Gregory Maxwell [ARCHIVE] on Nostr: 📅 Original date posted:2014-07-24 📝 Original message:On Thu, Jul 24, 2014 at ...
📅 Original date posted:2014-07-24
📝 Original message:On Thu, Jul 24, 2014 at 7:35 PM, Aaron Voisine <voisine at gmail.com> wrote:
> The upcoming release of breadwallet uses the height of the blockchain to
> enforce timed pin code lockouts for preventing an attacker from quickly
> making multiple pin guesses. This prevents them changing the devices system
> time to get around the lockout period.
Is breadwallet tamper resistant & zero on tamper hardware? otherwise
this sounds like security theater.... I attach a debugger to the
process (or modify the program) and ignore the block sourced time.
Published at
2023-06-07 15:24:22Event JSON
{
"id": "b5fdf3689b5ba56265e97e9ddee892ea973a41c63577952139daaaa08a5ef78d",
"pubkey": "4aa6cf9aa5c8e98f401dac603c6a10207509b6a07317676e9d6615f3d7103d73",
"created_at": 1686151462,
"kind": 1,
"tags": [
[
"e",
"5afc40a822450976800863f81cdab6d686da683e406014bdb408954568c533bf",
"",
"root"
],
[
"e",
"b8809c096930fb53e89816e5e31aa8732d7a80c77203cc9f803ca9cc44db03da",
"",
"reply"
],
[
"p",
"3a24ce2145c5488aebfb0fc113e7d44234e9d3733afa45e2d880eb259c3eade3"
]
],
"content": "📅 Original date posted:2014-07-24\n📝 Original message:On Thu, Jul 24, 2014 at 7:35 PM, Aaron Voisine \u003cvoisine at gmail.com\u003e wrote:\n\u003e The upcoming release of breadwallet uses the height of the blockchain to\n\u003e enforce timed pin code lockouts for preventing an attacker from quickly\n\u003e making multiple pin guesses. This prevents them changing the devices system\n\u003e time to get around the lockout period.\n\nIs breadwallet tamper resistant \u0026 zero on tamper hardware? otherwise\nthis sounds like security theater.... I attach a debugger to the\nprocess (or modify the program) and ignore the block sourced time.",
"sig": "f8d4cff6a21eb18d17aeeaa1e3068e38b6d850120a04bf1fec703dce806bbcbf3a27da7792bee02d8e2d318145d15357deb3388ca9140b754eac30a93eaa832c"
}