DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
December 13, 2022, 01:28:17 PM |
|
There are a few of "App Wallets" working on NFC support for both COLDCARD Mk4 and TAPSIGNER/SATSCARD. Like the years we had to push PSBT to be adopted, we expect NFC will take its time too. Not in a hurry. Nunchuk has integrated it well for both COLDCARD and TAPSIGNER/SATSCARD. It's working fairly well with the latest version and they keep on improving it.
Our approach to NFC is simple, almost anything you can do with the MicroSD/USB you can do with the NFC (signing, exporting data, etc...)
Cheers.
Thanks for the information about Nunchuk, I never heard of that one before. I will definitely give it a try, since NFC was the reason to get the MK4 and not the MK3. Honestly I think NFC is not a necessary feature and will probably even scare people away from buying the MK4, but since it is there I want to give it a try. What I dont really understand is, why you can scrape away the NFC link on the PCB, since it seems like an attacker could easily replace this link if he has physical access to the coldcard. In any case I like the coldcard so far and use it regularly. Scraping away the NFC means that if something went horribly wrong with the programming of the coldcard or there was a vulnerability found with NFC it could be disabled without destroying the unit itself. Or if you are just did not want any way for the unit to ever transmit anything. However, if someone gets physical access to your unit and there is another security issue, if the chip is active or not or even there or not makes little difference. The ONLY situation that would matter is if they got access to your coldcard, reconnected the NFC and then figured out a way to be near enough to you to get access to the radio waves in a way that they could do something with your funds. At that point see $5 wrench attack, quicker, easier and it just works..... -Dave
|
|
|
|
n0nce
|
|
December 13, 2022, 05:06:44 PM |
|
However, if someone gets physical access to your unit and there is another security issue, if the chip is active or not or even there or not makes little difference.
Correct; cutting the trace will protect you against a 'remote' attacker that will have 0 attack surface to try anything on. But a hardware attack directly on the PCB (connection to buses & probing side-channels) is much more likely to be successful than exploiting NFC. So an attacker with hardware access won't probably bother reconnecting the antenna.
|
|
|
|
nvK
|
|
December 13, 2022, 06:25:15 PM |
|
However, if someone gets physical access to your unit and there is another security issue, if the chip is active or not or even there or not makes little difference.
Correct; cutting the trace will protect you against a 'remote' attacker that will have 0 attack surface to try anything on. But a hardware attack directly on the PCB (connection to buses & probing side-channels) is much more likely to be successful than exploiting NFC. So an attacker with hardware access won't probably bother reconnecting the antenna. Maybe its a kindness attack, you wife thinks you accidentally broke it solder it back.
|
It's the bitcoin incentive that makes the "blockchain" technology work, stupid.
|
|
|
hZti (OP)
|
|
February 10, 2023, 02:24:09 PM |
|
Coinkite just released some infos about their new product, the ColdCard Q1: https://coldcard.com/docs/coldcard-q1Seems like it is basically a tuned version of the CC Mk4, with some feature that people requested (like QR Scanner, Battery, etc.)
|
|
|
|
nvK
|
|
April 18, 2023, 03:07:31 PM |
|
Coinkite just released some infos about their new product, the ColdCard Q1: https://coldcard.com/docs/coldcard-q1Seems like it is basically a tuned version of the CC Mk4, with some feature that people requested (like QR Scanner, Battery, etc.) Yes, we are still making a few tweaks but some good info here https://coldcard.com/docs/coldcard-q1
|
It's the bitcoin incentive that makes the "blockchain" technology work, stupid.
|
|
|
dkbit98
Legendary
Offline
Activity: 2450
Merit: 7634
|
|
April 18, 2023, 09:41:01 PM |
|
Are you going to paint the plastic in different colors like you did with Coldcard mk4? I can't find model Q1 in Coinkite store except for reservations, and I see release was planned for Q4 this year, that means it could happen even in 2024.
|
|
|
|
nvK
|
|
May 12, 2023, 04:34:51 PM |
|
Are you going to paint the plastic in different colors like you did with Coldcard mk4? I can't find model Q1 in Coinkite store except for reservations, and I see release was planned for Q4 this year, that means it could happen even in 2024. After the product is validated, so likely only by Q v2
|
It's the bitcoin incentive that makes the "blockchain" technology work, stupid.
