Bitcoin Forum
May 04, 2024, 03:16:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 [109] 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 ... 265 »
  Print  
Author Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet  (Read 965790 times)
Newscastix
Sr. Member
****
Offline Offline

Activity: 349
Merit: 250


View Profile
August 13, 2014, 10:07:12 AM
 #2161

I think I found a bug!

I redeemed one of my cold storage addresses and sent 1 output to a "3xxxxx" multisig address and the remainder to my TREZOR. Now the address of the Trezor was obviously not a multisig address. BUT! The trezor now shows it got the coins sent to a multisig address.

This is the address that is now shown in my TREZOR: 35cAcatwpoL5gbKF2Raahuh1Ts62eh3n16  (have no idea where it got it from!)
This is the transaction: https://blockchain.info/tx/257c8f37b48179668a07d1b0a25e864c3c28ea0b7dccdd96d80bd5b16ddb6cc5
The Trezor address is the 4.9999 output.



This seems to be the issue reported here:

http://www.reddit.com/r/TREZOR/comments/2dcpx4/first_mytrezor_bug/

1714835775
Hero Member
*
Offline Offline

Posts: 1714835775

View Profile Personal Message (Offline)

Ignore
1714835775
Reply with quote  #2

1714835775
Report to moderator
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714835775
Hero Member
*
Offline Offline

Posts: 1714835775

View Profile Personal Message (Offline)

Ignore
1714835775
Reply with quote  #2

1714835775
Report to moderator
instagibbs
Member
**
Offline Offline

Activity: 114
Merit: 12


View Profile
August 13, 2014, 11:58:57 AM
 #2162

I think I found a bug!

I redeemed one of my cold storage addresses and sent 1 output to a "3xxxxx" multisig address and the remainder to my TREZOR. Now the address of the Trezor was obviously not a multisig address. BUT! The trezor now shows it got the coins sent to a multisig address.

This is the address that is now shown in my TREZOR: 35cAcatwpoL5gbKF2Raahuh1Ts62eh3n16  (have no idea where it got it from!)
This is the transaction: https://blockchain.info/tx/257c8f37b48179668a07d1b0a25e864c3c28ea0b7dccdd96d80bd5b16ddb6cc5
The Trezor address is the 4.9999 output.



I had the same issue.

Just be careful and don't use "show used" to send to the same address again!
Perlover
Full Member
***
Offline Offline

Activity: 162
Merit: 109


View Profile
August 13, 2014, 12:39:21 PM
Last edit: August 13, 2014, 07:17:14 PM by Perlover
 #2163

I think the mytrezor.com site has the future vulnerability

If i right understood mytrezor.com site uses my xpub* keys for generating new addresses for receiving and checking balance (other way could be as user computer generates new addresses inside by javascript and only sends new addresses to mytrezor.com for balance checking but it's very difficult scheme). If hacker will have an access to victim computer (where Trezor to be attached) he can (by trojans, middle man attack with SSL certificate changing and etc):

1) to catch xpub* keys of users and will know all addresses (current and all new generated ones) of user, can know all balances in all addresses

2) He will be able to change address for receiving to his fishing addresses (right in browser instead mytrezor's generated addresses)

If it possible here may be some workarounds:

1) I don't know how resolve it. xpub keys should be used in computer in anyway - there will be mytrezor.com site or Electrum or Armory, for example. If computer will be infected hacker will know xpub key in anyway.

2) This vulnerability can fix by checking new generated addresses in computer with showing new address in Trezor screen. For example: we ask to mytrezor.com generate new address for receiving. Site sends new address (path of BIP32) to the Trezor by HID interface, the Trezor knows private seed key, knows path of new generated address it generates same address too and shows it in screen. User checks both addresses and if ok - he uses new address for money receiving. It's ideal solution as i think. Because fishing address will differ completely (very difficult to make quickly even 1-3 prefix or sufix) i think will be enough to check 3-4 letters before (prefix) and 3-4 after (sufix) in addresses.

Now as temporaly workaround for #2 may be as: we have Android phone, install there BTCRceive program from Google market, install there xpub key from one account ( BTCReceive now supports only one xpub key from one account Sad ) and do checking new addresses with Trezor addresses. Both systems have BIP32 wallets and new addresses will equal. I don't know fine program for common OSes with full support of BIP32. So i think it's single workaroud solution now.

P.S. If user uses not infected computer but connected through public network wifi or through hecked router he can be victim by using "middle man" attack. Attacker will decrypt traffic, change receiving address of bitcoin and sent encrypted traffic back to user. Yes, here will be other certificate signed by other secrtificate center for site mytrezor.com. But it can happens without any warnings if browser have certificate of such center in storage. It often happens in airports for example (airport of London for example). So it's not problem for implementation
BurtW
Legendary
*
Offline Offline

Activity: 2646
Merit: 1131

All paid signature campaigns should be banned.


View Profile WWW
August 13, 2014, 01:01:28 PM
 #2164

I was thinking the Trezor just needed to say "key is OK" or "key is BAD" but if the malware knows the xpub it can send the correct next public key to the Trezor to get it to say OK but display the incorrect pub key on the computer so the Trezor would have to show the actual pub key and you would have to compare the two keys, right?

I could see a "verify address" button next to each address on the screen.  If I press that button the displayed address is sent to the Trezor for verification and if the same address appears on the Trezor screen then the address is a good one.

Our family was terrorized by Homeland Security.  Read all about it here:  http://www.jmwagner.com/ and http://www.burtw.com/  Any donations to help us recover from the $300,000 in legal fees and forced donations to the Federal Asset Forfeiture slush fund are greatly appreciated!
Perlover
Full Member
***
Offline Offline

Activity: 162
Merit: 109


View Profile
August 13, 2014, 01:08:02 PM
Last edit: August 13, 2014, 01:20:24 PM by Perlover
 #2165

I think malware doesn't need to know xpub for "Key OK" or "Key is not OK"
Malware can simple modify DOM structure of page and change receive address. MyTrezor.com will not know that address was changed, the Trezor will write "Key is OK" because got right address from MyTrezor and user will be deceived...
I think the Trezor should show address for sent path to him. And user should check up it with gotten address from computer.

And i think this should be mandatory procedure (not from button click "Check address") bacause many people will ignore it but after will write in forums that they lose money from the Trezor...
TwinWinNerD
Legendary
*
Offline Offline

Activity: 1680
Merit: 1001


CEO Bitpanda.com


View Profile WWW
August 13, 2014, 01:34:52 PM
 #2166

I think I found a bug!

I redeemed one of my cold storage addresses and sent 1 output to a "3xxxxx" multisig address and the remainder to my TREZOR. Now the address of the Trezor was obviously not a multisig address. BUT! The trezor now shows it got the coins sent to a multisig address.

This is the address that is now shown in my TREZOR: 35cAcatwpoL5gbKF2Raahuh1Ts62eh3n16  (have no idea where it got it from!)
This is the transaction: https://blockchain.info/tx/257c8f37b48179668a07d1b0a25e864c3c28ea0b7dccdd96d80bd5b16ddb6cc5
The Trezor address is the 4.9999 output.



I had the same issue.

Just be careful and don't use "show used" to send to the same address again!

ok, so there must be a bug in the software then, good to know that I did nothing wrong. for once Cheesy

gweedo
Legendary
*
Offline Offline

Activity: 1498
Merit: 1000


View Profile
August 13, 2014, 06:23:12 PM
 #2167

I been seeing this for a couple of days.

TwinWinNerD
Legendary
*
Offline Offline

Activity: 1680
Merit: 1001


CEO Bitpanda.com


View Profile WWW
August 13, 2014, 07:04:28 PM
 #2168

I been seeing this for a couple of days.



Click forget device, then disconnect and then reconnect.

keithers
Legendary
*
Offline Offline

Activity: 1456
Merit: 1001


This is the land of wolves now & you're not a wolf


View Profile
August 13, 2014, 07:33:40 PM
 #2169

I been seeing this for a couple of days.



uh oh...that is not good.   I haven't had time to open it up yet to test it out...
stick
Sr. Member
****
Offline Offline

Activity: 441
Merit: 266



View Profile
August 13, 2014, 07:58:43 PM
 #2170

I been seeing this for a couple of days.

Reaching our support is usually better way how to deal with this kind of stuff.

MakeBelieve
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500


View Profile
August 13, 2014, 08:06:27 PM
 #2171

Any planned promo's?  Roll Eyes I'm thinking of getting one and I know it's worth the price but struggling a little bit giving me the final push...how do these things get updated if a flaw or something has been found?

