Bitcoin Forum
June 23, 2024, 08:18:09 AM *
News: Voting for pizza day contest
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Bitcoin / Hardware wallets / Re: Safepal hardware wallet review and opinions on: February 03, 2021, 12:07:54 AM
Hi again...

Bad news Sad Undecided after checking furthermore, the qrcodes can not really be decoded (thus said they does not contain nor private nor public key IN PLAIN text)... they theoretically contains public key in an encrypted manner, Check this official answer -> https://safepalsupport.zendesk.com/hc/en-us/articles/360054745351-Is-it-possible-to-pair-the-SafePal-S1-hardware-wallet-with-other-apps-   

- On the "Pro" side: this is a secure way to communicate and as we somehow trust Binance, we can then trust Safepal.
- On the "Con" side: users/developers can not check what the device is broadcasting on its Qrcodes, and everything is closed source, so no simple decoding possible, and no other application can use Safepal S1 (this is intended by Safepal).

In a business perspective I can understand such move, but this is not a licensed bank this is cryptocurrency and trust need to be proven not just obtained by reputation.
I really really loved this device, its conception, its price... BUT it's not worth of trust at 100% level Embarrassed  Undecided I really hope that Safepal will release some documentations, sources code or the used encryption to let the users/developer just be 100% sure of this device. this is not the case right now...

So for those of us that are really maniac about security, Safepal S1 is a strong NO! until Binance/Safepal release something that can proof what's the content of those qrcodes.

Note that I am not against Safepal S1 nor Binance nor did I find an exploit or a bug BUT I am on the side of a 100% proven security not just reputation.
2  Bitcoin / Hardware wallets / Re: Safepal hardware wallet review and opinions on: February 02, 2021, 09:18:16 PM
Hi Smiley

Can anyone help understand the qr code used by the Safepal S1... I extracted the HEX code of the different qr codes from this video https://www.youtube.com/watch?v=-_6uIIgJD7k (sorry I did not take it further i have a limited time for this)

Code:

Safepal S1 - QR-Code Analyze - From :
https://www.youtube.com/watch?v=-_6uIIgJD7k

Tools :
https://iancoleman.io/bip39/
and others...
 
-------------------------------------------------------------------------------------------------

Qr-Code Number : 1 (on the paper)
TXT : https://docs.safepal.io/user-manual

-------------------------------------------------------------------------------------------------

Qr-Code Number : 2 (on the device)
TXT : ************************************************************

-------------------------------------------------------------------------------------------------

Seed (no bip39 pass phrase set, the pin code is just for the device's security its not involved in the crypto) :
phone fee marine embark enrich weasel december sadness woman embrace dog symbol exhaust advance spell voice forget flavor spawn park abuse total egg crack

Root Prv Key
xprv9s21ZrQH143K3APPZKj7bAj9QjtU8xQrEcjkWrccAdJtUCYn59KGkMsjiMqgppKfJUoGg6Bim3dZNjcMhetBaJvSG8CDKt6E3cvqFTrgs56

BIP44 BTC Account Extended Public Key
xpub6CurGnmzinCW9QY77LN1wuLHHjc6JWQ7w2L4F7MtxxPCD8GrVYsasLaGWVZHnRUCGKUDTSukdKSaYN9KHeNy9BftPvWUoSFUMcUJi48FWmq

BIP44 BTC BIP32 Extended Public Key
xpub6EQWSsYokbzLNvmnHgJkHr8VBPeWjRWovg9CzfdFPWreHpPuZwCx8PrAtqRo3g2SNWR85J3iZwHYCHWrE1gmXa54rtAVgqJfpZpPDGTEdLf

First BTC address:
1J5iPEq5PkCQWbyw88eo5oJ5mXjyzNcKqi

-------------------------------------------------------------------------------------------------

Default coin list :
- BTC
- ETH
- BNB
- TRX
- USDT TRC20
- BitTorrent TRC10
- WINK TRC20
- ONE

-------------------------------------------------------------------------------------------------

Device Serial : S1F**************** => HEX : ***********************
Version : 1.0.14-10008

-------------------------------------------------------------------------------------------------

Qr-Code Number : 3 (on the phone)

HEX : ***

TXT : ***
TRX"
ONE"
USDT"
BTT"
WIN(

BIN : ***

-------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------

14 Qr codes to link both devices...

HEX : Original qr code value (Qr codes hex value contains space just for readability...)
TXT : Translation to text
BIN : Translation to binary code

