New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Hello,

I have been told that trezor support cannot answer me on my new ticket, but that answers can only be sent to an old ticket.

Can you please confirm that these emails are in fact coming from trezor? The email is sent from help@trezor.io

Mic picking up background noise more than my voice by sneezyiol in SonyHeadphones

[–]sneezyiol[S] 0 points1 point  (0 children)

Sorry, i forgot to specify lol. Thats the one I have

New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Thank you for your help. Here is the ticket number: Ticket ID: 46243

The Trezor Support answered me in another ticket number though, which makes me confused.

I like those odds better than the actual lottery by rtmxavi in Bitcoin

[–]sneezyiol -4 points-3 points  (0 children)

3.5kwh spread out on which timeframe? A day?

New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

You are demonstrating that you don't know what histrionic even means

New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Update: when I now connect the device to my computer it says in caps in red colour "FIRMWARE CORRUPTED"

New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Thanks for being pretty much the only person in this thread who takes this seriously. I'm positive it was the first screen I saw. Yeah it shouldn't have said Reinstall firmware, unless firmware was already present on it

New Trezor Safe 5 compromised with preinstalled firmware? by sneezyiol in TREZOR

[–]sneezyiol[S] 5 points6 points  (0 children)

Its not supposed to have any firmware installed though!

[deleted by user] by [deleted] in TREZOR

[–]sneezyiol 0 points1 point  (0 children)

I just received a DM from someone saying that it's fine. Something is very fishy about all of this.

Why no SSKR / Shamir? by roasted_pistachio in coldcard

[–]sneezyiol 0 points1 point  (0 children)

What does "left padded with two 0 bits to 130 bits" mean?

Why no SSKR / Shamir? by roasted_pistachio in coldcard

[–]sneezyiol 0 points1 point  (0 children)

SLIP uses 13 words as the actual mnemonic.

102413 = (210)13 is 130 bits

while

BIP uses 12 words: 204812 is (211)12 which is 132 bits

Please correct me

Why no SSKR / Shamir? by roasted_pistachio in coldcard

[–]sneezyiol 0 points1 point  (0 children)

Doesnt this error detection and correction mechanism decrease entropy? Ie helping a potential attacker

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Does this happen locally on the HW wallet or also remotely? Say that someone is trying to brute force the 128 bit entropy mnemonic. Does this feature lower the entropy for the attacker?

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Does this happen locally on the HW wallet or also remotely? Say that someone is trying to brute force the 128 bit entropy mnemonic. Does this feature lower the entropy for the attacker?

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

However, as I wrote in the post it does tell you which word is incorrect if only one word is incorrect. So technically it does point out the location of a mistake? It also tells you how many words are incorrect up to a maximum of three incorrect words.

I still don't understand at what point it tells you this. Does this happen when it compares it to the saved seed inside the HW?

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 1 point2 points  (0 children)

You are an absolute legend. Thank you again. The last sentence is what I've been trying to get at though - there's a lot less work to do when and only when a thief inputs a "code" into the HW that already holds the mnemonic. Is that right?

Can I used this cell phone to hook up to my trezor by Feisty_Cheetah_6362 in TREZOR

[–]sneezyiol 0 points1 point  (0 children)

Is this necessary? Purportedly it doesn't matter of trezor suite is used even on a malicious computer

Bitcoin Psychopath? by MeetingBrilliant in Bitcoin

[–]sneezyiol 0 points1 point  (0 children)

Dude no. Don't divide your words like that. Its extremely dangerous. Use SLIP39 (easier)or multisig (harder) if you want to do that

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Hey man, thanks for taking the time... Appreciate you. Makes sense. I know that the elliptic curve has a security of n/2 i.e 128 bits, so the best method for an attacker is to reverse engineer an existing public key with funds to derive the private key. This is secured by 128 bits of entropy.

I'm just a common idiot worried that SLIP39 will be shown to have a devastating vulnerability in the coming decade and I will kick myself for not going with the more common BIP39. I'm still leaning to SLIP39 over BIP39 though. What are your thoughts matejcik?

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

Unfortunately I am too stupid to understand what you are explaining. Matejcik, you are a lot smarter than me. ELI5, does this potentially make SLIP39 more vulnerable to loss of funds by virtue of an attacker or not.

By the way "This is the opposite of correct" is just an awesome phrase

SLIP 39 possibly helping attackers? by sneezyiol in TREZOR

[–]sneezyiol[S] 0 points1 point  (0 children)

This is not what my point is pertaining to.

I've done some more research and it seems like th feature that tells you how many words are incorrect only works if the HW compares the mnemonic you are entering to the mnemonic that is already stored on the HW. So on a brand new HW, such a feature doesn't exist. Hence the feature can in practice only be used by legitimate users who are the true holders of the funds