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
May 26, 2023, 11:35:58 AM |
|
Probably not right place to put this, but, if you want a MK3 ColdCard to tinker with and are US based, send me a PM.
It's used so you should not consider it safe and secure anymore but if you just want one to see what it's all about and tinker with one PM me. Not going to ship internationally, it's literally going to go in a padded envelope with first class postage. $25 and it's yours.
Truly amazing what you find when doing spring cleaning around the office....
-Dave
|
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
September 10, 2023, 03:57:12 PM Last edit: September 11, 2023, 05:05:26 PM by DaveF Merited by DireWolfM14 (1) |
|
Coldcard released an update for the Mk4 ColdCards: https://coldcard.com/docs/upgrade <-- As always don't trust anyone's posted links verify them. Looking at the updates for the Mk3, or lack of updates as it may be, I guess older units are slowly going to fall into the unsupported devices world. -Dave Mk4: Version 5.1.4 - Sept 8, 2023
New Feature: Batch sign multiple PSBT files. Advanced/Tools -> File Management -> Batch Sign PSBT Enhancement: Sparrow Wallet added as an individual export option (same file contents) Enhancement: change key origin information export format in multisig addresses.csv to match BIP-0380 was (m=0F056943)/m/48'/1'/0'/2'/0/0 now [0F056943/48'/1'/0'/2'/0/0] Enhancement: Address explorer UX cosmetics, now with arrows and dots. Enhancement: Linked settings (multisig, trick pins, backup password, hsm users and utxo cache) separation for new main secret. Rename Unchained Capital to Unchained Bugfix: Correct scriptPubkey parsing for segwit v1-v16 Bugfix: Do not infer segwit just by availability of PSBT_IN_WITNESS_UTXO in PSBT. Bugfix: Remove label from Bitcoin Core importdescriptors export as it is no longer supported with ranged descriptors in version 24.1 of Core. Bugfix: Empty number during BIP-39 passphrase entry could cause crash. Bugfix: Signing with BIP39 Passphrase showed master fingerprint as integer. Fixed to show hex. Bugfix: Fixed inability to generate paper wallet without secrets Bugfix: Activating trick pin duress wallet copied multisig settings from main wallet Bugfix: SD2FA setting is cleared when seed is wiped after failed login due to policy SD2FA enforce. Prevents infinite seed wipe loop when restoring backup after 2FA MicroSD lost or damaged. SD2FA is not backed up and also not restored from older backups. If SD2FA is set up, it will not survive restore of backup. Bugfix: Terms only presented if main PIN was not chosen already. Bugfix: Preserve defined order of Login Countdown settings list. Bugfix: Remove unsupported trick pin option Look Blank from if wrong (not supported by bootrom). Bugfix: v5.1.3 release had padding issue which causes red light on install.
|
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
December 19, 2023, 10:11:02 PM |
|
There have been a couple of updates since my last post one just came out today... https://coldcard.com/docs/upgrade <-- As always don't trust anyone's posted links verify them. Still nothing for the Mk3 I guess they are just going to keep them as is unless something bad happens and perhaps not even then. From the site: New Feature: Temporary Seed import from a COLDCARD encrypted backup. New Feature: Export seed words in SeedQR format (on screen QR). New Feature: Provide user with info about transaction level timelocks (nLockTime, nSequence) when signing. Enhancement: New submenu for saved BIP-39 Passphrases allowing delete of saved entries. Enhancement: Add current temporary seed to Seed Vault from within Seed Vault menu. If current seed is temporary and not saved yet, Add current tmp menu item is shown in Seed Vault menu. Enhancement: Speed up opening Passphrase menu when MicroSD card is available, by deferring card read (and decryption) until after Restore Saved menu item is selected. Enhancement: 12 Words menu option preferred on the top of the menu in all the seed menus (rather than 24 words). Enhancement: Allow passphrase via USB if passphrase already set - operates on master seed. Enhancement: Improve BIP39 Passphrase UX when temporary seed is active and applicable. Enhancement: Continuation of removal of obsolete Mk2/Mk3 code-paths from master branch. Bugfix: Confusing first-time UX replaced with simple welcome screen. Bugfix: One instant retry on SE1 communication failures Bugfix: Handle any failures in slot reading when loading settings Bugfix: Add missing "First Time UX" for extended key import as master seed Bugfix: Hide Upgrade Firmware menu item if temporary seed is active (it cannot work) Bugfix: Disallow using master seed as temporary seed Bugfix: Do not allow APPLY of empty BIP-39 passphrase. Use "Restore Master" instead. Bugfix: Fix yikes in Clone Coldcard (thanks to AnchorWatch)
|
|
|
|
dkbit98
Legendary
Offline
Activity: 2450
Merit: 7634
|
|
December 20, 2023, 10:45:47 AM |
|
Still nothing for the Mk3 I guess they are just going to keep them as is unless something bad happens and perhaps not even then.
Mk3 is most likely going to graveyard soon, unless master NVK shows some mercy. btw do you by any chance know what is going on with biggest ever giant hardware wallet in the world aka Coldcard Q... that thing to me appears to have reservation status for eons, or it must be only available for special VIPs
|
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
December 20, 2023, 12:59:39 PM |
|
Still nothing for the Mk3 I guess they are just going to keep them as is unless something bad happens and perhaps not even then.
Mk3 is most likely going to graveyard soon, unless master NVK shows some mercy. btw do you by any chance know what is going on with biggest ever giant hardware wallet in the world aka Coldcard Q... that thing to me appears to have reservation status for eons, or it must be only available for special VIPs Have not heard squat about the Q It's still on their website but you have to search for it to get to it and no mention of it in the store unless you go to it from the page you just had to search to find. It's now been over 10 1/2 months since it's announcement.... But you can get your Mk 4 in a bunch of different colors. Because you need that...... -Dave
|
|
|
|
dkbit98
Legendary
Offline
Activity: 2450
Merit: 7634
|
|
December 25, 2023, 08:40:59 PM |
|
But you can get your Mk 4 in a bunch of different colors. Because you need that......
Yeah, I guess it's colorful holiday season for coldcard, and nvk is getting active again spreading hate and false information on social media. Would you even buy that coldcard kingkongQ device if available? I know I wouldn't. I hope nvk feels safe and secure in his mental asylum eco chamber. Luckily I can still follow whatever I want using nitter dkbit98 2 nvk 1
|
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
December 26, 2023, 02:15:46 PM |
|
But you can get your Mk 4 in a bunch of different colors. Because you need that......
Yeah, I guess it's colorful holiday season for coldcard, and nvk is getting active again spreading hate and false information on social media. Would you even buy that coldcard kingkongQ device if available? I know I wouldn't. I hope nvk feels safe and secure in his mental asylum eco chamber. Luckily I can still follow whatever I want using nitter dkbit98 2 nvk 1 Would I buy one is an interesting question. I am something of a pragmatist. If it offered something different (it does not) I might buy one. If it was much cheaper then to competition I might buy one (it is not) If it had some compelling thing that I had to have (it does not) I might have bought one. But since at this point it's just another hardware wallet. From a company that has left me with a Mk1 that I can't update and a Mk3 that is gong the same way there is no way I would get one. Which is a shame since for years I really liked their products. -Dave
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2982
Merit: 7642
Playgram - The Telegram Casino
|
|
December 27, 2023, 09:11:45 AM |
|
@DaveF The Mk3 and Mk4 already have plenty of qualities if you are looking for an airgapped signing device. If open-source isn't a priority for you, of course. The Q model introduces a better keyboard and QR code scanning. Those are useful features to have, but not essential.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
satscraper
|
|
December 27, 2023, 10:57:16 AM |
|
@DaveF The Mk3 and Mk4 already have plenty of qualities if you are looking for an airgapped signing device. If open-source isn't a priority for you, of course. The Q model introduces a better keyboard and QR code scanning. Those are useful features to have, but not essential.
