Author

Topic: Bad news for BTC-devs!? (Read 1328 times)

sr. member
Activity: 302
Merit: 252
hero member
Activity: 518
Merit: 521
November 19, 2013, 04:37:37 AM
#14
Printout and then OCR scan to cross airgap?
sr. member
Activity: 252
Merit: 250
November 19, 2013, 04:36:13 AM
#13
The guy in this article describes an alien computer virus. Cyberpunk x-files.
Actually describes a virus that managed to do a lot more than what mit scientists are struggling with in research.
Seriously?  Roll Eyes
full member
Activity: 168
Merit: 100
November 19, 2013, 04:34:29 AM
#12
Quick Response code. The data you transmit is encoded in a picture.
legendary
Activity: 1890
Merit: 1086
Ian Knowles - CIYAM Lead Developer
November 19, 2013, 04:31:32 AM
#11
If that argument is allowed, then why should it not be possible through the camera. An adversary generates a "magic" QR code (same as the magic audio or USB hijack), which causes the camera to create some sort of malicious code that causes the offline computer to be infected.

All of them are a far stretch, which is the point I was trying to make.

There is no "code" transmitted via QR - just an unsigned raw tx (which you can check before signing).

So it is not a question of malicious code - there is *no code* at all.
full member
Activity: 168
Merit: 100
November 19, 2013, 04:23:58 AM
#10
Well, the argument is that somehow the USB or sound card can be manipulated for code injection.

If that argument is allowed, then why should it not be possible through the camera. An adversary generates a "magic" QR code (same as the magic audio or USB hijack), which causes the camera to create some sort of malicious code that causes the offline computer to be infected.

All of them are a far stretch, which is the point I was trying to make.
legendary
Activity: 1890
Merit: 1086
Ian Knowles - CIYAM Lead Developer
November 19, 2013, 04:23:33 AM
#9
QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

I use an old e-book that has a built in "slideshow" function for all the photos in a directory - currently am only using it with my offline computer (to move new addresses to the online computer) but am thinking of buying another one for the online computer (as they are dirt cheap devices).
legendary
Activity: 3598
Merit: 2386
Viva Ut Vivas
November 19, 2013, 04:16:27 AM
#8
USBs carrying viruses has been known.

Burn CDs from offline wallets to move private keys for spending.
legendary
Activity: 1890
Merit: 1086
Ian Knowles - CIYAM Lead Developer
November 19, 2013, 04:07:21 AM
#7
The offline computer wouldn't trust the online computer.   The online computer is simply used for blockchain data and to broadcast the offline signed transaction. 

Exactly - I use QR codes for the CIYAM Safe and it does feel a lot safer to be completely "air-gapped".
donator
Activity: 1218
Merit: 1079
Gerald Davis
November 19, 2013, 04:06:14 AM
#6
I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

You mean for offline transactions (e.g. Armory)? While it would be a nice feature, it feels more like security by obscurity. Nothing prevents an adversary to manipulate the sent QR codes, if the online computer is compromised.

The offline computer wouldn't trust the online computer.   The online computer is simply used for blockchain data and to broadcast the offline signed transaction.  
legendary
Activity: 1834
Merit: 1094
Learning the troll avoidance button :)
November 19, 2013, 04:05:58 AM
#5
Wow BIOS
NO ONE Edit
Brilliant Smiley
But seems almost April fools like on Halloween XD
Then again if it is real this is interesting no known defense but computer silence
full member
Activity: 168
Merit: 100
November 19, 2013, 04:04:09 AM
#4
I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

You mean for offline transactions (e.g. Armory)? While it would be a nice feature, it feels more like security by obscurity. Nothing prevents an adversary to manipulate the sent QR codes, if the online computer is compromised.
donator
Activity: 1218
Merit: 1079
Gerald Davis
November 19, 2013, 03:59:51 AM
#3
I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

full member
Activity: 168
Merit: 100
November 19, 2013, 03:54:59 AM
#2
Rumor has it properly disinfecting the usb port helps prevent spread!

Jokes aside, there is a difference to what is theoretically could be possible, and what really is.
Jump to: