5 ms·
>Extracting a secret key from an supposedly PIN protected device looks in scope to me. Prevented by not letting anyone casually hook up an oscilloscope to your
by FLUX-YOU 8y ago
>Extracting a secret key from an supposedly PIN protected device looks in scope to me.
Prevented by not letting anyone casually hook up an oscilloscope to your TREZOR.
- khedoros1 8y agoThat sounds like a work-around/mitigation, not a solution.
- FLUX-YOU 8y agoThere's very few solutions to "physical access = game over".
- xyzzyz 8y agoThere's a whole industry that's doing just that. Look up Hardware Security Modules. It is likely that you have a security device like that in the machine you are using right now (a Trusted Platform Module). People didn't simply threw their hands up, there are solutions for various problems in this space, with physical access being present in the threat model.
- gruez 8y ago>It is likely that you have a security device like that in the machine you are using right now funny you say that, because TPMs aren't actually mandated to be tamper resistant, only tamper evident[1]. what this means is that you won't be able to extract the keys without destroying the device, but if you delid the chip and probe it, you can probably extract the keys. I suspect it's the same with other HSMs you see in everyday life (smart cards, smartphone with trustzone, etc.). [1] sorry i don't have a better source: https://media.ccc.de/v/32c3-7343-beyond_anti_evil_maid https://media.ccc.de/v/32c3-7343-beyond_anti_evil_maid
- borgmace 8y agoNot true with real HSMs with FIPS 140-2 Level3+ The key material is protected from extraction.
- throwaway91345 8y agoYou are mistaken. TPMs these days are as tamper resistant as it gets, and a manufacturer would have severe difficulty selling one without an independent security certification proving that it actually is. Which means a state-of-the-art security lab with highly skilled experts and millions worth of specialized equipment attempts to break the chip for an extended amount of time, trying all sorts of known attacks, utilizing extensive access to information on chip internals that a real-life attacker normally would not have, _and in effect fails to break it nonetheless_. Google for 'Tarnovsky attack' and spend an evening watching thrilling videos to see to which lengths a top-notch adversary needed to go to break into these chips even in 2010-13. As for the chances in 2018, draw your own conclusions.
- throwawaymath 8y agoSmart cards are tamper resistant by definition. See https://people.cs.uchicago.edu/~dinoj/smartcard/security.html https://people.cs.uchicago.edu/~dinoj/smartcard/security.htm....
- gruez 8y agoi did a quick skim of the article for "resist" and couldn't find anything to back your claim. all the article says is that smart cards have better security because they're isolated from the host (which is a security measure, but doesn't say anything about physical tampering resistance), and that some smart cards have tamper resistance built in.
- dfox 8y agoFor true tamper resistance you need to have some way to actually detect tampering and erase the secrets, which usually leads to some battery-backed SRAM and associated tamper response circuitry. While there are some smart cards and smartcard-like HSMs (Fortezza comes to mind, but it uses the battery primarily for integrated RTC and seems to not contain any tamper detection mechanism) with integrated battery, common smartcards does not have battery.
- khedoros1 8y agoThere's no absolute solution. But that doesn't mean that they shouldn't have protected against well-understood classes of attack. Vulnerability to an attack that needs 5 minutes of physical access would be much better than vulnerability to an attack that needs 30 seconds.
- fiter 8y agoJust like you can prevent a "paper wallet" from being compromised by not letting anyone casually look at it? If I invested in one of these hardware wallets, I'd be interested in making it cost at least $X where $X is greater than the value in the wallet. I'd also like some time component, Y, that would allow me to transfer the money before the private key was found.
- thinkmassive 8y agoCost $X to attack? That makes complete sense. And if you know the physical device is compromised then you can "break the seal" by restoring the seed phrase on another device to transfer the funds elsewhere before an attacker is able.
- fastball 8y agoThe main selling point of hardware wallets is that they can interface with an internet-connected device to sign transactions without exposing the private key to that device, which has a much larger attack profile.
- X6S1x6Okd1st 8y agoWhy not just use a USB drive if your threat model doesn't involve physical access to the device?
- ChrisClark 8y agoBecause a USB drive is less secure for this use case. If you stick a USB drive into a compromised computer to make a transaction, a virus can steal the private key. If you stick a Trezor or Ledger into a compromised computer to make a transaction, your private key is still safe.
- mcpherrinm 8y agoMalware on the host PC can steal your private key. An attacker who gets brief physical access (eg, you look away for a minute) can quickly copy a USB drive. While this attack shows the trezor is probably a bit amateur-hour, it does provide some amount of value.
- exoesquitur 8y agoThat's not how it works. The trezor is not a USB storage device, it is a usb serial port that communicates with an MCU.
- paulhilbert 8y agoNo one claimed it is...
- mcpherrinm 8y agoI can see how reading my comment in isolation would be confusing. Specifically, I was answering the question "Why not just use a USB drive"
- sturmeh 8y agoBecause any process with i/o capability on the host OS can read the private key on the USB? Short of a oscilloscope hiding in the computer you use (totally possible), no process can derive the private key from the Trezor in theory. Even if you have processes that blatantly copy every USB's contents (or even log all interactions verbosely) and log all key presses/clipboard interactions on the machine, you can still use a Trezor without compromising anything. You can also verify that your clipboard is not being manipulated as the Trezor can verify the address it will be signing a transaction with on the display.