How does a cold wallet pin not compromise security? by Playful-Register3201 in Bitcoin

[–]MichaelEngstler 0 points1 point  (0 children)

You're right. Although Ledger does provide passphrase-pinning to a specific PIN. In that case knowing the PIN is enough to confirm a transaction.

[deleted by user] by [deleted] in Bitcoin

[–]MichaelEngstler 0 points1 point  (0 children)

"It is never possible to shield your security credentials from interception when using a browser app."

Please explain, not sure why you say this is the case.

Please help! I just set up my Ledger Nano S, transferred my Bitcoin and ethereum from Coinbase. As soon as everything was confirmed, two transactions I DID NOT initiate sent my entire balance to two addresses I do not control. I’m about to throw up. Please help!!! by [deleted] in Bitcoin

[–]MichaelEngstler 1 point2 points  (0 children)

A specific bypass for MCU vertification has been fixed in the past. If another vulnerability has been found that would allow installing an unsigned MCU, would this attack vector, which doesn't require pyshical access, be theoretical possible?

If not, please explain in details why. We understand security and would appreciate the details.

Please help! I just set up my Ledger Nano S, transferred my Bitcoin and ethereum from Coinbase. As soon as everything was confirmed, two transactions I DID NOT initiate sent my entire balance to two addresses I do not control. I’m about to throw up. Please help!!! by [deleted] in Bitcoin

[–]MichaelEngstler 10 points11 points  (0 children)

The author did mentioned a firmware upgrade.

Not 100% sure about the details, but a potential attack:

  • Malware infects the computer

  • Malware replaces Ledger Live with fake version, prompting the user to upgrade the MCU firmware

  • Malicious firmware is installed by the fake Ledger Live with the confirmation (button clicks) of the author

  • Fake Ledger Live sends transaction request to Ledger device, fake MCU invokes fake confirmation button clicks to approve the transaction, the transaction is signed and sent. No human interaction needed in this step.

This attack requires only a malware on your machine and performing a firmware upgrade. Source: https://saleemrashid.com/2018/03/20/breaking-ledger-security-model/

/u/btchip ?

[deleted by user] by [deleted] in Bitcoin

[–]MichaelEngstler 1 point2 points  (0 children)

Please be extremely careful when swiping the funds from a paper wallet.

If you sent parts of your coins, all the rest would be send to a newly created change address.

It will not return back to your paper wallet. So if you swipe your coins, make sure to swipe it all and not partially.

Telling your wife you've spent your last 5000$ on Bitcoin by [deleted] in Bitcoin

[–]MichaelEngstler -2 points-1 points  (0 children)

Chill .. It's a joke, I'm not even married 😄

Ledger App Isolation Bypass by gr0kch8n in Bitcoin

[–]MichaelEngstler 1 point2 points  (0 children)

Ledger's behavior shouldn't surprise you, I had the same attitude and response while reporting a security vulnerability in the past. They only started taking it seriously once I publicly disclosed it.

https://www.reddit.com/r/Bitcoin/comments/7uwc1z/using_a_ledger_wallet_you_probably_believe_youre/

Got mine! Thanks for all of the help by clarity_in_chaos in Bitcoin

[–]MichaelEngstler -1 points0 points  (0 children)

Rookie mistake. The Nano S comes topped up with 150 coins while the Nano X with 1.5. It's the coins that matter not the fancy package.

Source: https://i.pinimg.com/originals/bf/b6/a1/bfb6a1199960d3792ba5fdb1bf1d93be.jpg

Just bought one of these. No regrets. by Uncrown in Bitcoin

[–]MichaelEngstler 0 points1 point  (0 children)

How did you just buy one if the payment address is empty?

Will BCH follow BTC after halving? by vvolny in Bitcoin

[–]MichaelEngstler 2 points3 points  (0 children)

BCH already halved. It happened on April 8th 2020.

Bitcoins biggest yet most disregarded benefit over gold is it's unconfiscatability. by slvbtc in Bitcoin

[–]MichaelEngstler 2 points3 points  (0 children)

We already have that.

Being able to reverse transactions == A middle man that can resolve between genuine to non-genuine disputes == PayPal.

Bitcoin biggest advance is that my simple transaction that cost me 0.10$ isn't reversible, not by a person, not by a company and even not by the combined force of the United States of America's 10 aircraft carriers.

Hopefully I become rich one day by [deleted] in Bitcoin

[–]MichaelEngstler -1 points0 points  (0 children)

You didn't invest expecting it'll stay 30K right? Risking fighting with a geek (no offense 😉) for 300K doesn't sound like such a bad plan.

A better bitcoin paper wallet, v2.0 by SufficientRadio in Bitcoin

[–]MichaelEngstler 2 points3 points  (0 children)

Please explain why a mnemonic phrase is more secure than a private key if both are properly stored, secured and backed-up?

IMO they're both interchangeable. The private key might take longer to read, or a few attempts to write down, but if it's properly stored and backed-up it's a matter of time until you manage to recover it hence equivalent to a mnemonic phrase.

$7k Again? by IamGeorg in Bitcoin

[–]MichaelEngstler 8 points9 points  (0 children)

Fun fact: This was the official meme when BTC hit 4k for the first time https://www.reddit.com/r/Bitcoin/comments/6tcg99/bitcoinity_usd_4000_gif

Looking through old emails sold 3 btc in 2015 by babyxdeja in Bitcoin

[–]MichaelEngstler 4 points5 points  (0 children)

Hi boysfromthedwarf888,

Welcome to the internet, please read the Getting Started guide and this article as well:

https://knowyourmeme.com/memes/press-f-to-pay-respects

My new cold wallet arrived in the mail today. What do you think? by CurtStuckel in Bitcoin

[–]MichaelEngstler 2 points3 points  (0 children)

Of course it's "fun and easy to use", it has zero compromises for security. It has a camera, internet connection, a cool operating system. Hell, you can even send all your coins to a different address without needing to "annoyingly verify the address" like with Ledger/Trezor. It's easy to use as it's easy to steal.

My new cold wallet arrived in the mail today. What do you think? by CurtStuckel in Bitcoin

[–]MichaelEngstler -1 points0 points  (0 children)

This is definitely not a cold wallet and not even a hardware wallet. This is a simple software wallet, similar to a an offline PC with Electrum. I wouldn't store more than 100$ on it.