolen, but because it was devalued / diluted through minting of more magic beans. Not all loss is theft.

So, by printing money the government takes money from citizens' pockets. Cryptocurrency is protected from this by design.

No, by printing money, the government dilutes/devalues the money they already have. You still have 100 dollars. Theft would be that you have 98 dollars.

Converting dollars into something that isn't dollars, which doesn't get you as much of that something, is a different concept. It is the value of the dollar is lower.

> Cryptocurrency is protected from this by design.

Not really.

Today, bitcoin dilutes holders through inflation tied to securing the network. Eventually, that inflation will end, but not in some of our lifetimes. Ethereum was inflationary but is now deflationary thanks to burning of transaction fees and the switch to PoS. The tokenomics of all chains can be changed over time, even bitcoin. It requires a fork of the chain that everyone follows. When inflation for bitcoin ends, I could envision miners agreeing on a fork that better protects their interests.

Re: Funds of every Trust Wallet browser extension could have been stolen

#144
post #46

> Creating good randomness is a daunting task - Ledger devices rely on dedicated silicon logic in our certified smartcard chips that have been the gold standard of secure industries for the past 40 years to guarantee high quality randomness and tamper resistance. Which is worthless and entirely irrelevant when they keep leaking their customers' personal and purchase data (which they claimed not to collect or keep, an…

Wait, that's neither worthless nor irrelevant. You can't take all my money using my personal and purchase data.

They sell security, whilst habitually neglecting to secure their shit. Who knows what it'll be that's compromised next.

For being offline wallets, their products sure do come with many connectivity options and live/online service integrations.

Re: Funds of every Trust Wallet browser extension could have been stolen

#145

Earlier quoted context omitted.

Is that a no?

You are asking the wrong question. "Do you have a sufficient understanding of stock markets?" For most people that's a "yes". They know what stocks are, what they represent, who the big players are to buy stocks on your behalf, and can be assured that the money is going to get to the right place. This is just not the case for crypto (yet), not remotely. Tons of tech people hardly know how these things work.

> You are asking the wrong question.

I'm responding to the way the op phrased their initial statements. They implied that just because they did not have a deep understanding of something, it must be bad.

Crypto is something for them that they don't understand, just like the stock market is something that many people also don't understand.

Re: Funds of every Trust Wallet browser extension could have been stolen

#146

Earlier quoted context omitted.

Do you have a deep understanding of how the stock market works?

In the stock market there is a long history of regulatory protection of unsophisticated investors, starting with the Securities Act of 1933 and Securities and Exchange Act of 1934. The whole point of these acts is to protect unsophisticated investors so they can invest in the stock market without fully understanding the details of how it works.

Given that another large bank just failed, you could have picked a better day to say that.

Re: Funds of every Trust Wallet browser extension could have been stolen

#147
post #140

Earlier quoted context omitted.

Compared to what? The only realistic alternative here is mailing cash, which is arguably more inconvenient.

Why not use those gift credit cards loaded with cash if you want anonymity for less effort?

with the caveat that I dont personally use bitcoin, I still think the above description is simpler then using gift credit cards, for a couple of reasons:

- gift cards involves getting in a car and driving to a place to buy them, which introduces annoying logistical issues

- the purchases made on a single card are linked together, so you have to keep track of cards you use for x store and what cards you use for y product (this is also true with bitcoin though, which is why I prefer other more privacy-focused cryptocurrencies)

- with gift cards there is a very high chance that your funds will be rejected or flagged as suspicious. which also limits the amount you can spend to around 100-200 dollers, since any more risks having all the money you put into that card flushed down toilet

I do personally keep a couple of gift cards on hand for the rare occasion I find myself needing to pay for something online and there is no alternative vender that accepts cryptocurrency (usually event tickets or membership subscriptions), but its a pain and I much prefer paying for things with cryptocurrency.

Cryptocurrency is an unregulated and environmentally disastrous ecosystem rife with monopolistic vender lock in, fraud and abuse, and little to no accountability or legal recourse for end users. But that's also true with the credit card / debit card / other electronic payment ecosystem.

At least with cryptocurrency I get a modicum of privacy.

Re: Funds of every Trust Wallet browser extension could have been stolen

#148
post #131
post #119

Earlier quoted context omitted.

These data leaks are indeed very bad, but in what way do they make the actual core product and its security goals "worthless and entirely irrelevant"?

What good is all this super reliable gold-standard encryption when its provider has shown to be so incredibly careless with the exact sort of information this solution is meant to protect? Whatever security goals they claim to pursue exist only in their marketing copy.

The point of good randomness is to keep other people from just directly draining your funds by breaking your key. That has nothing to do with any data held by Ledger, since they never see your key.

The data leaks don't affect that, though they're still a serious problem since they exposed customers to different sorts of attacks.

Re: Funds of every Trust Wallet browser extension could have been stolen

#149
post #144

Earlier quoted context omitted.

Wait, that's neither worthless nor irrelevant. You can't take all my money using my personal and purchase data.

They sell security, whilst habitually neglecting to secure their shit. Who knows what it'll be that's compromised next. For being offline wallets, their products sure do come with many connectivity options and live/online service integrations.

Ultimately the point of a hardware wallet is to connect it to a blockchain somehow, without losing security.

Re: Funds of every Trust Wallet browser extension could have been stolen

#150
post #131
post #119

Earlier quoted context omitted.

These data leaks are indeed very bad, but in what way do they make the actual core product and its security goals "worthless and entirely irrelevant"?

What good is all this super reliable gold-standard encryption when its provider has shown to be so incredibly careless with the exact sort of information this solution is meant to protect? Whatever security goals they claim to pursue exist only in their marketing copy.

Properly operating/securing a web shop and developing a secure embedded device are two pretty different skill sets, and I'm quite impressed with the quality of their security team's research concerning the latter.

Of course they should be doing both, but there's an easy, pragmatic workaround until then: You can just buy their devices on Amazon. (This does somewhat increase the chance of supply chain attacks, but that's always present, and I believe Ledger devices support hardware attestation in addition to tamper protection.)

Post reply on HN