3 ms·
This is largely the issue with 'hardware wallets', the security models aren't particularly well defined and this leads to ambiguity like this. You're absolutely
by 32032141 8y ago
This is largely the issue with 'hardware wallets', the security models aren't particularly well defined and this leads to ambiguity like this. You're absolutely correct in that the concern is the device is not genuine, which is what attestation of the firmware is supposed to prevent. In the case of the Ledger, the attestation doesn't prove anything about the safety of the device unfortunately for a number of reasons (this attack, and other logical ones).
The obvious one is that the security domains in the device are idiotic. There's a "secure" processor with almost no processing power or IO, and a "insecure" one which handles the screen, buttons and IO. Both of them handle secrets (for example, the seed shown on the screen), which leaves you with essentially no gain whatsoever.
The more logical hardware implant than the one shown at CCC is a bluetooth module that can simply read the I2C lines going to the screen and transmit the seed as a beacon whenever it is plugged in. This has the advantage of not needing presence as with their demonstration, and with assistance doesn't need any physical presence.
I described this as a concept for a security review of a cold storage setup which was "unbreakable". Is this sort of thing realistic? Perhaps. Is a $5 wrench attack more sensible? Probably. It's worth considering what supply chain attacks are possible though.
- lima 8y ago> The obvious one is that the security domains in the device are idiotic. There's a "secure" processor with almost no processing power or IO, and a "insecure" one which handles the screen, buttons and IO. Both of them handle secrets (for example, the seed shown on the screen), which leaves you with essentially no gain whatsoever. I think the idea is that the secure processor will verify the insecure processor's firmware (the "MCU check"), making such attacks impractical. Of course, the design is broken and it can be bypassed by emulation, but security isn't all or nothing - "no gain whatsoever" is not true.
- 32032141 8y agoEven if the firmware on both firmwares are completely virgin, this doesn't say much about the safety of the device. I agree that security is not all or nothing, protection in layers is always the goal of secure products. I do however caution that it can cause complacency if things are presented as bulletproof, you need to be up front about what tools such as attestation afford you. In this case it can not tell you that the device is safe or not tamptered with.