Bitcoin Forum
May 06, 2024, 03:17:46 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 [7]  All
  Print  
Author Topic: Coldcard  (Read 1360 times)
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7134



View Profile
February 20, 2024, 05:04:37 PM
 #121

The only thing that I could imagine that would be very bad is if some newer wallet versions would not recognize the transactions from the older ColdCards, because maybe some kind of format change. But that does not seem to be the case in any near future.
Yeah, I don't see that happening, and even if it does, you can always use an older version of the same software where those changes were not made.

Coldcards, like most other hardware wallets, have a maximum size limit for signed transactions. I wasn't sure how big these were, so I had to look it up quickly. For the Mk3 model, the maximum size is 384k-bytes. Also, the transaction can have 20 inputs and up to 250 outputs. The Mk4 offers much more: 2M bytes in size and many more inputs and outputs. The source says they successfully tested signing a transaction of 250 inputs and 2000 outputs.

https://github.com/Coldcard/firmware/blob/master/docs/limitations.md

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
DaveF
Legendary
*
Offline Offline

Activity: 3472
Merit: 6263


Crypto Swap Exchange


View Profile WWW
February 22, 2024, 01:02:32 PM
 #122

As far as I understand all the Coldcards form MK1-MK4 can still be used safely as of now or is that not correct?

Sort of.

There are some really out there attacks that cannot be mitigated such as this one: https://blog.coinkite.com/laser-fault-injection/
or this one: https://blog.coinkite.com/version-3.0.6-released/

But worrying about these kinds of attacks is probably not a big deal since they would be targeted and it does come back to the $5 wrench attack.
And look they still do exist: https://www.harborfreight.com/hand-tools/wrenches/pipe-wrenches/8-inch-steel-pipe-wrench-39641.html

It's not a new thing, there are probably hundreds of millions old phones out there that people are using that vulnerable versions of the OS on them due to their age.
And just in general, those would make better targets.

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7134



View Profile
February 22, 2024, 04:57:16 PM
 #123

There are some really out there attacks that cannot be mitigated such as this one: https://blog.coinkite.com/laser-fault-injection/
All fault injection attacks require physical access to the hardware wallet. If someone gets their hands on your HW device, you should move your coins from it regardless of what model you own. I wouldn't be comfortable with someone, who perhaps knows what they are doing, playing around with my wallet and trying to break into it even if I had the world's safest one.

This particular attack is only possible on multisig wallets. If you are using a standard singlesig wallet, you aren't affected.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
DaveF
Legendary
*
Offline Offline

Activity: 3472
Merit: 6263


Crypto Swap Exchange


View Profile WWW
February 23, 2024, 09:20:21 PM
 #124

There are some really out there attacks that cannot be mitigated such as this one: https://blog.coinkite.com/laser-fault-injection/
All fault injection attacks require physical access to the hardware wallet. If someone gets their hands on your HW device, you should move your coins from it regardless of what model you own. I wouldn't be comfortable with someone, who perhaps knows what they are doing, playing around with my wallet and trying to break into it even if I had the world's safest one.

This particular attack is only possible on multisig wallets. If you are using a standard singlesig wallet, you aren't affected.

Not debating any of that. It was more of a yes you can still use it, but there are some very minor / obscure things that are not going to be fixed due to hardware limitations.

Yet again, what I had in my brain didn't make it to the screen.

At this point the Mk1 + Mk2 are very old devices and if an issue does come up even if it WAS fixable and they did fix it, it's probably not worth it.
For the Mk3 I would think that if possible they would patch it, because it would just make them look even worse if they did not.

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: « 1 2 3 4 5 6 [7]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!