Trezor - a hardware bitcoin wallet, now open for pre-orders
bitcointrezor.com
bitcointrezor.com
When I click on "About Trezor" it takes me to...a brief overview? I would expect that link to be a much more thorough explanation of what Trezor is, how it works, and why I should buy it.
Why would Trezor be better than an IronKey? Is it a push button interface for sending bitcoins? Does it just store my wallet or is it running a bitcoin client? I read it works with most bitcoin clients, what does that mean? What are the buttons for?
If it's just storing my wallet what kind of encryption is the device using? Does the device have hardware-based tamper proofing (IronKeys will self-destruct after X number of failed passphrase entries, it will self-destruct if someone tries to physically tamper with it)?
And a bitcointalk thread: https://bitcointalk.org/index.php?topic=122438.0
Hopefully they'll add something to the product site itself.
An IronKey is designed to defend against it being lost or stolen. A Trezor is designed to defend against malware. Malware can submit a transaction to the Trezor, but it can't push the button on it.
>Does it just store my wallet or is it running a bitcoin client?
It just stores your wallet. Your Bitcoin client needs to have Trezor support for this to work.
>When I click on "About Trezor" it takes me to...a very brief overview?
Yeah, didn't they say it was open source?
Malware can submit a transaction to the Trezor, but it can't push the button on it.
Okay, that's interesting, thanks.
> When I click on "About Trezor" it takes me to...a very brief overview?
Yeah, didn't they say it was open source?
And? As far as I can tell they are a for-profit venture that is simply open-sourcing their product.
Bitcoin clients will implement support for reading the list of transactions to/from your addresses to figure out how much money you have. They will also implement support for using the device to sign transactions, so the private keys never touch your computer, and therefore a compromised computer cannot steal bitcoins without the device prompting the user to confirm the transaction.
As the device is a single-purpose computer, likely running the absolute minimum code necessary to implement transaction signing, it should be significantly more secure than your PC just there. And you can easily physically secure it in any way you want, whether that's carrying it around with you at all times or locking it in a safe. Anything over that is a bonus, in my eyes.
I do not currently use Bitcoins, at least partially due to security concerns, but with this, I would be very interested.
A paper wallet (copied to several secure locations) seems safer, if less convenient: https://en.bitcoin.it/wiki/Paper_wallet
EDIT: Thanks to rplnt[1] for the Bitcointalk forum post link[2]. According to one of the apparent Trezor creators, "No need for periodic backups, writing down the seed to paper during the device initialization will be enough forever"
I don't know if Trezor has this feature or not.
this is dealt with currency futures and forwards.
Imagine you are buying goods denominated in euros and it takes two weeks for them to be delivered. You don't want to incur any P&L due to the change in exchange rate between now and delivery.
The exchange rate changes all the time. You would use a currency forward to hedge out that change.
If you'd rather speculate on the price of that 1 bitcoin, then you're free to do so.
If Bitcoin ever gets to the point where it's used for everything the deflation should be much more reasonable and predictable. Then maybe companies will offer a discount for prepaid preorders.
Theoretically, you have to use the real rate of return of your money and discount it on the time period. Of course, estimating the real rate of return is an art in itself. Considering value of bitcoin has been shown to be highly volatile, doing any semi-long term investment with it is basically gambling.
With a pre-order on the other hand, you give them the money and you get nothing for four months. Probably longer.
If the value of Bitcoin fluctuates between now and the time you receive your product, then you may "lose" or "win", but that's a chance you take, even with the product in hand. In other words, there is still the possibility that your 1 Bitcoin could have allowed you to purchase something more valuable than the product in hand at some point down the road.
Seems that the only thing you give up with a preorder is the interest potential or use of the money for some period before receiving the value (i.e. product). But, that would be the case with a preorder irrespective of the currency used.
I understand they have upfront costs, but they could work out a campaign where the cost per unit goes down as they reach certain sales goals.
"a campaign where the cost per unit goes down as they reach certain sales goals."
That's an interesting idea. It gives purchasers an incentive to promote the campaign, as opposed to "early bird" specials which incentivises early purchasers, but almost disincentivises later purchasers.
This has been done on Kickstarter and software bundles like MacHeist in the form of "unlocking" additional rewards, but I don't think I've ever seen them actually lower the price if they hit certain goals.
This phenomenon, where people wait until the last minute to go in on a product, is already pervasive on Kickstarter. (I'm not entirely sure why, but the most obvious reason is that people want to ensure that the project will definitely be funded or will attain some sort of stretch-reward before buying). Dynamic price-lowering will only exacerbate this trend, discourage initial purchases, and likely produce more failed projects.
I happen to be working on a design for a small electronic device in my free time. It is a much simpler device than the Trezor, and the ultimate manufacturing cost per unit will be around $5, despite its simplicity, because I'll only be making a few dozen of them. Cost for the first prototype will be close to $90, accounting for my time at $0/hr. If I get it wrong, I will have to redesign it and build another one. Hardware is expensive.
This is why I'm not as infatuated with crowdfunding as everyone else. Because individual customers are supposed to supplant traditional investors, initial costs are much higher for customers because we have to subsidize research, cost-of-living, etc. Moreover, we also incur all of the risk (which is formidable, considering the volume of failed projects and the ubiquity of scams on many crowdfunding sites).
I don't understand why I, as a consumer, would prefer a system where all of the cost and all of the risk are precipitated onto me, instead of onto the country's investment apparatus.
Better all these guys spend some rich VC's money than spend mine.
It's not "a shame" because it's what individual market participants each chose to tolerate. If you don't like it, offer better terms and steal their business, but don't complain about other people's voluntary acceptance of transaction terms.
Something like this makes me think the future of currency is bitcoin, or something like bitcoin.
I'd probably steer toward Yubikey as it's more universal and solves the same problem - keyloggers and malware.
As for the misuse, the device can be PIN protected (it's not much but saves you some time to transfer the bitcoins).
If the malware can hijack the firmware update process, then it copy itself onto the Trezor (making the device worse than useless.)
I assume it will display a fingerprint of the new firmware and the user will need to press the button (like with a BTC transaction.) Still, a few users will probably be caught out by this.
Unless they Tivoize it (then the "open source" claim is rather dubious, but I think this may be the best solution anyway.)
So don't buy a used one.
A well-documented, well-understood firmware update process with mutual authentication (firmware and device must both be validated) might improve things for secondhand Trezor buyers.
Seems to me it wouldn't be terribly difficult to throw some bitcoin info on an NFC disk.