Below are relevant specs laid out in comparison I would highlight also that Q model is equipped with the larger LCD display and improved dual SD slots which allow (as it stated) to pull off easily SD cards. "Dual slots means you can keep unsigned and signed transactions on different cards. Copying files and keeping dual backups is easier now."
|
| | . .Duelbits. | │ | ..........UNLEASH.......... THE ULTIMATE GAMING EXPERIENCE | │ | DUELBITS FANTASY SPORTS | ████▄▄▄█████▄▄▄ ░▄████████████████▄ ▐██████████████████▄ ████████████████████ ████████████████████▌ █████████████████████ ████████████████▀▀▀ ███████████████▌ ███████████████▌ ████████████████ ████████████████ ████████████████ ████▀▀███████▀▀ | . ▬▬ VS ▬▬ | ████▄▄▄█████▄▄▄ ░▄████████████████▄ ▐██████████████████▄ ████████████████████ ████████████████████▌ █████████████████████ ███████████████████ ███████████████▌ ███████████████▌ ████████████████ ████████████████ ████████████████ ████▀▀███████▀▀ | /// PLAY FOR FREE /// WIN FOR REAL | │ | ..PLAY NOW.. | |
|
|
|
DaveF
Legendary
Offline
Activity: 3696
Merit: 6686
Crypto Swap Exchange
|
|
December 27, 2023, 12:21:26 PM |
|
@satscraper and @Pmalek The point I was making is that it's been 11 months give or take a couple of days since it was announced. The took payments for it and have gone radio silent on the project. And beyond that, they now have a track record of dropping support for old products. I have 2 x Mk1 which are no longer supported and 1 x Mk2 and 2xMk3 that are destined to no longer be supported soon from the way they have been releasing firmware. I like their products, and they have even helped me out once when an opendime died. But, the market has changed. You have products like the keystone that although do not have a full keyboard are still a lot cheaper. I am the one who started the thread on the Q1 https://bitcointalk.org/index.php?topic=5439219.0And then *poof* *nothing* from them. You can still go here: https://store.coinkite.com/store/cc-q1 and give then $200 for a preorder that has no ship date. -Dave
|
|
|
|
dkbit98
Legendary
Offline
Activity: 2450
Merit: 7634
|
|
December 27, 2023, 08:28:05 PM |
|
Below are relevant specs laid out in comparison
This specs are only on virtual paper and means nothing... because Q wallet is in eternal presale reservation mod for $200, maybe until they collect enough money to actually start making them By the time they release it (if they ever release it), I bet they are going to us some outdated chips with flaws, so they will have to replace it with bigger Q2 version... Things could be much different for coldcard with nvk out of the picture.
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2982
Merit: 7642
Playgram - The Telegram Casino
|
|
December 28, 2023, 10:14:29 AM |
|
@satscraper The separation of unsigned and signed transactions isn't an important feature. You can name the files however you want. Just name then accordingly if you have problems differentiating one type from the other.
@DaveF I wouldn't worry too much about missing support. Don't forget, it's an airgapped wallet. All you need is for it to sign your transactions properly so you can export the files to your online device for broadcasting. Unless there is a vulnerability found in the older models and versions, everything is ok.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
satscraper
|
|
December 28, 2023, 11:12:16 AM |
|
@satscraper The separation of unsigned and signed transactions isn't an important feature. You can name the files however you want. Just name then accordingly if you have problems differentiating one type from the other.
Yeah, you are correct, however two separate SD slots could speed up the whole process and, thus, help to save on the spent time, but must be tested on the working device to be sure . Anyway, I’m burning up the hope for this model considering to assign it a role of the second cosigner in my multisig wallet in addition to the first one represented by Passport2.
|
| | . .Duelbits. | │ | ..........UNLEASH.......... THE ULTIMATE GAMING EXPERIENCE | │ | DUELBITS FANTASY SPORTS | ████▄▄▄█████▄▄▄ ░▄████████████████▄ ▐██████████████████▄ ████████████████████ ████████████████████▌ █████████████████████ ████████████████▀▀▀ ███████████████▌ ███████████████▌ ████████████████ ████████████████ ████████████████ ████▀▀███████▀▀ | . ▬▬ VS ▬▬ | ████▄▄▄█████▄▄▄ ░▄████████████████▄ ▐██████████████████▄ ████████████████████ ████████████████████▌ █████████████████████ ███████████████████ ███████████████▌ ███████████████▌ ████████████████ ████████████████ ████████████████ ████▀▀███████▀▀ | /// PLAY FOR FREE /// WIN FOR REAL | │ | ..PLAY NOW.. | |
|
|
|
|