Why Nostr? What is Njump?
2024-03-30 18:51:17

SeedSigner on Nostr: "...only needs access to the device for seconds to binary-patch the firmware..." So ...

"...only needs access to the device for seconds to binary-patch the firmware..." So dramatic, that darn evil maid is at it again.

Nothing new here, just a different type of theoretical attack that requires you to run malicious software on your signer. With our model, users are responsible for making sure they are running good software -- same as it ever was.
https://hackaday.com/2024/03/29/lora-with-no-radio

This hack is pretty wild and is affected as far as I can see. Or does it not enable a previously impossible Evil Maid Attack:

Eve only needs access to the device for seconds to binary-patch the firmware on it. The compromised firmware would send out the seed, encrypted for Eve's receiver that she's hiding anywhere inside the house, while functioning normally else.

Now, when Alice loads her wallet on the compromised SS, it blasts out the keys and the receiver catches it.

Prior to this hack, a companion app could detect exfiltration but now, any companion app is side-stepped completely.

As a fan of 's approach, I wish there was a simple mitigation but maybe there is. Maybe incorporating tinfoil in the casing fixes this. Of a full metal casing so the maid can't just remove the tinfoil.
Author Public Key
npub17tyke9lkgxd98ruyeul6wt3pj3s9uxzgp9hxu5tsenjmweue6sqq4y3mgl