A “tamper-proof” currency wallet just got trivially backdoored by a 15-year-old

A “tamper-proof” currency wallet just got trivially backdoored by a 15-year-old

6 years ago
Anonymous $gIi3-PxxKB

https://arstechnica.com/information-technology/2018/03/a-tamper-proof-currency-wallet-just-got-trivially-backdoored-by-a-15-year-old/

For years, executives at France-based Ledger have boasted their specialized hardware for storing cryptocurrencies is so securely designed that resellers or others in the supply chain can't tamper with the devices without it being painfully obvious to end users. The reason: "cryptographic attestation" that uses unforgeable digital signatures to ensure that only authorized code runs on the hardware wallet.

"There is absolutely no way that an attacker could replace the firmware and make it pass attestation without knowing the Ledger private key," officials said in 2015. Earlier this year, Ledger's CTO said attestation was so foolproof that it was safe to buy his company's devices on eBay.

Anonymous
6yr

I bet a few VCs got together and said, "Lets develop an invincible BTC wallet" followed by, "Alright, we're all in agreement, we'll hire a few devs in India, pay them $5/day and tell them to get it done in 3 weeks."

Then they all started counting their future profits.