Bitcoin Forum
December 11, 2024, 06:48:19 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 [86] 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 ... 265 »
  Print  
Author Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet  (Read 966224 times)
klokan
Full Member
***
Offline Offline

Activity: 120
Merit: 100


View Profile
July 28, 2014, 10:05:11 PM
 #1701

Hm... What if someone get holds of your Trezor without your knowledge, installs malicious firmware that saves your passphrase, returns it to you, then steals it again after you have used it, and downloads the pasphrase?  Or whaterver?

The storage area is erased when you upload unofficial firmware.

So the easiest way to get to the seed is to load satoshilabs signed seed-recovery-firmware, right? ;-)
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 28, 2014, 10:16:34 PM
 #1702

Opening a Trezor will break the casing, as far as I know. Even if you glue it back together it would look broken (and thus suspicious).
Criminals can replace photos on passports and forge dollar bills.  Surely can re-seal a plastic case so that it looks pristine.
They can also flash an  eprom or replace a rom
So I prefer to be able to update my firmware, as I have a brain and will not click on yes or not read the addresses on screen.
Good for you, but the "net fishing" class of criminals will be quite happy if even if only 5 of 100 people who got their Trezors with malicious firmware click "yes" and then enter their PIN.   They will not target you; they will aim for your grandmother and your 13-year-old cousin.

Quote
If you can steal a Trezor, mod it, send it to your target, and restole it, you can also decide to torture him if his trezor is unbrokable, so in this case, maybe it's better to be tricked by Trezor  Grin
The fake Trezor (or the malicious firmware, signed or unsigned)  can be programmed to select from a small set of private keys that were pre-generated by the thief, instead of random ones.  Therefore, the criminal does not need to steal the fake Trezor back.  He does not even have to know the victims or in which country they reside.  He has only to place the fake/reprogrammed Trezors in the market stream somehow, and then watch the blockchain until some of those precomputed addresses receive enough bitcoins.

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
July 28, 2014, 10:31:00 PM
 #1703

Good for you, but the "net fishing" class of criminals will be quite happy if even if only 5 of 100 people who got their Trezors with malicious firmware click "yes" and then enter their PIN.   They will not target you; they will aim for your grandmother and your 13-year-old cousin.

Actually it is still many degrees easier to target to tens of thousands people who simply don't care and use some webwallet. Attacking users who don't use any protection simply has better effort/reward ratio.

To perform advanced attacks like you described, you need to:
1) Get signed malicious software (highly unlikely considering security standards which we've chosen, because we're aware of this risk).
2) Distribute such software to end users and convince users to update.
3) Infect their computers to actually use that malicious firmware

In oposite, to hack into ANY OTHER wallet, you need
1) keylogger

Actually much likely hack to Trezor owner is to kidnap his wife. But if *this* is the only concern, then Trezor moves bitcoin security standard to completely another level considering current (pre-Trezor) epoch.

JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 28, 2014, 10:41:26 PM
 #1704

And with fake Trezor in the equation, you can't solve the issue by hardware changes (but maybe some checks process can do the job)
Hey, it was just free advice.  Cheesy

But: the point is that relatively few criminals can physically forge or modify a Trezor, whereas any teenager could buy a real Trezor and preload it with malicious unsigned firmware that he got from his hacker buddy.  So, even if the second variant has a low probability of success (owners who ignore the warning), it may be the bigger risk in absolute numbers.

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
cor
Full Member
***
Offline Offline

Activity: 121
Merit: 100



View Profile WWW
July 29, 2014, 12:51:50 AM
 #1705

And with fake Trezor in the equation, you can't solve the issue by hardware changes (but maybe some checks process can do the job)
Hey, it was just free advice.  Cheesy

But: the point is that relatively few criminals can physically forge or modify a Trezor, whereas any teenager could buy a real Trezor and preload it with malicious unsigned firmware that he got from his hacker buddy.  So, even if the second variant has a low probability of success (owners who ignore the warning), it may be the bigger risk in absolute numbers.



There was some Kaspersky Lab research - they've recorded over 8.000.000 attempts of a wallet-stealing malware in 2013.
Important thing to consider in the final numbers is that Kaspersky only has around 3-5% of the antivirus software  marketshare.
Count that ratio in and what you get may be the bigger risk in absolute numbers.

Source:
https://securelist.com/analysis/kaspersky-security-bulletin/59414/financial-cyber-threats-in-2013-part-2-malware/#24

JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 29, 2014, 01:30:42 AM
 #1706

There was some Kaspersky Lab research - they've recorded over 8.000.000 attempts of a wallet-stealing malware in 2013.
Important thing to consider in the final numbers is that Kaspersky only has around 3-5% of the antivirus software  marketshare.
Count that ratio in and what you get may be the bigger risk in absolute numbers.

Source:
https://securelist.com/analysis/kaspersky-security-bulletin/59414/financial-cyber-threats-in-2013-part-2-malware/#24
Interesting number!

I could not find the total number of KL users (to translate that into percentage of hosts that are infected),  do you have this number?

As I said twice before, keeping your keys in a Trezor surely must be safer than keeping them in your PC or smartphone (or in an unencrypted text file in your Dropbox folder).

And "what I tell you three times is true".  Smiley

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
kkurtmann
Sr. Member
****
Offline Offline

Activity: 475
Merit: 250



View Profile WWW
July 29, 2014, 06:39:29 AM
 #1707

back-end for myTREZOR, this bits of proof apparently is now owned by one of the worlds worst hardware manufacturers cointerra?

https://www.buytrezor.com?a=55c37b866c11   well sir, I like it!
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 29, 2014, 06:51:15 AM
 #1708

back-end for myTREZOR, this bits of proof apparently is now owned by one of the worlds worst hardware manufacturers cointerra?
You mean Cointerra is the manufacturer of the Trezor electronics?

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
kkurtmann
Sr. Member
****
Offline Offline

Activity: 475
Merit: 250



View Profile WWW
July 29, 2014, 06:56:30 AM
 #1709

good god lets hope not.  no that is not what I said at all. read it again

https://www.buytrezor.com?a=55c37b866c11   well sir, I like it!
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 29, 2014, 07:05:00 AM
 #1710

good god lets hope not.  no that is not what I said at all. read it again
Sorry, I did not understand.  You meant myTrezor the supporting app/website? What "proof"?

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
Kuma
Member
**
Offline Offline

Activity: 107
Merit: 10



View Profile
July 29, 2014, 07:14:32 AM
 #1711

Sorry, I did not understand.  You meant myTrezor the supporting app/website? What "proof"?

"Bits of Proof " is company who made the myTrezor backend (the web wallet).
AussieHash
Hero Member
*****
Offline Offline

Activity: 692
Merit: 500



View Profile
July 29, 2014, 07:15:40 AM
 #1712

http://www.coindesk.com/cointerra-acquires-bitcoin-software-developer-bits-proof/
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
July 29, 2014, 07:20:08 AM
 #1713

Sorry, I did not understand.  You meant myTrezor the supporting app/website? What "proof"?
"Bits of Proof " is company who made the myTrezor backend (the web wallet).
Thanks!

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
bitkilo
Legendary
*
Offline Offline

Activity: 1638
Merit: 1010


https://www.bitcoin.com/


View Profile WWW
July 29, 2014, 09:31:00 AM
 #1714

Good to see this is the news again, for someone who's not so tech-savy like myself i cant wait to get 1. Can anyone tell me the release date for these?

stick
Sr. Member
****
Offline Offline

Activity: 441
Merit: 268



View Profile
July 29, 2014, 09:35:41 AM
 #1715

"Bits of Proof " is company who made the myTrezor backend (the web wallet).

