Research and responsible disclosures are important and appreciated, but nothing fundamentally novel here -- as with previously demonstrated exfiltration attacks, this requires running a modified version of our software with malicious code inserted. Trade-offs, all the way down. nostr:note1ra4j0uct37w8ntapl90x0jvt0nl3axxxf25h4plr6guzp69zujfqjgk7md

Reply to this note

Please Login to reply.

Discussion

How do we manage to achieve what Matt corallo is promoting, what bitbox calls "anti klepto".

This is possible but would require a second round trip of QR codes to check the signatures. There are no wallet coordinators that support this, so there would need to be at least one before it would make any sense to consider implementing. You can view a video here that demonstrates how to verify your signer produces signatures consistent with Sparrow and bitcoin core:

https://x.com/seedsigner/status/1788945526806700091?s=46

Could an hacked hw create a correct signature when the amounts are low (or the signed data is a message, not a transaction), and a leaking signature when the tx is big?

Ooof, this is scary.

Does SeedSigner work with the Foundation Envoy app?

I can see them going for it 🤔

The real question is if there is a way to modify the code with out having physical access to the sd card tho right???

That or forcing you to download malicious firmware.

Phishing attack but with firmware.

Any idea on how possible it is to attack sd cards radio frequencies? I tried to look it up for a couple of hours and didn’t find anything.

Bruh 😂

🤷🏻‍♂️

👆

vibe hacking, vibrational frequencies. sd yokais. any might be worth try for a couple sats mo

no

Thank you

Reproducible builds

Forcing your coordinator to double check stuff is very good, thankfully we're here early.

What do you think about the mitigation techniques?

I guess the wallet app could require the hw wallet to calculate the nonces from some randomness provided by both the wallet app and the hw wallet.

(If both your computer and your hw wallet were compromised, you’re doomed anyway…).

https://darkskippy.com/mitigations.html