Artwork

Nội dung được cung cấp bởi Stephan Livera. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Stephan Livera hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.
Player FM - Ứng dụng Podcast
Chuyển sang chế độ ngoại tuyến với ứng dụng Player FM !

Dark Skippy: A New Attack on Bitcoin Hardware Wallets? With Nick, Lloyd and Robin SLP597

1:06:04
 
Chia sẻ
 

Manage episode 434148693 series 2408472
Nội dung được cung cấp bởi Stephan Livera. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Stephan Livera hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

Dark Skippy is a new attack that in theory, makes it much easier for a malicious person to steal your coins. Listen in to learn about some of the ins and outs here, as well as mitigation and the path forward for the industry from @utxoclub , @LLFOURN & @robin_linus .

  • Why air gapping is not the be all end all

  • Dark Skippy in context with other attacks

  • Security while signing transactions, and security while generating keys

  • RFC6979 Deterministic nonce generation

  • Updating PSBT to help mitigate this attack

Summary

The conversation discusses the ‘Dark Skippy’ attack, a new method for leaking secret keys from a malicious signing device. The attack takes advantage of the nonces used in the Schnorr and ECDSA signature schemes. The new attack vector can potentially extract private keys and seed words from hardware wallets. The attack targets the nonce generation process during key generation and signing. The previous versions of this attack were inefficient, but Dark Skippy improves upon them. The contributors explain how the attack came about and its implications for hardware wallet security. They also discuss the RFC6979 deterministic nonce generation and the concept of anti-klepto signing protocols as mitigations against the attack.

While Dark Skippy is a sophisticated attack, it requires a high level of expertise and is not currently seen in the wild. The discussion highlights the importance of secure boot, upgrading the Partially Signed Bitcoin Transaction (PSBT) process, and improving the randomness of upfront key generation as potential mitigations.

However, it is emphasized that current reputable hardware wallets still provide a high level of security, and there is no immediate action required for users.

Takeaways

  • Dark Skippy is a new attack that leaks secret keys from a malicious signing device.

  • The attack exploits the nonces used in the Schnorr and ECDSA signature schemes.

  • Previous versions of this attack were inefficient, but Dark Skippy improves upon them.

  • Mitigations against the attack include the RFC6979 deterministic nonce generation and anti-klepto signing protocols. Dark Skippy is a sophisticated attack that targets the nonce generation process during key generation and signing.

  • Mitigations for Dark Skippy include implementing secure boot, upgrading the PSBT process, and improving the randomness of upfront key generation.

  • Reputable hardware wallets currently provide a high level of security, and there is no immediate action required for users.

  • The discussion highlights the importance of ongoing research and development to enhance the security of hardware wallets and protect against potential future attacks.

Timestamps:

(00:00) - Intro

(00:45) - What is ‘Dark Skippy’?

(04:39) - Is it an old attack vector? Bitcoin’s security evolving with time

(12:41) - Sponsor

(15:22) - What is a nonce?, RFC6979 Deterministic nonce generation

(22:55) - Common ways of people losing their Bitcoin

(31:08) - Sponsor

(32:07) - Anti-klepto signing protocols; ways to mitigate risks of losing coins

(39:51) - Updating PSBT to help mitigate this attack

(43:26) - The role of Multisig in preventing the attack

(49:57) - Other attack vectors in malicious actor’s toolkit

(56:49) - Summarizing the steps to improve the ecosystem security

(1:00:18) - Closing thoughts

Links:

Sponsors:

Stephan Livera links:

  continue reading

612 tập

Artwork
iconChia sẻ
 
Manage episode 434148693 series 2408472
Nội dung được cung cấp bởi Stephan Livera. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Stephan Livera hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

Dark Skippy is a new attack that in theory, makes it much easier for a malicious person to steal your coins. Listen in to learn about some of the ins and outs here, as well as mitigation and the path forward for the industry from @utxoclub , @LLFOURN & @robin_linus .

  • Why air gapping is not the be all end all

  • Dark Skippy in context with other attacks

  • Security while signing transactions, and security while generating keys

  • RFC6979 Deterministic nonce generation

  • Updating PSBT to help mitigate this attack

Summary

The conversation discusses the ‘Dark Skippy’ attack, a new method for leaking secret keys from a malicious signing device. The attack takes advantage of the nonces used in the Schnorr and ECDSA signature schemes. The new attack vector can potentially extract private keys and seed words from hardware wallets. The attack targets the nonce generation process during key generation and signing. The previous versions of this attack were inefficient, but Dark Skippy improves upon them. The contributors explain how the attack came about and its implications for hardware wallet security. They also discuss the RFC6979 deterministic nonce generation and the concept of anti-klepto signing protocols as mitigations against the attack.

While Dark Skippy is a sophisticated attack, it requires a high level of expertise and is not currently seen in the wild. The discussion highlights the importance of secure boot, upgrading the Partially Signed Bitcoin Transaction (PSBT) process, and improving the randomness of upfront key generation as potential mitigations.

However, it is emphasized that current reputable hardware wallets still provide a high level of security, and there is no immediate action required for users.

Takeaways

  • Dark Skippy is a new attack that leaks secret keys from a malicious signing device.

  • The attack exploits the nonces used in the Schnorr and ECDSA signature schemes.

  • Previous versions of this attack were inefficient, but Dark Skippy improves upon them.

  • Mitigations against the attack include the RFC6979 deterministic nonce generation and anti-klepto signing protocols. Dark Skippy is a sophisticated attack that targets the nonce generation process during key generation and signing.

  • Mitigations for Dark Skippy include implementing secure boot, upgrading the PSBT process, and improving the randomness of upfront key generation.

  • Reputable hardware wallets currently provide a high level of security, and there is no immediate action required for users.

  • The discussion highlights the importance of ongoing research and development to enhance the security of hardware wallets and protect against potential future attacks.

Timestamps:

(00:00) - Intro

(00:45) - What is ‘Dark Skippy’?

(04:39) - Is it an old attack vector? Bitcoin’s security evolving with time

(12:41) - Sponsor

(15:22) - What is a nonce?, RFC6979 Deterministic nonce generation

(22:55) - Common ways of people losing their Bitcoin

(31:08) - Sponsor

(32:07) - Anti-klepto signing protocols; ways to mitigate risks of losing coins

(39:51) - Updating PSBT to help mitigate this attack

(43:26) - The role of Multisig in preventing the attack

(49:57) - Other attack vectors in malicious actor’s toolkit

(56:49) - Summarizing the steps to improve the ecosystem security

(1:00:18) - Closing thoughts

Links:

Sponsors:

Stephan Livera links:

  continue reading

612 tập

Все серии

×
 
Loading …

Chào mừng bạn đến với Player FM!

Player FM đang quét trang web để tìm các podcast chất lượng cao cho bạn thưởng thức ngay bây giờ. Đây là ứng dụng podcast tốt nhất và hoạt động trên Android, iPhone và web. Đăng ký để đồng bộ các theo dõi trên tất cả thiết bị.

 

Hướng dẫn sử dụng nhanh