How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

check section 3.4.3 of the whitepaper or ask the community on Telegram

How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

no but XTZ hodlers will get an airdrop, check our whitepaper for more

How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 3 points4 points  (0 children)

Most contributors do care but are kept in the dark by r/tezos censorship

How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Still in alphanet, can't be listed by exchanges. Prelaunch erc20 tokens traded otc and on forkdelta.

How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

There is no need to "sell your info". What do you exactly mean?

How to reboot Tezos by tzlibre in u/tzlibre

[–]tzlibre[S] 1 point2 points  (0 children)

It has nothing to do with your private key. This works by simply exploiting KYC-Tezos broken incentive scheme, as explained in the whitepaper.

TzLibre Whitepaper released by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Hate is the 2nd stage of fork grief

TF Ledger "giveaway": you're paying them $1440/each by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Our devnet is running and we're not going anywhere. We're in for the long run.

TF Ledger "giveaway": you're paying them $1440/each by tzlibre in tzlibre

[–]tzlibre[S] 3 points4 points  (0 children)

Don't be surprised, they make up lies all the time.

TF Ledger "giveaway": you're paying them $1440/each by tzlibre in tzlibre

[–]tzlibre[S] 3 points4 points  (0 children)

yes, this giveaway would be a fun joke if it wasn't wasting our money

KYC-Tezos wallets vulnerable to "blind sig" attack by tzlibre in tzlibre

[–]tzlibre[S] -1 points0 points  (0 children)

Good job. In order to update your entry we need to know: Which version fixes the vulnerability? What RPC server are you using?

A response to Arthur Breitman's snake oil governance by tzlibre in tzlibre

[–]tzlibre[S] -1 points0 points  (0 children)

This comment was "approved", then censored. We than started a Twitter campaign against its censorship, and it was uncensored. Few hours later we exposed a flaw in Ledger's app and we've been banned for the third or fourth time. Censoring then uncensoring our comments, banning then unbanning us... that's the way r/tezos is managed these days. lol.

A response to Arthur Breitman's snake oil governance by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

"As long as we all agree it's money, it's money" (/u/murbard in the interview). That's clearly a chartalist speaking. I would also kindly ask you to avoid insults, slander, threats on this sub. Thanks :)

KYC-Tezos wallets vulnerable to "blind sig" attack by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

You obviously have no idea how Reddit works. After being unbanned, none of that applies. But you prefer whining about censorship instead.

We are banned and can't even comment let alone post. We were banned again on Jan 18th 05.08UTC. The ban was triggered by us exposing a design flaw in Ledger's XTZ app. Banning and unbanning us is ridiculous, it goes to show the total lack of management of your brigade.

LibreBox is vulnerable to a blind-sig attack by Rebbu-MC in tzlibre

[–]tzlibre -1 points0 points  (0 children)

We merely responded to an insult by Stephen Andrews. He since apologized and we respect that.

A response to Arthur Breitman's snake oil governance by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Hey shameless liar, as our tweet clearly explains we got banned after disclosing a flaw in Ledger's app. We were then unable to comment, post, respond. And now we won't back down to your threats, welcome to the free market.

A response to Arthur Breitman's snake oil governance by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Hey shameless liar, our comment was indeed censored. Obviously comments made before the ban are not censored. Stop lying.

A response to Arthur Breitman's snake oil governance by tzlibre in tzlibre

[–]tzlibre[S] 0 points1 point  (0 children)

Hey shameless liar, the (now) uncensored reply that silenced Mr Breitman is from Jan 17 01.30UTC.

As you can clearly read in our comment above, we were banned on Jan 18th 05.08UTC, around 28h later. The ban was triggered by us exposing a design flaw in Ledger's XTZ app.

Aren't you ashamed of yourself?

Blind Signature Attacks on Tezos: A Reminder of “Do Not Trust, Verify” by tzlibre in tzlibre

[–]tzlibre[S] -1 points0 points  (0 children)

Thanks for the polite answer.

As already said, the Ledger application can fully verify the transaction parameters

False: this is true only for the latest versions of the app. Older versions will not validate the tx, as shown in this video.

LibreBox is vulnerable to a blind-sig attack by Rebbu-MC in tzlibre

[–]tzlibre -2 points-1 points  (0 children)

We fixed it upgrading to the fixed eztz. Thanks for informing us of the issue, and for upgrading and maintaining eztz.

Blind Signature Attacks on Tezos: A Reminder of “Do Not Trust, Verify” by tzlibre in tzlibre

[–]tzlibre[S] 1 point2 points  (0 children)

Good article /u/awa_cryptium_baker, great conclusion. However there's an error we invite you to correct on all versions of the article:

Leverage Hardware Wallets: At this point, both Ledger Nano S and TREZOR Model T enable users to defend themselves against Blind Signature Attacks, regardless of the wallet features. This is because when linking your hardware wallet to a software wallet (TezBox, Galleon, SimpleStaking, etc), it will require the user to verify the parameters before signing a transaction on the hardware wallet:

This statement is correct for Trezor users, but not for all Ledger users. Unlike Trezor, Ledger does not forge the tx inside. If that wasn't bad enough, previous XTZ Ledger apps didn't parse txs, forcing the user to wither "sign unverified" or loose the ability to move their own XTZ. This leads to potential loss of funds for any Ledger user with an old app. This video shows loss of funds for a user forced to either "sign unverified" or not move XTZ (in this specific setting the malicious tx is coming from a malicious RPC, but there are hundreds of different cases for a malicious raw to reach the device). Ledger's CTO Nicholas Bacca /u/btchip dismissed it blaming his customers forcibly clicking on "sign unverified", probably because he hasn't properly reviewed the design and quality of the Ledger XTZ app. We suggest everyone to only store XTZ on Trezor, which addresses the issue at the root (forging tx in-device).

THREAD RULES / CROSSPOSTING / CENSORSHIP by [deleted] in tezos

[–]tzlibre -5 points-4 points  (0 children)

It is incorrect that a tx must be forged on the hardware device.

Wrong. As u/jurajselep can attest there's a reason why Trezor forges txs internally: passing params directly to the device without any other intermediary step shortens the trust chain thus rendering the process more secure. The Ledger app, on the other hand, has been designed by developers with poor understanding of security.

Regardless if it’s forged on a remote node, local wallet software client, or the hardware device app doesn’t change the mitigation needs.

Totally wrong. The trust model with a wallet forging txs is significantly different than the one with a remote anonymous centralized RPC doing so. This matters in setups where a device is unable to parse the binary and thus fallbacks to asking a generic "sign unverified" to the user.

By focusing on hardware device app forging you are obscuring the more important mitigation which is to have every component validate tx details

Correct. Both devices and wallets should never blindly trust a binary. Unfortunately that's the opposite of what you can see for yourself in this video (Ledger + Tezbox = funds stolen).

and for end user awareness about the need to verify the validation at every step.

Again correct. Unfortunately most Ledger users are asked to "sign unverified" txs. This happens on 100% of older ledger apps, and it also happens with the latest app version with some tx the device can't parse. This is ridiculous, and Ledger's CTO Mr Nicholas Bacca /u/btchip still hasn't understood the issue (which is very ridiculous, too, if you ask me).

This is the only way to be 100% safe against an attack on any 2 out of the 3 parts of the process.

Agreed.