Bitcoin Forum
May 26, 2024, 01:48:35 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 [7] 8 9 10 11 »
121  Bitcoin / Bitcoin Discussion / Re: Bitcoin might soon be call altcoin on: February 04, 2018, 07:38:37 PM
Bitcoin is the basis. And bitcoin will always be bitcoin.
Now the fall is a fake game caused by the players.
122  Bitcoin / Project Development / Re: hyperledger or ethereum? on: February 04, 2018, 10:16:45 AM
It's a great idea to help developers for a good work experience. And then create your own project.
123  Bitcoin / Press / [2018-02-04] Ledger Addresses Man in the Middle Attack That Threatens Millions o on: February 04, 2018, 10:11:59 AM
Hardware wallet manufacturer Ledger, which sold over one million devices last year, has alerted its users to a major attack vector that’s recently been discovered. Although there are no reported cases of the attack being successfully deployed, the threat itself is very real. Today, Ledger urged users of its cryptocurrency wallets to take steps to avoid falling prey to the address spoofing attack.

Beware the Man in the Middle
Hardware wallets are regarded as one of the safest means of storing bitcoin and other cryptocurrencies. The USB cold storage devices eliminate the sort of attack vectors synonymous with being connected to the web. But to send funds or issue a receiving address, a hardware wallet has to be plugged in to an internet-enabled device, and researchers have discovered a vulnerability that affects Ledger devices at this stage. A newly published report reveals the way the MiTM attack would play out. It explains:

Ledger wallets generate the displayed receive address using JavaScript code running on the host machine…malware can simply replace the code responsible for generating the receive address with its own address, causing all future deposits to be sent to the attacker.


The attack, if executed, would leave the victim unaware at first that anything was the matter. To prove the the vulnerability is real, the report’s authors have posted a proof of concept that demonstrates the attack in action. The severity of the attack is heightened by the fact that, with Ledger’s wallet software stored in the AppData folder, it is relatively easy for malware to modify the receiving address. As the report notes, “All the malware needs to do is replace one line of code…this can be achieved with less than 10 lines of python”.

A Solution of Sorts
To avoid succumbing to this attack, there is a means of verifying the receiving address is correct, as the report explains, and as Ledger acknowledged in a tweet earlier today:

Ledger Addresses Man in the Middle Attack That Affects Millions of Hardware Wallets

This solution, while effective, is not failsafe in that it’s reliant on the user remembering to follow this procedure every time they transact. As the report points out, “A proper solution would be to [force] the user to validate the receive address before every receive transaction, just like the wallet [forces] the user to approve every send transaction”.

That’s the system that Trezor now uses with its hardware wallets, mandating the use of 2FA simply to access the receiving address. It is hoped that Ledger will follow suit in updating its devices to adopt this methodology. Hardware wallets are still significantly safer than leaving funds stored on a centralized exchange, but no solution is entirely foolproof, as the Ledger case demonstrates.

Do you think this vulnerability is cause for concern and do you think Ledger should enforce 2FA to resolve it? Let us know in the comments section below.

https://news.bitcoin.com/ledger-addresses-man-in-the-middle-attack-that-threatens-millions-of-hardware-wallets/
124  Alternate cryptocurrencies / Altcoin Discussion / Re: Vitrocoin real or scam? on: February 04, 2018, 09:52:26 AM
an unpopular coin, big money does not need to be invested.
125  Other / Meta / Re: I done good posts but not receive any merit on: February 04, 2018, 09:50:50 AM
I think it would be great if the users of the forum themselves put a "plus" for a good message
126  Bitcoin / Bitcoin Technical Support / Re: Safest wallet ? on: February 04, 2018, 12:38:03 AM
online wallet  -  blockchain.info
Or ledger.
127  Economy / Speculation / Re: Its too late to invest in Bitcoin! on: February 04, 2018, 12:30:36 AM
It is necessary to take bitcoin at a low cost. Altcoins - a good option, do not confine one bitcoin.
128  Bitcoin / Bitcoin Discussion / Re: Coinbase on: February 04, 2018, 12:15:24 AM
There will be no problems, keep it.
But if you need a very reliable place - store it on your computer.
129  Bitcoin / Bitcoin Discussion / Re: Do you think Bitcoin can ruin a Country? on: February 03, 2018, 01:39:01 PM
just need the right approach, bitcoin can not destroy anything.
130  Local / Альтернативные криптовалюты / Re: EOS vs Cardano on: February 03, 2018, 01:37:01 PM
Обе монеты заслуживают внимания, EOS - вроде как еще ICO, если не ошибаюсь.
131  Bitcoin / Wallet software / Re: Ledger blue and bluetooth on: February 03, 2018, 01:20:14 PM
So far there's no app/s available yet for this feature of ledger blue. I dunno why they add it so early when it can't be used.
*No wallet apps using Bluetooth are available for the moment

I also noticed that this is very strange. I wrote to the developers, since it would be very convenient to make money transfers using a smartphone with the application. It turns out that bluetooth is useless.
132  Bitcoin / Bitcoin Discussion / Re: Why does bitcoin have value? on: February 03, 2018, 01:15:09 PM
People made bitcoin valuable.
133  Economy / Securities / Re: where to invest? on: February 03, 2018, 01:06:21 PM
I would just keep the top of the coin for a long time and then bring it out with a profit
ICO - its risk, But if you are sure of IСO - then good.
134  Bitcoin / Press / Re: [2018-02-02] Report: Bank of America, JP Morgan Ban Credit Crypto Purchases on: February 03, 2018, 12:44:37 PM
I think a person should decide how to manage money.
135  Alternate cryptocurrencies / Altcoin Discussion / Re: Mining on Mobile Phone on: February 03, 2018, 12:36:32 PM
you will not pay back anything!
1. little power
2. Slowly
3. unprofitable
136  Economy / Trading Discussion / Re: BEST trading platform for fast trading? on: February 03, 2018, 12:33:54 PM
Binance, bittrex and bitfinex
137  Bitcoin / Wallet software / Ledger blue and bluetooth on: February 03, 2018, 12:28:08 PM
Hello!
I noticed that the Ledger blue has bluetooth, but there is no application. What for then bluetooth Ledger blue?
I think it would be great to connect via bluetooth to the application and make transactions.
138  Bitcoin / Bitcoin Wallet for Android / Re: What is the best bitcoin wallet on: February 03, 2018, 12:22:08 PM
Electrum and ledger wallet, it is better to store at yourself, but not on servers from someone
139  Alternate cryptocurrencies / Altcoin Discussion / Re: Learning blockchain programming on: February 03, 2018, 12:18:59 PM
Can you see this books - https://cointelegraph.com/news/8-best-sources-to-study-blockchain-technology
140  Alternate cryptocurrencies / Speculation (Altcoins) / Re: 2 Ethereum or 15 NEO for long term on: February 03, 2018, 11:11:25 AM
NEO has more chances to make a lot of money. See the capitalization, the etherium is stable, but the capitalization is big, it's hard for him to do X2,3,4...
Pages: « 1 2 3 4 5 6 [7] 8 9 10 11 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!