Trezor T kann gehackt werden
Home › Foren › Trezor Wallet › Trezor T kann gehackt werden
- Dieses Thema hat 7 Antworten sowie 1 Teilnehmer und wurde zuletzt vor vor 1 Jahr, 8 Monaten von
Glass_Marketing_2537 aktualisiert.
-
AutorBeiträge
-
-
24. Juni 2023 um 18:43 Uhr #2539103
root_s2yse8vt
Administrator::Es ist nicht das erste Mal, dass eine Trezor-Geldbörse gehackt wird:
[https://www.coindesk.com/tech/2023/05/24/crypto-security-firm-unciphered-claims-ability-to-physically-hack-trezor-t-wallet/](https://www.coindesk.com/tech/2023/05/24/crypto-security-firm-unciphered-claims-ability-to-physically-hack-trezor-t-wallet/)
Das ist beängstigend, denn Trezor weiß seit 3 Jahren von dieser Sicherheitslücke und hat nichts unternommen, um sie zu beheben.
Hier ein weiterer dokumentierter physischer Hack einer Trezor One Wallet
[https://www.youtube.com/watch?v=dT9y-KQbqi4](https://www.youtube.com/watch?v=dT9y-KQbqi4)
-
24. Juni 2023 um 18:43 Uhr #2539104
random_user7980
Gast::Let’s be clear: ANY 100% FOSS wallet that doesn’t use a secure element is hackable.
The odds that someone steals your HW and hacks is is very remote and ir still takes hours and hours to hack it.
But if you still are concerned, just use a passphrase and you’ll be protected from this, as passphrases aren’t stored on the Trezor. -
24. Juni 2023 um 18:43 Uhr #2539105
isit2amalready
Gast -
24. Juni 2023 um 18:43 Uhr #2539106
Patneu
Gast::And here’s Trezor’s response to this, for those who still haven’t heard of it, yet:
https://blog.trezor.io/our-response-to-the-read-protection-downgrade-attack-28d23f8949c6
TL;DR:
* Trezor cannot fix it, without building a completely new Trezor device, because it’s a hardware vulnerability with the chip they’re using.
* The attack tries to manipulate the chip for it to reveal the encrypted copy of the seed phrase that’s stored on the Trezor device, to then try and brute-force the PIN to decrypt it.
* The attacker would need *physical access* to your Trezor and a specialized device to make use of this, and the Trezor’s case would be visibly tampered with. You *cannot* just get hacked over the internet or by plugging your Trezor into an unknown computer.
* If someone getting physical access to your Trezor device and tampering with it is in your threat scenario, you can and should use a passphrase-protected hidden wallet, because the passphrase is never stored on your Trezor device, so that even if your seed phrase got compromised, you are still reasonably save (at least for a time, so you can move your funds to a new wallet). -
24. Juni 2023 um 18:43 Uhr #2539108
JerryGallow
Gast::> „This appears to be a vulnerability called an RDP downgrade attack and as communicated on our blog in early 2020, RDP downgrade attacks require physical theft of a device and extremely sophisticated technological knowledge and advanced equipment,“ Trezor’s chief technology officer Tomáš Sušánka said. „Even with the above, Trezors can be protected by a strong passphrase, which adds another layer of security that renders a RDP downgrade useless.”
-
24. Juni 2023 um 18:43 Uhr #2539109
-
24. Juni 2023 um 18:43 Uhr #2539110
-
24. Juni 2023 um 18:43 Uhr #2539111
-
-
AutorBeiträge
- Du musst angemeldet sein, um auf dieses Thema antworten zu können.