Bitcoin Forum
May 03, 2024, 07:23:58 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Possible Evil-Maid Attacks on Blockstream Jade  (Read 87 times)
B1-66ER (OP)
Jr. Member
*
Offline Offline

Activity: 48
Merit: 27


View Profile
June 27, 2023, 10:35:46 AM
Merited by hugeblack (3), dkbit98 (3)
 #1

Hi all,

I recently came across this blog post from Ledger titled

"Firmware Extraction: Evil-Maid Attacks on Blockstream Jade Hardware Wallet"
https://blog.ledger.com/blockstream/

Additionally, I found a response from Adam Back on Twitter,
https://twitter.com/adam3us/status/1673618343994212359

I'd like to hear your thoughts on how this might impact the Jade DIY.
1714764238
Hero Member
*
Offline Offline

Posts: 1714764238

View Profile Personal Message (Offline)

Ignore
1714764238
Reply with quote  #2

1714764238
Report to moderator
1714764238
Hero Member
*
Offline Offline

Posts: 1714764238

View Profile Personal Message (Offline)

Ignore
1714764238
Reply with quote  #2

1714764238
Report to moderator
Make sure you back up your wallet regularly! Unlike a bank account, nobody can help you if you lose access to your BTC.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714764238
Hero Member
*
Offline Offline

Posts: 1714764238

View Profile Personal Message (Offline)

Ignore
1714764238
Reply with quote  #2

1714764238
Report to moderator
1714764238
Hero Member
*
Offline Offline

Posts: 1714764238

View Profile Personal Message (Offline)

Ignore
1714764238
Reply with quote  #2

1714764238
Report to moderator
NotATether
Legendary
*
Offline Offline

Activity: 1596
Merit: 6726


bitcoincleanup.com / bitmixlist.org


View Profile WWW
June 27, 2023, 12:10:25 PM
 #2

I'm not sure which microcontroller the Jade is using, whether it's the ESP32-V3 or the V1, but it seems they're all vulnerable to the side-channel attacks and that no new microcontroller that fixes this is currently available. Your ledger link did say that the microcontroller manufacturer has plans to release a secured version of it in the future but didn't give an exact date. So Jade wallets are in serious trouble, regardless of whether you're DIY'ing it or not.

I see Adam Back is trying to run damage control on Twitter, but AFAIK this exploit has nothing to do with the device's PIN, it directly hits the microcontroller.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
The Sceptical Chymist
Legendary
*
Offline Offline

Activity: 3332
Merit: 6810


Cashback 15%


View Profile
June 27, 2023, 01:28:46 PM
 #3

Now I'm just askin' here, so forgive me:  Is this Ledger-playing-an-evil-maid thing an attempt to distract people from the unlubed assfucking still in progress they're delivering to Ledger customers via the Recovery option that ain't at all an option?  Just thinkin' aloud, mind you.

But dang it, that Jade was on my radar for a while.  It is indeed a sexy little HW wallet, all green and streamlined and open-source coded and such.  You guys think it just shat the bed?

I swear I think in a few years HW wallets are going to be sucker bait, things to be laughed at by those in the know.  Time will tell, but it's not looking good.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5635


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
June 27, 2023, 03:10:16 PM
Merited by Pmalek (2), hugeblack (2)
 #4

Now I'm just askin' here, so forgive me:  Is this Ledger-playing-an-evil-maid thing an attempt to distract people from the unlubed assfucking still in progress they're delivering to Ledger customers via the Recovery option that ain't at all an option?  Just thinkin' aloud, mind you.
~snip~

If you look at the date then you will see that the article was published on February 15, 2023, which means that it is already old news. This does not mean that Ledger will not use every opportunity to divert attention from its products and its incomprehensibly bad business practices.

In the past, their team published an article about vulnerability in Trezor HW, so this is not some isolated case but their way of trying to be good guys, and at the same time cast doubt on the competition.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7130



View Profile
June 27, 2023, 06:37:39 PM
 #5

Now I'm just askin' here, so forgive me:  Is this Ledger-playing-an-evil-maid thing an attempt to distract people from the unlubed assfucking still in progress they're delivering to Ledger customers via the Recovery option that ain't at all an option?  Just thinkin' aloud, mind you.
I think you got it wrong. I have just gone through Ledger's Twitter feed to see if they reposted or mentioned this Jade wallet extraction vulnerability in the last couple of days and they haven't. As Lucius pointed out, it's a blog post from February of this year. That's when it was originally posted. It's being discussed now because this Stadicus guy on Twitter brought it up today saying "How did I miss this?" That sparked a discussion where Adam Back also participated.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
June 27, 2023, 10:08:41 PM
 #6

I'd like to hear your thoughts on how this might impact the Jade DIY.
It's interesting that ledger donjon team mostly reports about issues with open source wallets....just saying  Cool
They are doing great job with all other wallets except with their own ledger device.

Back on Jade, I knew that ESP32 based devices are never going to be perfect as hardware wallets, that is why I like the idea of not storing anything but importing seed with QR code scan each time.
This can be few second/minutes slower than for regular wallets but it's much safer, and seed should be erased each time when power is turned down.
With this approach there is no communication with server for passwords.

Jade now has locking by server if PIN is entered wrong 3 times, and few months ago I researched this, each hardware wallet have different approach but only Jade communicates with server:
https://bitcointalk.org/index.php?topic=5416314

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7130



View Profile
June 28, 2023, 06:40:42 AM
 #7

It's interesting that ledger donjon team mostly reports about issues with open source wallets....just saying  Cool
No, not really. Open-source is a book you can open and start reading and analyzing. Since that is not the case with closed-source hardware wallets, I can see why they try to manipulate those from the first group.

They are doing great job with all other wallets except with their own ledger device.
It's important to distinguish between threats and vulnerabilities whose successful execution leads to the lose of coins versus things that affect ones privacy or the functionality of the wallet. At this time, I am not aware of a successful way to attack a Ledger hardware wallet to retrieve coins, the PIN, or seed from it. That doesn't mean there isn't one. The Ledger Donjon team focuses on attacks where you can actually lose your money.

It is true, though, that their proposed Ledger Recover mechanism is both a security and privacy threat.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!