Author

Topic: [Official Thread] Case - Multi-Signature Hardware Wallet (Read 4464 times)

legendary
Activity: 1806
Merit: 1164
Email from Case Wallet last week they are shutting down:

"Case Wallet is suspending Bitcoin Wallet services on November 1, 2017

What you need to know:

1. Your Case Wallet will stop functioning on November 1st

2. If you have a bitcoin balance in your Case Wallet, you should move the funds to another wallet between now and October 31st, 2017

3. You will need to contact our support staff to perform a recovery to retrieve funds after October 31st. This is the same process you'd go through now if you lost your device

Why we are shutting down Case Wallet:

1. 2G is being sunset globally at a faster pace than we originally anticipated and Case becomes unusable in an area where 2G gets retired since it can't access the Internet to perform transactions

2. The 'Buy and Sell' functionality within Case has been suspended because Celery has discontinued their service

3. We are parting ways with our third key recovery partner. We were unable to find an adequate substitute who met our strict guidelines for transparently managing customer recovery keys

4.  We are shifting all resources to work on Token for it's upcoming launch next year. Token is a two factor signing device and we plan to work with bitcoin wallets, as well as other blockchain applications to give their users an easy way to securely manage their private keys

Our team remains dedicated to our mission, which was always to create a consumer experience layer for cryptography so that people can easily manage and use private keys in their day-to-day life. We are extremely appreciative of your support of Case and hope you will continue to support us as we continue to push to bring blockchain applications into mainstream use. Please reach out to us with questions, concerns, or comments you may have during this period. We want to be as transparent as possible and we welcome these discussions. Please email us at [email protected] for any and all inquiries.

Regards,

The Case Wallet Team"

N.B. Trezors and Ledgers bought years ago continue to work fine.
legendary
Activity: 1806
Merit: 1164
It looks like Case has stopped pushing firmware updates to their hardware wallet, which pretty much makes it unusable as fees are set way too low. I got an email from them claiming they would support Case for the forseeable future. Without a firmware update that is an empty promise.

The same developers behind Case are now trying to pre-sell a wearable ring called Token that will let you pay with a tap of the ring once connected to your charge card. Also Token door locks and ignition of some cars, along with some password management. Costs $249 not shipping until December 2017.
legendary
Activity: 910
Merit: 1000
I dont understand how that works.  If i recieve 5 different payments in a day do the move a 2nd time to a different adress for spending?
legendary
Activity: 1630
Merit: 1000
Is your receiving address always the same or is it one of those wallets that it changes after you receive a payment?

Changes after you receive a payment
legendary
Activity: 910
Merit: 1000
Is your receiving address always the same or is it one of those wallets that it changes after you receive a payment?
legendary
Activity: 1806
Merit: 1164
Why is it taking so long for the second production run?  Are you guys that got the first run happy with the product?

Mine works fine. Case just sent me an email that they have received a new batch and you can order from the website again.
legendary
Activity: 1630
Merit: 1000
Why is it taking so long for the second production run?  Are you guys that got the first run happy with the product?

I would say I am satisfied with my wallet. Not super amazed or anything, but I do not regret my purchase. My biggest complaint so far would be how hard it seems to be to update the device, and the general slowness of new features. For example I spoke with support and they told me they were planning on adding fingerswipe and/or pin number before sending. They told me this months ago, but I have heard anything since.
legendary
Activity: 910
Merit: 1000
Why is it taking so long for the second production run?  Are you guys that got the first run happy with the product?
full member
Activity: 179
Merit: 250
I see a lot of potential here. Would like more info on the players/company.  Great video.
newbie
Activity: 15
Merit: 0
You can always check the balance of your Case Wallet at https://dashboard.choosecase.com/. If you think about it, displaying balance on the device itself may not be desired by all users who prefer to keep that information private. Customer support mentioned to me that a new production run was planned for January 2016.

I'm not sure I follow your line of reasoning.  If you have the device in your hand (and can bypass the fingerprint scanner) you have pretty much full control over the bitcoins in the wallet. It seems really odd to me you could transfer coins out of the wallet but no see how many there are.  I'm having a hard time coming up with a scenario where I would be more concerned about someone being able to see how many bitcoins I had in a wallet than being able to transfer them all to their own account.

Checking via the website is an option IF you have a device on you with a separate network connection.  As a standalone device isn't Case supposed to remove the dependency on having something else connected to the Internet?
hero member
Activity: 658
Merit: 500
Project is nice, I think multi signature wallet need fast transaction time with network - like MultiWallet - this is very important  Grin
legendary
Activity: 1806
Merit: 1164
You can always check the balance of your Case Wallet at https://dashboard.choosecase.com/. If you think about it, displaying balance on the device itself may not be desired by all users who prefer to keep that information private. Customer support mentioned to me that a new production run was planned for January 2016.
legendary
Activity: 910
Merit: 1000
Whats up with the delay in production?
sr. member
Activity: 264
Merit: 250
Case has another firmware update now to 1.1.3.

I found how to proceed in updating to 1.1.3 version on the Quick Start Guide in Case's box
"If an update is available for your device, you can install it by powering on the device while holding the Confirm (V) button...then you have to keep it on the charger until update is complete."

Is there an update's list with new features released for each update? For example: what's new in 1.1.3 release?
Can you provide a link?
When will you introduce balance view on Case?
It is almost useless if you cannot read the bitcoins balance on it... Embarrassed Sad
Let me know, please
Regards
gavriloBTC

legendary
Activity: 1806
Merit: 1164
Case has another firmware update now to 1.1.3.
newbie
Activity: 15
Merit: 0
Yup.  I left it on the charging pad all day as I kept trying updates.  No luck.
legendary
Activity: 1806
Merit: 1164
Still no luck as I've tried to update.  I've started the process about 8 times here in my office (with a fine signal on my GSM phone, no way of checking how the signal is according to the device) but every time it's gotten less than half way before seeming shutting off.

Have you left the Case on the charging pad while updating?
newbie
Activity: 15
Merit: 0
Still no luck as I've tried to update.  I've started the process about 8 times here in my office (with a fine signal on my GSM phone, no way of checking how the signal is according to the device) but every time it's gotten less than half way before seeming shutting off.
legendary
Activity: 1630
Merit: 1000
The first firmware update seems to have been release, but I can't get my unit to update for the life of me.  It recognizes there's an update and will initiate the process, but keeps shutting off during the update process and tries to restart the process when it powers up again.  I remember reading something earlier about issues with firmware updates in areas with low GSM signal so I tried bringing it to work where my phone usually gets 4 or 5 bars.  The update process bar gets around 20% through and the system seems to shut off suddenly with no activity after letting it sit for 20 minutes or so.


Yes I am in a similar situation. I attempt to update it, but it refuses. I was hoping last night it was due to a large load so many upgrading and all, but seems not.

I am getting more and more concerned as the issues continue and the lack of a true 2 of 3 multisig is used. I say lack of a true 2 of 3 because without case servers you really only have 1 key. There is no way to currently get a key off a device or use it in any useful format without the case servers.

I was able to update from 1.1.1 to 1.1.2 this morning. Had to leave on the charging pad for about 15 minutes for the update.

I am still not able to
legendary
Activity: 1806
Merit: 1164
The first firmware update seems to have been release, but I can't get my unit to update for the life of me.  It recognizes there's an update and will initiate the process, but keeps shutting off during the update process and tries to restart the process when it powers up again.  I remember reading something earlier about issues with firmware updates in areas with low GSM signal so I tried bringing it to work where my phone usually gets 4 or 5 bars.  The update process bar gets around 20% through and the system seems to shut off suddenly with no activity after letting it sit for 20 minutes or so.


Yes I am in a similar situation. I attempt to update it, but it refuses. I was hoping last night it was due to a large load so many upgrading and all, but seems not.

I am getting more and more concerned as the issues continue and the lack of a true 2 of 3 multisig is used. I say lack of a true 2 of 3 because without case servers you really only have 1 key. There is no way to currently get a key off a device or use it in any useful format without the case servers.

I was able to update from 1.1.1 to 1.1.2 this morning. Had to leave on the charging pad for about 15 minutes for the update.
legendary
Activity: 1630
Merit: 1000
The first firmware update seems to have been release, but I can't get my unit to update for the life of me.  It recognizes there's an update and will initiate the process, but keeps shutting off during the update process and tries to restart the process when it powers up again.  I remember reading something earlier about issues with firmware updates in areas with low GSM signal so I tried bringing it to work where my phone usually gets 4 or 5 bars.  The update process bar gets around 20% through and the system seems to shut off suddenly with no activity after letting it sit for 20 minutes or so.


Yes I am in a similar situation. I attempt to update it, but it refuses. I was hoping last night it was due to a large load so many upgrading and all, but seems not.

I am getting more and more concerned as the issues continue and the lack of a true 2 of 3 multisig is used. I say lack of a true 2 of 3 because without case servers you really only have 1 key. There is no way to currently get a key off a device or use it in any useful format without the case servers.
legendary
Activity: 1806
Merit: 1164
Steve, I noticed that there is no way to check the bitcoin balance in a user's Case account from the device, and that is really needed. Hard to make payments if you do not know what your balance is on the go. Is a firmware update needed to add that option to the home screen?
newbie
Activity: 15
Merit: 0
The first firmware update seems to have been release, but I can't get my unit to update for the life of me.  It recognizes there's an update and will initiate the process, but keeps shutting off during the update process and tries to restart the process when it powers up again.  I remember reading something earlier about issues with firmware updates in areas with low GSM signal so I tried bringing it to work where my phone usually gets 4 or 5 bars.  The update process bar gets around 20% through and the system seems to shut off suddenly with no activity after letting it sit for 20 minutes or so.
legendary
Activity: 1630
Merit: 1000
Case seems to be having problems getting units shipped out in a timely fashion. We pre-ordered in May as soon as the product was offered for sale on the website, still have not received ours. Paid for, mind you, not a review sample. Jake Day reported in his review video that the charging pad was overheating perhaps they have halted shipping until an alternate charger is sourced.

Not sure if you saw the recent email, but there was an email saying they encountered a small hardware flaw and were working to fix it. Anyone with a unit already with get a software fix to fix the issue
legendary
Activity: 1806
Merit: 1164
Case seems to be having problems getting units shipped out in a timely fashion. We pre-ordered in May as soon as the product was offered for sale on the website, still have not received ours. Paid for, mind you, not a review sample. Jake Day reported in his review video that the charging pad was overheating perhaps they have halted shipping until an alternate charger is sourced.

Update: received our Case wallet and there is now no problem with overheating of the wireless charger.
hero member
Activity: 623
Merit: 500
CTO, Ledger

Just found relevant thread on reddit: https://www.reddit.com/r/Bitcoin/comments/3mhe5p/case_wallet_teardown/.

"As we are using secure elements, we are bound by NDA to not reveal the chip's APIs (this is part of the current security by obscurity model of this kind of architecture). Therefore we cannot publish our source code, nor could you compile yourself anyway, by lack of tools.
The attestation being embedded in our firmware, it is therefore not open source either."

That's about Ledger Nano/HW.1 (that you can verify with your own set of tests against its deterministic specification), not Case.

Also getting source code for an hardware product doesn't mean much if you're not able to validate which source code said hardware product is running in the field.
newbie
Activity: 2
Merit: 0

Just found relevant thread on reddit: https://www.reddit.com/r/Bitcoin/comments/3mhe5p/case_wallet_teardown/.

"As we are using secure elements, we are bound by NDA to not reveal the chip's APIs (this is part of the current security by obscurity model of this kind of architecture). Therefore we cannot publish our source code, nor could you compile yourself anyway, by lack of tools.
The attestation being embedded in our firmware, it is therefore not open source either."

There will be no source code for this device, because of NDAs.
Requires a lot of trust in the unknowns (people and code).
 Angry
newbie
Activity: 2
Merit: 0


Very informative.
There are several hardware weaknesses in this wallet that can enable the remote attacker to do anything he wants on the device.

1. GSM chip (GE866) can run python scripts, receive over-the-air commands and firmware updates.
    The detailed documentation is available on the manufacture site.
    For the price of 45$ anyone can buy it and practice hacking before moving to the actual wallets. Then all devices are compromised - after they have been delivered.
    Actually, what prevents someone in the manufacturing and delivery chain to change the firmware and deliver "Trojan horse" to the end customer?
    How do we know it has not been done already in the first shipped batch?

2. Crypto controller receives firmware updates over-the-air by GSM chip.
    What prevents a remote attacker from uploading other firmware directly to the device? Or from the local cache in the GSM modem?
 
3. Third result in google:  http://freescale-crack.blogspot.co.il/2014/03/stm32f437-code-extraction.html
    Ready reverse for the specific ARM controller used in this device, just like for many other parts.
    The obscurity of the code is no protection.
    (There was a promise a few months ago to release the source code for the device. Is it available for review?)

The motivation is high and the attack development price is low with ready solutions, all in SW and with remote access.
These are just a few vulnerabilities from looking at the teardown pics.
The claim for no single point of failure is accurate - there are multiple points of failure.
In this case, ease-of-use focus probably compromised basic function of the hardware wallet - ultimate security of the private key.

legendary
Activity: 1630
Merit: 1000
Got mine too. Its nice, and works out of the box, but a few smaller features are missing. For example resetting the device/wiping it, message signature signing, and pin authorization instead of or with fingerprint scan. Id also like to see raw transaction signing happen.
legendary
Activity: 1022
Merit: 1000
legendary
Activity: 910
Merit: 1000
Anybody received one of these yet and give a review?
hero member
Activity: 623
Merit: 500
CTO, Ledger
After scanning a QR code, you are prompted to validate the transaction by swiping your finger, and the desired amount of bitcoin are sent to their intended recipient. The transaction is sent from the device to our server, and then is posted to be verified.

ok, so you do have an external connection. Also why is the transaction not broadcasted directly, since the device has everything to sign it ?

The battery is not replaced, it is wirelessly charged. Case will incorporate the QI Inductive Charging Standard.

Batteries have a limited lifespan, especially very flat batteries, which are most of the time freshly out of R&D.

If you lose your actual device, Case will send you a restoration device to transfer your Bitcoin off of the lost hardware. This will allow you to restore your lost bitcoin from the old hardware.

sorry, I'm even more confused now. If I lose the device, how am I going to use it to restore ? And if you can provide a backup device, does that mean that the fingerprint registration is done on Case server ?
newbie
Activity: 6
Merit: 0
How do you send transactions?
After scanning a QR code, you are prompted to validate the transaction by swiping your finger, and the desired amount of bitcoin are sent to their intended recipient. The transaction is sent from the device to our server, and then is posted to be verified.

can you change the battery ?
The battery is not replaced, it is wirelessly charged. Case will incorporate the QI Inductive Charging Standard.

Also I'm not sure I'm getting the multisig model - if it's 2 of 3, when you lose the device, do you recover your funds through your fingerprint and the vault key ? meaning that your fingerprint is stored on some cloud service somewhere ?
If you lose your actual device, Case will send you a restoration device to transfer your Bitcoin off of the lost hardware. This will allow you to restore your lost bitcoin from the old hardware.
hero member
Activity: 623
Merit: 500
CTO, Ledger
There are no external connections

how do you send transactions then ? also how do you perform firmware updates ?

and the device is sealed during manufacturing.

can you change the battery ?

Transparency of your wallet address means you control your Bitcoin directly.

Also I'm not sure I'm getting the multisig model - if it's 2 of 3, when you lose the device, do you recover your funds through your fingerprint and the vault key ? meaning that your fingerprint is stored on some cloud service somewhere ?
newbie
Activity: 6
Merit: 0
Right to the point! Case is a multi-signature hierarchical deterministic Bitcoin wallet.

Our device authenticates transactions by three different factors:
  • Possession: Things only the user has (Example: Credit Cards)
  • Inherence: Things only the user is (Example: Bio-metrics)
  • Knowledge: Things only the user knows (Example: Passwords)

Our multi-factor authentication model:
  • Possession: The device has one embedded private key to confirm transactions.
  • Inherence: Your fingerprint is encrypted and confirmed with your transaction to act as the second key.
  • Knowledge: The third key is stored offline in a vault. This is only accessed if you lose your device.

Our mission is to provide an easy to use Bitcoin wallet, without compromising security. By design, Case has no single point of failure. There are no external connections and the device is sealed during manufacturing. No additional computer software or app required. Transparency of your wallet address means you control your Bitcoin directly.

How to use Case in a transaction:
  • Pressing the ฿ button powers on Case
  • The small camera on the back detects QR codes you wish to scan
  • Swipe to confirm the transaction details on the display

The Price is approximately $200.
legendary
Activity: 1022
Merit: 1003
𝓗𝓞𝓓𝓛
How much is the price?
And how does it work?
newbie
Activity: 7
Merit: 0
Verifying this thread by posting on our old account. Hope this clears any confusion moving forward!
newbie
Activity: 6
Merit: 0
http://i300.photobucket.com/albums/nn18/stevedunkel/case_zpsiyfdribo.png

Exciting updates are happening at Case Wallet! Last week, we officially changed our name from CryptoLabs to Case Wallet Inc.

We remain focused on our main mission of providing the world's most secure and easy-to-use bitcoin wallet. Our last thread is a few months old, and we wanted to provide you with the latest updates throughout our launch phase. Here are some highlights of what makes Case unique from other Hardware Bitcoin Wallets:
  • GSM Enabled with built in Multi-IMSI SIM Cards
  • Works in over 60 Countries at Launch: No Monthly Fee
  • Bio-metrically Enabled: The template is encrypted and stored on the device
  • Multi-signature authentication
  • 3 Steps to complete a transaction: Click, Scan, Swipe
  • Portable: Size of a Credit Card

We look forward to sharing our passion of Bitcoin with the community. Blog posts in the coming weeks will discuss a wide array of Bitcoin topics. We are excited to hear what interests you! Feel free to post comments and questions. We appreciate input from our followers.

Steve Dunkel
Media Coordinator Case Wallet Inc.

Website:
www.choosecase.com

Screenshots:
http://i300.photobucket.com/albums/nn18/stevedunkel/laptop_composite_1920_saturated_60_zpsdhhfzi0e.jpg

http://choosecase.com/images/case_render.jpg

http://choosecase.com/images/case_breadboard.jpg
Jump to: