Bitcoin Forum
May 05, 2024, 07:10:24 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [PSA] Non-genuine Trezor One devices spotted  (Read 251 times)
HeRetiK (OP)
Legendary
*
Offline Offline

Activity: 2926
Merit: 2091


Cashback 15%


View Profile
November 19, 2018, 04:43:31 PM
Last edit: November 19, 2018, 04:57:39 PM by HeRetiK
Merited by o_e_l_e_o (2), bones261 (2), HCP (1)
 #1

Just a heads-up, SatoshiLabs just sent out a newsletter that the first 1:1 Trezor One clones have been finally spotted in the wild:

https://blog.trezor.io/psa-non-genuine-trezor-devices-979b64e359a7

For the longest time I expected the likes of an evil maid attack [1] to be of mostly theoretical concern, but while a different issue this problem is of similar concern. As of now it seems to be unsure whether these clones are malicious, but I personally wouldn't take any chances.

To any newbies reading this: Be reminded that buying hardware wallets anywhere but from the original vendors is a huge security risk. That's true for any sort of hardware wallet, not just Trezor.

[1] https://doc.satoshilabs.com/trezor-faq/threats.html#evil-maid-attack-replace-the-trezor-with-a-fake

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
1714936224
Hero Member
*
Offline Offline

Posts: 1714936224

View Profile Personal Message (Offline)

Ignore
1714936224
Reply with quote  #2

1714936224
Report to moderator
1714936224
Hero Member
*
Offline Offline

Posts: 1714936224

View Profile Personal Message (Offline)

Ignore
1714936224
Reply with quote  #2

1714936224
Report to moderator
"With e-currency based on cryptographic proof, without the need to trust a third party middleman, money can be secure and transactions effortless." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714936224
Hero Member
*
Offline Offline

Posts: 1714936224

View Profile Personal Message (Offline)

Ignore
1714936224
Reply with quote  #2

1714936224
Report to moderator
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
November 21, 2018, 03:32:35 PM
 #2

Unfortunately, they don't show difference between fake and real hardware wallet/device whether by physical or software/firmware different.
I'd like to know if desktop wallet software could identify between real/fake trezor and whether using genuine firmware update will break fake trezor.

Only way to see the difference between fake and real Trezor is for now only holographic seal as shown in the pictures, but these holograms are very similar and it is not easy to distinguish them if you not have original and fake package.

I guess when you connect fake Trezor to original UI it should work same as original, otherwise it would not make sense for forgers to make and sell them. The only question is whether such a device is made for intention to steal users coins, or it is just a identical copy made with a reason to profit on sales.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
November 22, 2018, 12:55:43 AM
 #3

I guess when you connect fake Trezor to original UI it should work same as original, otherwise it would not make sense for forgers to make and sell them. The only question is whether such a device is made for intention to steal users coins, or it is just a identical copy made with a reason to profit on sales.
Does the Trezor not show a warning about using a modified firmware? I was sure that it had a warning if a firmware that was not signed by SatoshiLabs was loaded... at least as far back as March this year anyway...

https://blog.trezor.io/trezor-one-firmware-update-1-6-1-eecd0534ab95

So are these 1:1 copies using modified Firmware AND Bootloaders? Huh SatoshiLabs haven't really mentioned much... and seem to say that only by looking at the box and label... no onscreen warnings??!? Huh

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
HeRetiK (OP)
Legendary
*
Offline Offline

Activity: 2926
Merit: 2091


Cashback 15%


View Profile
November 22, 2018, 01:16:23 PM
 #4

I guess when you connect fake Trezor to original UI it should work same as original, otherwise it would not make sense for forgers to make and sell them. The only question is whether such a device is made for intention to steal users coins, or it is just a identical copy made with a reason to profit on sales.
Does the Trezor not show a warning about using a modified firmware? I was sure that it had a warning if a firmware that was not signed by SatoshiLabs was loaded... at least as far back as March this year anyway...

https://blog.trezor.io/trezor-one-firmware-update-1-6-1-eecd0534ab95

So are these 1:1 copies using modified Firmware AND Bootloaders? Huh SatoshiLabs haven't really mentioned much... and seem to say that only by looking at the box and label... no onscreen warnings??!? Huh

Trezors come only with the bootloader pre-installed, the firmware is installed when first initializing the device making sure one can start from a clean slate.

Presumably the Trezor clones use the same bootloader, allowing it to install and run the official firmware. If that's the case no warning will be shown on the web interface.

Problem being that while the software may be verified, you have no way of knowing whether the hardware is trustworthy. They could have used less secure components, they could have installed a backdoor on the hardware level, etc.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
November 22, 2018, 03:26:44 PM
 #5


Trezors come only with the bootloader pre-installed, the firmware is installed when first initializing the device making sure one can start from a clean slate.

Presumably the Trezor clones use the same bootloader, allowing it to install and run the official firmware. If that's the case no warning will be shown on the web interface.

Problem being that while the software may be verified, you have no way of knowing whether the hardware is trustworthy. They could have used less secure components, they could have installed a backdoor on the hardware level, etc.

Actually then there is no way to determine if it is an original or a copy of Trezor hardware wallet, maybe only if user have 100% original Trezor ordered from the manufacturer directly and suspicious product in front of you.

Apart from the difference in holographic seal there are probably some differences in the box and in the hardware wallet itself. Some tips can be seen in this video, but only right way to buy hardware wallet is directly from manufacturer - in this way the possibility to get fake wallet is maximally reduced.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
LTU_btc
Legendary
*
Online Online

Activity: 3052
Merit: 1330


Slava Ukraini!


View Profile WWW
November 25, 2018, 12:21:03 AM
 #6

Does anyone knows where exactly it was spotted? I can't find this information. People need to know where they shouldn't buy this wallet.
It's another warning why people should buy hardware wallets only from official websites and authorised resellers. In this case it's really difficult to spot difference between fake and original wallet, especially if you never had Trezor in your hands.

aoluain
Legendary
*
Offline Offline

Activity: 2254
Merit: 1256



View Profile
November 25, 2018, 08:56:58 AM
 #7

We know by now that the only way to eliminate receiving a fake Trezor
is to purchase directly from the manufacturer but if you dont know
that it is easy to get caught by buying a fake at what seems like a deal.

Regarding the hologram, im sure these can be copied. I have seen
copies of PAMP carded Gold bars which were in fact fakes, everything
looked almost perfect including the hologram. The only noticable
difference was the thickness of the "gold" bar. So anything can be copied
near enough to the original to trick people.

Again only way is to buy from the official source.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3013


Welt Am Draht


View Profile
November 25, 2018, 11:20:04 PM
 #8

Does anyone knows where exactly it was spotted? I can't find this information. People need to know where they shouldn't buy this wallet.
It's another warning why people should buy hardware wallets only from official websites and authorised resellers. In this case it's really difficult to spot difference between fake and original wallet, especially if you never had Trezor in your hands.

The only mention I can find is 'online marketplaces' which is presumably Ebay and Amazon.

I can't find any mention of what happens when you connect it to a Trezor interface. It's a tad worrying that the only differences they can offer are the hologram and a mention of being made in China. Both are rectified easily enough.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!