Author

Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet - page 145. (Read 966173 times)

member
Activity: 70
Merit: 10
One thing I noticed though while restoring the seed while offline, the trezor never asked me to type in random words that werent part of my seed to throw off any keyloggers as it had done in the past, when i restored other seeds. its as if trezor knew I was on a secure computer.

Not true :-) We changed the behaviour in 1.2.1 firmware to "TREZOR always asks for 24 words" - i.e. asks for 0 fake words for 24 word mnemonic (was 12 fake words); asks for 6 fake words for 18 word mnemonic (was 9 words); asks for 12 fake words for 12 word mnemonic (was 6 fake words).

ah ok I was confused from when I was testing restoring the 12 and 18 word seeds. I restored a 24 word seed once before. Not sure why I didnt notice that it didnt have random words included while restoring it before.
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!

One thing I noticed though while restoring the seed while offline, the trezor never asked me to type in random words that werent part of my seed to throw off any keyloggers as it had done in the past, when i restored other seeds. its as if trezor knew I was on a secure computer.

When using a 24 word seed, no random words are added. I would be in favour of using at least a few random words. Restoring a seed is not a daily task, so typing in 24 or 36 words doesn't really matter to me...
sr. member
Activity: 441
Merit: 268
One thing I noticed though while restoring the seed while offline, the trezor never asked me to type in random words that werent part of my seed to throw off any keyloggers as it had done in the past, when i restored other seeds. its as if trezor knew I was on a secure computer.

Not true :-) We changed the behaviour in 1.2.1 firmware to "TREZOR always asks for 24 words" - i.e. asks for 0 fake words for 24 word mnemonic (was 12 fake words); asks for 6 fake words for 18 word mnemonic (was 9 words); asks for 12 fake words for 12 word mnemonic (was 6 fake words).
member
Activity: 70
Merit: 10
Does wiping the Trezor then restoring the seed in any way lessen the security of that particular seed? I feel a little uncomfortable moving my fortune onto the wallet without first testing that I can restore it. Before creating my final wallet, I did extensive testing with creating then restoring wallets with and without passwords. Even though I now feel like I am experienced, I feel an uneasy sense not testing the final wallet. What if somehow I wrote the seed down wrong or something. Is this just my O.C.D. messing with me? I would like to test it but I dont like the idea of typing my seed words of my final wallet into the computer either. I know there are a few other wallets that have you confirm that your wallet seed backup is good such as Electrum or Mycelium.

Yes it does. Not to the point of breakability, but it's less secure if keylogged: https://bitcointalksearch.org/topic/m.8243033
If you plan to test it, then it's a good idea to do it on a secure computer.


I think I figured out a method to test/restore the seed to the trezor with maintaining 100% security as before. Here is what I did:

1. I ran an Ubuntu live disk
2. While connected to the internet, I opened firefox then navigated to mytrezor.com and installed the plugin.
3. I then unplugged my ethernet cable insuring that I was no longer connected to the internet.
4.I then went back to the still open firefox tab containing mytrezor.com.
5. I wiped the trezor
6. I then proceeded to restore my seed while still disconnected from the internet.
7. When the seed was finally finished, i got an error on mytrezor.com claiming that the restore failed. I was thinking that it was saying this because it had no access to the internet to validate the wallet. So I plugged in my restored trezor to another computer and there it was, fully restored.
8. I then rebooted the computer that was running the live ubuntu cd before replugging my ethernet.

One thing I noticed though while restoring the seed while offline, the trezor never asked me to type in random words that werent part of my seed to throw off any keyloggers as it had done in the past, when i restored other seeds. its as if trezor knew I was on a secure computer.
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
the recovery procedure "helps" you with a drop down list of words. I don't really think it is needed to test. If somewhere in the future some usefull linux program is pubished so I can test it on my raspberry, I will probly do that (need to buy a second trezor first, because I don't want to move all the funds before wiping my Trezor)

But I'm pretty confident that I have done it correctly. I checked several times Tongue
donator
Activity: 2772
Merit: 1019
Does wiping the Trezor then restoring the seed in any way lessen the security of that particular seed? I feel a little uncomfortable moving my fortune onto the wallet without first testing that I can restore it. Before creating my final wallet, I did extensive testing with creating then restoring wallets with and without passwords.

I recommend testing the seed.

Here's a little story: I had a seed and quite a bit of money on my trezor. I had tested seed restore before, but hadn't tested that seed.

When I received my plastic trezors, I wanted to restore that seed to one of it as backup. Guess what: It wouldn't work. I tried roughly 5 times to restore the seed. Only after having moved the funds to a new seed and a couple of days later did I notice I was misreading my handwriting on one of the words.
donator
Activity: 2772
Merit: 1019
Why is payment only in Bitcoin?  Embarrassed

go buy some bitcoins (don't invest more than you can afford to lose)
full member
Activity: 120
Merit: 100
Does wiping the Trezor then restoring the seed in any way lessen the security of that particular seed? I feel a little uncomfortable moving my fortune onto the wallet without first testing that I can restore it. Before creating my final wallet, I did extensive testing with creating then restoring wallets with and without passwords. Even though I now feel like I am experienced, I feel an uneasy sense not testing the final wallet. What if somehow I wrote the seed down wrong or something. Is this just my O.C.D. messing with me? I would like to test it but I dont like the idea of typing my seed words of my final wallet into the computer either. I know there are a few other wallets that have you confirm that your wallet seed backup is good such as Electrum or Mycelium.