-------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------

Qr-Code Number : x/14
HEX : 423A69030000 900C1DE1005B0E03F163439EB76E8A1C1C01A91FE973D270ADA8991A3DD227B5483A37923BD02A21029F91E6C6C3A35D5046001CEC6D93FBA316D3DF0BC6D31C318D30B7AF9A102211302C2A6E0A1508021A0C6D2F3434
TXT : B:i....
TXT : B:i� �[�cC��n���s�p���=�'�H:7�;�*!����ã]PF�m����� ��1�0���"0,*n m/44
BIN :
010000100011101001101001000000110000000000000000100100000000110000011101111000010000000001011011000011100000001111110001011000110100001110011110101101110110111010001010000111000001110000000001101010010001111111101001011100111101001001110000101011011010100010011001000110100011110111010010001001111011010101001000001110100011011110010010001110111101000000101010001000010000001010011111100100011110011011000110110000111010001101011101010100000100011000000000000111001110110001101101100100111111101110100011000101101101001111011111000010111100011011010011000111000011000110001101001100001011011110101111100110100001000000100010000100010011000000101100001010100110111000001010000101010000100000000010000110100000110001101101001011110011010000110100
GUESS :

-

Qr-Code Number : x/14
HEX : 423A69030000 8E9C2CEB005B0E013617B66BCF6DAB6FA977525ED822630A164169426A715A3165384133706734414A53766F476B785203505A5512046C756361189E4E20984E2A0F533146303831383237373336363533320957414C4C
TXT : B:i....
TXT : B:i��,�[6�k�m�o�wR^�"cAiBjqZ1e8A3pg4AJSvoGkxRPZUluca�N �N*S1F0818277366532 WALL
BIN :
010000100011101001101001000000110000000000000000100011101001110000101100111010110000000001011011000011100000000100110110000101111011011001101011110011110110110110101011011011111010100101110111010100100101111011011000001000100110001100001010000101100100000101101001010000100110101001110001010110100011000101100101001110000100000100110011011100000110011100110100010000010100101001010011011101100110111101000111011010110111100001010010000000110101000001011010010101010001001000000100011011000111010101100011011000010001100010011110010011100010000010011000010011100010101000001111010100110011000101000110001100000011100000110001001110000011001000110111001101110011001100110110001101100011010100110011001100100000100101010111010000010100110001001100
GUESS :

-

Qr-Code Number : x/14
HEX : 423A69030000 0587AFF6005B0E0A80081098D3C7F40D2220F5A8FDC334BC93C862B3C7C5F532DCE8D720F741359832DAB3FECB29BAF3978C2A2102A3F0429DD7D78FF830E07628238DC13CD0C34B88AC2158DB97A4A33DF5EDD0DA302C
TXT : B:i....
TXT : B:i���[�����" ����4���b����2��� �A5�2ڳ��)��*!��B��׏�0�v(#��<��K��!Xۗ��=����0,
BIN :
010000100011101001101001000000110000000000000000000001011000011110101111111101100000000001011011000011100000101010000000000010000001000010011000110100111100011111110100000011010010001000100000111101011010100011111101110000110011010010111100100100111100100001100010101100111100011111000101111101010011001011011100111010001101011100100000111101110100000100110101100110000011001011011010101100111111111011001011001010011011101011110011100101111000110000101010001000010000001010100011111100000100001010011101110101111101011110001111111110000011000011100000011101100010100000100011100011011100000100111100110100001100001101001011100010001010110000100001010110001101101110010111101001001010001100111101111101011110110111010000110110100011000000101100
GUESS :

-

Qr-Code Number : x/14
HEX : 423A69030000 CF71494D005B0E000A146F62575471447676345943315541367A3177714E10DB011A410436DC1D5AC0C73AAB96A1ABC0B42CFF5C0933CCCF37E233EAF7CAADD920A2718CCCE7EA335283EA7BBE9A5AB7BE404A8F2D901F
TXT : B:i....
TXT : B:i�qIM[obWTqDvv4YC1UA6z1wqN�A6�Z��:������,�\ 3��7�3��ʭ� �q����3R��{��Z��@J�-�
BIN :
010000100011101001101001000000110000000000000000110011110111000101001001010011010000000001011011000011100000000000001010000101000110111101100010010101110101010001110001010001000111011001110110001101000101100101000011001100010101010101000001001101100111101000110001011101110111000101001110000100001101101100000001000110100100000100000100001101101101110000011101010110101100000011000111001110101010101110010110101000011010101111000000101101000010110011111111010111000000100100110011110011001100111100110111111000100011001111101010111101111100101010101101110110010010000010100010011100011000110011001100111001111110101000110011010100101000001111101010011110111011111010011010010110101011011110111110010000000100101010001111001011011001000000011111
GUESS :

-

Qr-Code Number : x/14
HEX : 423A69030000 BEA3E0FD005B0E075258125508031880808080081098D3C7F40D2220F5A8FDC334BC93C862B3C7C5F532DCE8D720F741359832DAB3FECB29BAF3978C2A2102A3F0429DD7D78FF830E07628238DC13CD0C34B88AC2158DB
TXT : B:i....
TXT : B:i����[RXU��������" ����4���b����2��� �A5�2ڳ��)��*!��B��׏�0�v(#��<��K��!X�
BIN :
010000100011101001101001000000110000000000000000101111101010001111100000111111010000000001011011000011100000011101010010010110000001001001010101000010000000001100011000100000001000000010000000100000000000100000010000100110001101001111000111111101000000110100100010001000001111010110101000111111011100001100110100101111001001001111001000011000101011001111000111110001011111010100110010110111001110100011010111001000001111011101000001001101011001100000110010110110101011001111111110110010110010100110111010111100111001011110001100001010100010000100000010101000111111000001000010100111011101011111010111100011111111100000110000111000000111011000101000001000111000110111000001001111001101000011000011010010111000100010101100001000010101100011011011
GUESS :

-

Qr-Code Number : x/14
HEX : 423A61030000 CE8EB5BC00550E0DAED97231298642A539343028D1BFF54E562019FF4EF1245ED9708E0D7B8E42A02A2102444FE4FD9428889A8954FAE87B5D484D06755C23E5F0C99E471AFEF3CC56EC4E302CF29604D8
TXT : B:i....
TXT : B:aΎ��U��r1)�B�940(ѿ�NV �N�$^�p�{�B�*!DO���(���T��{]HMu\#��ɞG���V�N0,��
BIN :
010000100011101001100001000000110000000000000000110011101000111010110101101111000000000001010101000011100000110110101110110110010111001000110001001010011000011001000010101001010011100100110100001100000010100011010001101111111111010101001110010101100010000000011001111111110100111011110001001001000101111011011001011100001000111000001101011110111000111001000010101000000010101000100001000000100100010001001111111001001111110110010100001010001000100010011010100010010101010011111010111010000111101101011101010010000100110100000110011101010101110000100011111001011111000011001001100111100100011100011010111111101111001111001100010101101110110001001110001100000010110011110010100101100000010011011000
GUESS :

-

Qr-Code Number : x/14
HEX : 423A69030000 C4C75F80005B0E0245545F53313A0653315F523433420253314A075361666550616C589A9EA0F20568901C2A6D0A1408011A0B6D2F3434682F30682F306812034254431255080318808080800810EF88B6DB0A2220D904
TXT : B:i....
TXT : B:i��_�[ET_S1:S1_R43BS1JSafePalX����h�*m m/44h/0h/0hBTCU�����" �
BIN :
010000100011101001101001000000110000000000000000110001001100011101011111100000000000000001011011000011100000001001000101010101000101111101010011001100010011101000000110010100110011000101011111010100100011010000110011010000100000001001010011001100010100101000000111010100110110000101100110011001010101000001100001011011000101100010011010100111101010000011110010000001010110100010010000000111000010101001101101000010100001010000001000000000010001101000001011011011010010111100110100001101000110100000101111001100000110100000101111001100000110100000010010000000110100001001010100010000110001001001010101000010000000001100011000100000001000000010000000100000000000100000010000111011111000100010110110110110110000101000100010001000001101100100000100
GUESS : BTC Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 57975C7B005B0E04682F3630682F306812034554481255080318808080800810E0BEFDC1092220F7E72459390A5F6034261D02F5C5ABE6AC6FDF39224FDDF0E3F5991368C60B972A2103697C8FA4576A3519BCBC444298
TXT : B:i....
TXT : B:iW�\{[h/60h/0hETHU������� " ��$Y9_`4&�ū�o�9"O�����h� �*!i|��Wj5��DB�
BIN :
010000100011101001101001000000110000000000000000010101111001011101011100011110110000000001011011000011100000010001101000001011110011011000110000011010000010111100110000011010000001001000000011010001010101010001001000000100100101010100001000000000110001100010000000100000001000000010000000000010000001000011100000101111101111110111000001000010010010001000100000111101111110011100100100010110010011100100001010010111110110000000110100001001100001110100000010111101011100010110101011111001101010110001101111110111110011100100100010010011111101110111110000111000111111010110011001000100110110100011000110000010111001011100101010001000010000001101101001011111001000111110100100010101110110101000110101000110011011110010111100010001000100001010011000
GUESS : ETH Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 D22458C9005B0E059FEE167A72A34FA53A1655B86B1F193138E153302C2A6F0A1608041A0D6D2F3434682F373134682F30681203424E42125508031880808080081086E1E8D20C22201FFD2FC752EC6E274F8BEE5F6220
TXT : B:i....                                                                                                                                                                              
TXT : B:i�$X�[��zr�O�:U�k18�S0,*om/44h/714h/0hBNBU�������� " �/�R�n'O��_b
BIN :
010000100011101001101001000000110000000000000000110100100010010001011000110010010000000001011011000011100000010110011111111011100001011001111010011100101010001101001111101001010011101000010110010101011011100001101011000111110001100100110001001110001110000101010011001100000010110000101010011011110000101000010110000010000000010000011010000011010110110100101111001101000011010001101000001011110011011100110001001101000110100000101111001100000110100000010010000000110100001001001110010000100001001001010101000010000000001100011000100000001000000010000000100000000000100000010000100001101110000111101000110100100000110000100010001000000001111111111101001011111100011101010010111011000110111000100111010011111000101111101110010111110110001000100000
GUESS : BNB Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 9E940867005B0E06090BBDEECE99B88C6BE7663186FD4FF34AD32A21038786F32F695658FC211084B9400E6AB510AF8E8C9E54461882902221D8B1B9FD302C2A 6F0A1608081A0D 6D2F3434682F313935682F3068 120354
TXT : B:i....                                                                                                                                                      m/44h/195h/0h
TXT : B:i��g[ ��I��k�f1��O�J�*!���/iVX�!��@j�����TF��"!ر��0,*om/44h/195h/0hT
BIN :
010000100011101001101001000000110000000000000000100111101001010000001000011001110000000001011011000011100000011000001001000010111011110111101110110011101001100110111000100011000110101111100111011001100011000110000110111111010100111111110011010010101101001100101010001000010000001110000111100001101111001100101111011010010101011001011000111111000010000100010000100001001011100101000000000011100110101010110101000100001010111110001110100011001001111001010100010001100001100010000010100100000010001000100001110110001011000110111001111111010011000000101100001010100110111100001010000101100000100000001000000110100000110101101101001011110011010000110100011010000010111100110001001110010011010101101000001011110011000001101000000100100000001101010100
GUESS : TRX Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 E844C31B005B0E0897A4A33DF5EDD0DA302C2A700A17080A1A0D6D2F3434682F313935682F3068120455534454125508031880808080081098D3C7F40D2220F5A8FDC334BC93C862B3C7C5F532DCE8D720F741359832DA
TXT : B:i....
TXT : B:i�D�[���=����0,*pm/44h/195h/0hUSDTU��������" ����4���b����2��� �A5�2�
BIN :
010000100011101001101001000000110000000000000000111010000100010011000011000110110000000001011011000011100000100010010111101001001010001100111101111101011110110111010000110110100011000000101100001010100111000000001010000101110000100000001010000110100000110101101101001011110011010000110100011010000010111100110001001110010011010101101000001011110011000001101000000100100000010001010101010100110100010001010100000100100101010100001000000000110001100010000000100000001000000010000000000010000001000010011000110100111100011111110100000011010010001000100000111101011010100011111101110000110011010010111100100100111100100001100010101100111100011111000101111101010011001011011100111010001101011100100000111101110100000100110101100110000011001011011010
GUESS : USDT TRC20 Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 301AD35B005B0E09B3FECB29BAF3978C2A2102A3F0429DD7D78FF830E07628238DC13CD0C34B88AC2158DB97A4A33DF5EDD0DA302C2A6F0A1608091A0D6D2F34 34682F313935682F306812034254541255080318 808080
TXT : B:i....                                                                                                                                       4h/195h/0hBTTU                    €€€
TXT : B:i0�[[ ���)��*!��B��׏�0�v(#��<��K��!Xۗ��=����0,*o m/44h/195h/0hBTTU���
BIN :
010000100011101001101001000000110000000000000000001100000001101011010011010110110000000001011011000011100000100110110011111111101100101100101001101110101111001110010111100011000010101000100001000000101010001111110000010000101001110111010111110101111000111111111000001100001110000001110110001010000010001110001101110000010011110011010000110000110100101110001000101011000010000101011000110110111001011110100100101000110011110111110101111011011101000011011010001100000010110000101010011011110000101000010110000010000000100100011010000011010110110100101111001101000011010001101000001011110011000100111001001101010110100000101111001100000110100000010010000000110100001001010100010101000001001001010101000010000000001100011000100000001000000010000000
GUESS : BitTorrent TRC10 Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 E418D4B8005B0E0B2A6F0A16080A1A0D6D2F3434682F313935682F3068120357494E125508031880808080081098D3C7F40D2220F5A8FDC334BC93C862B3C7C5F532DCE8D720F741359832DAB3FECB29BAF3978C2A2102
TXT : B:i....
TXT : B:i�Ը[ *om/44h/195h/0hWINU��������" ����4���b����2��� �A5�2ڳ��)��*!
BIN :
010000100011101001101001000000110000000000000000111001000001100011010100101110000000000001011011000011100000101100101010011011110000101000010110000010000000101000011010000011010110110100101111001101000011010001101000001011110011000100111001001101010110100000101111001100000110100000010010000000110101011101001001010011100001001001010101000010000000001100011000100000001000000010000000100000000000100000010000100110001101001111000111111101000000110100100010001000001111010110101000111111011100001100110100101111001001001111001000011000101011001111000111110001011111010100110010110111001110100011010111001000001111011101000001001101011001100000110010110110101011001111111110110010110010100110111010111100111001011110001100001010100010000100000010
GUESS : WINK TRC20 Qr-Code Block

