Live data from Hacker News

Critical flaw in Trezor hardware wallets

blog.kraken.com

51–52 of 52 posts

Re: Critical flaw in Trezor hardware wallets

#51

Earlier quoted context omitted.

To me, this is full admission of a complete lack of security competency. Building a hardware wallet without using a smart card or some other secure element that at least has mitigation’s against voltage/clock glitching, detects light, reduces the ability to measure power consumption, etc is negligent. Either they don’t know how to design secure solutions or they wanted to use cheaper chips since tamper resistant chip…

As most on HN know, if anyone has physical access it's game over - so when I read "critical flaw" in the title to me that meant remote key extraction (or similar remote flaw), and since there's nothing remote about this I consider it a clickbait article. No, what has been written up is not "critical". physical in-person key extraction after literally opening up a piece of hardware and glitching its exposed innards is…

Trezor's security features list [0] mentions firmware verification, JTAG, and welding - strongly implying that intends on at least some resistance to physical attack. This is not uncommon for hardware cryptography modules. Since 2001, the federal government has had a certification program, FIPS 140-2 [1], recognizing four different levels of physical attack resistance.

The security engineering industry is very interested in the capability to physically ship secrets to potentially hostile actors inside devices that limit their use or duplication. There are many many applications:

- Payment cards: EMV credit/debit, transit, laundry, parking, prepaid electric meters, etc.

- DRM: Widevine for Netflix, DCP for your local movie theater, anti-piracy and anti-cheat in your Xbox.

- Privacy: the iPhone's Secure Element only decrypts user data given the right PIN, rate limits or caps attempts, resists extraction of private key, much to FBI's disappointment.

- Root of trust: enterprise HSMs for PKI will only enable signing operations with their internal private keys after the presentation of a quorum of operator credentials [2].

Ross Anderson's Security Engineering has a great chapter on this [3].

[0] https://trezor.io/security/ [1] https://en.wikipedia.org/wiki/FIPS_140-2 [2] https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/ [3] https://www.cl.cam.ac.uk/~rja14/Papers/SEv3-ch18-dec18.pdf

Re: Critical flaw in Trezor hardware wallets

#52

Earlier quoted context omitted.

You wouldn't carry large sums of cash on your person, so why are people considering large piles of cryptocurrency?

People actually carry large sums in many places where credit cards aren't prevalent. Like Japan.

The analogy isn't credit. It's a bank. I doubt people carry much of a percent of their total Yen wealth in their pockets.
Post reply on HN