Bitcoin Forum
October 19, 2018, 05:57:11 AM *
News: Make sure you are not using versions of Bitcoin Core other than 0.17.0 [Torrent], 0.16.3, 0.15.2, or 0.14.3. More info.
 
   Home   Help Search Donate Login Register  
Pages: [1]
  Print  
Author Topic: TREZOR SECURITY UPDATE  (Read 441 times)
poordeveloper
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500



View Profile
August 16, 2017, 07:51:40 PM
 #1

Quote
TREZOR Firmware Security Update — 1.5.2

Today, SatoshiLabs released a security update to your TREZOR; a new firmware version — 1.5.2 — was pushed out to all users. This update fixes a security issue which affects all devices with firmware versions lower than 1.5.2.

TREZOR Wallet will notify you about this update. Please make sure you have your recovery seed nearby, before starting the update process. Refer to the User Manual if you need assistance with the firmware update. For users with Bootloader version 1.3.0, please consult this guide first.

It is important to note that this is not a remote execution attack. To exploit this issue, an attacker would need physical access to a disassembled TREZOR device with uncovered electronics. It is impossible to do this without destroying the plastic case.

If your device does not leave your presence, your coins are safe. Moreover, if you have a passphrase enabled and actively use it, your coins are safe. Yet, we strongly recommend you to update your TREZOR anyway.

We are not releasing a detailed description of the issue today to give enough time for users to update and for other hardware wallets based on TREZOR to distribute an update. We will publish a detailed report in the coming days.

How do I know that my TREZOR has not been broken into?
In order to exploit this issue, an attacker would have to break into the device, destroying the case in the process. They would also need to flash the device with a specially-crafted firmware. If your device is intact, your seed is safe, and you should update your firmware to 1.5.2 as soon as possible.

With firmware 1.5.2, this attack vector is eliminated and your device is safe.


░░░░░░▄▄█▀▀▀▀▀▀▀▀█▄▄

░░░░▄█░░▄▄▄▄▄▄▄▄▄▄░░█▄
░░▄█░░▄█░░░░░░░░░█▄░░█▄
░░▄█░░░░▄███▄░░░░░█▄░░
░░░░░░░░░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░░░░░░░██░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░▀█░░░░▀███▀░░░░░█▀░░
░░▀█░░▀█░░░░░░░░░█▀░░█▀
░░░░▀█░░▀▀▀▀▀▀▀▀▀▀░░█▀
░░░░░░▀▀█▄▄▄▄▄▄▄▄█▀▀
▁ ▂ ▁ Facebook | DECOIN.IO| Bounty ▁ ▂ ▁
•-» World's leading Cryptocurrency Exchange and Trading Platform «-•
▂ ▅ ▂ ANN▂ ▅ ▂ Telegram▂ ▅ ▂ Whitepaper ▂ ▅ ▂ Twitter ▂ ▅ ▂
1539928631
Hero Member
*
Offline Offline

Posts: 1539928631

View Profile Personal Message (Offline)

Ignore
1539928631
Reply with quote  #2

1539928631
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1539928631
Hero Member
*
Offline Offline

Posts: 1539928631

View Profile Personal Message (Offline)

Ignore
1539928631
Reply with quote  #2

1539928631
Report to moderator
poordeveloper
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500



View Profile
August 17, 2017, 01:36:56 AM
 #2

How to update your firmware?
When you login to your Trezor Wallet you will see a button at the header which will allow you to update your firmware.


░░░░░░▄▄█▀▀▀▀▀▀▀▀█▄▄

░░░░▄█░░▄▄▄▄▄▄▄▄▄▄░░█▄
░░▄█░░▄█░░░░░░░░░█▄░░█▄
░░▄█░░░░▄███▄░░░░░█▄░░
░░░░░░░░░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░░░░░░░██░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░░░░░░░░░░░░░░░░
░░▀█░░░░▀███▀░░░░░█▀░░
░░▀█░░▀█░░░░░░░░░█▀░░█▀
░░░░▀█░░▀▀▀▀▀▀▀▀▀▀░░█▀
░░░░░░▀▀█▄▄▄▄▄▄▄▄█▀▀
▁ ▂ ▁ Facebook | DECOIN.IO| Bounty ▁ ▂ ▁
•-» World's leading Cryptocurrency Exchange and Trading Platform «-•
▂ ▅ ▂ ANN▂ ▅ ▂ Telegram▂ ▅ ▂ Whitepaper ▂ ▅ ▂ Twitter ▂ ▅ ▂
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 573
Merit: 502



View Profile
August 17, 2017, 11:39:34 PM
 #3

OP you should close this thread because there is another one running right in the forum.  Lets keep it all in one place!  I am so used to being a Mod but not here,  LOL

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!