Bitcoin Forum
November 06, 2024, 10:35:21 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Trezor - seed extraction  (Read 236 times)
witcher_sense
Legendary
*
Offline Offline

Activity: 2450
Merit: 4415


🔐BitcoinMessage.Tools🔑


View Profile WWW
March 10, 2022, 06:29:34 AM
 #21

Depends on the hardware wallet. I can't possible speak for all hardware wallets, but most do not store private keys but instead derive them each time they are required and "forget" them when you unplug the device. The passphrase is another matter. There are some which do not store the passphrase, some which do, and some which can do either. Ledger wallets, for example, give you the option to attach the passphrase to a secondary PIN (in which case it is stored in the device), or to attach it temporarily each time you want to use it (in which case it isn't stored in the device).
I was mainly referring to a Trezor hardware wallet since it is open-source and on-topic. Because in the case of closed-source wallets like Ledger, it is anyway very difficult to figure out or verify what it is doing behind the scene. From my point of view, keeping a passphrase inside a hardware wallet defeats the purpose of hidden wallets. No matter how well it is implemented: it shouldn't store it. Period.


I said before there are DIY hardware wallets who are doing exactly that with non-consistent file storage, and memory gets deleted each time when device power is turned off.
Two examples I know are SeedSigner based on Raspberry Pi Zero, and Krux Wallet based on M5StickV device... importing seed words is quick for both of them with QR code.
Both of them are relative cheap to make and you won't be targeted by anyone for using general use devices like this not connected with cryptocurrencies.
They are more like signing devices than hardware wallets, but I see no reason why someone couldn't release something similar that is not DIY.
What happens if you accidentally scan the mnemonic QR-code with the camera of your smartphone instead of the signing device? Will an attacker be able to intercept it and quickly steal your savings? I think the answer is yes, they can, which makes me think that storing your seed in a form of QR-codes is not a good idea in principle. With signing devices as you mentioned above, it is very convenient to spend bitcoin from a paper wallet or something. But it is not at all suitable for everyday transactions due to the necessity of importing the seed every time you want to send someone bitcoin. It might work for cold-cold storage because you spend from it very rarely, but in such a case, there is no point in keeping QR-codes for your seed. The more time you spend directly interacting with your seed, the higher the chance of messing everything up and compromising your seed. Just my thought, I may be gravely mistaken.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18746


View Profile
March 10, 2022, 03:37:50 PM
 #22

From my point of view, keeping a passphrase inside a hardware wallet defeats the purpose of hidden wallets. No matter how well it is implemented: it shouldn't store it. Period.
Completely agree. If you are storing the passphrase on the same device that stores your seed phrase, regardless of what that device is, then you have negated much of the benefit of using a passphrase at all. It doesn't matter if that is device is a hardware wallet which touts itself as being safe and immune from hacks, since we've seen time and again that these devices can be breached in a variety of ways.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!