Yes it does. Not to the point of breakability, but it's less secure if keylogged: https://bitcointalksearch.org/topic/m.8243033
If you plan to test it, then it's a good idea to do it on a secure computer.
member
Activity: 70
Merit: 10
Does wiping the Trezor then restoring the seed in any way lessen the security of that particular seed? I feel a little uncomfortable moving my fortune onto the wallet without first testing that I can restore it. Before creating my final wallet, I did extensive testing with creating then restoring wallets with and without passwords. Even though I now feel like I am experienced, I feel an uneasy sense not testing the final wallet. What if somehow I wrote the seed down wrong or something. Is this just my O.C.D. messing with me? I would like to test it but I dont like the idea of typing my seed words of my final wallet into the computer either. I know there are a few other wallets that have you confirm that your wallet seed backup is good such as Electrum or Mycelium.
legendary
Activity: 2646
Merit: 1137
All paid signature campaigns should be banned.
Why is payment only in Bitcoin?  Embarrassed

You're kidding right?
No, he wants to pay in Zimbabweee dollars.
legendary
Activity: 1722
Merit: 1217
Why is payment only in Bitcoin?  Embarrassed

You're kidding right?
newbie
Activity: 15
Merit: 0
Why is payment only in Bitcoin?  Embarrassed
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).

I second this feature request.

me 2
you could add it on the home page together with "change label" and "change pin"
just add a checkbox and it's done Smiley

If you want to acces a password protected wallet, just check the box and "forget device", connect again and it's done.
If you want to acces the unprotected wallet, uncheck box, "forget device", connect again and it's done Smiley
sr. member
Activity: 408
Merit: 250
I do have Xcode and Brew. What should I do then? BTW, I'm also seeing people pointing out to python-trezor so that's yet another thing I'm trying to make sense out of it in addition to the Electrum plug-in for OS X.
Thx for your help.

I sucessfully installed Electrum 1.9.8 release from the github repo following the MacOSX instructions here
https://electrum.org/download.html

As you already have xcode and brew installed I assume you are comfortable with the command line !

I haven't yet tried the latest master with the Trezor commits as I am still awaiting my classic first edition to reach me.
https://github.com/spesmilo/electrum/commits/master

This plugin
https://github.com/m0mchil/electrum/blob/master/plugins/trezor.py

clearly requires python-trezor
https://github.com/trezor/python-trezor/tree/master/trezorlib

Code:
try:
    from trezorlib.client import types
    from trezorlib.client import proto, BaseClient, ProtocolMixin
    from trezorlib.qt.pinmatrix import PinMatrixWidget
    from trezorlib.transport import ConnectionError
    from trezorlib.transport_hid import HidTransport
    TREZOR = True
except ImportError:
    TREZOR = False

The webbrowser plugin is completely different, you need it to setup your Trezor with myTrezor (unless you want to setup/restore your Trezor with the python tools)

Are you referring to installing the Ubuntu's *Development version* and not the "Latest release" in that link?

Does your install process for OS X create any .app entries as well in your Applications folder. I was able to get Electrum wallet to start via command line only but couldn't locate the .app/.dmg file that the github *Developer version* README file refers to.

Does the python setup provide additional features not available in  myTrezor (order of change address spending, freeze, etc?)

In the long-run, I'd like to be able to restore access to all my private keys in the unlikely scenario Trezor completely ceases to exist or USB interface is discontinued.
legendary
Activity: 1498
Merit: 1000
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).

I second this feature request.


I second the feature request to have them ACTUALLY FIX THEIR WALLET so it ACTUALLY WORKS, but me and another person are the only ones that are having the trouble, no one actually cares about that feature.

Plus I want know why they were blaming bitcoin-lib js when that isn't the problem?
donator
Activity: 2772
Merit: 1019
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).

I second this feature request.
hero member
Activity: 527
Merit: 500
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).

What makes you think that the "no password" is the same wallet as an "empty password"? I doubt it is true. If you switched that flag, you would probably loose access to your "no password" account. Just reinitialize the device with the passphrase enabled.

1. It makes sense because the wallet is based on seed + password (probably put through some hashing functions).
2. I tried it  Smiley


edit: typo
full member
Activity: 120
Merit: 100
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).

What makes you think that the "no password" is the same wallet as an "empty password"? I doubt it is true. If you switched that flag, you would probably loose access to your "no password" account. Just reinitialize the device with the passphrase enabled.
hero member
Activity: 527
Merit: 500
Is there a way to toggle the "request-password"-flag in the trezor without reinitializing it?
As no-password results in the same wallet as an empy password it would be nice to be able to switch between the settings (without having to generate a new seed).
jr. member
Activity: 50
Merit: 1
stick, BurtW, molecular,

Thanks for providing the clarity on the multi-passphrase process.  I appreciate it.
Jump to: