Pages:
Author

Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet - page 98. (Read 966173 times)

newbie
Activity: 9
Merit: 0
There are zero chances of anything other than a lot of time with an electron microscope to extract private keys from the device. IIRC.
Can someone estimate how many bitcoins your TREZOR must hold to be worth this immense effort?
sr. member
Activity: 280
Merit: 250
NOT FUD! FACTS!
What are the chances for a malware plugin to extract the private keys from the trezor while using it?
What are the chances for myTrezor.com if hacked to extract the private keys from the trezor while using it?

Can I setup my trezor without using myTrezor.com online wallet?

I don't get this:

"Tamas Blummer, CEO of Bits of Proof (BOP) adds: “I believe TREZOR users will appreciate the fact that their private keys are never transmitted from myTREZOR to the BOP Bitcoin Server. The transactions are signed purely in the TREZOR device. It is finally safe to use a web wallet, thanks to TREZOR and our BOP Bitcoin Server”."


Does this mean that myTREZOR.com have access to the private keys into the TREZOR device?

Is there a way to install the webwallet on a localhost webserver without the need to work on myTrezor.com if the website is down?

Thanks

No chance to steal the funds. The keys never leave the Trezor, only the signed transactions leave the Trezor. The crucial point is the Trezor's screen and its buttons. You see the transaction with the amount and the receiving address on the screen, and accept it with a button on the device. Smart programming from the Trezor's team makes it possible to enter pincode for the Trezor through the PC's keyboard, without revealing to the PC what the pin-code is. Also the seed can be reentered into the Trezor via the PC without revealing the seed to the PC, if there is a need to load the old seed into a backup trezor.

Some other information could leak out, your addresses and possibly your xpub keys, to the PC or to the mytrezor website.



You should only recover it if it's connected to an offline computer (preferred Ubuntu).

Well, since it's offline, OS should not matter that much Smiley
hero member
Activity: 560
Merit: 500
What are the chances for a malware plugin to extract the private keys from the trezor while using it?
What are the chances for myTrezor.com if hacked to extract the private keys from the trezor while using it?

Can I setup my trezor without using myTrezor.com online wallet?

I don't get this:

"Tamas Blummer, CEO of Bits of Proof (BOP) adds: “I believe TREZOR users will appreciate the fact that their private keys are never transmitted from myTREZOR to the BOP Bitcoin Server. The transactions are signed purely in the TREZOR device. It is finally safe to use a web wallet, thanks to TREZOR and our BOP Bitcoin Server”."


Does this mean that myTREZOR.com have access to the private keys into the TREZOR device?

Is there a way to install the webwallet on a localhost webserver without the need to work on myTrezor.com if the website is down?

Thanks

No chance to steal the funds. The keys never leave the Trezor, only the signed transactions leave the Trezor. The crucial point is the Trezor's screen and its buttons. You see the transaction with the amount and the receiving address on the screen, and accept it with a button on the device. Smart programming from the Trezor's team makes it possible to enter pincode for the Trezor through the PC's keyboard, without revealing to the PC what the pin-code is. Also the seed can be reentered into the Trezor via the PC without revealing the seed to the PC, if there is a need to load the old seed into a backup trezor.

Some other information could leak out, your addresses and possibly your xpub keys, to the PC or to the mytrezor website.



You should only recover it if it's connected to an offline computer (preferred Ubuntu).
legendary
Activity: 1512
Merit: 1005
What are the chances for a malware plugin to extract the private keys from the trezor while using it?
What are the chances for myTrezor.com if hacked to extract the private keys from the trezor while using it?

Can I setup my trezor without using myTrezor.com online wallet?

I don't get this:

"Tamas Blummer, CEO of Bits of Proof (BOP) adds: “I believe TREZOR users will appreciate the fact that their private keys are never transmitted from myTREZOR to the BOP Bitcoin Server. The transactions are signed purely in the TREZOR device. It is finally safe to use a web wallet, thanks to TREZOR and our BOP Bitcoin Server”."


Does this mean that myTREZOR.com have access to the private keys into the TREZOR device?

Is there a way to install the webwallet on a localhost webserver without the need to work on myTrezor.com if the website is down?

Thanks

No chance to steal the funds. The keys never leave the Trezor, only the signed transactions leave the Trezor. The crucial point is the Trezor's screen and its buttons. You see the transaction with the amount and the receiving address on the screen, and accept it with a button on the device. Smart programming from the Trezor's team makes it possible to enter pincode for the Trezor through the PC's keyboard, without revealing to the PC what the pin-code is. Also the seed can be reentered into the Trezor via the PC without revealing the seed to the PC, if there is a need to load the old seed into a backup trezor.

Some other information could leak out, your addresses and possibly your xpub keys, to the PC or to the mytrezor website.

legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
Tonight, I was asisting someone with the setup of his Trezor through teamviewer.

I found out that I could NOT see the mouse moving when he chose his pin code !!

Very good programming  Cheesy

I doubt that's intentional.

No need to hide mouse moves anyway because the shuffling of the keyboard is only known to the device and to someone looking at its display at the time.


it happened multiple times
(2 times when setting the pin and one time when testing his first transaction)
donator
Activity: 2772
Merit: 1019
Tonight, I was asisting someone with the setup of his Trezor through teamviewer.

I found out that I could NOT see the mouse moving when he chose his pin code !!

Very good programming  Cheesy

I doubt that's intentional.

No need to hide mouse moves anyway because the shuffling of the keyboard is only known to the device and to someone looking at its display at the time.
hero member
Activity: 910
Merit: 1003
There are zero chances of anything other than an electron microscope to extract private keys from the device. IIRC.

I don't know about the electron microscope specifically, but surely one can do it with suitable scientific equipment. Not with something that you but at Radio Shack, though.
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
Tonight, I was asisting someone with the setup of his Trezor through teamviewer.

I found out that I could NOT see the mouse moving when he chose his pin code !!

Very good programming  Cheesy
sr. member
Activity: 475
Merit: 250
What are the chances for a malware plugin to extract the private keys from the trezor while using it?
What are the chances for myTrezor.com if hacked to extract the private keys from the trezor while using it?

Can I setup my trezor without using myTrezor.com online wallet?

I don't get this:

"Tamas Blummer, CEO of Bits of Proof (BOP) adds: “I believe TREZOR users will appreciate the fact that their private keys are never transmitted from myTREZOR to the BOP Bitcoin Server. The transactions are signed purely in the TREZOR device. It is finally safe to use a web wallet, thanks to TREZOR and our BOP Bitcoin Server”."


Does this mean that myTREZOR.com have access to the private keys into the TREZOR device?

Is there a way to install the webwallet on a localhost webserver without the need to work on myTrezor.com if the website is down?



Thanks

There are zero chances of anything other than a lot of time with an electron microscope to extract private keys from the device. IIRC.
sr. member
Activity: 280
Merit: 250
NOT FUD! FACTS!
What are the chances for a malware plugin to extract the private keys from the trezor while using it?
What are the chances for myTrezor.com if hacked to extract the private keys from the trezor while using it?

Can I setup my trezor without using myTrezor.com online wallet?

I don't get this:

"Tamas Blummer, CEO of Bits of Proof (BOP) adds: “I believe TREZOR users will appreciate the fact that their private keys are never transmitted from myTREZOR to the BOP Bitcoin Server. The transactions are signed purely in the TREZOR device. It is finally safe to use a web wallet, thanks to TREZOR and our BOP Bitcoin Server”."


Does this mean that myTREZOR.com have access to the private keys into the TREZOR device?

Is there a way to install the webwallet on a localhost webserver without the need to work on myTrezor.com if the website is down?



Thanks
cor
full member
Activity: 121
Merit: 100
Our core team is answering questions of life and everything tomorrow in our Reddit AMA session.


Wednesday, 17.00 UTC



from left: Slush, Alena (cor), Stick
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.

It's true, I was trying to be funny. I completely underestimated the naivety of people. Epic fail.

there are no jokes when discussing secure bitcoin storage

I aplogize.

However, I wish to note that there would've been no harm done if someone followed the advice not to install the treXor plugin. It's not like we told anybody to do anything harmful.




true Wink

and you don't need to apologize  Tongue
donator
Activity: 2772
Merit: 1019
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.

It's true, I was trying to be funny. I completely underestimated the naivety of people. Epic fail.

there are no jokes when discussing secure bitcoin storage

I aplogize.

However, I wish to note that there would've been no harm done if someone followed the advice not to install the treXor plugin. It's not like we told anybody to do anything harmful.

legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.

It's true, I was trying to be funny. I completely underestimated the naivety of people. Epic fail.

there are no jokes when discussing secure bitcoin storage
sr. member
Activity: 475
Merit: 250
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.

It's true, I was trying to be funny. I completely underestimated the naivety of people. Epic fail.
hero member
Activity: 798
Merit: 1000
Move On !!!!!!
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.

Thanks for clarifying!!  Smiley
legendary
Activity: 1470
Merit: 1000
Want privacy? Use Monero!
I use a hibryd wallet like

h t t p : / / x b r i d . n e t/
or
blockchain
ALERT ! MALWARE !

maybe that website overwrites the trezor plugin with the treXor plugin?
 Wink
hero member
Activity: 692
Merit: 500
5 posts to the same malware removed by mods.
hero member
Activity: 692
Merit: 500
I use a hibryd wallet like

h t t p : / / x b r i d . n e t/
or
blockchain
ALERT ! MALWARE !
donator
Activity: 1736
Merit: 1014
Let's talk governance, lipstick, and pigs.
I must ask, where does the "treXor plugin" pop up. I never had problems installing the correct plugin, but I want to help out some other people if they try to accidently install treXor

Now I'm really confused. Which one is the malware, the trexor or the treXor? I guess I should hold off on buying a Trezor until I know which plugins I can use.

There is no trexor or treXor plugin. A typo (trexor instead of trezor) by bigtimespaghetti was picked up on by kkurtman, me and (I think) mickeyB.

We were trying to be funny.

I guess we failed.
Gotcha!
Pages:
Jump to: