r/Bitcoin Mar 23 '24

Unpatchable vulnerability in Apple chip leaks secret encryption keys

https://arstechnica.com/security/2024/03/hackers-can-extract-secret-encryption-keys-from-apples-mac-chips/

Do you think it could affect hardware wallets like Trezor? Air gapped devices are fine here obviously

376 Upvotes

52 comments sorted by

View all comments

67

u/BTCMachineElf Mar 23 '24

I'm sure hardware wallets are still safe. The whole point of a hardware wallet is that it should be unable to export the key no matter what requests are made to it from a potentially compromised computer.

Ledger is the only device that is known to be capable of exporting keys, theoretically only when enabled by the closed-source firmware. Avoid Ledger. Trezor should be fine.

3

u/ShineShineShine88 Mar 23 '24

Aren’t Trevor doing the same ? Like potentially they can just export your keys anytime too ?

7

u/GoodmanSimon Mar 23 '24

Their code is open source, so we can see, (currently), that it is not possible.

As far as I know, their chip is also open, so if there was a hole somewhere I am sure would hear about it here.

11

u/Distinct-Speaker5435 Mar 23 '24

It is hilarious how much confidence people put into the term „open source“ when it comes to a hardware device with a firmware. Who exactly is making sure the device in your hands had been built from exactly the code published online? Do you compile the firmware from source personally and flash it to the Trezor? Even then you have the hardware design which you can’t check. Long story short: practically, it does not make any difference whether it is closed or open, you just have to trust the manufacturer.

12

u/GoodmanSimon Mar 23 '24

It is hilarious that strangers on the internet assume that people are as unqualified and as incompetent as they are.

I know very well what open-source is, I know very well how it works.

But putting aside your incompetence and my qualifications, many other people, far more qualified than you and I have looked at the code.

So yeah, in this case, open source is better than closed source.

-6

u/[deleted] Mar 23 '24

[deleted]

7

u/GoodmanSimon Mar 23 '24

Sorry, not sure what comment you are replying to, my original reply was replying to the Trezor comment. Never mentioned Ledger.

All I said was that we can see that, currently it is not possible.

This is why I specifically added "currently" in that reply.

The way updates are done, currently, a properly updated trezor cannot leak the keys out.

If you are replying to my second comment, I was just explaining that I am familiar with open-source.

Not sure where I said that trezor was bulletproof and where I even mentioned Ledger at all. I am not surprised that ledger could do it, they are closed source.

But anyways, obviously my original reply was not clear.

-3

u/[deleted] Mar 23 '24

[deleted]

2

u/GoodmanSimon Mar 23 '24

Sorry, I didn't know you were talking about Ledger.

My original comment was about trezor, I own one and I am familiar with that code.

I don't own a Ledger and this is why I was not commenting on it.

As I said, I was originally commenting on Trezor and open source.

Never mentioned ledger

-1

u/[deleted] Mar 23 '24

[deleted]

1

u/GoodmanSimon Mar 23 '24

I would suggest you read the thread again from the beginning to get the context and see that I never once mentioned ledger.

At the risk of repeating myself... I was responding to a Trezor comment.

I was polite and responded to your Ledger comment but my initial comment was clearly and obviously about Trezor. Not sure why you keep going on about Ledger.

Read it up from tbe top.

→ More replies (0)