10 ms·
Ledger Live: A mobile companion app for Ledger hardware wallets
- Temasik 8y agoNo Bitcoin (SV implemention) support I'm out https://bitsocket.org https://bitsocket.org Message Bus for Bitcoin (SV)
- lewi 8y agoThanks for the constructive comment and plug of your product.
- Temasik 8y agoI'm not unwriter
- lawlessone 8y agowho cares?
- topynate 8y agoGood to see Bluetooth in the new hardware. Lack of real mobile support for hardware wallets has been by far the biggest pain point for me. (With regard to the best possible physical security, I would have preferred NFC over Bluetooth, but the latter is alright for everyday use.)
- YjSe2GMQ 8y agoAFAIK given the Ledger's on-screen confirmation process it really doesn't matter what's the medium of communication between the host machine and the device. It could as well be sent via unencrypted http routed through China, then Russia and then an NSA server all while your host device is heavily backdoored. The supply chain attacks/evil maid attacks are a much bigger issue, as pointed out in other comments.
- otoburb 8y ago>>It could as well be sent via unencrypted http routed through China, then Russia and then an NSA server all while your host device is heavily backdoored. As much as we'd like to believe this is the case, MITM (network or host) allows for replacement of destination addresses that show up on your screen. Redirected/malicious destination addresses showing up on your host screen will be cryptographically verified with Ledger's on-screen confirmation, but will not prevent you from sending your cryptoassets to the "wrong" endpoint. I think this is much more of a reality if your host device is "heavily backdoored" than unencrypted HTTP, but could happen in either case. Another attack vector was BGP & DNS hijacking, which happened to My Ether Wallet in April 2018[1][2]. [1] https://qz.com/1261540/mew-ethereum-hack-the-internets-infrastructure-was-compromised-to-target-myetherwallet/ https://qz.com/1261540/mew-ethereum-hack-the-internets-infra... [2] https://doublepulsar.com/hijack-of-amazons-internet-domain-service-used-to-reroute-web-traffic-for-two-hours-unnoticed-3a6f0dda6a6f https://doublepulsar.com/hijack-of-amazons-internet-domain-s...
- YjSe2GMQ 8y ago> but will not prevent you from sending your cryptoassets to the "wrong" endpoint. Can you explain how's that a problem? The only thing you can do with a signed transaction is to either broadcast it or not. MyEtherWallet suffers from the equivalent of supply chain attack here, where the JavaScript gets replaced with malicious code.
- otoburb 8y agoI'm treating network & host attacks as a supply chain attack where the authentic/intended destination address is replaced by the attacker with the attacker's address. Hence my air quotes around the word "wrong". As with MEW, as far as Ledger is concerned, a correct transaction is being signed and will in turn be broadcast. But the final outputs don't actually end up where the sender intended them to be sent because their host or network was compromised.
- YjSe2GMQ 8y ago
- mihaifm 8y agoMy greatest concern with the Ledger hardware wallet has been making sure the device hasn't been tampered with during shipment. Fortunately they provide a script to check hardware integrity, it's probably a good idea to run it before doing anything with the device. https://support.ledger.com/hc/en-us/articles/115005321449 https://support.ledger.com/hc/en-us/articles/115005321449
- 32032141 8y agoNote that this doesn't actually do anything to attest the safety of the device, as has been pointed out in a CCC talk recently. It attempts to confirm that the code running on another processor is legitimate by asking it to read its entire flash to a "HSM" chip, which is obviously simple to deceive by reading back something that is not the processors flash. I personally think that this is deceptive and counter productive.
- sowbug 8y agoRemote attestation implementations via HSMs will always remain subject to a confused-deputy problem, but they're still leaps and bounds better than pure software solutions. Any threat you can describe that involves a facade hardware UI is much easier to implement in software, meaning that attackers are more likely to invest resources in software attacks (like spraying bad Electrum servers into the pool) than hardware attacks (like modifying hardware wallets and setting up a storefront on eBay).
- jobbagy 8y agoI'm not able to find the md5 signature for Ledger Live: would you please help me?
- jobbagy 8y agowow the md5 does NOT exist: https://github.com/LedgerHQ/ledger-live-desktop/issues/942 https://github.com/LedgerHQ/ledger-live-desktop/issues/942 How is this possible
- 188201 8y agoA mobile app managing cryptocurrency, but does not sign all their release, and don't even react the situation quickly. Apparently they have no clue what they are doing in terms of security. Since they also use react native, and npm is notorious for being exploit to distribute malware. I have a brief look at the package.json. Seems to be a typical javascript project where developers tend to put one more dependency for a simple feature rather than implementing themselves. So, if one of the hobbyist project owner's key is compromised or hand over their orphan project to somebody malicious to manage their npm, then they are screwed. Although same could apply to other language which have package management, npm is the worst among those. Do they ensure the dependencies are signed before building the binary? And always use the last known good version for building new binary? I really doubt.
- AgentME 8y agoThe repo has a yarn.lock file, which contains the hashes of all of the dependencies, so yarn verifies the dependencies match that at least.
- mtgx 8y agoShouldn't everyone use SHA2, or at least Blake 2 (same software performance as MD5) by now?
- mr_sturd 8y agoI'm still very much in favour of managing my own private keys in an encrypted database on my desktop/laptop. I feel like everyone is blindly trusting these devices, having been scared in to it by horror stories of malware lifting keys off machines. I will eat my paper wallets if my meagre holdings are stolen from me like that.
- matt2000 8y agoAnother interesting alternative is multisignature wallets, like the new Gnosis Safe: https://safe.gnosis.io/ https://safe.gnosis.io/ An on-chain contract holds your funds and requires some number of signatures to authorize transactions (for personal use usually 2, i.e. one from your desktop computer and one from your phone). That way at least you know two separate devices would have to be compromised to cause loss of funds. This also allows for interesting key recovery strategies like having a third paper wallet that is also authorized. You could use that as a backup key that would allow authorization of a new key if your phone were stolen, etc.
- jki275 8y agoThese should be safer than that. The keys are generated on a secure processor and should not ever be able to be removed from the device.
- 32032141 8y agoA "secure", closed source processor. Given the Ledger bootloader had a rather nasty and bluntly obvious bug in it that allowed you to bypass all of the write protection and boot any firmware, I'd give them nearly zero chance of having got anything else right.
- _nalply 8y agoI wonder whether these apps cache sensitive information like account numbers and balances. I think they shouldn't.
- 32032141 8y agoThe way they operate, I expect that there's HTTP logs of all activity. They do not operate in a way which is conductive to privacy.
- YjSe2GMQ 8y agoYes they do - you don't need to plug in your device to see your current balance, even after power cycling the host device. That being said - there's virtually no privacy in most cryptocurrencies. Your Bitcoin/Ethereum/Ripple/... balance is fully public.
- homero 8y agoIs the hardware device required?
- dmos62 8y agoI thought this was about ledger, the cli accounting tool. I thought ledger + hardware + wallet? Wow! https://ledger-cli.org/ https://ledger-cli.org/
- senorsmile 8y agoMe too.
- gapinggasher1 8y agoledger is garbage and their software falls over if too many people are using it. Why do I know this? Their customer service literally told me that I cant access my wallet because too many people are trying to use the software. As a silly consequence I was not able to update the firmware. I switched to a more open source solution for the hardware, and for mobile mycelium. Ledger can suck a fat one.
- jscheel 8y agoUgh, I haven't even moved my existing crypto from cold storage to the original Ledger Nano sitting on my desk for a year.