Bitcoin Forum
June 21, 2024, 07:20:20 AM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: The “Auditability” of QR Code Signature Outputs  (Read 121 times)
bitbro678 (OP)
Jr. Member
*
Offline Offline

Activity: 40
Merit: 1


View Profile
December 16, 2019, 05:47:49 AM
 #1

People purchase hardware wallets because they know the most secure way to store their private keys is to take them offline into cold storage. All hardware wallet services need a means of communicating between offline storage and online terminals. While the cold end (offline storage) is responsible for storing private keys and signing transactions, a hot end (online terminals) is needed to obtain data from the blockchain, construct transactions for the cold storage end to sign, and broadcast signed transactions to the blockchain.

In transmitting signature outputs, the majority of cold storage hardware uses data cables, Bluetooth, or even NFC. Because of the opacity of their data transmission, these methods make signature outputs extremely difficult to audit. An overlooked means of cold storage hardware communication is the QR code, a “what you see is what you get” solution. The QR code is the ideal means of data transmission between cold ends and hot ends because data output by QR codes is transparent. This enables users to easily ensure each unsigned transaction that is transmitted to the cold storage device is valid, as well as ensure signature outputs from the cold end do not reveal private keys or sensitive information in any way.

How many hardware wallets use QR codes to make transactions?
Pmalek
Legendary
*
Offline Offline

Activity: 2800
Merit: 7206



View Profile
December 16, 2019, 09:46:50 AM
 #2

I haven't checked bu I guess the one you are advertising all over the place does.  Wink

Btw, if you didn't write the Medium article from where you got this content from you need to give credit to the source and post a link from where you took it. if not it could be seen as copy/pasting.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
hugeblack
Legendary
*
Offline Offline

Activity: 2548
Merit: 3775


View Profile WWW
December 16, 2019, 12:57:15 PM
 #3

Thank God you did not mention Cobo products. I read the post specifically to confirm this.

I agree that scanning QR is the ideal solution, but as long as you keep your device protected and you do not download any untrusted apps, you are safe.
Any type of physical contact between these wallets and your devices may expose you to losing your money.

Do not forget to make sure that your computer is clean because some viruses modify the result of QR's scan.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!