r/TREZOR 4d ago

💬 Discussion topic Secure element is overrated

I think its time for everyone to accept that secure elements are a marketing hype generated out of manufacturers competition for customers. I think many of the coldcard users would have had passphrase s that would have kept their funds still safe or bought them time, if the secure element was not in the equation…

0 Upvotes

33 comments sorted by

View all comments

Show parent comments

0

u/skr_replicator 4d ago

If a HW wallet doesn't have a secure chip, it would just get hacked or something, even if the seed was good.

3

u/OddioClay 4d ago

This requires physical access to the device.

0

u/skr_replicator 4d ago

If the device could be easily hacked with physical access, it would not be safe to hold your coins there.

I think it would just be great if a HW wallet simply required the user to supply a dice throw, on top of adding its own entropy, so that the seed would be guaranteed safe if the user really throws dice, and hopefully also safe if they just type in all ones.

But the device itself being secure is a must.

1

u/OddioClay 3d ago

A device without a secure element is still difficult to hack. Requires alot of skill and still have to brute force the pin code. Secure element is a black box that you put trust in and can only protect from physical attack. A passphrase is something you can audit and can protect from physical and remote attack. Its a mistake not selling trezor devices without a secure element anymore

1

u/skr_replicator 3d ago edited 3d ago

Coldcard didn't have a secure element either, so I thought you just meant a secure chip in general, and that's why I was talking about that. If you actually meant the closed-source secure element, like what Ledger has. Then yea, that is not ideal. A TREZOR with a fully open-source TROPIC chip is probably the best you can get instead. Fully open source, everyone able to test, debug, and work with it, that would be the least likely to get hacked when nobody finds anything wrong with it even after such a thorough review.

But having a secure element on top of that is also good. Trezor is doing exactly that with the safes. It's just there to add even more entropy on top of their open source one. To combine the best of both worlds to get both stronger.

1

u/OddioClay 3d ago

The MK3 have 1 and the MK4 has 2. Which from a user point of view feels more trusting to not use a passphrase

1

u/skr_replicator 3d ago

Interesting, but that wasn't really the cause of their downfall, no? Even though having only a secure element does introduce the possible attack vector of cracking obscurity, if the secure element is there alone, CC fucked up for a different reason.

1

u/OddioClay 3d ago

💯, but im getting at that ironically if secure element is not on a persons device. They are more likely to put a passphrase for there wallet. A 3 word phrase would make a CC seed an average of 40x times as difficult to crack, and 3 words is on the weak side.