Bitcoin Forum
December 15, 2024, 02:37:49 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 ... 265 »
  Print  
Author Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet  (Read 966230 times)
caveden
Legendary
*
Offline Offline

Activity: 1106
Merit: 1004



View Profile
November 21, 2012, 09:40:02 AM
 #161

Only better way is to replace the password with the hash of a biometric scan (fingerprints maybe) but in this way cost are higher and not all devices can support it.

Biometric scans, AFAIK, are like images. Different scans of the same individual will produce different data, which would produce different hashes. You can compare different images to see if they belong to the same person, but if you use one of these images as an encryption key, there's no guarantee you'll ever be able to unencrypt your data.
Of course that biometric scans could be used as an authentication method by a sophisticated device, but if the device is "physically hacked" and the biometric check is bypassed, you'll need something else to protect the data.

And, honestly, if you're afraid of physical thefts, shouldn't you also be afraid of physical coercion? What good is a biometric scan if the thief can simply force you to put your finger/eye/whatever?

As slush said before, we are not at the point where this is a reasonable threat for most of us. Hackers are a serious threat though, so we should first focus on how to protect ourselves from them first.
ercolinux
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile WWW
November 21, 2012, 11:07:44 AM
 #162

Only better way is to replace the password with the hash of a biometric scan (fingerprints maybe) but in this way cost are higher and not all devices can support it.

Biometric scans, AFAIK, are like images. Different scans of the same individual will produce different data, which would produce different hashes

You're true for a hash of the full image, but fingerprint scanner actually save only a "path" of the minutiaes of the fingerprints. And using that work in a reliable way.

Quote
. You can compare different images to see if they belong to the same person, but if you use one of these images as an encryption key, there's no guarantee you'll ever be able to unencrypt your data.

I didn't mean use the hash as password but only as authentication method.

Quote
Of course that biometric scans could be used as an authentication method by a sophisticated device, but if the device is "physically hacked" and the biometric check is bypassed, you'll need something else to protect the data.

And, honestly, if you're afraid of physical thefts, shouldn't you also be afraid of physical coercion? What good is a biometric scan if the thief can simply force you to put your finger/eye/whatever?

As slush said before, we are not at the point where this is a reasonable threat for most of us. Hackers are a serious threat though, so we should first focus on how to protect ourselves from them first.

On that I agree totally with you: my reply was to luicon who had expressed concern about forgetting the password. If one can obtain access to both you and the device there is really few things to do.
BTW to avoid physical coericion there is a  way, even not too difficult to implement: some times ago I've a phone with an encrypted area in which store password and pins. If you input the good password you decrypt the area, if you put a wrong one you obtain an error, but if you put a "special" one you go into a fake area with other data. Maybe is possible, for extra-paranoid implement a similar approach: one pin for real wallet, another one for another with only few BTC in it.
But again we are talking of extra-paranoid people here. IMHO slush design is more than adeguate.

Bitrated user: ercolinux.
luicon
Sr. Member
****
Offline Offline

Activity: 262
Merit: 250



View Profile
November 21, 2012, 11:30:03 AM
 #163

does the device comes with some kind of memory?
how many addresses can be stored on it?

slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 21, 2012, 12:55:37 PM
 #164

does the device comes with some kind of memory?
how many addresses can be stored on it?

There's very small flash memory on the device (256 kB for code and data), but device don't need to store addresses on the flash. It uses deterministic wallet approach instead, so even device with 256kB memory can handle unlimited amount of addresses.

caveden
Legendary
*
Offline Offline

Activity: 1106
Merit: 1004



View Profile
November 21, 2012, 02:57:57 PM
 #165

You're true for a hash of the full image, but fingerprint scanner actually save only a "path" of the minutiaes of the fingerprints. And using that work in a reliable way.

You mean that, for a given individual, you can always obtain the same unique "path"?

BTW to avoid physical coericion there is a  way, even not too difficult to implement: some times ago I've a phone with an encrypted area in which store password and pins. If you input the good password you decrypt the area, if you put a wrong one you obtain an error, but if you put a "special" one you go into a fake area with other data. Maybe is possible, for extra-paranoid implement a similar approach: one pin for real wallet, another one for another with only few BTC in it.
But again we are talking of extra-paranoid people here. IMHO slush design is more than adeguate.

That's plausible deniability, or more specifically, deniable encryption. Truecrypt does it.
I'd expect future dedicated device wallets to implement this, but as you note it's not a priority, at least not while most burglars remain ignorant about bitcoin. Smiley
ercolinux
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile WWW
November 21, 2012, 03:15:31 PM
 #166

You're true for a hash of the full image, but fingerprint scanner actually save only a "path" of the minutiaes of the fingerprints. And using that work in a reliable way.

You mean that, for a given individual, you can always obtain the same unique "path"?

I'm not actually expert on biometrics but I've done some research on it for work and producer of scanner told me so. Low cost scanner integrated in laptop works that way, so some bank door opener. They have a small database of path and check on it it there is corrispondence. Is fast and quite secure: while a full identify request a check on lots of points (15-16 actually), just few minutiaes are sufficient for the login pourpose (with 10 point you've over 1 milion of different pattern possible, with 8  65536).

Bitrated user: ercolinux.
caveden
Legendary
*
Offline Offline

Activity: 1106
Merit: 1004



View Profile
November 21, 2012, 03:27:01 PM
 #167

I'm not actually expert on biometrics but I've done some research on it for work and producer of scanner told me so. Low cost scanner integrated in laptop works that way, so some bank door opener. They have a small database of path and check on it it there is corrispondence.

Wait, but if you need a database of paths, it means the scan alone is not enough to produce the exact same path that was produced before for that individual. You're back to "comparing images".
Unless you mean they use a database of path hashes, in which case the scan would have to produce the exact same path before hashing. The scan would be just like a password, and could then be used as an encryption key, provided there's enough entropy in fingerprints - in case there isn't, it could be added to an actual password.
eldentyrell
Donator
Legendary
*
Offline Offline

Activity: 980
Merit: 1004


felonious vagrancy, personified


View Profile WWW
November 22, 2012, 06:03:45 AM
 #168

First preview of the design. Dimensions are 60x40x10 mm.



Hey cool!

But it looks like that's a female USB mini/micro-B connector, which means you need a cable in order to use it.  Is that true, or am I mistaken?  I kinda think most people would prefer a device that's cable-wise self-sufficient (like Yubikeys) so they don't have to go hunting around for the right type of cable.

One of the big advantages of a device like this with its own display and buttons is that it's safe (*) to connect it to machines you don't trust, which means people will probably want to use it when they aren't at their own home/office/whatever with the handy drawer-o-cables-and-adapters within arm's reach.

Neat stuff!

(*) I suppose a hostile computer could take the signed transaction and throw it away.  Not sure if the device keeps copies of stuff it signs.

The printing press heralded the end of the Dark Ages and made the Enlightenment possible, but it took another three centuries before any country managed to put freedom of the press beyond the reach of legislators.  So it may take a while before cryptocurrencies are free of the AML-NSA-KYC surveillance plague.
ercolinux
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile WWW
November 22, 2012, 07:31:37 AM
 #169



But it looks like that's a female USB mini/micro-B connector, which means you need a cable in order to use it.  Is that true, or am I mistaken?  I kinda think most people would prefer a device that's cable-wise self-sufficient (like Yubikeys) so they don't have to go hunting around for the right type of cable.

Due to the size of the device (is near twice the width of a standard USB key)  is better to have a cable: lot of notebooks/netbooks have usb ports in weird locations, not all desktop PC have a frontal working usb port, and anyway have the piglet (or how is called now) few inches from floor don't make easy to operate with it; and if the device can work with smartphones too they have only micro-usb. So having a micro-usb female is IMHO the right choice for most of the situations. And adding the lenght of the male usb connector will add other 20mm to the lenght, and with 80mm of overall length it will become as big as credit card.

