log☇︎
193 entries in 0.574s
mrstickball_: who are you using to get the trezor's shipped out with?
bitcoinpete: @slushcz: I'm so overworked that I even cannot celebrate that we've shipped all #bitcoin #trezor preorders few moments ago.
jurov: maybe even most of trezor code can be ported to have best of both worlds
asciilifeform: jurov: if you mean my widget - as soon as it's done. but please remember that it does not serve the same purpose as 'trezor.'
asciilifeform: note that i have never touched, smelled, used, 'trezor.' all i know comes from the manufacturer's specs.
asciilifeform: artifexd, jurov: 'trezor' uses arm's satanic rng for ecdsa signing nonce. if this bothers you (it bothers me) - don't use.
artifexd: jurov: Was the box your trezor came in glued shut on both sides? Did it have a holographic sticker?
fluffypony: "He said their hardware wallet had many more features than Trezor"
assbot: Got the Bitcoin Trezor - serialized delusions
jurov: http://explo.yt/post/2014/05/12/Unpacking-Trezor
kakobrekla: i think asciilifeform had some things to say re trezor
benkay: is the trezor actually shipping?
dexX7: would it be possible to create a gpg targeted firmware for a trezor device?
kakobrekla: thats trezor
kakobrekla: as to rng on trezor
danielpbarron: from what I understand, a lot of the cardano research is getting the right hardware RNG; is trezor up to the same standard?
danielpbarron: i guess what I mean is, ... ultimately this is about securing BTC right? is trezor any good at that?
danielpbarron: what's the deal with trezor? I'm gonna assume it's not as good as cardano will be?
jurov: should have made bet on trezor instead
asciilifeform: antephialtic: re: trezor: open the widget and let it speak for itself.
antephialtic: right now its a lot clunkier than using normal GPG signatures, but if the trezor becomes widespread, I could see people improving the tooling
antephialtic: trezor can sign arbitrary messages, not just bitcoin transactions
antephialtic: asciilifeform: do you worry that trezor's message signing capabilities might reduce demand for the cardano?
jurov: BCB, Trezor folks used this on facebook and wrote a comment "can't happen with Trezor"
ozbot: My new TREZOR
novusordo: the only thing I use the forum for nowadays is following updates from friedcat and the trezor fellows
asciilifeform: novusordo: what does trezor look like to host machine? tty ?
asciilifeform: novusordo: what prompts? last i saw, 'trezor' had no keyboard
novusordo: if you take a factory-fresh trezor and you have a bip32 wallet you'd like to put on it
novusordo: so apparently the trezor has a better recovery system than I thought
dexX7: "Some of the sources are at http://github.com/trezor/. We are in the process of finalizing and cleaning up the sources and preparing a security audit of the code. We will publish the sources before shipping TREZOR to our customers."
Ademan: mircea_popescu: considering the trezor hasn't been released yet though, it hardly bothers me.
dexX7: ninjashogun: trezor firmware is open source afaik, so you can always verify for yourself or push your own version
asciilifeform: ninjashogun: there is sufficient information available about 'trezor' to learn the answer to this. but please do own homework
ninjashogun: (question: has trezor been audited?)
Apocalyptic: is trezor still a thing ?
asciilifeform: ninjashogun: anyway, take this to the 'trezor' folks, not me. i've personally no interest in manufacturing 'lukewarm wallets.'
ninjashogun: I mean if you took Trezor and made it look like an ATM card, by shrinking it down to the same chip size. (chip and pin)
ninjashogun: asciilifeform, yes, if you moved trezor into the form factor of an ATM card with a PIN, and using the same technology - then it would be interesting.
asciilifeform: that'd be something like 'trezor'
asciilifeform: ninjashogun: i think you have the wrong address. that'd be 'trezor' et al.
asciilifeform: but tell the 'trezor' etc. folks that.
