TL;DR
Tools and techniques used to "break" hardware wallets demystified ...
https://steemitimages.com/0x0/https://jochen-hoenicke.de/trezor-power-analysis/osci.jpg
_Your ideas about the **security** of your hardware wallet might be wrong!_
* "Why do I need to ~~care~~ worry about technical details 'n' stuff?!" you might ask.
-
"I've been down with crypto currency for over a decade!" you say.
-
"Crypto is secure!" you say.
-
"I'm a crypto legend!" you say.
OK OK! I get it; you know what you are doing!
This doesn't mean that despite your best efforts there aren't risks you've either avoided or somehow passed over which you might want to know about ...
Scenario A:
-
Thanks to ALL that Blogging, You are Targeted
https://steemitimages.com/0x0/https://imgs.xkcd.com/comics/security.png
[AKA Rubber-Hose Cryptanalysis](https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis)
Please see/use: [Hide Your TREZOR Wallets with Multiple Passphrases](https://blog.trezor.io/hide-your-trezor-wallets-with-multiple-passphrases-f2e0834026eb)
# Scenario B: #
* # First, You Learned the Value of Decentralization ... #
https://steemitimages.com/0x0/https://cdn.meme.am/cache/instances/folder871/500x/61306871/skeptical-african-child-so-youre-telling-us-that-our-decentralized-free-from-banks-digital-gold-is-b.jpg
##
(w1nn1ng!) ##
* ## Then You Learned the Importance of Cold-Storage ... ##
(as opposed to leaving your capital with exchanges)
https://steemitimages.com/0x0/https://i2.wp.com/cryptorials.io/wp-content/uploads/2015/03/bitcoin-rule-of-acquisition.jpg
##
(w00t!) ##
* ## Next, You Picked Up a [Trezor](https://trezor.io) or a [Nano S](https://www.ledgerwallet.com/products/12-ledger-nano-s) w/o Looking Back ... ##
https://steemitimages.com/0x0/https://pbs.twimg.com/media/C-FgbtnXgAAZ1nM.jpg
##
(Bravo!) ##
* # *Whoops, LOST that Shit!* #
https://steemitimages.com/0x0/https://media.giphy.com/media/3o6UB5RrlQuMfZp82Y/giphy.gif
##
(D0h!) ##
* ## Order a Replacement via Amazin Drone ... ##
https://steemitimages.com/0x0/http://bitcoinsinireland.com/wp-content/uploads/2016/02/trezor-package.jpg
##
(nice!) ##
* ## Call Grandma and Get the Necessary Key(s) ... ##
(Visit Safety Deposit Box or Dig Up the Backyard etc.)
https://steemitimages.com/0x0/https://img.buzzfeed.com/buzzfeed-static/static/2016-12/28/14/enhanced/buzzfeed-prod-web-14/anigif_original-grid-image-11056-1482955004-6.gif
##
(WHEW!) ##
* ## Reconfigure Hardware Wallet ##
https://steemitimages.com/0x0/https://cdn-images-1.medium.com/max/1600/1*i4UQ7ELOrA2p84LM8a0XNw.gif
##
(ahhhhh) ##
* ## Continue Living the Dream ##
https://steemitimages.com/0x0/http://s2.quickmeme.com/img/f2/f288ee5a840ec4ff9fd50c42a65ccaf0b5b347c06aac398ba624f7722070eae3.jpg
##
(YES sauce!) ##
# What are Side-Channel Attacks? #
Per [Wikiedia](https://en.wikipedia.org/wiki/Side-channel_attack):
"In cryptography, a side-channel attack is any attack based on information gained from the physical implementation of a cryptosystem, rather than brute force or theoretical weaknesses in the algorithms (compare cryptanalysis).
For example, timing information, power consumption, electromagnetic leaks or even sound can provide an extra source of information, which can be exploited to break the system.
Some side-channel attacks require technical knowledge of the internal operation of the system on which the cryptography is implemented, although others such as differential power analysis are effective as black-box attacks."
Common classes of side channel attacks include:
- Cache Attack
- Timing Attack
- Power-Monitoring Attack
- Electromagnetic Attack
- Acoustic Cryptanalysis
- Differential Fault Analysis
- Data Remanence
- Software-Initiated Fault Attacks
- Optical
https://steemitimages.com/0x0/http://i.ytimg.com/vi/35DgZN6zqz8/mqdefault.jpg
## [Intro to Side-Channel Analysis Course](http://learn.chipwhisperer.io/courses/introduction-to-side-channel-analysis) ##
https://steemitimages.com/0x0/https://s3.amazonaws.com/thinkific/courses/showcase_000/009/6141453777150.original.jpg
https://www.youtube.com/watch?v=OlX-p4AGhWs
Demonstration Against RSA (MUST watch. Reality happens @ 9:00)
https://www.youtube.com/watch?v=bFfyROX7V0s
Side-Channel Analysis Hardware Buying Guide
Breaking Bitcoin Board
@ DIY
If you aren't into soldering, a local shop ought be able to help you out.

[ChipWhisperer-Lite (CW1173) Basic Board](http://store.newae.com/chipwhisperer-lite-cw1173-basic-board)
@ $250.00 USD
If you love to solder or just on a budget, go for this is the entry level option from Mr. O'Flynn.
https://steemitimages.com/0x0/http://cdn1.bigcommerce.com/n-ou1isn/pk5aiywx/products/102/images/314/cwdetails__48526.1438263465.490.588.jpg
#
[ChipWhisperer-Lite (CW1173) Two-Part Version](http://store.newae.com/chipwhisperer-lite-cw1173-two-part-version)
@ $325.00 USD
If you'd rather not solder (just how many more hours do you need to work to cover the additional $75?) and just "get to it", this step above the entry level option is a good balance of bang for the buck.
https://steemitimages.com/0x0/http://cdn1.bigcommerce.com/n-ou1isn/pk5aiywx/products/105/images/341/P1080851__48123.1452822187.490.588.jpg
#
[Side-Channel & Glitching Starter Pack (Level 1)](http://store.newae.com/side-channel-glitching-starter-pack-level-1)
@ $550.00 USD
If you expect to be performing this type of research regularly, you might want to consider this package with a helpful few extras. The extras are available individually also so, you are free to build your test lab as you grow.
https://steemitimages.com/0x0/http://cdn1.bigcommerce.com/n-ou1isn/pk5aiywx/products/116/images/381/PICT9035__05345.1474944046.490.588.jpg
#
[SAKURA-X](http://www.morita-tech.co.jp/security_system.html)
@ ¥ 370,000 (Roughly $3,500 USD!)
If you've secured Gov't funding, this might be up your ally!
https://steemitimages.com/0x0/http://satoh.cs.uec.ac.jp/SAKURA/hardware/SASEBO-GIII.jpg
#
# Reference #
[Breaking Bitcoin Hardware Wallets @ DC25](https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Datko-and-Quartier-Breaking-Bitcoin-Hardware-Wallets.pdf)
[Bitcoin hardware wallets security](https://www.slideshare.net/EricLarcheveque/bitcoin-hardware-wallets-security)
Here's some other posts you might be interested in:
[Steemit's Easiest Anonymous VPS Setup Guide](https://steemit.com/technology/@cayce/sunday-school-steemit-s-easiest-anonymous-vps-setup-guide)
[Steemit's Easiest Personal Setup Guide](https://steemit.com/privacy/@cayce/sunday-school-steemit-s-easiest-personal-vpn-setup-guide)
[Steemit's Easiest Witness Setup Guide](https://steemit.com/witness-category/@cayce/monday-school-steemit-s-easiest-witness-setup-guide)
[Steemit's Easiest EOS Setup Guide](https://steemit.com/eos-dev/@cayce/monday-school-steemit-s-easiest-eos-setup-guide)
If this helped you out, ~~follow~~ tip me @cayce
Replies (9)
@cayce this is awesome and insightful info thankss!!! I think simply awareness of threats is crucial part of just participating in the new industry.
This post received a 4.1% upvote from @randowhale thanks to @satchmo! For more information, click here!
This.... is totally not for N00bs to understand at this point of time.... I am already fainting, I need to read this again to digest it better. Probably without the gifs making my head spin.
So let me try to grasp it in a n00b's point of view.
It is safer to make your own hardware wallet than to buy it off from 3rd party production?
Yet I have this saying that I have learned (to be less stressed)
The 2nd video is really briliant. I want to write posts like he does the video explanation.
So to summarize. Keep your HW in a safe ;-) And once a week or month transfer some little amount to some USB key or smartcard you can take with you. Just like with a bank account but then you have mutliple accounts, one for savings (secure in vault) and for spending, you send it each week to that one.
Yea, that guy is fuckin' great eh!?
To summarize I might say: whether it's an exchange or a daily-carry hardware wallet, "Don't keep ALL the eggs in one basket." From talking with a few users and seeing responses to HWs online, I believe that many users feel they are a "silver bullet". The greater the attack surface, the greater the risk.
Fundamental understanding of crypto keys and how digital signing works is key to any solution. The other factor which you have alluded to that can greatly increase likelihood of success is operations/process management.
If you intend to use COTS products, the same scenario will likely be present.
For the same reason most do not walk around with more cash they can spend in a day, don't do the equivalent with a HW!
I figured yesterday that as soon as you noticed your HW wallet is stolen transfer the funds so the secret key they'll find will be worthless to them. Not sure how long it takes them.. ?
The guy is funny! Admitting his mistakes and all LOL!
Congratulations @cayce! You received a personal award!
You can view your badges on your Steem Board and compare to others on the Steem Ranking
Do not miss the last post from @steemitboard:
Vote for @Steemitboard as a witness to get one more award and increased upvotes!