follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here

Author Topic: Hardware Bitcoin Wallets Hacked: The Importance Of Responsible Disclosure  (Read 1013 times)

Offline sirty143

  • Mythical
  • *
  • *
  • *
  • Activity: 8672
  • points:
    296559
  • Karma: 293
  • Trade Count: (0)
  • Referrals: 19
  • Last Active: Today at 02:08:13 PM
    • View Profile

  • Total Badges: 27
    Badges: (View All)
    Fifth year Anniversary Fourth year Anniversary 10 Posts
Following yesterday’s article regarding vulnerabilities uncovered in hardware wallets, both Trezor and Ledger have called ‘foul play’ over irresponsible disclosure. Hardware hacking group, wallet.fail, who exposed the security issues, at least partially deny this claim.

RESPONSIBLE DISCLOSURE

In the security world, hackers generally only go public with their findings after giving companies time to patch the vulnerabilities. Disclosing potential methods of attack before vendors have addressed them leaves users exposed to unnecessary risk.

Responsible vendors actually encourage hackers to attack their products, as by identifying weaknesses, overall security improves. Both Trezor and Ledger offer bug bounty programs, rewarding researchers who find vulnerabilities and report them directly.

EPIC FAIL

Wallet.fail’s presentation at the #35C3 security conference appears to have struck like a bolt from the blue, however. Trezor were clearly unaware of the vulnerabilities, as CTO Pavel Rusnak, leaped straight onto Twitter to say so. He found out about the issues with the rest of the audience, so explained that the issue would take some time to fix.

https://twitter.com/pavolrusnak/status/1078568510182309889

However, he later Tweeted that he had had a constructive two-hour discussion with wallet.fail regarding the vulnerabilities. He certainly seemed a lot happier following the outcome of this meeting.

PRACTICAL VULNERABILITIES OF BITCOIN HARDWARE WALLETS

Ledger was also quick to respond, pointing out in a blog-post that wallet.fail had not followed standard security principles. However, Ledger also called into question the practicality of the vulnerabilities outlined in the presentation.

It specifically pointed out that the group did not extract the seed or PIN from any device. A not too subtle reference to its competitor, Trezor, perhaps.

In addition to the RF side-attack on the Ledger Blue’s PIN, wallet.fail detailed an attack utilizing a device hardware implant, and compromised PC software to authorize rogue transactions on a Ledger Nano S. The blog-post pointed out that both of these attacks require far more effort than simply installing a spy camera to discover a user’s PIN.

0XF00DBABE MCU BYPASS

A further vulnerability involved bypassing the MCU check to flash and execute unsigned firmware. Ledger claim that this is a feature, although a bug allowed installation of non-featured firmware. In any case, the MCU does not allow access to the PIN or seed.

Wallet.fail claim to have advised Ledger about this issues months ago, and indeed, Ledger says this has already been patched in the next firmware update.

https://twitter.com/walletfail/status/1078784796506144769



Source:  BITCOINIST

Altcoins Talks - Cryptocurrency Forum


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here Ads bidding Bidding Open


 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod