Home Foren Trezor Wallet Schützt Shamir Backup vor Hardware-Hacking?

Ansicht von 3 Antwort-Themen
  • Autor
    Beiträge
    • #2344963
      root_s2yse8vt
      Administrator
      Up
      0
      Down
      ::

      Trezor hat vor kurzem die Möglichkeit veröffentlicht, Ihre Geldbörse mit Shamir Backup einzurichten.
      Es ist auch bekannt, dass Trezor-Geräte gehackt werden können, indem man auf die Hardware zugreift und sie manipuliert.
      Frage: Schützt ein Shamir-Backup-Setup vor dieser Schwachstelle oder ist es nur eine weitere Schicht über einer regulären Seed-Phrase, die auf dem Chip gespeichert ist?

    • #2344964
      random_user7980
      Gast
      Up
      0
      Down
      ::

      AFAIK, shamir just splits the seeds, so you can store in different geographic locations. The private keys stored on your trezor doesn’t change.
      Adding a passphrase to your seeds is what really protects you in case your HW gets physically hacked.
      Even if the attacker extracts the seeds from your trezor, he won’t be able to restore the wallet without the passphrase and passphrase doesn’t get stored in the trezor, like the seeds.
      But keep in mind that in case you lose or forget your passphrase, you will lose your funds forever

    • #2344965
      brianddk
      Gast
      Up
      0
      Down
      ::

      No… only `sd-protect` can circumvent the HW hack you imagine.

    • #2344966
      meatwaddancin
      Gast
      Up
      0
      Down
      ::

      Shamir doesn’t change the fact the key is stored on the Trezor, so while Shamir does add protection to your key storage, it wouldn’t protect against a theoretical physical hack of the Trezor itself.

      That said, the hacks of Trezor’s have been for older versions, as well as some can be corrected via firmware updates. The most famous exploit you sometimes see news articles about people recovering funds via, no longer works due to changes to the hardware.

      I admit I haven’t gone looking, but to my knowledge this isn’t a current hardware exploit on Trezors. That’s not to say there isn’t or never will be one, but your post’s wording made it sound like there was actively an attack being abused right now, which I do not think is the case.

Ansicht von 3 Antwort-Themen
  • Du musst angemeldet sein, um auf dieses Thema antworten zu können.