JorgeStolfi
|
|
October 04, 2014, 06:31:33 AM |
|
for what it's worth as an independant audit, the bootloader functionally does what it's supposed to do and doesn't contain a backdoor. (+ proof of RE) The bootloader is written in Python? I'm a bit surprised about that. I would guess that the code above is a manual translation into python-like language of some part of the executable binary extracted from the bootloader.
|
Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
|
|
|
instagibbs
Member
Offline
Activity: 114
Merit: 12
|
|
October 04, 2014, 02:29:29 PM |
|
I would guess that the code above is a manual translation into python-like language of some part of the executable binary extracted from the bootloader.
Exactly. And coming from a "competitor" is a pretty good sign.
|
|
|
|
devthedev
Legendary
Offline
Activity: 1050
Merit: 1004
|
|
October 04, 2014, 03:15:00 PM |
|
I would guess that the code above is a manual translation into python-like language of some part of the executable binary extracted from the bootloader.
Exactly. And coming from a "competitor" is a pretty good sign. We're all early adopters, teamwork is good! (;
|
|
|
|
GreatBug
|
|
October 04, 2014, 03:38:37 PM |
|
I would guess that the code above is a manual translation into python-like language of some part of the executable binary extracted from the bootloader.
How do you come to this conclusion? Its just python code that verifies signatures on a firmware image. nothing more.
|
|
|
|
JorgeStolfi
|
|
October 04, 2014, 04:01:13 PM |
|
I would guess that the code above is a manual translation into python-like language of some part of the executable binary extracted from the bootloader.
How do you come to this conclusion? Its just python code that verifies signatures on a firmware image. nothing more. The poster offered that pseudo-code as evidence that he did reverse-engineer the bootloader. That is all. Anyone who can get the binary out of the Trezor can check whether that part of the binary corresponds to that pseudo-code. That pseudo-code alone does not prove that the poster reverse-engineered the entire binary code (but if that pseudo-code is the output of a disassembler, surely he did). It does not prove that the bootloader has no backdoor (one must check the whole binary for that). It does not prove that the official firmware is not malicious. I
|
Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
|
|
|
Perlover
|
|
October 04, 2014, 10:12:48 PM |
|
My browser (Firefox) shows to me warning at myTrezor.com It warnings that certificate doesn't have a mytrezor.com in domain list of certificate... Certificate issued at 29.09.2014 by GlobalSign nv-sa and only for domains: Not Critical DNS Name: ssl2000.cloudflare.com DNS Name: cloudflare.com DNS Name: *.cloudflare.com
Slush, please fix up this
|
|
|
|
Bitcoinreminder.com
|
|
October 04, 2014, 10:15:16 PM |
|
My browser (Firefox) shows to me warning at myTrezor.com It warnings that certificate doesn't have a mytrezor.com in domain list of certificate... Certificate issued at 29.09.2014 by GlobalSign nv-sa and only for domains: Not Critical DNS Name: ssl2000.cloudflare.com DNS Name: cloudflare.com DNS Name: *.cloudflare.com
Slush, please fix up this
I dont get this warning.. Seems ok from here..
|
|
|
|
Perlover
|
|
October 04, 2014, 10:31:22 PM |
|
Strange... Now i don't see warning and there is other certificate...
|
|
|
|
stick
|
|
October 05, 2014, 09:19:07 AM |
|
Strange... Now i don't see warning and there is other certificate...
Probably some Cloudflare glitch.
|
|
|
|
Perlover
|
|
October 05, 2014, 07:50:24 PM |
|
Strange... Now i don't see warning and there is other certificate...
Probably some Cloudflare glitch. I got this waning again Here fingerprint of this certificate: SHA1: AE:03:2A:4B:3E:53:39:65:CB:02:67:56:D7:70:3B:69:20:6F:79:D4 Begins on: 29.09.2014 The Firefox doesn't allow to me get this certificate and to add exception - "Permanent add" is disabled. So i cannot open site if i got this certificate. In this moments i use BTCReceive or myTrezor Android's application for generating of addresses. This is very bothering, given that must agree with the certificate for the site, which generates the address of my bitcoin Trezor. EDITED: After 5 minutes i did refresh and now there normal certificate: SHA1 93:AC:E0:4D:15:1C:D6:40:5F:8E:9A:E3:C8:A0:9B:60:CB:DD:08:29
|
|
|
|
keithers
Legendary
Offline
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
|
|
October 05, 2014, 11:19:25 PM Last edit: October 05, 2014, 11:33:43 PM by keithers |
|
my balances are not currently showing on mytrezor.com. It is stuck on the loading transactions screen...is there something wrong with the site? This is the first time this has happened to me since I have started using trezor...
