Bitcoin Forum
July 12, 2024, 03:53:20 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ledger hard wallet possible hack  (Read 398 times)
Borilla (OP)
Jr. Member
*
Offline Offline

Activity: 83
Merit: 1


View Profile
November 27, 2017, 10:51:59 AM
Last edit: November 27, 2017, 11:04:01 AM by Borilla
 #1

How difficult would it be for a hacker to put a fake ledger nano (or other HW) app on my computer so that when i plug my wallet it opens the fake app with the hacker's addresses?
A quick fix could be a website, we trust, checking the address is legit (website connects to your HW and you sign something with that address) ??
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 27, 2017, 04:39:38 PM
 #2

The difficulty in replacing the app on your pc with a malicious version itself is moderate.
This would technically require 1) physical access to your pc or 2) admin privileges (which is doable, especially on windows).
But this wouln't lead to a loss of your funds if you double check the addresses you type in.
On your Nano S, Blue you have to confirm your payment address on the screen of the device.
On the older versions (nano and HW..) you need to verify the payment via security card. This second layer protects you from this kind of attacks.

Borilla (OP)
Jr. Member
*
Offline Offline

Activity: 83
Merit: 1


View Profile
November 27, 2017, 05:20:53 PM
Last edit: November 27, 2017, 09:57:10 PM by Borilla
 #3

The difficulty in replacing the app on your pc with a malicious version itself is moderate.
This would technically require 1) physical access to your pc or 2) admin privileges (which is doable, especially on windows).
But this wouln't lead to a loss of your funds if you double check the addresses you type in.
On your Nano S, Blue you have to confirm your payment address on the screen of the device.
On the older versions (nano and HW..) you need to verify the payment via security card. This second layer protects you from this kind of attacks.

On my ledger nano s there's no address on the screen. Maybe ledger blue has that.

Actually the website could just show up the addresses generated by the ledger no? then you check that you are indeed sending your coins to one of your addresses and not to the hacker.  I don't know why i wrote this thing about signing something. Ha yes, i know: you  copy the address from the app and paste it into the website. The website tells you if it comes from your ledger (your ledger signs something and the website checks it). This is faster and the website doesn't have to show addresses that you have to check one by one.  

Borilla (OP)
Jr. Member
*
Offline Offline

Activity: 83
Merit: 1


View Profile
November 27, 2017, 05:59:46 PM
 #4


But this wouln't lead to a loss of your funds if you double check the addresses you type in.
.

i realize i misread your comment. Yes you lose your fund if you send them to the hacker address that shows up in the app. There's no way to know with the ledger nano s which address is legit. So i believe this is a serious threat. Never trust the French! Damn!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!