Bitcoin Forum
May 27, 2024, 02:27:47 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Ledger wallet App Isolation Bypass Alert  (Read 274 times)
Pmalek
Legendary
*
Offline Offline

Activity: 2772
Merit: 7160



View Profile
August 07, 2020, 04:58:32 PM
 #21

I find it quite worrying that their security team decided to sit on this vulnerability for several months while working on other things. Using COVID-19 as an excuse is shameful. They started testing the new Bitcoin app only when the deadline was reached. It is even worse that the fix came out just one day after the vulnerability was made public. That means that it was pretty easy for their team to fix it, they just didn't care or took their time to do it before.

As a Ledger user, this makes me think is this a company I should trust with my Bitcoin?!

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
August 07, 2020, 05:31:36 PM
 #22

They did release an update (to the Trezor One) to address issues related to this vulnerability: https://blog.trezor.io/firmware-updates-for-trezor-model-t-version-2-3-2-and-trezor-model-one-version-1-9-2-f4f9c0f1ed7c

Quote
Missing path isolation check

We have amended our Trezor One code to include a missing path isolation check, which is already in place for the Trezor Model T. This check prevents a user from spending coins from known paths (BIP44, BIP49, BIP84), if the coin type does not match the path. Without this check, an attacker could trick the user into signing a Bitcoin transaction while thinking they are signing a testnet or altcoin transaction.

Yes, that's the quote i have posted.
But the question was whether there was a bug bounty from trezor (just like with ledger) through which they received the information regarding this or whether they just checked their HW wallet after seeing ledgers being vulnerable to that.
And in this case i'd guess its #2 because their bug bounty page doesn't show anything related to this vulnerability.

TryNinja
Legendary
*
Offline Offline

Activity: 2842
Merit: 7048


Crypto Swap Exchange


View Profile WWW
August 07, 2020, 05:37:36 PM
 #23

But the question was whether there was a bug bounty from trezor (just like with ledger) through which they received the information regarding this or whether they just checked their HW wallet after seeing ledgers being vulnerable to that.
And in this case i'd guess its #2 because their bug bounty page doesn't show anything related to this vulnerability.
Considering that the guy that reported the vulnerability about Ledger didn’t even mention Trezor, I also assume #2 is correct. Trezor also only fixed the issue after the report, so he would certainly also call them out.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
August 07, 2020, 05:41:12 PM
 #24

Considering that the guy that reported the vulnerability about Ledger didn’t even mention Trezor, I also assume #2 is correct. Trezor also only fixed the issue after the report, so he would certainly also call them out.

This makes sense, but i wonder why he didn't also report the vulnerability to trezor.
He might have been able to get another bounty reward.

It probably wouldn't be too much additional work to test it on a trezor.
I guess he maybe didn't have a trezor lying around  Huh

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!