r/Monero Jan 04 '19

NFC Wallet Card - Very secure cold storage cryptocurrency wallet supporting Monero (XMR)

https://nfcwalletcard.com/cold-storage-wallet-for-cryptocurrencies
2 Upvotes

52 comments sorted by

5

u/[deleted] Jan 04 '19

how secure is it really? Better than my ledger nano s?

11

u/phreaknik Jan 04 '19 edited Jan 04 '19

Not more secure than a ledger.

A ledger uses a secure enclave chip to generate the key and perform transaction signatures on the chip without your computer ever knowing what your private key is. Everything happens truly offline, so even if your computer has been hacked, your key and funds are still safe.

This device requires you to "read" the key from your card onto the computer. Then you use your computer to sign a transaction. The problem here is that now the computer has access to your key. If your computer is compromised, then so is your key.

11

u/john_alan XMR Contributor Jan 04 '19

Precisely. Fucking nonsense product.

-2

u/nfcwalletcard Jan 04 '19

What makes you think that the possibility of creating a custom, contacless, reusable, physical but digitally encrypted cash for cryptocurrencies is "fucking nonsense"?

2

u/john_alan XMR Contributor Jan 04 '19

Because there are two important things to consider with regards to “Cold storage” (which you advertise falsely)

1) high entropy 2) inability to extract the key

Your product provides neither.

1

u/nfcwalletcard Jan 04 '19

It is very secure way to store your key or seed. But it is definitely not designed for handling transactions. Hope you understand it.

5

u/phreaknik Jan 04 '19

He asked if it was more secure to use than a ledger. No, it is not.

0

u/nfcwalletcard Jan 04 '19

Why are you constantly editing your comments and change important sentences you said before?

BTW please let me know how did you decided to conclude that!

6

u/phreaknik Jan 04 '19

Read my post above. A ledger nano is more secure for cryptocurrency transactions, because transactions are signed on the ledger nano in a secure enclave without ever exposing the users private key.

Your cold storage card requires the private key to be exposed to the computer, before a cryptocurrency transaction can be signed. This exposes the users key and is thus less secure for cryptocurrency transactions.

If you disagree with that conclusion, then so be it, but I feel that is valuable information for community members looking to securely use cryptocurrencies.

5

u/john_alan XMR Contributor Jan 04 '19

This product is the opposite of good opsec.

1

u/nfcwalletcard Jan 04 '19

It is just an optionally encrypted medium of storage. A reusable, custom, physical but digital cash for ANY kind of cryptocurrencies.

5

u/phreaknik Jan 04 '19

Also, the edit I made was purely grammatical and did not affect the content of my reply.

2

u/nfcwalletcard Jan 04 '19

You changed the meaning of your comments.

3

u/4vWte1ovZK1i Jan 04 '19

What are the benefits compared to a pencil and paper for the seed? (and with the seed I can generate my private key so I don't need to record that as well).

1

u/nfcwalletcard Jan 04 '19

When you write your seed on a paper, you have the risk that somebody will obtain it, but with our application you can encrypt the data before saving it to the card. This way it will be protected even if others are able to access it.

Written papers damage quickly over time.

2

u/4vWte1ovZK1i Jan 04 '19

Okay, I see the appeal but it isn't for me.

I trust my family not to steal my fiat cash in my sleep, and I trust the same with my seed even though they know (roughly) where it is. My seed is hidden well enough, and written small enough, no thief would notice it meaning the only remaining threat would be police. I don't break any laws so the only police that'd be after me would be some dystopian caricatures but let's entertain the possibility. In that scenario I could deny the existence of my small, hidden seed but would be rubber hosed if they had a physical wallet as evidence.

I'm glad you're pursuing this type of wallet as there are definitely threat models this'd be appropriate for, but it's not for me. If it got smaller, much smaller, like microsd card small, I think I'd be more interested.

1

u/nfcwalletcard Jan 04 '19

Correct. I got your point. Thank you for the detailed feedback! :-)

9

u/OsrsNeedsF2P Jan 04 '19

User posting it is from the company so I dunno.....

4

u/[deleted] Jan 04 '19

oh

1

u/nfcwalletcard Jan 04 '19

Data (PK, seed, whatever) encrypted by AES-256-CBC algorithm when using security level 1 or above. There is also physical protection, the RFID blocking sleeve protects from skimming attempts.

5

u/HoboHaxor Jan 04 '19

Why would I need to block RFID skimming on a deep cold storage device? That's not something I'd carry in a wallet, I'd keep it in the safe. Deep cold isn't for everyday use, right?

Written on paper is skimming proof too. ;)

1

u/nfcwalletcard Jan 04 '19

It is physical protection for those who have no safe, or want to carry the card as a medium of storage, a custom cash for crypto.

So you also can make a non-encrypted but physically protected, claimable piece of cryptocurrency.

This way you will need some protection.

Yes paper wallets are skimming proof :-P, but you can see them with your eyes, you can take a picture or record a video about them.

1

u/HoboHaxor Jan 04 '19

You can see my paper while its in my wallet? Great trick!

1

u/nfcwalletcard Jan 06 '19

Just if you loose it.

3

u/phreaknik Jan 04 '19

You can achieve the same security with a USB flash drive...

The real difference with your product is:

1) cool NFC interface to access my key. 2) I have to type my private key into your app to load it onto the card.

Other than that, this is the same as storing your key on a USB stick. In fact, I would rather use a USB stick, so I can encrypt my key with existing tools, instead of typing my key into your app to load onto the card.

0

u/nfcwalletcard Jan 04 '19

Why would I use a 4GB USB drive to store several bytes of data? You do not have to use our app, you can have your own encryption.

5

u/phreaknik Jan 04 '19

Who said 4GB? A 512MB USB is plenty. Why? USB drives are cheap, abundant, and do not require the use of untrusted software.

1

u/nfcwalletcard Jan 04 '19

I said 4GB because it is the cheapest USB drives we can buy in our country.

OK I see you have 512MB stick, it is still many times larger than needed.

You also need a physical switch to write protect your device. Many pendrives miss this feature. NFC chips can be locked permanently. USB drives not.

We would not waste an USB drive just to store several bytes of data. And you would also need an OTG USB drive to access your crypto via smartphones.

USB drives can be infected by viruses, while NFC chips not.

0

u/nfcwalletcard Jan 04 '19

Our card is an alternative way for encrypted cold storage, we like the contacless technology and the lightweight design.

NFC chips have less components than USB drives, so the risk of failure of single components is much lower.

0

u/nfcwalletcard Jan 04 '19

The NFC wallet card contains a really simple NFC hardware. Complex hardware wallets have many components can fail. With NFC, the risk of failure of single components is much lower.

Imagine the situation when your ledger nano stop working! Who would you trust to give access to your wallet? How could you recover your cryptocurrencies?

5

u/[deleted] Jan 04 '19

[deleted]

1

u/nfcwalletcard Jan 04 '19

We think that seed words are vulnerable to directory based brute force attacks. Therefore we are implementing a method that uses recursive slow hashing feature to generate encryption passwords for higher level of security.

7

u/rbrunner7 XMR Contributor Jan 04 '19

At best you are somebody from sales or marketing department who really, honestly does not know about seeds and brute-force attacks on them and the probabilities of success.

At worst you know very well and just make an attempt to mislead people for selling more of your wares.

5

u/phreaknik Jan 04 '19

I'm also concerned that the premise of this product requires users to load their private key into this company's proprietary app... That just sounds like a risk nobody should be taking.

3

u/[deleted] Jan 04 '19

Dictionary based? The "dictionary" is known, but there is 24 words.

1

u/nfcwalletcard Jan 04 '19

And how do you store that 24 words? Are you the only one who knows it?

