Buzzword or real security for crypto wallets?

[ad_1]

Last month, hardware crypto wallet maker Ledger announced its Ledger Recover program designed to allow customers to back up their seed phrases to the cloud and link them to their real identity.

The announcement was strongly pushed back by the crypto community, as many saw it as an opposition to the ideals of blockchain security and the decade-old mantra of keeping custody of your own keys.

Ledger responded quickly, assuring customers that their seed phrases were safe and that the Ledger Recover program was opt-in. But the whole saga has led to a growing demand for open-source hardware wallets, which could allow the community to rule out any hardware or software backdoors.

Just a week later, Ledger announced that it was accelerating its open source roadmap. But what does an open source hardware wallet mean? What are the benefits? And most importantly, are they actually more secure than their closed-source counterparts?

What your hardware wallet is not

First, it will help dispel some misconceptions about hardware wallets.

Your wallet does not store crypto.

Many people think that hardware wallets are used to store cryptocurrencies, but in reality they are used to store your private keys. All cryptocurrencies exist on the blockchain and your private keys prove that you own your tokens. That’s why it’s important to keep your private key, well, private.

Your spare phone is not a hardware wallet.

Making hardware wallets is complicated and for good reason. People use these devices to secure millions of dollars in digital assets, and ensuring the safety of customer funds is essential to building and maintaining a successful hardware wallet brand.

For this reason, various components of the hardware wallet are usually proprietary, which means that they cannot be purchased or inspected outside of purchasing a device and tearing it down. Some wallets even have built-in tamper protection to prevent this. Phones use much more accessible parts, making it much easier for an attacker to study and break.

Hardware wallets are not %100 secure

No device or software is completely invulnerable to attacks. Accidentally interacting with a malicious smart contract can be catastrophic, and even the most secure wallet can’t protect you against mat attacks or phishing attacks. Hardware wallets are not digital bank vaults, rather they are like keys to a secure public vault. They are a tool to help you store and access your assets securely and are never as safe as you are.

Will going open source help you?

If wallets were built with publicly available source code, mass individual audits could prevent malicious actors from getting in or so it is claimed. But making hardware wallets requires a lot more trust than you might think, and not just from the manufacturer.

Other companies in the supply chain have reasonable opportunities to insert their own backdoors, and these devices have complex supply chains. Most hardware wallet companies rely on contract manufacturers, which tend to rely on supply chains originating in China.

Recent: Bitcoin 2023 in Miami takes on shitcoins on Bitcoin

Another supposed benefit of open source hardware wallets is increased compatibility and greater community involvement in development. However, making the code publicly available makes it easier for hackers to scour it for vulnerabilities. And since the wallet would be created using publicly available components, it would be easier for scammers to create fake wallets that can steal your funds.

Nicolas Bacca, co-founder and vice president of Innovation Lab at Ledger, told Cointelegraph that the biggest challenge facing open-source hardware wallets is creating a way for users to easily verify if their device is genuine. with strong guarantees. Most reputable manufacturers allow you to check the serial number of the device on their website to confirm its legitimacy. Would you trust every company in an open source hardware wallet supply chain?

It’s important to remember that an open-source hardware wallet will almost always rely on closed-source components, Bacca said. The only way to really know how secure it is is to try breaking it up and deboning it. With closed-source wallets, this is not possible.

So far, no wallet has ever released firmware with a proven backdoor. If the firmware is open, it is scanned worldwide. In closed-source wallets, this is never possible, Vipul Saini, co-founder and chief technology officer of hardware wallet company Cypherock, told Cointelegraph.

He believes that operations involving the generation and use of private keys should be made open-source. This is where major backdoors, like kleptographic attacks and predictive random numbers, can be easily established, he said.

In April 2022, a white hat hacker from the Ledgers security team discovered a similar backdoor vulnerability in the seed generation of Trust Wallet, an open-source software wallet owned by Binance. With off-the-shelf chips, any part of the supply chain could modify the code that loads the bootloader, a critical part of ensuring the customer receives a device with genuine firmware.

This would not be noticed by code listeners since the backdoor could be inserted while the code is loaded on the device.

Given this limitation, it is not possible to build a robust chain of trust for open-source hardware wallets, which severely limits their safe distribution and use by the widest number of users, it said. -he adds. The many-eyes paradigm doesn’t really work for security code, the best example being the Heartbleed OpenSSL exploit.

Are open source wallets the future?

As centralized exchanges continue their efforts to rebuild trust with the crypto community, people are encouraged to store their coins in hardware wallets more than ever. If the open source movement is gaining popularity, the ability to verify that your device has not been tampered with is essential, and it is not easy without an intermediary.

One solution is to encourage producers of open source hardware wallets to comply with the Open Source Hardware Association (OSHWA) criteria and obtain the CERN Open Hardware License. But as examples like the 2008 global financial crisis have shown, licenses and certifications can’t guarantee much.

OSHWA helps provide proper labels, defines and certifies what is open material, Bacca said, saying it doesn’t help protect against attacks, but is helpful in avoiding attacks. dubious marketing claims. Bacca also mentioned a few existing vendors that claimed to be open source without having an open source license, or with proprietary code mixed into their open source code base.

Recent: How Security, Education, and Regulation Can Mitigate the Rise of Crypto Scams

From unclear incentive structures to restricted testing under predefined circumstances, it is important to address the limitations of certification bodies. The move could also lead to a rush of companies capitalizing on the open source buzzword, hiding their proprietary elements behind substandard certifications.

Closed-source manufacturers use proprietary chips to enforce strong root-of-trust guarantees, but what would a purely open-source wallet use? The market reality is that security ratings are more nuanced than a simple dichotomy between open source and closed source.

Ultimately, consumers want the safest option that forces them to trust the fewest number of people.

Sources

1/ https://Google.com/

2/ https://cointelegraph.com/news/open-source-buzzword-or-real-security-for-crypto-wallets/amp

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts