Bitcoin Forum
April 30, 2024, 01:30:13 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Trezor Wallets have new update waiting.  (Read 148 times)
Coin-Keeper (OP)
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
September 03, 2020, 09:34:23 PM
Last edit: September 03, 2020, 09:54:56 PM by Coin-Keeper
 #1

Trezor's new update requires users to confirm their password on the device screen after entering it.  I downloaded the new bitcoin-only firmware and its slick!

Paste from Trezor's site:

We have just launched our latest firmware updates for the Trezor Model T (firmware 2.3.3) and the Trezor Model One (firmware version 1.9.3). These updates are not mandatory but it is still recommended that you update your device, as the latest updates contain a security improvement related to how you use your passphrase. Read on for more information about this and other enhancements.

Passphrase

For both Trezor device models, we have improved the passphrase feature to take advantage of Trezor’s on-device confirmation. This offsets a previously known issue, reducing the chance of a host substituting a different
passphrase.

In such a hypothetical scenario, malware could direct you to a wallet obscured by a passphrase that you don’t actually know, and lock your funds there until you pay a ransom.

Now instead, you will be prompted by a warning on your Trezor screen that your passphrase will be shown, so you can make sure no-one is looking over your shoulder before you display it. Afterward, you will be able to check your passphrase on the screen of the device.

End of Paste

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
1714483813
Hero Member
*
Offline Offline

Posts: 1714483813

View Profile Personal Message (Offline)

Ignore
1714483813
Reply with quote  #2

1714483813
Report to moderator
1714483813
Hero Member
*
Offline Offline

Posts: 1714483813

View Profile Personal Message (Offline)

Ignore
1714483813
Reply with quote  #2

1714483813
Report to moderator
1714483813
Hero Member
*
Offline Offline

Posts: 1714483813

View Profile Personal Message (Offline)

Ignore
1714483813
Reply with quote  #2

1714483813
Report to moderator
If you want to be a moderator, report many posts with accuracy. You will be noticed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
September 04, 2020, 12:54:46 PM
 #2

It seems like Trezor is bringing out one hotfix after another.
To me, it seems like the device is broken itself, but kept together with patches.

I mean.. it works.. but it's not how it is supposed to be. A new generation device is needed IMO.

HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
September 04, 2020, 10:22:33 PM
 #3

It's like anything... OSes, applications, even hardware... people keep poking at them, sooner or later, someone will find a "hole"... At least Trezor are actively working to fix issues as they are notified. I hope they are also actively working on finding the issues themselves, rather than relying on "responsible disclosure"...

But I get what you're saying... that lucky coin and some waterproof paper are starting to look better and better again Wink

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
hugeblack
Legendary
*
Offline Offline

Activity: 2492
Merit: 3623


Buy/Sell crypto at BestChange


View Profile WWW
September 05, 2020, 02:01:54 PM
 #4

Now instead, you will be prompted by a warning on your Trezor screen that your passphrase will be shown, so you can make sure no-one is looking over your shoulder before you display it. Afterward, you will be able to check your passphrase on the screen of the device.
Are such easy solutions considered final solutions to the problem or do they have a long-term plan for such problems? Many times they resort to the easy solution.
Also, I think that there have been a lot of updates recently, the many updates are good, but they give a negative indication that the system is incomplete and it is possible to find many loopholes.

It is better for them to wait and launch a new generation or integrated updates, especially as the confidence index continues to decline.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Coin-Keeper (OP)
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
September 05, 2020, 11:25:47 PM
 #5

I see all the attention with numerous updates as a good thing.  In my world "open source" tools are the way to go in the long run.  Examining this last update as an example.  This "attack" was a theory only, never even noticed/tried in the wild, not ever against any hardware wallet.  When you hear about this and don't think it through, it appears that the Trezor device is being bombarded.  That is GOOD because millions of the best coders hammering away on every little aspect of the device is FAR FAR better than a closed source device where users simply have to trust the maker of the device.  Those too have the best coders hammering away on them but that may just be for nefarious reasons, we will never know.  If a hole is found (trust me there are holes) the white hat community may never learn of it until its wayyyyyyy too late and coins go missing from many wallets.  None of the recent updates had any impact on me or on my operations with coins.  I cannot state more strongly how OPPOSED to closed source I will forever be.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
Pmalek
Legendary
*
Offline Offline

Activity: 2744
Merit: 7120



View Profile
September 10, 2020, 12:36:08 PM
 #6

That is GOOD because millions of the best coders hammering away on every little aspect of the device is FAR FAR better than a closed source device where users simply have to trust the maker of the device. 
That goes both ways brother. There are people working on correcting the code and bugs to make it better, while others are working on solutions to empty our wallets. If/when a major vulnerability is found it's all down to luck: Will that vulnerability be found by a hacker or someone with good intentions?

That is both a pro and a con of open-source software. I agree, of course, that open-source is much better than closed-source, but it still a point worth remembering.   

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!