On a mission to make Bitcointalk.org Marketplace a safer place to Buy/Sell/Trade
Perlover
Full Member
***
Offline Offline

Activity: 162
Merit: 109


View Profile
August 13, 2014, 08:09:07 PM
 #2172

I wish there was an alternative way to recover the Bitcoin in case of hardware failure or other abnormality. Instead of having to wait for another Trezor to come in.
You can install "Wallet32" application to Android device.
This fully compatible with seeds of Trezor. And this appliacation will allow to move your Bitcoins to other addresses without the Trezor ;-)
Anon136
Legendary
*
Offline Offline

Activity: 1722
Merit: 1217



View Profile
August 13, 2014, 08:25:01 PM
 #2173

Just got my trezor in the mail. Plugged it in. And its not working. Sad

Rep Thread: https://bitcointalk.org/index.php?topic=381041
If one can not confer upon another a right which he does not himself first possess, by what means does the state derive the right to engage in behaviors from which the public is prohibited?
klokan
Full Member
***
Offline Offline

Activity: 120
Merit: 100


View Profile
August 13, 2014, 08:30:11 PM
 #2174

Just got my trezor in the mail. Plugged it in. And its not working. Sad

Try another USB cable. If that does not help, write to support.
MakeBelieve
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500


View Profile
August 13, 2014, 08:45:10 PM
 #2175

Just got my trezor in the mail. Plugged it in. And its not working. Sad

What usb are you using is it a usb3? what operating system are you using?

On a mission to make Bitcointalk.org Marketplace a safer place to Buy/Sell/Trade
Anon136
Legendary
*
Offline Offline

Activity: 1722
Merit: 1217



View Profile
August 13, 2014, 08:51:29 PM
 #2176

Just got my trezor in the mail. Plugged it in. And its not working. Sad

What usb are you using is it a usb3? what operating system are you using?

Tried USB2 and USB3. Firefox on Ubuntu.

Rep Thread: https://bitcointalk.org/index.php?topic=381041
If one can not confer upon another a right which he does not himself first possess, by what means does the state derive the right to engage in behaviors from which the public is prohibited?
BurtW
Legendary
*
Offline Offline

Activity: 2646
Merit: 1131

All paid signature campaigns should be banned.


View Profile WWW
August 13, 2014, 09:00:48 PM
 #2177

Just got my trezor in the mail. Plugged it in. And its not working. Sad

What usb are you using is it a usb3? what operating system are you using?

Tried USB2 and USB3. Firefox on Ubuntu.
Did it light up at all?

Our family was terrorized by Homeland Security.  Read all about it here:  http://www.jmwagner.com/ and http://www.burtw.com/  Any donations to help us recover from the $300,000 in legal fees and forced donations to the Federal Asset Forfeiture slush fund are greatly appreciated!
TwinWinNerD
Legendary
*
Offline Offline

Activity: 1680
Merit: 1001


CEO Bitpanda.com


View Profile WWW
August 13, 2014, 09:01:45 PM
 #2178

Just got my trezor in the mail. Plugged it in. And its not working. Sad

What usb are you using is it a usb3? what operating system are you using?

Tried USB2 and USB3. Firefox on Ubuntu.

I needed to buy an USB hub with power cable. Edit, also the blue short cable is broken!

gweedo
Legendary
*
Offline Offline

Activity: 1498
Merit: 1000


View Profile
August 13, 2014, 09:03:08 PM
 #2179

I been seeing this for a couple of days.

Reaching our support is usually better way how to deal with this kind of stuff.

Just did Smiley

I been seeing this for a couple of days.


Click forget device, then disconnect and then reconnect.

Did this and it didn't work.
chrisrico
Hero Member
*****
Offline Offline

Activity: 496
Merit: 500


View Profile
August 13, 2014, 10:06:40 PM
 #2180

concerning Wallet32

Can I export the private key of one account only and use that on wallet-32 compatible with trezor.

Just like exporting only parts of the trezor DH-tree

You can't export any private information from TREZOR.

It would be nice in a sort of expert mode, to be able to export an account's extended private key, in order to import into other BIP32 wallet software. Perhaps when done, it would mark the account as such on the Trezor, so you didn't accidentally use it. Either way, if the device containing that extended private key is lost, it can always be recovered using the Trezor.
Pages: « 1 ... 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 [109] 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 ... 265 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!