Dark Skippy: A New Attack on Bitcoin Hardware Wallets? With Nick, Lloyd and Robin SLP597

Dark Skippy: A New Attack on Bitcoin Hardware Wallets? With Nick, Lloyd and Robin SLP597

Dark Skippy is a new attack that in theory, makes it much easier for a malicious person to steal your coins. Listen in to learn about some of the ins and outs here, as well as mitigation and the path forward for the industry from @utxoclub , @LLFOURN & @robin_linus .

  • Why air gapping is not the be all end all

  • Dark Skippy in context with other attacks

  • Security while signing transactions, and security while generating keys

  • RFC6979 Deterministic nonce generation

  • Updating PSBT to help mitigate this attack

Summary

The conversation discusses the ‘Dark Skippy’ attack, a new method for leaking secret keys from a malicious signing device. The attack takes advantage of the nonces used in the Schnorr and ECDSA signature schemes. The new attack vector can potentially extract private keys and seed words from hardware wallets. The attack targets the nonce generation process during key generation and signing. The previous versions of this attack were inefficient, but Dark Skippy improves upon them. The contributors explain how the attack came about and its implications for hardware wallet security. They also discuss the RFC6979 deterministic nonce generation and the concept of anti-klepto signing protocols as mitigations against the attack.

While Dark Skippy is a sophisticated attack, it requires a high level of expertise and is not currently seen in the wild. The discussion highlights the importance of secure boot, upgrading the Partially Signed Bitcoin Transaction (PSBT) process, and improving the randomness of upfront key generation as potential mitigations.

However, it is emphasized that current reputable hardware wallets still provide a high level of security, and there is no immediate action required for users.

Takeaways

  • Dark Skippy is a new attack that leaks secret keys from a malicious signing device.

  • The attack exploits the nonces used in the Schnorr and ECDSA signature schemes.

  • Previous versions of this attack were inefficient, but Dark Skippy improves upon them.

  • Mitigations against the attack include the RFC6979 deterministic nonce generation and anti-klepto signing protocols. Dark Skippy is a sophisticated attack that targets the nonce generation process during key generation and signing.

  • Mitigations for Dark Skippy include implementing secure boot, upgrading the PSBT process, and improving the randomness of upfront key generation.

  • Reputable hardware wallets currently provide a high level of security, and there is no immediate action required for users.

  • The discussion highlights the importance of ongoing research and development to enhance the security of hardware wallets and protect against potential future attacks.

Timestamps:

(00:00) - Intro

(00:45) - What is ‘Dark Skippy’?

(04:39) - Is it an old attack vector? Bitcoin’s security evolving with time

(12:41) - Sponsor

(15:22) - What is a nonce?, RFC6979 Deterministic nonce generation

(22:55) - Common ways of people losing their Bitcoin

(31:08) - Sponsor

(32:07) - Anti-klepto signing protocols; ways to mitigate risks of losing coins

(39:51) - Updating PSBT to help mitigate this attack

(43:26) - The role of Multisig in preventing the attack

(49:57) - Other attack vectors in malicious actor’s toolkit

(56:49) - Summarizing the steps to improve the ecosystem security

(1:00:18) - Closing thoughts

Links:

Sponsors:

Stephan Livera links:

Avsnitt(733)

Bitcoin Adoption in Mexico and Aureo with Gustavo Flores | SLP701

Bitcoin Adoption in Mexico and Aureo with Gustavo Flores | SLP701

In this conversation, Stephan Livera interviews Gustavo Flores, the CEO and founder of Aureo, a Bitcoin startup in Mexico. They discuss Gustavo's journey in the Bitcoin space, the cultural differences...

12 Nov 202548min

Spark: A New L2 for Bitcoin with Kevin Hurley | SLP700

Spark: A New L2 for Bitcoin with Kevin Hurley | SLP700

In this episode, Kevin Hurley, CTO and co-founder of Lightspark, discusses the Layer 2 solution called Spark, which aims to enhance Bitcoin's scalability and user experience. He shares insights from h...

31 Okt 202556min

Bitcoin's Sovereignty Paradox for UHNW Bitcoiners with Matt McClintock | SLP699

Bitcoin's Sovereignty Paradox for UHNW Bitcoiners with Matt McClintock | SLP699

In this conversation, Stephan Livera and Matt McClintock delve into the complexities of wealth management in the context of Bitcoin, exploring the concept of the Sovereignty Paradox. They discuss the ...

30 Okt 20251h 2min

PLAN B Lugano Podcast - Day 2 with Jack Mallers & Chris Pavlovski | SLP698

PLAN B Lugano Podcast - Day 2 with Jack Mallers & Chris Pavlovski | SLP698

On Day 2 of Plan B Lugano, I sat down with Jack Mallers to discuss the rapid growth in the market for bitcoin collateralized loans, and with Chris Pavlovski on freedom technology and the state of free...

29 Okt 202545min

PLAN B Lugano Podcast - Day 1 with Philip Walton, Roy Sheinfeld, Tiero | SLP697

PLAN B Lugano Podcast - Day 1 with Philip Walton, Roy Sheinfeld, Tiero | SLP697

Join me as I interview some of the leading voices that are building on Bitcoin - Philip Walton Bringing affordable energy to Africa, Value transfer over payments & Time2Build by Roy and how Arkade is ...

27 Okt 20251h 22min

Bitcoin Core v30 and libbitcoinkernel with The Charlatan (bitcoin core dev) | SLP696

Bitcoin Core v30 and libbitcoinkernel with The Charlatan (bitcoin core dev) | SLP696

In this episode, Stephan Livera discusses the latest developments in Bitcoin Core with The Charlatan, focusing on the significant updates in version 30, including the removal of the legacy wallet, pre...

24 Okt 20251h 30min

Sovereign Individuals Spend & Replace Bitcoin with André Loja | SLP695

Sovereign Individuals Spend & Replace Bitcoin with André Loja | SLP695

In this conversation, André Loja discusses the Free Madeira project, which aims to promote Bitcoin adoption through education and community engagement. He highlights the success of merchant adoption o...

17 Okt 20251h 1min

Why aren't people doing self custody? with NVK | SLP694

Why aren't people doing self custody? with NVK | SLP694

In this episode, NVK, CEO of CoinKite, discusses the advancements in Bitcoin self-custody solutions, particularly focusing on the Coldcard wallet and its new spending policies. The conversation explor...

12 Okt 202556min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
skogsforum-podcast
market-makers
rss-elektrikerpodden
rss-uppgang-och-fall
rss-powerboat-sverige-podcast
gubbar-som-tjotar-om-bilar
rss-veckans-ai
rss-technokratin
hej-bruksbil
har-vi-akt-till-mars-an
developers-mer-an-bara-kod
bli-saker-podden
rss-fabriken-2
rss-en-ai-till-kaffet
rss-laddstationen-med-elbilen-i-sverige
rss-snacka-om-ai
rss-digitala-influencer-podden