create account

RE: Ledger Nano S Hardware Wallet Users Update Firmware Immediately by mrbearbear

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @themarkymark/ledger-hardware-wallet-users-update-firmware-immediately

· @mrbearbear · (edited)
$0.50
It's not as bad of a flaw as the researcher made it out to be. 

Taken directly from Reddit:
> This is not a critical flaw. The security researcher is doing an unfortunate publicity stunt.
> EDIT: we have decided to share more information, even though we wished we wouldn't have to (to not reveal anything useful to black hat attackers). The vulnerability reported by Saleem requires physical access to the device BEFORE setup of the seed, installing a custom version of the MCU firmware, installing a malware on the target’s computer and have him confirm a very specific transaction. While possible, this proof of concept ranks by no mean as a critical severity level and has never been demonstrated. Saleem got visibly upset when we didn't communicate as "critical security update" and decided to share his opinion on the subject. This generated a lot of panic with threads such as this one, and I do not believe it was to the benefit of anyone. A complete blogpost (which was already scheduled to be published according to our reponsible disclosure program) will be available in time.  

https://np.reddit.com/r/ledgerwallet/comments/82frwu/critical_flaw_in_the_nano_s_is_causing_this/dv9wqrc/

In summary, they would need your device BEFORE u got a 24 word recovery, install their malware on it, still have the device in hand.... INCLUDING installing more malware onto the computer you use to access your wallet. Don't worry.... Everyone's safe. Just update it and move on.edit: I upvoted this comment for visibility
👍  , , , , ,
properties (23)
authormrbearbear
permlinkre-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t215425989z
categorybitcoin
json_metadata{"tags":["bitcoin"],"links":["https://np.reddit.com/r/ledgerwallet/comments/82frwu/critical_flaw_in_the_nano_s_is_causing_this/dv9wqrc/"],"app":"steemit/0.1"}
created2018-03-06 21:54:24
last_update2018-03-06 22:07:27
depth1
children4
last_payout2018-03-13 21:54:24
cashout_time1969-12-31 23:59:59
total_payout_value0.422 HBD
curator_payout_value0.080 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,526
author_reputation1,673,146,312,820
root_title"Ledger Nano S Hardware Wallet Users Update Firmware Immediately"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,719,830
net_rshares127,545,137,272
author_curate_reward""
vote details (6)
@safetony ·
That is the problem with security people feel they need to use sensationalism to force users to update thus diminishing the credibility when the issue really is serious and critical! But users should still do all their updates especially in the crypto space as your wallet can be cleaned out although the likelihood of this happening with a hardware wallet is very low it's still better to be up to date than not!
properties (22)
authorsafetony
permlinkre-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180307t113047743z
categorybitcoin
json_metadata{"tags":["bitcoin"],"app":"steemit/0.1"}
created2018-03-07 11:30:51
last_update2018-03-07 11:30:51
depth2
children1
last_payout2018-03-14 11:30:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length413
author_reputation1,616,237,967,768
root_title"Ledger Nano S Hardware Wallet Users Update Firmware Immediately"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,849,872
net_rshares0
@mrbearbear ·
It's given to update a device, period. With hardware wallets, it's your money on the line. Not to mention, this update also does away with one of things i was critical  about, lack of space. You can now install up to 14 apps on it. No longer will you need to remove one and install another.
properties (22)
authormrbearbear
permlinkre-safetony-re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180307t195316002z
categorybitcoin
json_metadata{"tags":["bitcoin"],"app":"steemit/0.1"}
created2018-03-07 19:53:15
last_update2018-03-07 19:53:15
depth3
children0
last_payout2018-03-14 19:53:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length290
author_reputation1,673,146,312,820
root_title"Ledger Nano S Hardware Wallet Users Update Firmware Immediately"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,946,295
net_rshares0
@themarkymark ·
Good find!
👍  ,
properties (23)
authorthemarkymark
permlinkre-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t221414302z
categorybitcoin
json_metadata{"tags":["bitcoin"],"app":"steemit/0.1"}
created2018-03-06 22:14:12
last_update2018-03-06 22:14:12
depth2
children1
last_payout2018-03-13 22:14:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length10
author_reputation1,778,537,732,577,030
root_title"Ledger Nano S Hardware Wallet Users Update Firmware Immediately"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,723,253
net_rshares5,506,222,161
author_curate_reward""
vote details (2)
@mrbearbear · (edited)
Thanks.  You prolly posted it right when the researcher got mad from the official statement from ledger. I really didnt think it was news worthy to make a post to correct it. Anyways, I'll be following you from now on :)
properties (22)
authormrbearbear
permlinkre-themarkymark-re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t222832358z
categorybitcoin
json_metadata{"tags":["bitcoin"],"app":"steemit/0.1"}
created2018-03-06 22:28:33
last_update2018-03-06 22:35:06
depth3
children0
last_payout2018-03-13 22:28:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length220
author_reputation1,673,146,312,820
root_title"Ledger Nano S Hardware Wallet Users Update Firmware Immediately"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,725,717
net_rshares0