Pages:
Author

Topic: My new TREZOR - page 4. (Read 21350 times)

legendary
Activity: 2212
Merit: 1199
April 02, 2014, 08:11:17 PM
#61
I don't have any financial relationship or otherwise with SatoshiLabs, other than the pre-order I made, which is now delivered. It's just a project I think is important.


Thanks. I agree TREZOR, and other user-friendly hardware wallets, are for me the most pressing bottleneck for bitcoin adoption.

Good work all around guys!

Yes well those devices helps people of Bitcoin a lot. This is totally true!

Trezor is very good project and device (I hope - time will compare:P) and I believe it is a future of Bitcoin too!
legendary
Activity: 3920
Merit: 2349
Eadem mutata resurgo
April 02, 2014, 07:06:36 PM
#60
I don't have any financial relationship or otherwise with SatoshiLabs, other than the pre-order I made, which is now delivered. It's just a project I think is important.


Thanks. I agree TREZOR, and other user-friendly hardware wallets, are for me the most pressing bottleneck for bitcoin adoption.

Good work all around guys!
legendary
Activity: 2800
Merit: 1115
Leading Crypto Sports Betting & Casino Platform
April 02, 2014, 06:37:13 PM
#59
That is cool I wanted a trezor but then they sold out of course they open sourced it for people to get later
But I will wait for a batch 2  Grin

Are there theme'able devices in the roadmap? I'd kill for a red and white Hello Kitty one =^).

that's sweet  Grin if there's enough hello kitty lovers we could make it possible...

O_O I would buy a batch of Gundam Themed ones Smiley
sr. member
Activity: 406
Merit: 252
April 02, 2014, 06:14:35 PM
#58
Any more information on this?

Awesome development—truly!

Keep up the amazing work.  Smiley
cor
full member
Activity: 121
Merit: 100
April 02, 2014, 05:26:22 PM
#57
Are there theme'able devices in the roadmap? I'd kill for a red and white Hello Kitty one =^).

that's sweet  Grin if there's enough hello kitty lovers we could make it possible...
legendary
Activity: 2212
Merit: 1199
April 02, 2014, 04:18:55 PM
#56
Soon trezor should think about "trezor watch" - that could be a great idea Tongue
legendary
Activity: 1974
Merit: 1029
April 02, 2014, 03:41:04 PM
#55
Are there theme'able devices in the roadmap? I'd kill for a red and white Hello Kitty one =^).
sr. member
Activity: 441
Merit: 266
April 02, 2014, 03:20:14 PM
#54
Well, one of my fears (perhaps unfounded) is that a tampered device will ignore my randomly generated input seed, and instead use some kind of weak method for generating the master private key.

That is a valid concern. What TREZOR does is that it shows its internal entropy on display (if asked to) before requesting an external one. Once provided, these two entropies are mixed (using hash) and you can verify that external was used and not omitted.
legendary
Activity: 1008
Merit: 1000
April 02, 2014, 02:51:13 PM
#53
The risk with a backdoored TREZOR is not that it generates public/private keys incorrectly (which is what the BIP32 test vectors test). It's that it can leak the private keys/seed via some side channel, or can be told to sign transactions bypassing the usual user confirmation logic.

For leaking private keys via side channels, there are virtually none available, except the ECDSA k value. Deterministic ECDSA is the solution to this. A backdoor that allows the computer to tell the device to empty itself out cannot really be defended against easily, because it's hard to know what software the device is truly running, but the reputation of the creators is sufficient to give good assurance for genuine/unmodified TREZORs. In future software remote attestation techniques might be interesting.

Well, one of my fears (perhaps unfounded) is that a tampered device will ignore my randomly generated input seed, and instead use some kind of weak method for generating the master private key. If all of the algorithms are published however, I should be able to test whether the device is using the input seed as intended right? (i.e., compare the master public key generated on my laptop using the same algorithm as the public key generated by the trezor, where both used the same input seed).

