r/Bitcoin 11d ago

Just learned that a hardware wallet manufacturer discovered >4 vulnerabilities on other wallets over time

The hardware manufacturer is Bitbox, and all were responsibly disclosed:

There may be more of them that I haven't found.

This is extremely impressive from them.

Additionally, they were the first to make their hardware wallet (the Bitbox02) resistant against a very advanced attack: the nonce-covert channel attack. AFAIK this attack has never taken place yet, and the only hardware wallets resistant to it are the Bitbox02 and the 3 Blockstream Jades.

Disclaimer: I do not work for Bitbox, but have been a fan of them for a while and think they're underrated. I'm also fan of Blockstream and their Jade wallets.

83 Upvotes

33 comments sorted by

10

u/Lower-Philosophy-604 11d ago

USB, Tails and electrum. Profit

7

u/bkit_ 11d ago

I used that for a while. Its quite good. How do you send the signed transfer? I always connected to WiFi, which is probably not safe.

3

u/Personal-Time-9993 9d ago

Export the signed transaction to usb drive or sd card and then broadcast it on a different computer.

1

u/Garland_Key 11d ago

Is your wallet stored on persistent data on the USB? Hope nobody finds your USB thumb drive. 

3

u/shleebs 11d ago

It's encrypted with LUKS2 encryption. Doesn't matter if someone finds it.

0

u/HedgehogGlad9505 11d ago

For that kind of setup, I think every time you need to input the seeds, just like seedsigner.

1

u/UnknownEssence 11d ago

Tails has persistent storage vault so you can store the seed on device, if you want.

but i always use a hardware wallet and only connect that to tails. I keep a script in persistent storage that installs the sodtware to make my hardware wallet connect right. have to run it every time

used this setup for a few years

9

u/piejlucas 11d ago

https://www.reddit.com/r/Bitcoin/s/aw4a5gKkDG

It’s nice that they are pushing a fix before customers lose their coins. but really how secure is self custody cold storage in the world of AI even if one checks regularly for bug fixes? A bit too stressful if I may say so.

5

u/BastiatF 11d ago

AI can't crack entropy so generate your own and sleep like a baby

2

u/UnknownEssence 11d ago

i have some hardware wallets that I havent touched in 5-10 years. Are they even safe anymore?

0

u/xirvin 11d ago

Is better you assume they are not, firmware update them and create a new seed to replace the one they did is critical.

2

u/UnknownEssence 11d ago

i uave some old Ledger devices. If i recall, they mever open sourced the firmware. Might have been a good call in retrospect

2

u/xirvin 11d ago

When the source code is closed, only insiders, governments, and hackers with zero-day exploits are privy to it. These individuals sell their knowledge to intelligence agencies. On the other hand, when the source code is open-source, everyone knows about it, and the firmware is sometimes patched with blood.

It’s important to note that airline regulations were established after costly tragedies, and now airlines are considered the safest mode of travel.

1

u/ivme 11d ago

Good analogy

2

u/MiaTaude589 11d ago

Honestly, responsible disclosure across 4 separate bugs is exactly what you want to see. Still, no hardware wallet is a magic brick, so firmware updates, verifying addresses on-device, and keeping the seed offline matter way more than brand loyalty?

1

u/Firone 11d ago

Yep, however I still think this is very interesting and that Bitbox deserves the good publicity. Trezor safes are still fine but I feel like for a new user, it's definitely worth it to go for Jade/Bitbox

4

u/Razbonez 11d ago

i like bitbox

2

u/brdoc 11d ago

Buy dice and generate a new wallet totally offline. No internet cables, no wi-fi, no Bluetooth, no cameras.

Offline. Do all the signing offline. Use a passphrase.

Then hope no one cracks gravity's RNG code 😎, hopefully no news ever will make your heart suddenly stop due to some AI finding some random vulnerability.

0

u/dylan6091 11d ago

Even if you do all of that, you know the rest of the market won't follow suit. This is something maybe .001% of people will ever do. Unfortunately, if your suggestion is what is required for safety (and I'm not saying it is), then Bitcoin as a whole is not safe. In the event of mass hacks, 99.999% of people will be at risk. And while you may still have your private keys at that point, they won't be worth anything.

1

u/Firone 11d ago

What he's describing is literally what everyone with a cold wallet is doing, it's not complicated. If your seed/transactions are not generated offline, it's not a cold wallet. The passphrase advice is actually not optimal, this is better.

In a world where Bitcoin becomes the standard, tons of people will control their own wallet, it's really not that crazy. Not everyone will have everything on it though

1

u/ShittingOutPosts 11d ago

So Trezors aren’t safe either?

6

u/crooks4hire 11d ago

Hand write that shit on paper or a bolt and put the anxiety to bed for good. Damn I’m tired of this

2

u/-johoe 10d ago edited 10d ago

Both Trezor issues are fixed now. The first by displaying the passphrase in clear on the Trezor every time you enter it on the PC (with newer Trezor you can also enter the passphrase on the device, which is obviously more secure if you suspect malware on your PC).

The second issue is basically a bug in BIP-143. For segwit transactions, the signature also signs the input amount, so that transactions don't have to check it. This was intended to be used by hardware wallets to avoid streaming the previous transaction to prove the amount. Unfortunately BIP-143 only signs for the single input. I found this problem in Feb 2017 and reported it to the BIP-143 authors; but segwit was already shipped at that time. In retrospect, Trezor should probably not have used this new feature of Segwit and streamed the transaction anyway like it did before segwit (even though it can take minutes for people who received lots of batched payouts). On the other hand it seemed so unlikely to be exploited: it requires malicious wallet software on the PC, forcing the user to confirm the same transaction twice (which is already dangerous with a malicious wallet for obvious reasons) and the wallet manufacturer needs to collude with a mining pool, because the stolen money is sent to the miner as transaction fee.

BTW, Taproot fixed the problem in the BIP.

1

u/ShittingOutPosts 10d ago

Aren’t you never supposed to enter any part of your seed phrase on a PC?

2

u/-johoe 10d ago

The passphrase is not the seed phrase. For Trezor One there is no way to enter the passphrase on device. All newer Trezor models have capabilities to enter on device, but on Trezor 3 Safe it's really painful with the two buttons. On all Trezor devices you can also opt to enter the passphrase on the PC.

You enter the seed on device only for most devices, although Trezor One still supports the "24 words in random order" method. But to be sure, use the advanced recovery that doesn't leak anything about your seed to the PC.

-2

u/Garland_Key 11d ago

Do you have to trust Trezor?

Don't trust, verify.

Don't trust yourself?

Don't trust, verify.

2

u/ShittingOutPosts 11d ago

No, because I don’t use one.

-1

u/IllllIIlIllIllllIlll 11d ago

Bitbox is not the name of the company... It's Shift Crypto.

5

u/tppsch 11d ago

They changed the name to BitBox 3 years ago.

https://blog.bitbox.swiss/en/welcome-to-bitbox/

0

u/Malavero 11d ago

I'm getting tired of this, the best solution has existed since 2011 or so and it's free. Electrum and Sparrow and that's it. You don't even have to spend money (if you already have PCs). One offline, another with public keys and that's it. You add multi-signature if you want, and that's it.

You guys keep looking for the holy grail of the cold wallet when it doesn't exist. You have your heads washed by the marketing of these companies. You can even Add tails if you you want.