Is anyone else experiencing this as well?
I tried using "forget device", and then replugging it in. The web wallet recognizes the trezor, but won't load any of the transactions.... Kind of worries me...
|
|
|
|
chriswilmer
Legendary
Offline
Activity: 1008
Merit: 1000
|
|
October 05, 2014, 11:25:45 PM |
|
my balances are not currently showing on mytrezor.com. It is stuck on the loading transactions screen...is there something wrong with the site? This is the first time this has happened to me since I have started using trezor...
I'm having the same error!
|
|
|
|
chriswilmer
Legendary
Offline
Activity: 1008
Merit: 1000
|
|
October 05, 2014, 11:37:22 PM |
|
Sorry, I haven't been keeping up with the latest Trezor developments... how many wallets support Trezor now? I heard something about Electrum but that it was still in development....
|
|
|
|
keithers
Legendary
Offline
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
|
|
October 05, 2014, 11:38:07 PM |
|
my balances are not currently showing on mytrezor.com. It is stuck on the loading transactions screen...is there something wrong with the site? This is the first time this has happened to me since I have started using trezor...
I'm having the same error! I wonder if this is affecting all users then? I thought this was one of the main features of using the trezor, is that you would have full control over the coins at all time. I didn't think we were relying on a third party to be able to access our coins...
|
|
|
|
keithers
Legendary
Offline
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
|
|
October 05, 2014, 11:49:50 PM |
|
I have now tried mytrezor on two different laptops, with two different browers (internet explorer, and chrome), both laptops recognize the trezor, but neither will pull up any of my transactions or coins....
hoping someone responds in this thread soon...
|
|
|
|
chriswilmer
Legendary
Offline
Activity: 1008
Merit: 1000
|
|
October 05, 2014, 11:55:09 PM |
|
my balances are not currently showing on mytrezor.com. It is stuck on the loading transactions screen...is there something wrong with the site? This is the first time this has happened to me since I have started using trezor...
I'm having the same error! I wonder if this is affecting all users then? I thought this was one of the main features of using the trezor, is that you would have full control over the coins at all time. I didn't think we were relying on a third party to be able to access our coins... In their defense... that's still technically true. You don't need the mytrezor website to access your coins... in principle. In practice it's one of the only wallets that has implemented Trezor support (although see my note above indicating my ignorance on the current situation). So, yeah, because the website isn't working, I'm looking for another wallet to access the coins on my trezor.
|
|
|
|
chrisrico
|
|
October 06, 2014, 01:02:09 AM |
|
how many wallets support Trezor now?
It's not so much how many wallets does Trezor support, but how many wallets support Trezor. To the best of my knowledge, only MyTrezor still unless you can follow these instructions (under Development Version) for Electrum.
|
|
|
|
keithers
Legendary
Offline
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
|
|
October 06, 2014, 01:02:31 AM |
|
my balances are not currently showing on mytrezor.com. It is stuck on the loading transactions screen...is there something wrong with the site? This is the first time this has happened to me since I have started using trezor...
I'm having the same error! I wonder if this is affecting all users then? I thought this was one of the main features of using the trezor, is that you would have full control over the coins at all time. I didn't think we were relying on a third party to be able to access our coins... In their defense... that's still technically true. You don't need the mytrezor website to access your coins... in principle. In practice it's one of the only wallets that has implemented Trezor support (although see my note above indicating my ignorance on the current situation). So, yeah, because the website isn't working, I'm looking for another wallet to access the coins on my trezor. I don't really want to go loading the recovery into a different wallet and doing all of that... it would just be nice to hear someone from trezor say "yeah we know there is an issue, and we are working on it" or let us know what is going on... silence stinks when you are trying to figure out what is going on
|
|
|
|
TwinWinNerD
Legendary
Offline
Activity: 1680
Merit: 1001
CEO Bitpanda.com
|
|
October 06, 2014, 01:47:11 AM |
|
Looks like their API is down. (Bits of proof?)
This sucks big time. I have locked the seed in the bank, how to recover this? Major inconvenience....
|
|
|
|
keithers
Legendary
Offline
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
|
|
October 06, 2014, 02:09:32 AM |
|
Looks like their API is down. (Bits of proof?)
This sucks big time. I have locked the seed in the bank, how to recover this? Major inconvenience....
This is the first time that I have seen this occur since I started using trezor...is this the same for you twinwinnerd? Part of the reason why I chose trezor to hold some of my BTC is because I didn't think I had to worry about reliability of a third party
|
|
|
|
|