Just to clarify, when I say "seed" what I really mean is the random data (dice rolls or whatever) that are used as a source of entropy.
legendary
Activity: 2212
Merit: 1199
April 02, 2014, 02:13:57 PM
#52



Yes it looks lovely! Smiley after all that delays it should looks and works great Smiley

I hope you will enjoy using Trezor!

Regards!

legendary
Activity: 1526
Merit: 1129
April 02, 2014, 02:11:40 PM
#51
The risk with a backdoored TREZOR is not that it generates public/private keys incorrectly (which is what the BIP32 test vectors test). It's that it can leak the private keys/seed via some side channel, or can be told to sign transactions bypassing the usual user confirmation logic.

For leaking private keys via side channels, there are virtually none available, except the ECDSA k value. Deterministic ECDSA is the solution to this. A backdoor that allows the computer to tell the device to empty itself out cannot really be defended against easily, because it's hard to know what software the device is truly running, but the reputation of the creators is sufficient to give good assurance for genuine/unmodified TREZORs. In future software remote attestation techniques might be interesting.
legendary
Activity: 1008
Merit: 1000
April 02, 2014, 02:05:53 PM
#50

Yes, Trezor supports bip32 "as they spec'd", it passes all test vectors and it has been tested also with other bip32-compatible software (Bits of proof server) that it generates same bip32 trees. No need to ask bitcoin core devs...

Shouldn't this also be a way to check for backdoors and/or whether the device has been tampered with? Wouldn't any change to the core part of the firmware result in getting different answers with the test vectors?

I hope you don't mind my bumping this question, but I really want to know about how a back door or otherwise tampered electronic device could get around the test vectors? Or am I misunderstanding something fundamentally?
legendary
Activity: 1568
Merit: 1001
April 02, 2014, 01:25:52 PM
#49
Glad to see these finally are a go and yes, they look fantastic. Just curious as to when my pre-order (8-9-13) will arrive? Should also check your emails from time to time. Wink
legendary
Activity: 1386
Merit: 1097
April 02, 2014, 01:24:23 PM
#48
So the software is being installed from the device?

Trezor works as HID (mouse, keyboard) and does not need any system drivers. Device does not carry any desktop software (it would be security hole otherwise), but you can connect it with other software. Multibit and Armory teams are actively working on Trezor support. And in the meantime there's mytrezor.com, our webwallet talking to Trezor over browser plugin.
legendary
Activity: 1372
Merit: 1000
--------------->¿?
April 02, 2014, 12:52:22 PM
#47
So the software is being installed from the device?
legendary
Activity: 3654
Merit: 1217
April 02, 2014, 12:51:36 PM
#46
There are no third party vendors (as of now). If you have found any then you had found a scam.

Oh... so it is impossible for new users to obtain Trezors.  Angry
legendary
Activity: 1027
Merit: 1005
April 02, 2014, 12:43:52 PM
#45
Very cool, glad to see one in the 'wild'. Cant wait for them to open up ordering.
newbie
Activity: 37
Merit: 0
April 02, 2014, 12:28:55 PM
#44
show us some more shots how it works, how it looks when accessing through USB by PC etc. managment panel etc.


A video would be pretty great.  I've heard of TREZOR but really have no idea how it's supposed to work. 
legendary
Activity: 2296
Merit: 1014
April 02, 2014, 12:13:59 PM
#43
show us some more shots how it works, how it looks when accessing through USB by PC etc. managment panel etc.
sr. member
Activity: 441
Merit: 266
April 02, 2014, 10:00:07 AM
#42
Why is the confirm button on the right? General convention is that yes/confirm buttons are on the left

(reposting from reddit)

We always put "positive" actions (next, confirm, ok) on the right and "negative" on the left (previous, abort, cancel) button.
It makes sense when you realize that in order to confirm transaction you have to press "next" several times (for each output) and then "confirm". I guess you agree that putting Next on the left and Back on the right is not a good idea.
Pages:
Jump to: