Viewing a response to: @themarkymark/ledger-hardware-wallet-users-update-firmware-immediately
It's not as bad of a flaw as the researcher made it out to be. Taken directly from Reddit: > This is not a critical flaw. The security researcher is doing an unfortunate publicity stunt. > EDIT: we have decided to share more information, even though we wished we wouldn't have to (to not reveal anything useful to black hat attackers). The vulnerability reported by Saleem requires physical access to the device BEFORE setup of the seed, installing a custom version of the MCU firmware, installing a malware on the target’s computer and have him confirm a very specific transaction. While possible, this proof of concept ranks by no mean as a critical severity level and has never been demonstrated. Saleem got visibly upset when we didn't communicate as "critical security update" and decided to share his opinion on the subject. This generated a lot of panic with threads such as this one, and I do not believe it was to the benefit of anyone. A complete blogpost (which was already scheduled to be published according to our reponsible disclosure program) will be available in time. https://np.reddit.com/r/ledgerwallet/comments/82frwu/critical_flaw_in_the_nano_s_is_causing_this/dv9wqrc/ In summary, they would need your device BEFORE u got a 24 word recovery, install their malware on it, still have the device in hand.... INCLUDING installing more malware onto the computer you use to access your wallet. Don't worry.... Everyone's safe. Just update it and move on.edit: I upvoted this comment for visibility
author | mrbearbear |
---|---|
permlink | re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t215425989z |
category | bitcoin |
json_metadata | {"tags":["bitcoin"],"links":["https://np.reddit.com/r/ledgerwallet/comments/82frwu/critical_flaw_in_the_nano_s_is_causing_this/dv9wqrc/"],"app":"steemit/0.1"} |
created | 2018-03-06 21:54:24 |
last_update | 2018-03-06 22:07:27 |
depth | 1 |
children | 4 |
last_payout | 2018-03-13 21:54:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.422 HBD |
curator_payout_value | 0.080 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,526 |
author_reputation | 1,673,146,312,820 |
root_title | "Ledger Nano S Hardware Wallet Users Update Firmware Immediately" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 42,719,830 |
net_rshares | 127,545,137,272 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
ausbitbank | 0 | 87,250,291,459 | 1% | ||
mrbearbear | 0 | 5,226,610,340 | 100% | ||
cryptotem | 0 | 4,445,879,172 | 7% | ||
themarkymark | 0 | 29,698,436,871 | 50% | ||
abitcoinskeptic | 0 | 593,783,800 | 100% | ||
safetony | 0 | 330,135,630 | 100% |
That is the problem with security people feel they need to use sensationalism to force users to update thus diminishing the credibility when the issue really is serious and critical! But users should still do all their updates especially in the crypto space as your wallet can be cleaned out although the likelihood of this happening with a hardware wallet is very low it's still better to be up to date than not!
author | safetony |
---|---|
permlink | re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180307t113047743z |
category | bitcoin |
json_metadata | {"tags":["bitcoin"],"app":"steemit/0.1"} |
created | 2018-03-07 11:30:51 |
last_update | 2018-03-07 11:30:51 |
depth | 2 |
children | 1 |
last_payout | 2018-03-14 11:30:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 413 |
author_reputation | 1,616,237,967,768 |
root_title | "Ledger Nano S Hardware Wallet Users Update Firmware Immediately" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 42,849,872 |
net_rshares | 0 |
It's given to update a device, period. With hardware wallets, it's your money on the line. Not to mention, this update also does away with one of things i was critical about, lack of space. You can now install up to 14 apps on it. No longer will you need to remove one and install another.
author | mrbearbear |
---|---|
permlink | re-safetony-re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180307t195316002z |
category | bitcoin |
json_metadata | {"tags":["bitcoin"],"app":"steemit/0.1"} |
created | 2018-03-07 19:53:15 |
last_update | 2018-03-07 19:53:15 |
depth | 3 |
children | 0 |
last_payout | 2018-03-14 19:53:15 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 290 |
author_reputation | 1,673,146,312,820 |
root_title | "Ledger Nano S Hardware Wallet Users Update Firmware Immediately" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 42,946,295 |
net_rshares | 0 |
Good find!
author | themarkymark |
---|---|
permlink | re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t221414302z |
category | bitcoin |
json_metadata | {"tags":["bitcoin"],"app":"steemit/0.1"} |
created | 2018-03-06 22:14:12 |
last_update | 2018-03-06 22:14:12 |
depth | 2 |
children | 1 |
last_payout | 2018-03-13 22:14:12 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 10 |
author_reputation | 1,778,537,732,577,030 |
root_title | "Ledger Nano S Hardware Wallet Users Update Firmware Immediately" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 42,723,253 |
net_rshares | 5,506,222,161 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
mrbearbear | 0 | 5,182,689,244 | 100% | ||
safetony | 0 | 323,532,917 | 100% |
Thanks. You prolly posted it right when the researcher got mad from the official statement from ledger. I really didnt think it was news worthy to make a post to correct it. Anyways, I'll be following you from now on :)
author | mrbearbear |
---|---|
permlink | re-themarkymark-re-mrbearbear-re-themarkymark-ledger-hardware-wallet-users-update-firmware-immediately-20180306t222832358z |
category | bitcoin |
json_metadata | {"tags":["bitcoin"],"app":"steemit/0.1"} |
created | 2018-03-06 22:28:33 |
last_update | 2018-03-06 22:35:06 |
depth | 3 |
children | 0 |
last_payout | 2018-03-13 22:28:33 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 220 |
author_reputation | 1,673,146,312,820 |
root_title | "Ledger Nano S Hardware Wallet Users Update Firmware Immediately" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 42,725,717 |
net_rshares | 0 |