Ledger Stax – Hardware wallet with eInk display for digital assets
shop.ledger.com
shop.ledger.com
Given that, I'm not sure I understand why you'd put an e-Ink display (much less a JPEG parser, presumably, given the NFT stuff) on what should really just be an HSM. That seems like asking for trouble.
Edit: Not to mention Bluetooth and wireless charging, apparently.
I don't see a use for wireless charging. Maybe you can charge your wallet by placing it over your phone ?
The security model already assumes that the entity requesting authorization is untrusted, so the security model is basically unchanged. An attacker who can forge BT packets to submit bad data for approval is not really different from an attacker who compromises the laptop/phone/etc to submit bad data for approval.
You're assuming that the Bluetooth implementation does not introduce vulnerabilities that thwart this assumption; GP & GGGP are suggesting that you shouldn't have to make this assumption in a hardware wallet (or hardware that requires this very high level of assurance), by not including it at all. The same goes for, say, an attacker who's able to swap your wireless charger for a malicious one, and potentially execute a power usage-based side channel if you access the device while it's charging, or who's able to extract some useful information from the RF noise produced by the monitor.
The counterargument to this, in my mind, would be that you plan to use these features of the wallet regularly, and that they provide sufficient benefit to justify the risk (which you may argue is quite modest), and perhaps that you've implemented additional mitigations against them (like never using it while it's charging). Your argument about a monitor adding additional assurance in a sibling thread was quite good I thought, and a tact I didn't anticipate in this list originally.
So this isn’t really different from having a USB cable: in either case, some untrusted messages arrive at the secure element over some wires, and get processed there. The only difference is that the wires come from another chip on-device rather than from an external cable.
[0]: https://www.ledger.com/ledger-nano-x-bluetooth-security-mode...
I'd be surprised if that was the case. Nano X and S+ use the secure element for key operations as well as for user I/O (display and button control), which is significantly better than delegating that to a "main processor".
Given the complexity of driving a touchscreen and e-ink display, I think they might have had to return to that weaker "multi-chip" model (used in the original Nano and earlier and by many other hardware wallets), where the non-secure chip drives both the UI and I/O, rather than only latter.
There's probably more code in the Bluetooth stack than the entire rest of the code on the device.
Treating the baseband more like a peripheral device and less as a coprocessor can prevent against much of this attack surface.
That said, just adding Bluetooth (even given a perfectly isolated stack) opens several unnecessary attack vectors, including a MITM between the wallet and the device driving it. This could be used to e.g. subtly modify destination addresses or transfer amounts.
But why make it such a large/complex one, that definitely requires more trusted hardware and software in the validation and confirmation path?
Their previous wallets did this much better, in my opinion. The Stax just seems flashy at the expense of security.
If your device can receive OTA updates via Bluetooth, no. If your device has a "developer" API, almost certainly no. If the two chips share a power rail, possibly not. Without serious thought to security of requests and responses (such that MITMs are impossible), no.
There are a lot of ways this can go wrong even with separate chips.
Second case would be obvious to user, he would see the failing attempts at updating.
pt 1: https://googleprojectzero.blogspot.com/2017/04/over-air-expl... pt 2: https://googleprojectzero.blogspot.com/2017/04/over-air-expl...
TLDR: Google research exploits wifi firmware of broadcom chip in iphone, then uses that to exploit a driver bug, and manages to root the iphone. All without even connecting it to a specific AP, just from broadcast packets.
You can’t, so you’re forced to trust that the software talking to the HSM isn’t lying to you about what data it’s asking to be signed, and at that point you’re only marginally more secure than not using an HSM at all. (Sure, it’s harder to steal the long-term key material, but if I compromise your software, I get a signing oracle, and that might be good enough.)
This is actually something that the blockchain ecosystem gets right: every hardware wallet has a secure display of some kind, to avoid blind signing, because it’s a context where security actually matters (unlike, e.g., “signing git commits with a yubikey”, which nobody cares enough about to attack).
I'm not so sure about this one, there's plenty of damage you could do if you were a malicious actor who could send trusted commits to a git repo. Especially if said repo were for some important software (like Linux, wget, glibc, etc. I know they're not necessarily on public repos but we're assuming at least somewhat targeted attacks here).
I might be missing what you mean, but with a normal security module I control the inputs and outputs: the device only signs what I tell it to sign, and I can test it for honesty by verifying that any signature(s) I get back are actually signatures over the inputs I put in. That still requires me to trust that my interface to the hardware is the only interface, but that's the point of the parsimony (no bluetooth to worry about!).
HSMs have plenty of problems (and I've encountered a good share of them from designing trust ceremonies), but I don't think adding a screen addresses any of them. If I was an attacker, the pins on an e-ink display would probably be much easier to tamper with than the secure hardware itself.
A screen doesn't eliminate the necessity of this check; it's a pure convenience. And that's not to say that it's a bad one, per se, just one that is in tension with the normal key management desiderata (as few moving pieces as possible, as little code as possible, etc.).
But what if, after checking, you realize that instead of "send $50 to $friend for dinner", you signed "send my life savings to $fraudster"? That's the main attacker model of cryptocurrency wallets.
But more seriously: I've never fully understood why this is such a common issue with cryptocurrencies. My understanding of how Bitcoin works is that you need to actually submit your transaction for inclusion in a block, meaning that you have ample opportunity to verify the transaction's correctness before offering it for submission. Why aren't hardware wallets encouraging that?
If it's on your computer or phone, this means that you trust it enough to not need a hardware wallet in the first place.
If your computer is compromised, you can trust the attacker to take care of the submission for you.
I think the idea is malware on your computer could submit the signed, fraudulent transaction against your will.
In the threat model that hardware wallets address, you don't, though. Your computer could be running malware that swaps your desired target address with that of the attacker, for example.
In that sense, they go beyond (low-level) HSMs by introducing a trusted user interface so that you can verify what you sign.
However, they arguably also fall short of really solving that problem: What are you going to compare the destination address to, if you can't trust your computer to correctly display it?
Even placing alongside some-generic-iPhoneish-smartphone isn't a great help, as those now vary in size so much.
Here's a thought, given its use: show it alongside some of the world's most-recognized fiat monies, like the USD bill or quarter, or several EUR bills/coins.
Numerical specs are a poor substitute for a visual-intuitive sense of something's size, versus common referents.
My suggestion is only if Ledger wants their product to be easily understandable to the largest possible audience of buyers. If they're only interested in the smaller subset of people for spend extra time digging, & can interpret numerical dimensions well (perhaps with the aid of rulers/etc), then being more obscure about its size makes sense.
Credit card-sized.
Dimensions: 85mm x 54mm x 6mm
Weight: 45,2g
The USB port and the left button had a short somewhere. Everytime you plugged it in, it would rapidly trigger the left button.
Two months of support for them and they kept making my jump through hoops, including uploading a YouTube video of the problem. And still the best the can say is "It's the USB-C cable, use a different one." I tried 8 cables, including the one that shipped with it, and 4 different computers. Same failure every time.
I had to file a claim with my payment processor because they would not refund me either. Another month I and finally got refunded.
Never ever again.
Didn't even have the decency to delete my email from their spam list after hackers got my name address, phone number and that I have a ledger.
No matter how much I unsubscribe from their mailing list.
Passport is my recommended bitcoin wallet
> Like Coldcard, the Bitcoin private keys are encrypted on the processor and stored on the secure element
And from https://coldcard.com/docs/faq:
> The ATECC608 is a fixed-function device for private key storage. [...] To be able to read the secrets (ie. wallet seed) out of the secure element [...]
Finally, you can apparently just display it in the "advanced" menu: https://coldcard.com/docs/advanced
So it seems to me like the secure element limits PIN attempts, but when successfully enter it, the keys are indeed exposed to the main processor.
A lot of the spam seems to be either proxied through insecure wordpress comment plugins or simply signing my email up for accounts on random websites and somehow injecting their phishing attempts into the account confirmation emails. They come from all sorts of domains, most of which having nothing to do with crytpo, and nearly all of the messages are embedded in some sort of broken HTML email body.
Although I no longer follow or have much interest in the industry, I am hesitant to outright blacklist crypto terms. Has anyone come up with a good solution to combating crypto email spam?
Yeah, stop using centralized services
That being said if I could go back in time and avoid making them, I think I still would....
Turns out that I don't have a compelling use case for it even though I own some crypto.
If I wanted liquidity in my crypto (to transfer or buy stuff) then I would just store my keys in my password manager which I seem to trust with the rest of my assets (I get crypto transactions are non-reversible).
If I do not want liquidity then I really am better off writing/engraving my keys on something and into a safe.
A combination of these two make the most sense for me.
The trouble here is the transfer of assets from the manager into your apps. Lots of opportunity for thefts or screw up. Imagine you use the clipboard and some random app happens to be scanning it.
Android does well, but my experience with Windows has remained copy paste
That being said, I believe storing private keys on a general computing device is very foolish and you will likely find out the hard way. I wouldn't store any more in a hot wallet than the amount of cash I'd be comfortable walking around with in my pocket.
https://web.archive.org/web/20221030030843/https://cointeleg...
https://web.archive.org/web/20220901153130/https://www.coind...
https://old.reddit.com/r/ledgerwalletleak/comments/ki1nsz/re...
https://old.reddit.com/r/CryptoCurrency/comments/rts1w2/got_...
Tony Fadell Is Trying to Build the iPod of Crypto
https://www.wired.com/story/tony-fadell-is-trying-to-build-t...
In his (Tony Fadell's) mind, the wallet should be about the size of a credit card and have a touchscreen. ...envisioned people owning several wallets, one for each category of digital collecting or banking. He liked the concept of stacking them on top of each other, like a cash bundle of $100 bills. He came up with the idea of having magnets to snap the units into a tidy stack. That feature provided the name for the device: Stax.
Of course, when you lock real money with it, the average person puts much more energy into ensuring good passcodes and backups.
This one looks really cool and I like the features but I will never buy one because too many features and too much connectivity.
My suspicion is that they'll use a model more similar to their original offerings, running key operations on secure hardware, but delegating both I/O and the user interface to a non (or rather not as) trusted "main CPU" [2], which enables certain attacks [3].
But unfortunately, these important architectural details seem to be lost on most crypto users, promoters/influencers, and even wallet manufacturers, so I guess Ledger is trying to catch up on form – at the expense of function (which I consider security to be, for a hardware wallet).
[1] https://www.ledger.com/enhancing-the-ledger-nano-xs-security
[2] https://developers.ledger.com/docs/nano-app/bolos-hardware-a...
[3] https://saleemrashid.com/2018/03/20/breaking-ledger-security...
The Stax is designed by Tony Fadell, creator of the iPod.
Edit: Ah, Tony Fadell, makes sense.
[1] https://developers.ledger.com/docs/nano-app/bolos-hardware-a...
It's still not ideal though, given that every additional feature or library blows up the trusted code base and increases the scope of any audit as a result.
Well, I just hope the existing wallets will remain supported going forward.
Just kidding.
But you know… if these guys thinks that crypto is a real currency and think you should use it for trade…
Why do I have to pay for it using “real” money? They don’t really seem to be fully invested in what they’re selling.
A crypto-wallet vendor is literally blocking crypto payments, even when they (according to you) support it (for some users)?
I mean come on. That’s ridiculous?
I’ve added one to the cart and gone to checkout and literally gone all the way until I’m required to enter a shipping address and register an account.
At no point yet have I been offered the option to pay in anything except local currency (NOK).
If crypto payment is an option they are doing everything they can to keep it secret.