3 ms·
Decent breakdown. Good job. 8. You can usually export it more conveniently. 10-13 is overkill. Most wallets have some reasonable way to move txes between hardw
by globalreset 4y ago
Decent breakdown. Good job.
8. You can usually export it more conveniently.
10-13 is overkill. Most wallets have some reasonable way to move txes between hardware wallet and online system (like SD card). They don't really compromise the practical security and are a much better UX.
3. checking if hardware really have no internet connectivity is indeed a thing. You could use Faraday Cage to be certain. Some wallets like ColdCard are translucent so you can inspect the components.
6. It is maximally secure to generate seed phrase manually using dices and paper lookup table. If you enter it into two wallets from two different vendors, you can see if they generate same addresses.
There's one attack you're missing: Hardware wallets could possibly slowly leak your private key by biasing bits in the signatures by grinding nonce. It would take whole lot of txes, but it is theoretically possible.
There's also possibility of someone just analyzing the electromagnetic waves during hw wallet signing txes to extra a key. Very very sophisticated and unlikely, but since we already have the tin foil hat on... just invest in Faraday Cage. :D
For maximum tin foil hat security, use multisig between two or more different devices (and/or parties), signing in different locations.
Edit: Oh. And since you're so into it it's worth mentioning that using seed passphrase is always a good idea!
- operator-name 4y agoAssuming the hardware wallet isn't following convention and impliments RFC 6979 (a huge red flag) that is. At that point the hardware wallet can be considered to do all kinds of messed up stuff - what about a wallet that deletes the private keys after X transactions? This is actually a realistic failure mode - hardware wallets do fail even if rare.
- JonathanBeuys 4y ago8: Using an SD card seems to completely throw the trustlessness regarding the hardware wallet out of the window? How do you know it does not write your seed phrase to the SD? The "leak via grinding nonce" seems scary. That means signing a transaction is not a deterministic process? The same transaction can be signed in multiple ways?
- globalreset 4y ago> How do you know it does not write your seed phrase to the SD? What's the point of an attack that writes the seed to the SD card that you are holding in your hand and can possibly easily notice that something was written there and attacker has no access to it? Sure, it's theoretically possible but it's such a ineffective approach that it's highly, highly unlikely. The hardware wallet using power consumption modulation to generate signal with electromagnetic waves that leak your private keys is far easier, stealthier and effective. With sophisticated equipment it could be detected from quite far away. So I would worry about getting a Faraday's Cage, before bothering with not using SD card. :) > That means signing a transaction is not a deterministic process Indeed. Signing with secp256k1 consist of signer picking an arbitrary nonce. I'm not sure if that's the case with Schnorr Signatures that are used for Taproot addresses.
- JonathanBeuys 4y agoThere is no way you can check if additional data was written to the SD. It can be hidden in file creation times, file modification times, file access times, file permissions and infinite other parameters of the file system. You can probably write a file to a arbitrarily chosen position on the block device and have it stil be a valid filesystem. So the position becomes the message. The attacker has access to it if he in some way runs software on your computer. That might be the software wallet you use or some other code that got onto your machine. "picking an arbitrary nonce" - that seems to be the biggest problem so far. So even an air gapped wallet can send out data to the world. Every bit it can send out halves the security of your seed phrase. So a tiny amount of data will quickly make it brute forceable.
- globalreset 4y agoThat's true, but again - it requires hacking the online computer AND malicious device. I guess one could use some offline machine to copy over only the file with the signed tx to be certain. :D > Every bit it can send out halves the security of your seed phrase. The device still needs to produce valid signatures in a reasonable time, so practically it can only leak handful of bits at the time.
- redox99 4y ago> There's one attack you're missing: Hardware wallets could possibly slowly leak your private key by biasing bits in the signatures by grinding nonce. It would take whole lot of txes, but it is theoretically possible. That's really cool. I had never thought of that. All these points make me think that the best way is ditching the hardware wallet, and creating your own hardware wallet on a generic, airgapped PC where you write your own software (you always hear don't roll your own crypto, but in these case where you don't have to worry about side channel attacks, and you would do the random generation with dice, it should be fine). In such case you're only relying on lets say, Intel, an airgapped generic Linux, GCC and maybe something else. But all these are things that would be extremely hard to modify in a way to affect your custom written software on an airgapped PC. Plus the incentives to do some sophisticated but funny business on a commercial Hardware Wallet is quite high. While adding such sophisticated attack to GCC or Intel chips somehow would be extremely unlikely. Add to this multisig with other methods, and the probability of some technical attack is so unlikely compared to a rubberhose attack, that it might as well be 0.
- JonathanBeuys 4y agoIt turned out that the hardware wallet does not sign the whole transaction data but only a hash of it. So it cannot change the nonce. But it is even worse: The act of signing the hash is not deterministic: https://medium.com/@simonwarta/signature-determinism-for-blockchain-developers-dbd84865a93e https://medium.com/@simonwarta/signature-determinism-for-blo... So it seems that: 1: Every hardware wallet can phone home 2: There is nothing that can be done about it