TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Still Got Your Crypto: In Response to Wallet.fail’s Presentation

49 pointsby asymmetricover 6 years ago

4 comments

pmoriciover 6 years ago
This seems a little disingenuous to me. The implication of the first attack is not that someone might sneak into your house and modify your Ledger hardware. It's that hardware could come to you with modified firmware from the get go.
评论 #18800396 未加载
paulpauperover 6 years ago
i have occasionally heard stores of ppl losing funds from hardware wallets. usually it's after buying it on Amazon.
评论 #18801332 未加载
Ayeshover 6 years ago
I didn&#x27;t watch the 35c3 presentation, but it certainly looks like it&#x27;s an absurd attack. Kudos to Ledger people for constructively replying to it.<p>Some talks in 35c3, defcon, etc remind me of the rubber hose security (<a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;</a>).<p>On the other hand, www.ledger.fr web site does not properly redirect to HTTPS (e.g <a href="http:&#x2F;&#x2F;www.ledger.fr&#x2F;bounty-program&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.ledger.fr&#x2F;bounty-program&#x2F;</a>) and that would&#x27;ve been a more practical one.
评论 #18800430 未加载
anonymouzzover 6 years ago
What bothers me is that they did not responsibly disclose the vulnerabilities to the manufacturers ahead of time. This is not moral, and I&#x27;m not sure what one gains by not doing that. I think that conference organizers should pressure presenters to do that before talks.<p>Either that or attendees should apply bottom up pressure and ask live questions like &quot;what did you do to responsibly disclose this issue?&quot;. I think I&#x27;ll do that on future security conferences I attend.
评论 #18800449 未加载
评论 #18800413 未加载