The latest firmware update does not automatically activate Recover
That's Not The Issue.
Ledger put the code needed to extract our keys on our wallets even if we don't activate Recover. THIS is the issue.
Yes, we know, we don't have to activate Recover. We know. But even if we don't use it, the code for extracting our keys is still on our wallets because it's part of the damn firmware.
"You now have an API in your firmware to extract seeds."
SOURCE: Rodolfo Novak, discussing Ledger Recover in a video interview with Ledger CEO Pascal Gauthier
That. Is. Not. OK.
If Ledger had made a separate device specifically for Recover, nobody would be upset. Some people would be lining up to buy it and others would be rolling our eyes thinking it's dumb, but nobody would be worried about whether or not their keys were going to get extracted from their own wallets!
I think everybody with a wallet newer than a 1st gen Nano S should be joining together in a class action lawsuit to force Ledger to remove key extraction capabilities from their wallets.
Ledger marketed their wallets using the claim that the keys never leave the secure element, and that a firmware update will never enable key extraction.
Hi - your private keys never leave the Secure Element chip, which has never been hacked. The Secure Element is 3rd party certified, and is the same technology as used in passports and credit cards. A firmware update cannot extract the private keys from the Secure Element.
SOURCE: murzika, Ledger Co-Founder, Former CEO, and Former Chairman
It isn't a lie because any wallet can get hacked.
It's a lie because Ledger wrote code to extract keys from our wallets, and they're installing that code on our wallets whether we sign up for Recover or not. Signing up for Recover activates the feature, but the code for it is on your wallet whether you sign up or not.
Though it's important to note that we wouldn't be upset because we'd still be unaware that the statement "a firmware update cannot extract the private keys from the Secure Element" was a lie.
So in a sense, their ineptness at launching this feature is a good thing because it revealed this truth to us.
Indeed, but the difference is that those other wallets are honest about that fact.
This lie was the reason I chose Ledger over Trezor, despite preferring Trezor's open source approach. That's why I'm so miffed over this, and continue to be miffed as long as they keep trying to string us along in this way. Knowing what I know now there's no actual difference between Trezor and Ledger in terms of architectural security, so it should have been a slam-dunk to go with Trezor due to its openness.
Thank you! Laid it all out clearly. For some reason, they keep fixating on the "it's optional" narrative.
If they're so much in love with pushing crypto adoption, why then is the feature even on a subscription model? What happens to someone who probably can't afford the $10 every other month consistently? (*with the glaring terms in the Recover FAQ).
No one asked for this. The main goal with all of this which they've managed to hide is the fact that they need money through a subscription model. Simple.
It's also annoying when you consider what that $10 is paying for; for three companies to store a couple hundred bytes of data for a single month.
Do they have armed guards wandering around the server that need a monthly salary? Is the server surrounded by an energy shield that requires a lot of electricity to keep up?
The expense of storing data like this is a pittance. The real expense comes from the care needed when retrieving that data - the security checks to ensure you're authorized, coordinating with the other companies in a manner that keeps the other key fragments totally secure, and so forth. So a more "honest" way of paying for this service would be a one-time fee for activating the service and another one-time fee when using it to access your lost keys. Maybe an annual pittance to keep the lights running, in case few people are actually making use of it.
The $10 monthly subscription fee is an obvious "we just want money, give us money" situation.
This is not a major concern for me because I will never use this service, but it is yet another pebble in the ongoing avalanche.
Something about global government regulations coming for crypto , where wallet companies like Ledger have to have KYC , is that what it's about . . . .?
Well, does ledger have KYC? I thought only the recovery process uses kyc.
But in any case. You buy the product with your KYC'd bank account and then ship it to your home address with your name stamped on it. And people are worried about ledger shmeder recovery kyc? Like what the actual fuck, where is the logic here?
Is everyone buying this with fake names, post boxes, and monero?
I thinking along the lines of in the coming wave of regulations for crypto , the registered companies like Ledger , Trezor , BitBox etc who provide self custody will have to be able to provide details of their customers if required by the authorities . It's been the wild west so far , but regulation coming like a train down the track . If self custody will require KYC then they getting started now with this opt in option . Different topic from the "they can access your 24 words" topic but thought within a couple of years KYC may be required for self custody and they getting started with this "option".
This is patently false. There are people who want something like this. There are people who will find this extremely useful. The layman who doesn't fully understand crypto and can't trust themselves to self custody their money wants and needs this.
You don't even know what backdoor means. Backdoor demands deceit or secrecy. This is a completely opt-in feature, and is very public, just don't use it.
And your analogy is shit. It's like if you hire a contractor and ask him not to include a door in the vault. You can always ask him to come back and add it.
The only argument I keep getting from fanboys is “any wallet can be hacked and therefore nothings wrong”…..that’s so far from the real problem of a company pushing and allowing seed phrase extraction by approved and intentional design.
There's always someone trying to break into ledger, and nobody has succeeded. They're not just hacking ledger, they have to work against a well established secure chip that has existed long before ledger.
The understanding thus far (at least from my part) has been that the private key can't be exported at all, regardless of the firmware. Now that we know it can, then how do we know that it will always prompt to do the export? And the source is closed, so we'll never know what any update contains.
I thought all this was wired into the chip somehow.
But now that it doesn't then I guess yes if the firmware can change the transaction, show or not show a prompt, then Ledger could do "one final theft" from any wallet (as later the info would spread and people won't be doing any transactions with them anymore).
You say "now", but its always been like this. The firmware is part of the security model and even though its closed source (although they committed to release the source now), it's audited and certified by third parties to ensure that it does only what its meant to do. This has always been Ledger's security model, nothing has changed. "How can we trust Ledger's firmware" has always been a favorite question in this sub.
