Bitcoin Forum
May 03, 2024, 01:02:03 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Should hardware wallets use secure elements for max security?  (Read 188 times)
Ducker Smith (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
December 11, 2019, 09:45:19 AM
 #1

Your crypto is particularly vulnerable to physical attacks if your hardware wallet doesn't have a secure element. Physical attacks or a lost device are always going to be a threat to Hodlers, but all the more so if your hardware wallet doesn't have a secure element.

Any thoughts?
1714698123
Hero Member
*
Offline Offline

Posts: 1714698123

View Profile Personal Message (Offline)

Ignore
1714698123
Reply with quote  #2

1714698123
Report to moderator
1714698123
Hero Member
*
Offline Offline

Posts: 1714698123

View Profile Personal Message (Offline)

Ignore
1714698123
Reply with quote  #2

1714698123
Report to moderator
1714698123
Hero Member
*
Offline Offline

Posts: 1714698123

View Profile Personal Message (Offline)

Ignore
1714698123
Reply with quote  #2

1714698123
Report to moderator
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714698123
Hero Member
*
Offline Offline

Posts: 1714698123

View Profile Personal Message (Offline)

Ignore
1714698123
Reply with quote  #2

1714698123
Report to moderator
1714698123
Hero Member
*
Offline Offline

Posts: 1714698123

View Profile Personal Message (Offline)

Ignore
1714698123
Reply with quote  #2

1714698123
Report to moderator
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7125



View Profile
December 11, 2019, 10:07:09 AM
 #2

They should have a secure element, yes. The secure element is where the private keys are generated and stored and it makes sure that your private keys never leave the safety of the device.

Ledger explains the Secure Element topic very well here > https://www.ledger.com/academy/security/the-secure-element-whistanding-security-attacks/

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
ThatRandom8543
Sr. Member
****
Offline Offline

Activity: 1330
Merit: 307


View Profile
December 11, 2019, 02:17:30 PM
 #3

Your crypto is particularly vulnerable to physical attacks if your hardware wallet doesn't have a secure element. Physical attacks or a lost device are always going to be a threat to Hodlers, but all the more so if your hardware wallet doesn't have a secure element.

Any thoughts?

While its true that hw wallet can be vulnerable to physical attacks, if you dont have a strong additional passphrase, an secure element could be just as vulnerable. Some wallets have taken additional steps to wipe the private key from the hw wallet if the wallet is opened or tampered with, which is a smart move, but could also be problematic. Having an additional passphrase will provide more protection since its not stored on an hw wallet and you could also split your coins across different passphrases.
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5916


bitcoindata.science


View Profile WWW
December 11, 2019, 05:12:30 PM
 #4

I don't understand what is the op so worried about.
If you lose your device and for some reason a hacker finds it, he will not be able to steal your funds, unless if it is a zero day exploit (which nobody knows any for now).
If someone try your pin 3 times  device will reset.

The maximum security for now for your bitcoins is a ledger nano or a trezor.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
bitbro678
Jr. Member
*
Offline Offline

Activity: 40
Merit: 1


View Profile
December 12, 2019, 02:43:02 AM
 #5

I don't understand what is the op so worried about.
If you lose your device and for some reason a hacker finds it, he will not be able to steal your funds, unless if it is a zero day exploit (which nobody knows any for now).
If someone try your pin 3 times  device will reset.

The maximum security for now for your bitcoins is a ledger nano or a trezor.
Without a secure element, the hardware wallet cab be easily hacked with side channel attack. Check this: https://thenextweb.com/hardfork/2019/12/10/cryptocurrency-shapeshift-keepkey-wallet-cold-hacker-voltage-attack/
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5916


bitcoindata.science


View Profile WWW
December 12, 2019, 09:59:17 AM
 #6


The maximum security for now for your bitcoins is a ledger nano or a trezor.
Without a secure element, the hardware wallet cab be easily hacked with side channel attack. Check this: https://thenextweb.com/hardfork/2019/12/10/cryptocurrency-shapeshift-keepkey-wallet-cold-hacker-voltage-attack/

Well, this is why I suggested ledger o trezor, and not shitkeys

You cannot buy any shitful product and just because it is labeled"hardware wallet" expect it to have security.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
December 13, 2019, 06:45:39 PM
 #7

Well, this is why I suggested ledger o trezor, and not shitkeys
It's worth noting that both Ledger and Trezor have been affected by "exploits" in the past... The Trezor ONE actually has a similar (the same?) problem as the KeepKey, as they use the same micro-controllers...

https://medium.com/@Zero404Cool/trezor-security-glitches-reveal-your-private-keys-761eeab03ff8
https://medium.com/@Zero404Cool/frozen-trezor-data-remanence-attacks-de4d70c9ee8c

I guess this is the problem with being "popular"... you're always going to be the target Undecided

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
TimDavis
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
December 20, 2019, 04:56:13 AM
 #8

Your crypto is particularly vulnerable to physical attacks if your hardware wallet doesn't have a secure element. Physical attacks or a lost device are always going to be a threat to Hodlers, but all the more so if your hardware wallet doesn't have a secure element.

Any thoughts?

While its true that hw wallet can be vulnerable to physical attacks, if you dont have a strong additional passphrase, an secure element could be just as vulnerable. Some wallets have taken additional steps to wipe the private key from the hw wallet if the wallet is opened or tampered with, which is a smart move, but could also be problematic. Having an additional passphrase will provide more protection since its not stored on an hw wallet and you could also split your coins across different passphrases.
There is actually a good reason why a hardware wallet should use a secure element. It ensures that your private key never leaves your hardware wallet, even if your phone or software is compromised. It's like your best final line of defense. Also...what if I forget or lose the passphrase?
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7125



View Profile
December 21, 2019, 07:39:31 AM
 #9

what if I forget or lose the passphrase?
If you lost just the password, aka the 25th seed word, you might be able to recover it. Brute forcing it with the appropriate software could work if you know parts of the passphrase, special characters used it it and how it should look. If you have no idea what the passphrase was brute forcing it would be impossible or take a lifetime.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!