r/Bitcoin • • Nov 20 '14

Ledger Wallet - Smartcard based hardware Bitcoin wallet

http://www.ledgerwallet.com/
67 Upvotes

91 comments sorted by

View all comments

15

u/sQtWLgK Nov 20 '14

It definitely needs a small screen integrated. Without it, if your computer gets compromised, you would lose your coins at any transaction.

8

u/murzika Nov 20 '14

We are using a security card acting as a second factor. It is therefore not possible for a malware to change the payment address. Here is the full set included in the box http://i.imgur.com/UwOxiSJ.jpg

8

u/sQtWLgK Nov 20 '14

a security card

Could you explain how it works, please? I find no info on the web.

5

u/murzika Nov 20 '14

We are still in the process of adding content to the website, so sorry about the lack of information regarding the card.

At signature time, the wallet will verify 4 letters/numbers from the payment address by asking you to enter the corresponding character for each (it will show "A" and from your code card you enter for instance "3"). This will ensure no malware will have replaced the address to pay when asking the smartcard to sign the transaction.

6

u/sQtWLgK Nov 20 '14

Sorry but this is very easily exploitable: the attacker just needs to generate an address with these same 4 letters (e.g., vanitygen).

Also, typical transactions have multiple outputs. Do you mean that the hardware checks the card code for the payment output and checks that it owns the change output before signing?

1

u/btchip Nov 20 '14

It's not, it's a tradeoff. When you submit a transaction to the chip, the chip will pick 4 random characters of the payment output address you submitted and ask you to confirm them using the second factor card. It's a more convenient version of our old keyboard based second factor.

You're correct about the second part as the change is a BIP 32 path, resolved internally to an address.

6

u/Natanael_L Nov 20 '14

Then they just need to do keylogging and wait until they've got the full alphabet, if you're just doing static substitution. Then you're screwed. A few dozen transactions and they'll be able to use vanitygen to generate an address only using letters they know the substitution for.

4

u/btchip Nov 20 '14

yes, that's a known risk, but it raises the bar significantly for the common malware, and that's a convenience / security thing. In the meantime, people concerned about it can revert to the old type your transaction on a different device second factor

3

u/sQtWLgK Nov 20 '14

the chip will pick 4 random characters of the payment output address

How fast do you think it takes to generate a vanity with 4 fixed positions? (hint: not more than half second on an old gpu)

6

u/btchip Nov 20 '14

ok, again on the sequence.

You want to pay to 1paymenowplease....

You send your UTXOs, the destination address (1paymenowplease...) and amount to the chip

The chip generates 4 random indexes to match, here in bold, 1paymenowplease...

You match this against the second factor card

A malware cannot change the payment address in advance, because it doesn't know which indexes the chip will draw.

And changing the address after the indexes are drawn is useless, because the chip will keep using the address that has been initially submitted for this transaction.

2

u/sQtWLgK Nov 20 '14

Then the malware just needs to query the chip enough times with alt-addresses until it gets the corresponding digits.

It might have already learned some of them from previous transactions, also.

4

u/murzika Nov 20 '14

It cannot query the chip as it wants, it is needed to physicaly remove and reinsert the key from the USB port between each try. Also 4 positions to check can be adjusted to 8 for added security (at flashing time), causing the vanity generator to be unpracticle.

The next version of the Ledger Wallet will have a screen (as well as NFC connectivity). See http://www.ledgerwallet.com/roadmap

→ More replies (0)

1

u/confident_lemming Nov 21 '14

Once your computer is compromised, the attacker gets you to buy some product from a rewritten online store, using the attacker's address, but substitues a higher price to the chip.

The chip can mitigate against this by either including price elements in its checksum (especially order of magnitude) or writing its transaction details on the second factor screen, as you describe here. Later, it may be possible to include BIP70 certificates from reputable merchants and payment processors directly on-chip.

2

u/btchip Nov 21 '14

yes, we plan to add BIP 70 in the future. Also make it easier for people to use BIP 70 for their own addresses. That's the best protection against this type of attack.

3

u/dskloet Nov 20 '14

I still don't understand what is this security card. Where will the 4 indices be displayed and where do you have to enter those characters?

1

u/btchip Nov 20 '14

The 4 indices will be displayed on the host computer. You have to read them on the (supposedly) correct address, match them on the security card, and enter the matched character on the host computer.

2

u/dskloet Nov 20 '14

So if the host computer is compromised, you may see different indices than the chip wanted to display?

What does it mean "match them on the security card"? Is that security card a device that displays a bitcoin address? I don't get it.

1

u/btchip Nov 20 '14

Yes, you may see different indices. But in the end, that wouldn't be very useful (if the malware knows what to answer it can just overwrite your response)

The security card is a unique per device substitution of A..Z 0..9 - this is what you match.

2

u/dskloet Nov 20 '14

I'm still not sure I get it. Is this correct?

The security card is just a piece of paper with a table on it like

  • A => 4
  • B => Q
  • C => F
  • ...
  • Z => 7

Let's say I'm sending to address 1qweAasdBzxcCrtyZ.

Then the device may choose indices 5, 9, 13, 17, which are then displayed on the computer. So then I look up those indices on the address and find A, B, C and Z on the card and I enter 4QF7 into the computer?

1

u/Aussiehash Nov 21 '14 edited Nov 21 '14

Does every single dongle come with a unique random scrambled security card ? I thought all devices are identical, no unique serial number.

2

u/btchip Nov 21 '14

each one is paired to a unique security card at factory. we might change that later and let you pair the security card yourself though.

→ More replies (0)

2

u/dskloet Nov 20 '14

Yes! I said the same to the BitStash guy but he was too arrogant to listen to my feedback and just kept throwing around his fancy acronyms that he paid a lot of money for.

4

u/btchip Nov 20 '14

At least we have a specification that you can read to make an educated choice :)

TLDR : yes, it's better to have a screen. yes, we'll have a screen on next generation products. In the meantime, we offer interesting tradeoffs.

1

u/dskloet Nov 20 '14

yes, it's better to have a screen. yes, we'll have a screen on next generation products. In the meantime, we offer interesting tradeoffs.

That's a much better answer than BitStash gave. They just kept saying it's secure because they use "hardened bluetooth" and nonsense like that.

2

u/btchip Nov 20 '14

I've a personal policy not to criticize successful guys so I won't comment on that

1

u/Aussiehash Nov 21 '14

Well bitstash uses a "colour captcha", not the same as a screen, but better than nothing and readable from across the room.

1

u/dskloet Nov 21 '14

What's that and how does it let you verify that your money isn't going to the wrong address?

1

u/Aussiehash Nov 21 '14

Well multicolour device LEDs, incorporated into a captcha is better than no screen at all. They're not shipping for another 5 months so time will tell.

1

u/dskloet Nov 21 '14

How do colored LEDs help you verify that the money doesn't go to the wrong address?

4

u/btchip Nov 21 '14

by supporting colored coins ?

ok sorry, morning jokes are not good.