That's not true. myTREZOR webwallet was done by us. The thing done by BoP was the backend which myTREZOR connects to and asks for transaction history.

cor
Full Member
***
Offline Offline

Activity: 121
Merit: 100



View Profile WWW
July 29, 2014, 10:20:31 AM
 #1716

Good to see this is the news again, for someone who's not so tech-savy like myself i cant wait to get 1. Can anyone tell me the release date for these?

eshop should be ready by the end of this week

lemonte
Hero Member
*****
Offline Offline

Activity: 624
Merit: 502


View Profile
July 29, 2014, 10:52:19 AM
 #1717

Good to see this is the news again, for someone who's not so tech-savy like myself i cant wait to get 1. Can anyone tell me the release date for these?

eshop should be ready by the end of this week

Is there going to be an affiliate system for anyone wanting to try and resell?
Thanks

cor
Full Member
***
Offline Offline

Activity: 121
Merit: 100



View Profile WWW
July 29, 2014, 11:18:55 AM
 #1718

back-end for myTREZOR, this bits of proof apparently is now owned by one of the worlds worst hardware manufacturers cointerra?
You mean Cointerra is the manufacturer of the Trezor electronics?

We have no association with Cointerra.

TREZOR as well as TREZOR Web Wallet and its backend is our product (the backend delivered to us upon a contract of works with Bits of Proof)

myTREZOR Web Wallet is using BOP Bitcoin Server
https://bitsofproof.com/?page_id=826


The coindesk post might sound a little misleading but that happens in communication.
I hope they will at least correct the link to myTREZOR Smiley


cor
Full Member
***
Offline Offline

Activity: 121
Merit: 100



View Profile WWW
July 29, 2014, 11:20:08 AM
 #1719

Good to see this is the news again, for someone who's not so tech-savy like myself i cant wait to get 1. Can anyone tell me the release date for these?

eshop should be ready by the end of this week

Is there going to be an affiliate system for anyone wanting to try and resell?
Thanks

yes
subscribe to our newsletter please and we'll let you know

Mitchell
Staff
Legendary
*
Offline Offline

Activity: 4130
Merit: 2337


Verified awesomeness ✔


View Profile WWW
July 29, 2014, 11:24:56 AM
 #1720

I am going to ask this question, before more people do (and thus saving you the trouble):
Any idea what the price will be? I don't need a specific number, a range would be sufficient.

I know that this has been asked many times, over and over again, but you should have an estimate if you are going to open a webshop that sells them Tongue

.
Duelbits
            ▄████▄▄
          ▄█████████▄
        ▄█████████████▄
     ▄██████████████████▄
   ▄████▄▄▄█████████▄▄▄███▄
 ▄████▐▀▄▄▀▌████▐▀▄▄▀▌██

 ██████▀▀▀▀███████▀▀▀▀█████

▐████████████■▄▄▄■██████████▀
▐██████████████████████████▀
██████████████████████████▀
▀███████████████████████▀
  ▀███████████████████▀
    ▀███████████████▀
.
         ▄ ▄▄▀▀▀▀▄▄
         ▄▀▀▄      █
         █   ▀▄     █
       ▄█▄     ▀▄   █
      ▄▀ ▀▄      ▀█▀
    ▄▀     ▀█▄▄▄▀▀ ▀
  ▄▀  ▄▀  ▄▀

Live Games

   ▄▄▀▀▀▀▀▀▀▄▄
 ▄▀ ▄▄▀▀▀▀▀▄▄ ▀▄
▄▀ █ ▄  █  ▄ █ ▀▄
█ █   ▀   ▀   █ █  ▄▄▄
█ ▀▀▀▀▀▀▀▀▀▀▀▀▀ █ █   █
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█  █▄█
█ ▀▀█  ▀▀█  ▀▀█ █  █▄█

Slots
.
        ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄
        █         ▄▄  █
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄       █
█  ▄▄         █       █
█             █       █
█   ▄▀▀▄▀▀▄   █       █
█   ▀▄   ▄▀   █       █

Blackjack
|█▀▀▀▀▀█▄▄▄
       ▀████▄▄
         ██████▄
▄▄▄▄▄▄▄▄█▀    ▀▀█
████████▄        █
█████████▄        █
██████████▄     ▄██
█████████▀▀▀█▄▄████
▀▀███▀▀       ████
   █          ███
   █          █▀
▄█████▄▄▄ ▄▄▀▀
███████▀▀▀
.
                 NEW!                  
SPORTS BETTING 
|||
[ Đ ][ Ł ]
AVAILABLE NOW

Advertisements are not endorsed by me.
Pages: « 1 ... 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 [86] 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 ... 265 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!