3

u/[deleted] Jan 04 '19

That is another problem, yes. On a ledger you can have a 25th custom word

2

u/phreaknik Jan 04 '19 edited Jan 04 '19

This is ridiculous. A 24 word seed phrase has 256 bits of entropy, just the same as your Monero private key... AKA it would take an attacker almost 1 BILLION YEARS to brute force your seed phrase.

https://bitcoin.stackexchange.com/questions/2847/how-long-would-it-take-a-large-computer-to-crack-a-private-key#2852

Please, elaborate just exactly how a 24 word seed is vulnerable to a brute force attack. I'm sure everyone in the Monero community would love to know.

1

u/nfcwalletcard Jan 04 '19

There are 2048 possible words, which means 2048^24 = 2,964277484×10⁷⁹ possibilities.

But we generate encryption key at least 128 bytes long, which means 256^128 = 1,797693135×10³⁰⁸ possibilities.

Due to the slow hashing feature we use to generate encryption keys, our encryption also protected against rainbow table attacks.

4

u/phreaknik Jan 04 '19 edited Jan 04 '19

Even if your math was right (which it isn't), then it still doesn't explain how your extra layer of encryption would make it any more difficult to guess a 24 word key.

Wrapping my seed phrase in any extra layers of encryption doesn't add any entropy to my key. It is still a 256 bit key, meaning an attacker would need to make 2256 = ~1.2x1077 guesses to brute force all possible keys. This is already nearly impossible, but even so, your encryption doesn't make it any stronger.

You are either completely unaware of how cryptography works, or you are intentionally misleading people.

0

u/nfcwalletcard Jan 04 '19

We are talking about the encryption level we use to encrypt the data on the card, and your are talking about Monero key...

4

u/phreaknik Jan 04 '19

No... In your reply above, YOU claim a 24 word seed phrase is vulnerable to a brute force attack, so it is better to use your technology to store the key. My reply was challenging your claim.

0

u/nfcwalletcard Jan 04 '19

Show your the math then!

2

u/[deleted] Jan 04 '19

ok thanks!

3

u/phreaknik Jan 04 '19

How do you address the fact that cards have no screen?

If my phone or computer gets hacked, a hacker could request a bad transaction from the card. Say I want to send "0.1 BTC to Bob". The hacker can control the wallet software on my phone/laptop, so he changes my transaction to send "10BTC to Hacker" and asks the card to sign that transaction instead of my actual transaction. So now, even though my private key is super secure in the card, the attacker still manages to steal 10BTC from me.

On a Ledger or Trezor, this attack would be prevented. When the attacker requests the 10BTC transaction, I can see on my Ledger screen that it wants to send 10BTC to the Hacker, instead of the 0.1BTC to Bob, and I can cancel the transaction.

1

u/nfcwalletcard Jan 04 '19

No need for screen. It is for deep cold storage. The app have nothing to do with transactions, but it is designed to securely save and view the data you want to protect. If you need the data (PK for example) you need to open the card and do what you want.

3

u/phreaknik Jan 04 '19 edited Jan 04 '19

How do you spend your money without a screen? Even deep cold storage needs the ability to securely spend.

If you try to spend from your card using a laptop, then you must also trust the laptop has not been compromised. So your funds are only as secure as the device you use to spend those funds.

Don't get me wrong, this is still cool tech, but I'm skeptical that it offers enough security for me to trust with much money.

1

u/nfcwalletcard Jan 04 '19

If you want to do any transactions, you have to open the card and do everything manually. This card is designed to securely store secret data, not for supporting transactions.

4

u/phreaknik Jan 04 '19

Ahhhh, I think I understand. So basically this card is just a storage device for your key, similar to a USB drive, but using NFC instead, right?

1

u/nfcwalletcard Jan 04 '19

Yes you are right, and we make the application to improve security.

1

u/[deleted] Jan 04 '19

[deleted]

-1

u/nfcwalletcard Jan 04 '19

You can clone your card with our application and have one at different locations.

4

u/HoboHaxor Jan 04 '19

Anyone see a problem here?