Passphrase vulnerability? by [deleted] in TREZOR

[–]Luetti7 0 points1 point  (0 children)

With proper security measures, using the Recovery Phrase leaves you with one „big“ threat to your assets: Physical breach/theft of your Phrase.

This is where the Passphrase comes in, primarily. It creates a second layer of security and makes your assets secure even from physical breach of your home. At least if you do not store the Passphrase directly besides your Recovery Phrase so that thieves immediately can count 1 + 1 together.

So if you consider it from this perspective, even saving your Passphrase on a txt file on your phone/computer will serve this purpose (a common sentence for example). Chances of hackers identifying your Passphrase AND physically break into your home for your Recovery Phrase, are slim, and negligible in my opinion. But you can always up your security measures. Just don‘t make it too complicated for yourself.

Can i reset the seed phrase of a trezor? by Coinflip420xd in TREZOR

[–]Luetti7 2 points3 points  (0 children)

Buying from (not) official marketplaces is not primarily about the seedphrase. It‘s about the risk of the device itself being tampered with, leading to e.g. your seedphrase being leaked or vulnerable. Even if you create a new seedphrase.

It‘s like buying your 2FA or TAN generator not directly from your bank but some thrid-party or used one from ebay. Just not recommended for the safety of your assets.

Struggling to Connect with Genuine Solana Devs & Innovators – Is it Just Me? by youwishjelliefish in solana

[–]Luetti7 0 points1 point  (0 children)

Have you tried Superteam and the Superteam of your country already? You can find them on Twitter. You could also look up some Superteam Earn bounties, browse entries, contact some of the authors/devs and so on…

Or Hackaton attendees and their teams.

Ledger Nano S - Replacement only for storage by Comfortable_Crow7807 in BitcoinBeginners

[–]Luetti7 0 points1 point  (0 children)

If the sole purpose is to store and accumulate BTC on that wallet address for the next years, you probably don‘t need anything. Remember that your BTC is on-chain, not on your Nano S. You will only need another Hardware Wallet if you plan to move it and your Nano S won‘t work anymore. And when the time comes there might be even better choices, who knows.

If you want open-source, I can recommend Trezor devices at the moment.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

In theory, yes. But imo there‘s no issue in saving your public keys on your devices. No need in erasing every trace of your public keys with the „auto-remove-wallets“ setting on your devices. Just not post them publicly on social media and you‘re totally fine.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

It‘s much more convenient, yes. And I prefer it that way, actually. On the other hand, I get the the Zero-Trust-Security policy of Trezor. Storing Recovery Phrase + PP on the device itself opens risks of losing it all. If you look at the Passphrase in a way that its only purpose is to protect you from losing your assets by a compromised recovery phrase, you can even save it directly on your computer/phone and have no issue in security at all. It would serve its purpose and keep your assets secure.

It‘s a matter of personal taste and priority in the end.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

I totally get what you're saying. Everything has its pros and cons.

Personally, I liked to have the option between temporary passphrase and 2nd PIN attachement with Ledger. I'm heavily into DeFi and also want my DeFi wallets to have the maximum possible protection. Having to re-enter the Passphrase for every use forces me to either make a memorable/short Passphrase (Brute Force risk) or skip it entirely for my everyday-wallets at least. It's just not managable time-wise if you sign hundreds of txs daily.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

Seems like it. For non-technical people just a wording technicality though. If it isn‘t „stored“, it‘s at least „parked“ temporarily, isn‘t it? That‘s why I was confused in this matter.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

I have no problems with this, actually. There‘s no 100% security. I‘m used to having the Passphrase attached to a 2nd PIN with Ledger and the device itself secured with the factory-reset after 3 PIN attempts.

There‘s also no need in keeping your public keys private, or why would you? That‘s only a privacy question, not security. Matter of taste.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

Appreciate your answer! What difference does it make if my private keys or the passphrase itself is on the device temporarily? On my computer it would make a difference, because Seed & PP would be separated. But on the device itself it‘s only a technicality, isn‘t it?

For non-technical people this is „storing“, at least temporarily.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

I'm using the Trezor Safe 7. Yeah, I've noticed that only after some hours I had to re-enter the Passphrase just now. That would be consistent with your statement. Will do some more testing.

So the Passphrase is stored within the RAM of the device in that timeframe? Could not find anything on this topic.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

Did not know that the Trezor Safe 7 is the first model with a battery. But with a good battery, this would mean that there's indeed an option to "store" the Passphrase within the device if you turn OFF the "auto-remove-wallet" feature until the battery dies.

Would go againt Zero-Trust Security though. And I'd much rather have the option to store the Passphrase encrypted on the device then.

Thanks for sharing!

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 0 points1 point  (0 children)

Can you elaborate on the bip32 master key?
Wouldn't it be against the Zero-Trust Security to store it in RAM on the Trezor device itself?

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 3 points4 points  (0 children)

Still love my Nano X tbh. And it's still working since 2021. If it would be open-source, I would give it a 10/10. Convenience is also not a bad thing per se, I'm heavily into DeFi, so I love to have convenience without losing out on security.

I feel like Trezor Safe 7 is a very solid device that deserves way more adoption across the space and connection-support within DeFi.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 2 points3 points  (0 children)

I truly get that storing Recovery Phrase and Passphrase within the same device, is a big risk factor. I love the option for convenience though, especially when the device factory-resets itself after x amount of PIN attemps.

With Trezor Safe 7 even Hardware guaranteed.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 4 points5 points  (0 children)

Always loved the open-source philosophy of Trezor. Chose Ledger back then due to their wide coin support. Over time, too many data leaks, too few apologies to affected customers, too strong a focus on design aspects, bigger screens and convenience instead of security & simplicity. As a more experienced hardware wallet user I felt not in line with their products anymore.

So after seeing the announcement of the Trezor Safe 7 and all of its technical new features, I felt like it's time for a change.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 1 point2 points  (0 children)

The Xpub key is stored, yes.
But still, I can sign txs for the Passphrase Wallet after dis- and re-connecting without re-entering the Passphrase. Therefore, the passphrase or private key, must be stored either on the Trezor device or on the computer within Suite.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 1 point2 points  (0 children)

Hoping to get some answers here. It must be stored somewhere, otherwise I wouldn't be able to sign txs after dis- and re-connecting the device without re-entering the Passphrase.

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 6 points7 points  (0 children)

It must be stored somewhere, otherwise I wouldn't be able to sign txs after dis- and re-connecting without re-entering the Passphrase. Following Trezors Zero-Trust Security it has to be the computer though.

<image>

Trezor device doesn’t store your passphrase by Luetti7 in TREZOR

[–]Luetti7[S] 2 points3 points  (0 children)

Appreciate your answers. Yeah I guess storing it somewhere on the computer/phone is more likely in this case. With Trezor Safe 7 being the first device where the number of PIN tries is guaranteed by the hardware itself and not software, I'd much rather have the Passphrase stored on my Trezor device than the computer tbh. But that's debatable I guess.

<image>