4 ms·
> How do you know it does not write your seed phrase to the SD? What's the point of an attack that writes the seed to the SD card that you are holding in your
by globalreset 4y ago
> How do you know it does not write your seed phrase to the SD?
What's the point of an attack that writes the seed to the SD card that you are holding in your hand and can possibly easily notice that something was written there and attacker has no access to it? Sure, it's theoretically possible but it's such a ineffective approach that it's highly, highly unlikely.
The hardware wallet using power consumption modulation to generate signal with electromagnetic waves that leak your private keys is far easier, stealthier and effective. With sophisticated equipment it could be detected from quite far away.
So I would worry about getting a Faraday's Cage, before bothering with not using SD card. :)
> That means signing a transaction is not a deterministic process
Indeed. Signing with secp256k1 consist of signer picking an arbitrary nonce. I'm not sure if that's the case with Schnorr Signatures that are used for Taproot addresses.
- JonathanBeuys 4y agoThere is no way you can check if additional data was written to the SD. It can be hidden in file creation times, file modification times, file access times, file permissions and infinite other parameters of the file system. You can probably write a file to a arbitrarily chosen position on the block device and have it stil be a valid filesystem. So the position becomes the message. The attacker has access to it if he in some way runs software on your computer. That might be the software wallet you use or some other code that got onto your machine. "picking an arbitrary nonce" - that seems to be the biggest problem so far. So even an air gapped wallet can send out data to the world. Every bit it can send out halves the security of your seed phrase. So a tiny amount of data will quickly make it brute forceable.
- globalreset 4y agoThat's true, but again - it requires hacking the online computer AND malicious device. I guess one could use some offline machine to copy over only the file with the signed tx to be certain. :D > Every bit it can send out halves the security of your seed phrase. The device still needs to produce valid signatures in a reasonable time, so practically it can only leak handful of bits at the time.
- yencabulator 4y ago> "picking an arbitrary nonce" Yet, it's just random bytes. You could generate that with dice, and customize the wallet to take it as user input.