-

Qr-Code Number : x/14
HEX : 423A69030000 C0F9D2A5005B0E0CA3F0429DD7D78FF830E07628238DC13CD0C34B88AC2158DB97A4A33DF5EDD0DA302C2A700A1708061A0E6D2F3434682F31303233682F306812034F4E4512550803188080808008109D9FE8EF082220
TXT : B:i....
TXT : B:i��ҥ[ ��B��׏�0�v(#��<��K��!Xۗ��=����0,*pm/44h/1023h/0hONEU��������"
BIN :
01000010001110100110100100000011000000000000000011000000111110011101001010100101000000000101101100001110000011001010001111110000010000101001110111010111110101111000111111111000001100001110000001110110001010000010001110001101110000010011110011010000110000110100101110001000101011000010000101011000110110111001011110100100101000110011110111110101111011011101000011011010001100000010110000101010011100000000101000010111000010000000011000011010000011100110110100101111001101000011010001101000001011110011000100110000001100100011001101101000001011110011000001101000000100100000001101001111010011100100010100010010010101010000100000000011000110001000000010000000100000001000000000001000000100001001110110011111111010001110111100001000001000100010
GUESS : ONE Qr-Code Block

------------------------------------------------------------------
------------------------------------------------------------------

Qr-Code Number : 18 (on the phone)
Add new coin from app (adding LTC) :
HEX : ***********************
3  Bitcoin / Hardware wallets / Re: Safepal hardware wallet review and opinions on: February 02, 2021, 09:38:33 AM
I am highly interested as well in analyzing the qr codes that are being sent by the device... I did scan some of the qr codes from some youtube videos (reviews videos) I did not had the time to fully analyze/reverse the qr code... but it contain the derivation path in clear text... the phone model and I guess its serial are broadcasted to the S1 when coupled over qr codes (the first time)... normally the qr code would contain the different public keys of the different used currencies wallets and may be some additional informations... I really need to look into this to see if there is some leakage and if the wallet can be trusted fully... otherwise I'll test that extensively when I receive mine... but honestly I don't think they will risk their reputation by sending sensitive data like the private key, even encrypted this would ruin them for good and make the device completely useless... anyway I would really love to see this device communicating in a "clear" way; that would make it easily compatible with other app/wallets and would let us check it furthermore... personally I prefer analyzing qr codes instead of bluetooth communication even if it's told "opensource" this word is throwed everywhere now days without real possibility to check what's going on.    

Any way anyone checked the qr-codes?

Aside from that as it's not opensource, I would kind a check manually every qr code on production loool... but at first look it look all legit and working as intended... yet I did not had the time to complete the analysis.
4  Local / Anfänger und Hilfe / Re: BitGo-Wallet in Electrum? on: January 17, 2021, 08:47:50 AM
Hi,

Facing the same issue as well, i posted a question here https://bitcoin.stackexchange.com/questions/101563/is-it-possible-to-use-bitgo-wallet-with-other-software-electrum-or-else-what

Hope we will find a solution to this...
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!