Bitcoin Forum
May 03, 2024, 07:19:57 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 [18] 19 20 »  All
  Print  
Author Topic: [NOW AVAILABLE] BTChip / Ledger HW1 : Bitcoin Hardware Wallet in a USB smartcard  (Read 62446 times)
torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
October 31, 2015, 09:27:43 PM
 #341

When signing a message I'm asked to use a different computer if the current one is compromised.

Let's assume the computer is compromised.
What are the possibilities of a hacker?
Could he change the text and trick me in signing a different message?

Are there other things a hacker could do?


Actually there is no way I can know with certainty if my computer is compromised.
Thus best practice would be to use an air gaped computer to get the 2FA pin, or is this overkill?

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
1714763997
Hero Member
*
Offline Offline

Posts: 1714763997

View Profile Personal Message (Offline)

Ignore
1714763997
Reply with quote  #2

1714763997
Report to moderator
1714763997
Hero Member
*
Offline Offline

Posts: 1714763997

View Profile Personal Message (Offline)

Ignore
1714763997
Reply with quote  #2

1714763997
Report to moderator
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714763997
Hero Member
*
Offline Offline

Posts: 1714763997

View Profile Personal Message (Offline)

Ignore
1714763997
Reply with quote  #2

1714763997
Report to moderator
1714763997
Hero Member
*
Offline Offline

Posts: 1714763997

View Profile Personal Message (Offline)

Ignore
1714763997
Reply with quote  #2

1714763997
Report to moderator
1714763997
Hero Member
*
Offline Offline

Posts: 1714763997

View Profile Personal Message (Offline)

Ignore
1714763997
Reply with quote  #2

1714763997
Report to moderator
btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
October 31, 2015, 09:55:16 PM
 #342

Could he change the text and trick me in signing a different message?

yes, that's the idea. Nothing else but that's bad enough.

Actually there is no way I can know with certainty if my computer is compromised.
Thus best practice would be to use an air gaped computer to get the 2FA pin, or is this overkill?

if you're signing something critical, that's the best option. Note that you can use anything that recognizes a HID keyboard - it could be a phone or a smart TV or a Windows PC with no session open for example.

The next firmware version will provide an option to verify the message content on the paired smartphone when signing.

torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 02, 2015, 01:41:49 PM
Last edit: November 02, 2015, 02:44:18 PM by torusJKL
 #343

if you're signing something critical, that's the best option. Note that you can use anything that recognizes a HID keyboard - it could be a phone or a smart TV or a Windows PC with no session open for example.

Would it make sense to have this functionality in the Ledger Starter distribution?

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
November 02, 2015, 07:15:02 PM
 #344

Would it make sense to have this functionality in the Ledger Starter distribution?

I think it does it by default - you can boot starter, plug the device when it's supposed to write something and it'll just write it where the focus is currently set.

torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 04, 2015, 06:07:25 AM
 #345

A question regarding the upgrade process.
I'm asked to enter the 32 letters of my security card.

As any computer could be compromised I have to assume that this input is intercepted and thus I loose another layer of security.
The pin code and the security card would be known to the attacker.

Is there a better way to upgrade?
Could the Ledger Starter be enhanced with the possibility to upgrade?

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
November 04, 2015, 09:47:10 AM
 #346

Is there a better way to upgrade?
Could the Ledger Starter be enhanced with the possibility to upgrade?

I think it can already do that

torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 04, 2015, 10:13:00 AM
 #347

I think it can already do that

Could you tell me how?
I did not find any menu item to initiate the upgrade.
Thanks.

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 05, 2015, 08:03:54 AM
Last edit: November 05, 2015, 08:25:09 AM by torusJKL
 #348

A short list of features I would like to see in the Ledger Starter distro:

- update the Nano/HW.1 OS
- generate the security card (like on https://www.ledgerwallet.com/wallet/keycard)
- reprogram the Nano/HW.1 with a different security card (so that I could change the security card myself every x days)

Would this be possible?

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
November 05, 2015, 02:16:17 PM
 #349

definitely doable, I'll push that and the other question to the team dealing with Starter

Morveus
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
November 05, 2015, 02:39:40 PM
 #350

A short list of features I would like to see in the Ledger Starter distro:

- update the Nano/HW.1 OS
- generate the security card (like on https://www.ledgerwallet.com/wallet/keycard)
- reprogram the Nano/HW.1 with a different security card (so that I could change the security card myself every x days)

Would this be possible?

Hi!

The Starter can already be upgraded very simply: by dropping a new rootfs image on the flash drive. When we'll publish a new version, you will be able to download it (+ match the file with our signature) and then overwrite the previous one.

Generating the security card will be very trivial, we'll start working on it asap.

The two other features are doable but will require more work. The Chrome app team has an idea about that which could be very interesting if we can make it work, so stay tuned!
japerry
Sr. Member
****
Offline Offline

Activity: 306
Merit: 250



View Profile WWW
November 05, 2015, 05:43:17 PM
 #351

definitely doable, I'll push that and the other question to the team dealing with Starter

Wow!! Very nice! I'll be looking forward to the new starter!


torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 05, 2015, 06:04:21 PM
 #352

definitely doable, I'll push that and the other question to the team dealing with Starter
Thanks for taking my feature requests to the team.

Generating the security card will be very trivial, we'll start working on it asap.
Looking forward using the next release.

The two other features are doable but will require more work. The Chrome app team has an idea about that which could be very interesting if we can make it work, so stay tuned!
Hopefully you can do it.
In the mean time I'll reanimate my old notebook with a CD-ROM and update the ledger with a Live-System. :-)

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 18, 2015, 07:39:19 AM
 #353

Would it be possible to request a specific address from the Ledger API?
E.g. requesting the address of the path "44'/0'/0'/0/0" and get that specific address back.

I opened an issues describing the details about this on github: https://github.com/LedgerHQ/ledger-wallet-api/issues/2

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
AussieHash
Hero Member
*****
Offline Offline

Activity: 692
Merit: 500



View Profile
November 18, 2015, 08:43:07 AM
 #354

Would it be possible to request a specific address from the Ledger API?
E.g. requesting the address of the path "44'/0'/0'/0/0" and get that specific address back.
https://www.reddit.com/r/Bitcoin/comments/33q6mc/ledger_releases_high_level_developper_api_for_the/
torusJKL
Hero Member
*****
Offline Offline

Activity: 619
Merit: 500


View Profile
November 18, 2015, 09:11:49 AM
Last edit: November 18, 2015, 11:45:58 AM by torusJKL
 #355

Unfortunately I can't see how that answers my question.
Could you please explain more in detail how I can get a specific address from the API?

If you find my post useful send some Bitcoin: 167XM1Za8aG9CdbYuHFMpL2kvPsw6uC8da
Bitrated || bitcoin-otc || Moon Bitcoin Faucet
gogxmagog
Legendary
*
Offline Offline

Activity: 1456
Merit: 1009

Ad maiora!


View Profile
November 19, 2015, 03:42:45 AM
 #356

I've been using the ledger wallet for a while and am very happy. The low cost is what convinced me at first, and it looks like the bitchip is even cheaper. The one thing I would suggest is some sort of protective casing. I am confident to carry my ledger around in my pocket if need be because it is in a little slip case. If bit chip had something similar it would be perfect
Bridgewater
Full Member
***
Offline Offline

Activity: 133
Merit: 100


View Profile
January 28, 2016, 09:56:28 AM
 #357

For the Ledger Chrome app to work, what IP addresses/ports do I need to open for basic functionality (sync/spend/confirm on mobile device)
btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
January 29, 2016, 08:35:04 AM
 #358

For the Ledger Chrome app to work, what IP addresses/ports do I need to open for basic functionality (sync/spend/confirm on mobile device)

You only need to open port 443 on *.ledgerwallet.com

japerry
Sr. Member
****
Offline Offline

Activity: 306
Merit: 250



View Profile WWW
January 30, 2016, 10:43:04 AM
 #359

For the Ledger Chrome app to work, what IP addresses/ports do I need to open for basic functionality (sync/spend/confirm on mobile device)

You only need to open port 443 on *.ledgerwallet.com

I looked at the traffic generated a while back. I thought chain.com was accessed by the app also?


btchip (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
January 30, 2016, 11:28:57 PM
 #360

The application had a websocket open to Chain in the past, now we are using our own service.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 [18] 19 20 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!