Bitcoin Forum
June 14, 2024, 12:31:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: “BadUSB” exploit - How would you protect your bitcoins on backup memory sticks?  (Read 1542 times)
Kprawn (OP)
Legendary
*
Offline Offline

Activity: 1904
Merit: 1074


View Profile
August 02, 2014, 10:53:35 AM
 #1

Just thought I'd ask.

Look at this latest exploit --> http://arstechnica.com/security/2014/07/this-thumbdrive-hacks-computers-badusb-exploit-makes-devices-turn-evil/

I know some people "save" or "backup" their BTC public address and private key on memory sticks.

What if this exploit, embed a piece of software in the firmware of these devices, to capture this information and to send it to them, once it's used again?

Most people format the memory stick after it's used, and think it's save, but the firmware stays on there.

Just a thought.. play with it. 


THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
bomb177
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
August 02, 2014, 11:10:37 AM
 #2

If I buy my USB sticks from trusted companies like Kingston, Sandisk or others I shouldn't have any trouble right?
tatu
Full Member
***
Offline Offline

Activity: 138
Merit: 100


View Profile
August 02, 2014, 11:17:28 AM
 #3

Only if the nsa doesnt intercept them or they havent already got their backdoors built into the software.
blacksails
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
August 02, 2014, 11:50:22 AM
 #4

I have my wallet backed up on a USB stick. Encrypted of course! Smiley
Even if the firmware is evil it can't crack the encryption.
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
August 02, 2014, 11:57:05 AM
 #5

Protecting your wallet backup with a strong password should be able to migrate most of the attacks. It would take a lot of resources and time to bruteforce a long and strong password.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
InwardContour
Sr. Member
****
Offline Offline

Activity: 644
Merit: 260


View Profile
August 02, 2014, 12:01:14 PM
 #6

I have my wallet backed up on a USB stick. Encrypted of course! Smiley
Even if the firmware is evil it can't crack the encryption.

I have a backup of the wallet on several USB sticks and each one is encrypted with a strong (...and long) password,
I feel safe but probably the next cold storage will be on a paper wallet.
blacksails
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
August 02, 2014, 12:58:25 PM
 #7

I have my wallet backed up on a USB stick. Encrypted of course! Smiley
Even if the firmware is evil it can't crack the encryption.

I have a backup of the wallet on several USB sticks and each one is encrypted with a strong (...and long) password,
I feel safe but probably the next cold storage will be on a paper wallet.
Yeah, of course my only backup is not on a USB, I have it on external harddrives, USB sticks, CD:s, DVD:s, on multiple file-upload sites (the file is of course not public), on a few mail addresses and so on (always heavily encrypted of course!).
JohnFromWIT
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
August 02, 2014, 01:11:10 PM
 #8

That's not really the worry though.
If you somehow recieve a BadUSB infected device and connect it to your computer, your computer is now also at risk.

ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
August 02, 2014, 01:16:07 PM
 #9

That's not really the worry though.
If you somehow recieve a BadUSB infected device and connect it to your computer, your computer is now also at risk.
If you connect it to a offline computer and create wallet, it wouldn't be much of a worry. You can also create raw transactions on that offline computer too. It is considered as safe if you never connect it to a online computer or if the computer you have connected to goes online.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Kprawn (OP)
Legendary
*
Offline Offline

Activity: 1904
Merit: 1074


View Profile
August 02, 2014, 08:00:33 PM
 #10

Well previously it was thought, that if you did a few full formats on the memory stick, it would remove everything. But it does not remove the content of the firmware, so you stuffed.  Angry

There used to be memory sticks with a "write protect" button, but I do not see them anymore. Do not even know, if it was really effective. {Like the write protection on stiffies 720k or 1.44 mb back in the days ....now I give away my age.  Grin Grin}

THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
notlist3d
Legendary
*
Offline Offline

Activity: 1456
Merit: 1000



View Profile
August 03, 2014, 04:25:01 PM
 #11

As far as "BadUSB" there is nothing new about usb drives being able to carry something "bad".  NEVER NEVER let someone stick their thumb drive as a general rule in a computer with information you are worried about. 

