I thought there are air gapped hardware wallets?
Without a keyboard, how do you enter your seed phrase?
Connecting the hardware wallet to the computer brings up a bunch of complex security questions.
I thought there are air gapped hardware wallets?
Without a keyboard, how do you enter your seed phrase?
Connecting the hardware wallet to the computer brings up a bunch of complex security questions.
You sign the hash; but you need the entire transaction to verify it does what you want (send funds to the expected addresses).
You can create the transaction hash on as many untrusted machines as you like. To make sure the hash represents the correct transaction.
Then you can enter only the hash into the hardware wallet.
That solves the problem of how to operate an air gapped hardware wallet!
I think this also does away with the "wallet publishes your seed via nonces" problem? I would hope signing the transaction hash is deterministic?
> I would hope signing the transaction hash is deterministic?
Not really. A signer can generate an arbitrary number of valid signatures for the same message, using the same private key because the signature algorithm requires a secret random number. There are ways to generate the signature deterministically by deriving that secret random number from the private key but AFAIK, the only way to verify this was actually done requires knowing the private key in the first place.
I believe you a malicious signer could iterate through valid signatures until the first n bits correspond to bits it wants to leak.
That's actually an even bigger problem that I hadn't considered before.
https://medium.com/@simonwarta/signature-determinism-for-blo...
That signing the transaction is not deterministic but involves a "random" number is indeed huge.
Now we are back to square one. The hardware wallet can phone home. No way to use Bitcoin in a trustless way.
I had to Google that and they do indeed exist. It seems they use QR codes to send and receive data. It's probably a step up from USB since you can visually inspect how much data is transferred. But then again, the device could theoretically transmit your seed to your computer camera and you might not even notice[0]. Probably a step up from USB in terms of security but at the cost of some convenience.
> Without a keyboard, how do you enter your seed phrase?
They have a very rudimentary virtual keyboard which takes forever to type.
[0] As part of the QR code itself, as a separate QR code that flashes too quickly to be noticed to the naked eye, encoded as slight pixel brightness variations within the QR code itself, etc. It could even exfiltrate the seed one bit at a time which would make it pretty much impossible to detect (but would take ~256 transactions to complete).
There are infinite ways to hide data in them.
For maximum security, the best would probably be to use an airgaped/secured/encrypted general-purpose computer and use a SD card to transmit transaction data. You could even use pre-bitcoin computer hardware if you are super paranoid.
Also, if I recall correctly, there are fully open source hardware wallets like Trezor. In theory, you could review the firmware and flash it yourself. You then just need to trust the hardware isn't backdoored to steal Bitcoin seeds. But that would require some rather large companies like ARM to get in the Bitcoin seed stealing business (and for your computer to be infected by ARM-developed seed stealing malware).
[0] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
Gist is you can create a transaction from any device that doesn’t have your private key … send that transaction via a QR code to your cold wallet, then your cold wallet can sign transaction and create a new QR code for the other device to use.