Bitcoin Forum
May 01, 2024, 01:36:22 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: Seed phrase security question  (Read 547 times)
aysg76
Legendary
*
Offline Offline

Activity: 1960
Merit: 2124



View Profile
June 27, 2021, 03:03:21 PM
Merited by vapourminer (2)
 #41

Hi this is a random question but is it possible for my seed phrase on hardware wallet to be compromised by an app using my iPhone microphone ? I was singing my seed phrase to memorize it and realized my phone was right next to me. I’m also kinda high and paranoid? I see lots of posts about ppl taking photos of their phrases and losing their coins so I didn’t know if saying my phrase out loud was a bad idea.VidMate  Mobdro

We are living in technical era and every kind of hack is possible these days if you are not much aware about them.You don't know how these Voice assistant features work in the backend but your microphone records are also maintained by the company server to provide some better results.You must be aware about the Google,iphone,Facebook data leak breach on the dark web and so you can imagine that seed can also be compromised.The experts have stated one type of hack that can send some silent commands to Siri in through waveform generator that can hack your phone and listens to all your Siri conversation.

Quote
By talking with the voice assistant, bad actors can gain access to, say, your text messages, which may contain two-factor authentication codes for your other accounts.
To protect yourself from this form of attack, make sure your voice assistant is password-protected or disabled from the lock screen.

Learn about them at Siri hacks

So you must do take care about security measures and be safe with your seed phrase because they will just enter them in any Electrum wallet and then funds will be withdrawn to any address.So change the seed or take any other necessary step to avoid any further inconvenience.Next time save them in cold storage somewhere safe without storing them in mind Library.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
1714527382
Hero Member
*
Offline Offline

Posts: 1714527382

View Profile Personal Message (Offline)

Ignore
1714527382
Reply with quote  #2

1714527382
Report to moderator
1714527382
Hero Member
*
Offline Offline

Posts: 1714527382

View Profile Personal Message (Offline)

Ignore
1714527382
Reply with quote  #2

1714527382
Report to moderator
1714527382
Hero Member
*
Offline Offline

Posts: 1714527382

View Profile Personal Message (Offline)

Ignore
1714527382
Reply with quote  #2

1714527382
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714527382
Hero Member
*
Offline Offline

Posts: 1714527382

View Profile Personal Message (Offline)

Ignore
1714527382
Reply with quote  #2

1714527382
Report to moderator
jerry0
Full Member
***
Offline Offline

Activity: 1736
Merit: 186


View Profile
July 10, 2021, 08:25:57 PM
 #42

Well i got laptop and iphone.  But the way i have my laptop on my desk, its like pointing at my computer monitors, got a dual monitor setup so the laptop is to the right of it where the laptop camera is well pointing towards the camera.



So you should tape the laptop camera at all times?  Because anything that is on my computer monitor screen, well my laptop camera is essentially pointing straight at it.



Is that a concern?  Like imagine you were typing your seed in a software wallet and the laptop camera is pointing straight at it.  Has there been known hacks like this?  Also so if you were to actually sing your seed while your iphone is on... that is a huge concern?  What if you record it with the voice memo?  That is obviously bad but has anyone tested this with a seed and put a tiny amount of crypto in it just to see if anything would happen?
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10519



View Profile
July 11, 2021, 03:47:21 AM
 #43

Is that a concern?
There is a possibility and it is always best to be safe than sorry!

Quote
Has there been known hacks like this?
Not that I know of. People don't usually have strange setups like this where their camera is pointed directly at their screen instead of at their face.

Quote
Also so if you were to actually sing your seed while your iphone is on... that is a huge concern?  What if you record it with the voice memo? 
You can go in a windowless room with no electronics in it, shut down all the lights and enter your seed Smiley

Quote
That is obviously bad but has anyone tested this with a seed and put a tiny amount of crypto in it just to see if anything would happen?
That won't prove anything.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
July 11, 2021, 08:06:48 AM
 #44

So you should tape the laptop camera at all times?
I would either tape or disabled all your cameras at all times, since they are constantly being targeted by various mass surveillance programs around the world.

Like imagine you were typing your seed in a software wallet and the laptop camera is pointing straight at it.  Has there been known hacks like this?
Who knows? No one who is careless enough to point a camera directly at their seed phrase will then go to forums and say "Hey, I took every possible precaution except pointing a camera my seed phrase and now my coins have been stolen!" The point is it is a potential risk and your coins could be stolen this way.

Also so if you were to actually sing your seed while your iphone is on... that is a huge concern?  What if you record it with the voice memo?  That is obviously bad but has anyone tested this with a seed and put a tiny amount of crypto in it just to see if anything would happen?
Again, this proves nothing. Your coins could be stolen this way. It's like saying "Well, I've driven without a seat belt for 10 years and I'm still alive to driving without a seat belt is perfectly safe." All these things could result in your coins being stolen. Just because they haven't yet resulted in your coins being stolen doesn't mean they are a good idea. I could write my seed phrase in huge letters in permanent ink on my bedroom wall and my coins would stay safe for quite some time - doesn't mean it's a good way to store my seed phrase.
vapourminer
Legendary
*
Offline Offline

Activity: 4312
Merit: 3519


what is this "brake pedal" you speak of?


View Profile
July 11, 2021, 01:27:28 PM
Last edit: July 11, 2021, 01:39:09 PM by vapourminer
Merited by o_e_l_e_o (4), KingsDen (1)
 #45

That is something i never thought of.  But when you guys write your seed or look at your seed, do you all make sure your phone or laptop camera isn't pointing straight at your paper that has your seed in it?

when generating a new seed or key i remove all phones from the room and power them off. all security cams that might have line of site are disabled. unplug desktop webcams or cover the webcam if laptop. all window shades in the room are drawn (include skylights too). i have no alexa/google thing (never will either) so no worries there. if you have a smart tv attached to your network unplug it. have any of those voice activated remote controls for your cable/sat tv? take the batteries out and move those remotes out of the house for the duration.

once the seed/key is generated/tested ill make dupes and stash some off site. add a passphrase too but dont store that with the seeds of course. multiple copies of that too.

then after all that i take my tinfoil hat off and re enable all the potential bugs (phones tvs etc).
BlackHatCoiner
Legendary
*
Offline Offline

Activity: 1498
Merit: 7340


Farewell, Leo


View Profile
July 11, 2021, 02:22:34 PM
 #46

Is that a concern?  Like imagine you were typing your seed in a software wallet and the laptop camera is pointing straight at it.  Has there been known hacks like this?  Also so if you were to actually sing your seed while your iphone is on... that is a huge concern?  What if you record it with the voice memo?  That is obviously bad but has anyone tested this with a seed and put a tiny amount of crypto in it just to see if anything would happen?

It depends on what you understand as “concern”. Once you generate a wallet, there are tons of ways you can screw the whole thing up, but your money may be safe. You should minimize the odds of screwing up to cover these concerns. No, I've never heard of a hack like this, neither from singing the seed. But, you know what? Now that it's publicly known, there may be people who'll write a malicious code regarding your records.

Just for your information, I've never heard of funds' loss from the classic procedure of seed generation. But, it doesn't matter what I have heard; I always minimize these odds.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!