<<  >> (p.171)
    Author Topic: [ESHOP launched] Trezor: Bitcoin hardware wallet  (Read 966772 times)
    JorgeStolfi
    Hero Member
    *****
    Offline Offline

    Activity: 910
    Merit: 1003



    View Profile
    December 08, 2014, 04:04:11 PM
     #3401

    A fake Trezor can do anything.... you pulled that out of your FUD hat?  Roll Eyes
    Why couldn't a fake trezor impersonate a real one and do whatever it wants underneath the hood?
    I'm not saying this is easy to accomplish, but certainly technically possible.

    A fake Trezor can, for example imitate the real one but generate only weak keys (say, from among 2^30 possible pairs rather than 2^160).  Then the thief needs only monitor the blockchain until enough coins have been stored in those addresses, which he has precomputed.  Then he just moves the coins to his own addresses, all at once.

    Note that the thief does not need to know who got the fake Trezors, and the user has no practical way of checking whether the keys are strong.

    How many coins people may keep in those fake Trezors? That is the expected payoff of this attack. How much does it cost to make a fake Trezor with malicious bootloader?

    EDIT: grammar

    Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
Page 170
Viewing Page: 171