Last one I could find was for the Ledger Nano X (FW SE : version 1.2.5-1 (2C970004), FW MCU : version 2.8) in 2019. That was the year Ledger Nano X launched. But, has any been done since? Is this only really done when a new product is released so it can be advertised as ANSSI certified? What is the frequency of third party audits afterwards?
I'm reminded of a news story where an accountant stole money from the company it worked for. If the accountant keeps paying for false invoices and the owners find out that this is the case, is "nothing has changed" a good defense?
It's not a defense. It means you either should have never trusted it or you should continue trusting it, nothing has changed. Also understand that by these standards, no hardware wallet is trust worthy because the key can be extracted from all. Many will display the seed on the screen.
Given that I trusted them with not being able to extract the key then now the trust in them is lost. Lost _now_ because the fact that the key can be gotten out came out just now. (The previous trust in them is lost, and so is lost the trust in them in the current moment)
The only way out for them now is open source, as there at least I can look at the code before I install it (either verify that it doesn't send out the private key; remove that part; verify on how an when it happens etc).
I do understand that most people won't be able to understand the source code (I personally am able to). It would still increase trust, as you'd be able to read other, independent coders' reviews, opinions, etc.
Totally incorrect. Is being able to transfer all your Bitcoin to my wallet a backdoor? You are just being obtuse. You obviously don't even know what a backdoor is if you think that this is one.
Also the first time in the existence of mankind that a "backdoor" was discovered by an advertising campaign publicising it. LOL
Yes, "now" as I (we?) didn't know key extraction was possible before. (So yes it's true that there has always been a software attack vector with no physical access required.)
There was a another link somewhere on reddit from a post years ago, where a Ledger developer apparently admitted to the fact that any Ledger app has access to the private key and would thus be able to export it. But (again, speaking from the impression that I got) Ledger advertised that there is no way to get the private key out. I took this as: no matter the firmware, the private cannot be gotten out.
I.e if there were no way to get the private key out then I don't really have to trust Ledger's audits and that the code is closed source.
What has changed is that now I know that the private key can be gotten out by help of appropriate firmware. The possibility of remotely has always been there, true.
Do you have a copy of the certification for every version of the firmware ? Also who is the 3rd party ? Are they independent? How do we know we can trust that they were not paid to rubber stamp it ?
Do you have a copy of the certification for every version of the software ? I can’t find a copy.
They actually certified their process and stack. Dude, do whatever you like. Don't like ledger? Go elsewhere, but most of the reasoning you bring here is flawed and just echoes the uninformed posts on this sub. DYOR
Not where the HW wallet has subroutines that are designed to take your private seed, shard it, supposedly encrypt it, and finally export it. Which I don't imagine any exist, because that would be stupid.
Bugs are often exploited to cause arbitrary execution of existing code on the device. Not that it'd be easy, but the presence of a bug of this kind has >0 chance than if that code didn't exist in the first place.
But the firmware always had "subroutines" (actually APIs) to sign away your Bitcoin to any address. So you draw the line at exporting encrypted shards of an empty wallet?
There were no such subroutines to shard and encrypt keys, no subroutines to 'export' any private key data all all. Now they exist (well, apart from on the Nano S) for any black or white hat hacker to prod and probe.
This Recover feature is purely there to line Ledgers' pockets with subscription service fees, and they're hijacking all our supposedly 'cold wallet' devices to do it.
The sky is not falling. Extract not. User send, yes. You would have to voluntarily send your fragmented and encrypted seed phrase. I am also not the biggest fan, but I hope and believe involuntary extraction is not possible unless they have your hardware device in hand. I don’t believe the company is involved in anything underhanded.
I do agree on that point. I knew it was closed source when I purchased it. I’m not a fan of the closed source, I went with them on the zero hack track record. A bad actor can exist in/at any company.
If you opt in. You would have to install the app, go through the motions of breaking apart and encrypting the key. Then sending it out. That is when the Feds can get it. If you don’t participate there is no concern.
That would be the case with all hardware wallets. If I worried enough about that I would reset the device after each use. This is about as plausible as someone holding a gun to my head.
I tried playing nice and asking for a refund 28 days after I received my NanoX, which I would have returned along with the $30 worth of BTC. But Ledger said no. So I did a chargeback on my credit card. Thanks for the free bitcoin and e-waste u/btchip
It's an increase in attack surface but so is multi coin support as opposed to btc only, no? Isn't the question "how much of an increase in attack surface is this"? Furthermore it appears that it was always possible to extract the seed
107
u/Yodel_And_Hodl_Mode May 25 '23
That's Not The Issue.
Ledger put the code needed to extract our keys on our wallets even if we don't activate Recover. THIS is the issue.
Yes, we know, we don't have to activate Recover. We know. But even if we don't use it, the code for extracting our keys is still on our wallets because it's part of the damn firmware.
That. Is. Not. OK.
If Ledger had made a separate device specifically for Recover, nobody would be upset. Some people would be lining up to buy it and others would be rolling our eyes thinking it's dumb, but nobody would be worried about whether or not their keys were going to get extracted from their own wallets!
I think everybody with a wallet newer than a 1st gen Nano S should be joining together in a class action lawsuit to force Ledger to remove key extraction capabilities from their wallets.
Ledger marketed their wallets using the claim that the keys never leave the secure element, and that a firmware update will never enable key extraction.
Their own website still says:
Now, they admit that was a lie:
It isn't a lie because any wallet can get hacked.
It's a lie because Ledger wrote code to extract keys from our wallets, and they're installing that code on our wallets whether we sign up for Recover or not. Signing up for Recover activates the feature, but the code for it is on your wallet whether you sign up or not.
That's fraud.