dexX7: asciilifeform: what do the trezor guys wrong for example? i didn't really follow the progress
asciilifeform: the 'trezor' stuff is almost physically painful to read. it's as if they knew every single correct design decision, and did... the exact opposite.
dexX7: neat http://www.bitcointrezor.com/news/2014-03-13-public-demo-trezor-status
asciilifeform: https://github.com/trezor
asciilifeform: trezor's published code is curiously missing the interesting bits.
ozbot: More Pre Order Scams..... (TREZOR)
asciilifeform: mircea_popescu: the trezor folks took preorders !?!11!
asciilifeform: 'It’s not clear how you would build a secure way to initialise the Trezor, as you’d need to use an untrusted computer to present trusted keys into the device. A virus (MITM) could intercept and rewrite the keys as they were being loaded into the device. Unless you had key fingerprints written down on paper, it’d be impossible to notice a mismatch. Pre-agreed root certs installed at the factory solve this
mircea_popescu: incidentally, i hear that's why the trezor kid got shot.
nubbins`: i dunno, i think you're fucked if you're trusting a trezor as a cold wallet
ozbot: TREZOR The Bitcoin Safe - news
jurov: http://www.bitcointrezor.com/news/2014-01-20-trezor-first-edition-delivery
asciilifeform: difficult, lacking a trezor
mike_c: it would be awesome if you published a trezor hack with the cardano release.
asciilifeform: 'trezor' appears to use a cheapo consumer ARM
asciilifeform: when was 'trezor' 1st announced?
asciilifeform: wait, maybe trezor isn't u.s. based
jurov: trezor isn't sold yet either
asciilifeform: how do the 'trezor' folks even get away with shipping the damn thing internationally without publishing source?
asciilifeform: https://github.com/trezor contains no source for the embedded micro, as far as i can see.
ozbot: TREZOR The Bitcoin Safe - news
asciilifeform: http://www.bitcointrezor.com/news/celebrate-day-of-bitcoin-trezor
jurov: i have seen only trezor prototype board, to be delivered in 2 weeks
asciilifeform: anybody here get hold of a 'trezor' and pick it apart?
asciilifeform: 'Now the Trezor is fully deterministic device...'
jurov: http://www.reddit.com/r/Bitcoin/comments/1pesms/trezor_showing_signs_of_life/cd1mo1m
thestringpuller: looks like the cardano will be more secure if used as a wallet than the trezor...
thestringpuller: the trezor only uses PRNG?
asciilifeform: https://github.com/trezor/rng-test/blob/master/dev_random_1.dieharder
asciilifeform: https://github.com/trezor/rng-test
asciilifeform: phun phact: 'trezor' machine uses vendor's on-chip TRNG.
nubbins`: i should design a trezor-looking HID that, when connected, sends "[windows-r], www.mydomain.com/horsedick.avi, [enter]"
ozbot: TREZOR The Bitcoin Safe
asciilifeform: wat's a trezor
skinnkavaj: pankkake: Armory and Trezor is coming with LTC support
jurov: asciilifeform: you have not considered adding a display? it's the thing i like about trezor
thestringpuller: is this the trezor wallet?
nubbins`: now, suppose the trezor instead just displayed private keys
nubbins`: plugging a trezor into a computer = plugging a keyboard/mouse into a computer
nubbins`: problem is, how does the OS know whether "send all BTC to xyz" is coming from the actual keyboard or the fake trezor?
mircea_popescu: i dont know much about trezor, never used it, never considered it.
nubbins`: TREZOR
nubbins`: trezor
kakobrekla: not trezor
kakobrekla: i said trezor like
nubbins`: trezor
kakobrekla: or trezor like device
nubbins`: let's discuss why devices like the trezor exist when it's obviously a bad idea
nubbins`: and you could make hardware wallets WAY less complicated than the trezor
kakobrekla: trezor is slush and company
ThickAsThieves: Trezor will be there, isn't someone here involved with that?