If you have information on your pc don't use plain text use some kind of encryption to protect it.
btcguys
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
August 03, 2014, 05:57:32 PM
 #12

use your old USB and not the new ones for Bitcoin pruposes  Grin

Also, I do not recommend printing paper wallet private keys as private keys may be retrievable from printer's memory.

it is best to use a PC to create paper wallets that will never go online
Bitsaurus
Hero Member
*****
Offline Offline

Activity: 873
Merit: 1007



View Profile
August 04, 2014, 05:43:26 AM
 #13

use your old USB and not the new ones for Bitcoin pruposes  Grin

Also, I do not recommend printing paper wallet private keys as private keys may be retrievable from printer's memory.

it is best to use a PC to create paper wallets that will never go online

While that may be true, it would be nearly impossible if the printers buffers have been flushed repeatedly.

Armory also utilizes a way to bypass this issue with scancodes.
w4ssop
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
August 04, 2014, 07:40:01 AM
 #14

I have a wallet backup on an old pendrive, it is about 5 years old so I hope it is safe.
medUSA
Legendary
*
Offline Offline

Activity: 952
Merit: 1003


--Signature Designs-- http://bit.ly/1Pjbx77


View Profile WWW
August 04, 2014, 08:54:49 AM
 #15

This "BadUSB" exploit should be a targeted attack, we are not going to see hacked USB devices right off the shelf. I am not that worried to be honest.
paradoxum
Full Member
***
Offline Offline

Activity: 138
Merit: 100


View Profile
August 04, 2014, 09:34:00 AM
 #16

You could always rely on an older device like a 512MB thumbdrive or an older portable HD. 
keyscore44
Legendary
*
Offline Offline

Activity: 2002
Merit: 1016



View Profile
August 04, 2014, 12:39:35 PM
 #17

Wonder whether this applies to people running Tails OS from USB sticks? Think I'll be stocking up on some SD cards (assuming they can't be exploited aswell).

.
.7 BTC  WELCOME BONUS!..
███████████████████████████
██████████▀▀▄▄▄▄▄ ▄▀▀██████
█████████▄██████ ████ ▀████
██████▀▀ ▄▄▄▄ ▀▀███▀▄██ ███
████▀   ██████   ▀██████ ██
███ ▄▄▄████████▄▄▄ ██▄▄▄ ██
██ █████▀    ▀█████ ████ ██
██  ▀██        ███▀ ███ ███
██   ▄██▄    ▄██▄   █▀▄████
███ ▄████████████▄ ████████
████▄▀███▀▀▀▀███▀▄█████████
██████▄▄      ▄▄███████████
███████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████▄▄▄█████▄▄▄████████████████████████████████████████████████████
██████████▄█████▄█▄███▄█▄██████████▄██▀▀▀████████████████████████████████████████████████████
██████████████▀████▄████▀██████████████████████████▄█████▄██▄█████▄████▄████▄████▄████████
█████████████████▐█████▌███████████▄█████▀███▀▀████████▀▀▀▀█████▀▀▀██████▀▀███▀▀███████████
██████████████▄████▀████▄██████████████████▄▄▄▄▄███▄▄▄▄█████▄▄▄████████████████████████
████████████████▀█▀███▀█▀██████████▀███████▀█████████▀█████▀██▀█████▀███████████████████████
██████████████████████████████▀▀▀████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████
████████▀▀  ▐█▌  ▀▀████████
██████▄     ▐█▌     ▄██████
████ ▀██▄▄███████▄▄██▀ ████
███    ██▀▀  ▄  ▀▀██    ███
██    ██   ▄███▄   ██    ██
████████  ███████  ████████
██    ██  ▀▀ █ ▀▀  ██    ██
███    ██▄▄ ▀▀▀ ▄▄██    ███
████ ▄██▀▀██████▀▀▀██▄ ████
██████▀     ▐█▌     ▀██████
████████▄▄  ▐█▌  ▄▄████████
███████████████████████████
.
.30+  ALTCOINS AVAILABLE..
ensurance982
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


Trust me!


View Profile
August 04, 2014, 04:53:42 PM
 #18

Just don't. Keeping your BTC on flash drives doesn't make them any safer than storing them on a regular hard drive in your machine. As soon as the flash drive is connected, a potential attacker could get hold of your BTC if they're not encrypted in any way. Paper wallets and offline transaction signing. That's the way to go!

                                                                                                                      We Support Currencies: BTC, LTC, USD, EUR, GBP
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!