Bitrated user: ercolinux.
luicon
Sr. Member
****
Offline Offline

Activity: 262
Merit: 250



View Profile
November 22, 2012, 08:19:27 AM
 #170

any idea about how expensive could be the final price? just an approximation

2112
Legendary
*
Offline Offline

Activity: 2128
Merit: 1073



View Profile
November 22, 2012, 09:11:29 AM
 #171

with the handy drawer-o-cables-and-adapters within arm's reach.
EU-landia has since 2009 a law requiring that a cellphone sold there needs to be rechargable through the micro-USB port.  So maybe not every household does have micro-USB to USB cable, but the situation is on the way to where it becomes ubiquitous.

Hopefully the less progressive lands (like the USA) will join this standard sometime this century. Or maybe not. But there's no need for a device targeted for a global acceptance to specifically pander to the backward.

Please comment, critique, criticize or ridicule BIP 2112: https://bitcointalk.org/index.php?topic=54382.0
Long-term mining prognosis: https://bitcointalk.org/index.php?topic=91101.0
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 22, 2012, 12:00:35 PM
 #172

We've just received first batch of displays. They're pretty tiny :-)



P.S. Casascius coin after wearing it in my wallet for one year ;-).

molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
November 22, 2012, 12:49:16 PM
 #173

We've just received first batch of displays. They're pretty tiny :-)



P.S. Casascius coin after wearing it in my wallet for one year ;-).

could you post a photo of the back of the coin in the casascius thread? (https://bitcointalk.org/index.php?topic=41892.0). People are interested how a coin will degrade, especially the firstbits of series 1.

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 22, 2012, 12:50:48 PM
 #174

could you post a photo of the back of the coin in the casascius thread? (https://bitcointalk.org/index.php?topic=41892.0). People are interested how a coin will degrade, especially the firstbits of series 1.

This coin is already redeemed. As far as I can say, wearing the coin in the wallet with other coins is not-so-good-idea :-(.

jim618
Legendary
*
Offline Offline

Activity: 1708
Merit: 1066



View Profile WWW
November 22, 2012, 02:55:47 PM
 #175

Those displays are tiny !

Really looking forward to these devices coming out.
Crypto made real.

MultiBit HD   Lightweight desktop client.                    Bitcoin Solutions Ltd   Bespoke software. Consultancy.
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
November 22, 2012, 03:09:54 PM
 #176

could you post a photo of the back of the coin in the casascius thread? (https://bitcointalk.org/index.php?topic=41892.0). People are interested how a coin will degrade, especially the firstbits of series 1.

This coin is already redeemed. As far as I can say, wearing the coin in the wallet with other coins is not-so-good-idea :-(.

yeah. series 2 should be better, though, because the firstbits is actually behind the hologram (little window in it)

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 22, 2012, 03:39:46 PM
 #177

First casing prototype has been printed! The model is optimized for CNC/metal, not for 3D printing/plastic, so some parts are a bit malformed (especially the eyelet and edges). However, now we see that the device can be even smaller than we expected and our designer is making another version which will be 50x35mm!


slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 22, 2012, 03:44:55 PM
 #178

Video of Reprap printing the prototype ;-)
http://www.youtube.com/watch?v=-uYW3ks0WwA

hazek
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003


View Profile
November 22, 2012, 04:42:15 PM
 #179

Video of Reprap printing the prototype ;-)
http://www.youtube.com/watch?v=-uYW3ks0WwA


My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)

If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
November 22, 2012, 05:53:30 PM
 #180

Donations are welcome at 1BitkeyP2nDd5oa647AjvBbbwST54W5Zmx :-). Coins will be used by me and stick to fund&build first prototypes.


Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 ... 265 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!