Cyph3rp9nk on Nostr: No, the seed is encrypted with PIN (Local) + secret (Blockstream Server). The seed is ...
No, the seed is encrypted with PIN (Local) + secret (Blockstream Server).
The seed is stored locally on the Jade.
What does this do? If you extract the seed from the chip and try to brute force attack it, it will be useless, because apart from the pin, you need the secret (256 bits) stored in the blockstream server.
So they would have to hack also the Blockstream server and have your jade and also know the pin.
On the other hand the blockstream server can not do anything, it is only a shared secret, the blockstream server at no time access to the Jade.
https://help.blockstream.com/hc/en-us/articles/9639949755673-How-does-Blockstream-Jade-s-oracle-enforced-PIN-protection-workPublished at
2024-08-06 10:58:17Event JSON
{
"id": "af105181b2e7192bddcd5cb90c370329de5c0b76646cb0574c7b1208fe971657",
"pubkey": "fcf70a45cfa817eaa813b9ba8a375d713d3169f4a27f3dcac3d49112df67d37e",
"created_at": 1722941897,
"kind": 1,
"tags": [
[
"e",
"c0c5ef38606002ec9976530db604a2df0023f6fb85844754f6512faed72f1f32",
"wss://nos.lol",
"root"
],
[
"e",
"edf4115a4fff14f503baaa728b1da95c83fa4617e3cf3375eb9ac843d1758171",
"wss://nos.lol",
"reply"
],
[
"p",
"fcf70a45cfa817eaa813b9ba8a375d713d3169f4a27f3dcac3d49112df67d37e"
],
[
"p",
"18f54af1e10c5bb7a35468b0f62b295d12347903c9f95738d065c84bef1402ef"
]
],
"content": "No, the seed is encrypted with PIN (Local) + secret (Blockstream Server).\n\nThe seed is stored locally on the Jade.\n\nWhat does this do? If you extract the seed from the chip and try to brute force attack it, it will be useless, because apart from the pin, you need the secret (256 bits) stored in the blockstream server.\n\nSo they would have to hack also the Blockstream server and have your jade and also know the pin.\n\nOn the other hand the blockstream server can not do anything, it is only a shared secret, the blockstream server at no time access to the Jade.\n\nhttps://help.blockstream.com/hc/en-us/articles/9639949755673-How-does-Blockstream-Jade-s-oracle-enforced-PIN-protection-work",
"sig": "3fffdfa9e49e5f618965692d8d4a002d4819b99d9f26cb4786f54cb33b011f00e621f65ba922c50c10e61d179dd3106aad2981938228b8239669d35d74403e7d"
}