https://github.com/Coldcard/firmware/blob/master/docs/pin-entry.md
If you have learned something valuable, donate a couple sats to Max as a thank you note: 3DqEnU6dW6bZesrVdThrrQjQKgN7dpY5vv https://tallyco.in/HillebrandMax
Support the show by buying bitcoin on https://hodlhodl.com/join/ERCT
List...
fy the Coldcard's authenticity.
* PIN Prefix Verification: The prefix is a crucial element, and if it's incorrect, the device will not proceed.
* Secure Element Role: The secure element is central to many of these features, handling hashing, key storage, and enforcing security policies.
* Firmware Updates: Firmware updates are signed and require user approval (blessing) after installation.
* Physical Security: The Coldcard's physical design incorporates tamper-evident features and requires physical access for firmware modification.
* Lost Seed Backup: The podcast emphasizes the importance of securely storing the seed phrase, as there is no recovery mechanism for lost PINs or seed phrases.
Notable Quotes:
- "It’s a one-way function, so you can derive the duress wallet from the main wallet, but you can’t derive the main wallet from the duress wallet."
- "The duress pin is designed to be a safety net, not a replacement for proper security practices."
- "The secure element is the heart of the Coldcard’s security."
People/Bitcoin Prices:
- No specific people were mentioned by name.
- No Bitcoin prices were mentioned.
---
Here's a summary of part 4/5 of the Coldcard PIN Design and Operation podcast transcript:
Key Topics & Design Philosophy
- Firmware Signing and Trust: The Coldcard's bootloader only executes firmware signed with trusted keys. This significantly restricts who can modify the device's software.
- Key Zero and Experimental Code: Key zero is a publicly available key on GitHub, allowing developers to sign experimental firmware. However, using firmware signed with key zero triggers a warning screen on the device.
- User Blessing of Firmware: Users can "bless" firmware signed with key zero, removing the warning screen. This process requires entering the main PIN.
- Factory Interception Risks: Devices intercepted from the factory before a main PIN is set are vulnerable to having arbitrary code loaded. This highlights the importance of users receiving and setting up their Coldcards directly.
- Tamper Evidence: The Coldcard's physical design includes tamper-evident features to deter unauthorized modification.
- Firmware Modification Difficulty: While firmware modification is possible, it requires physical access, case cracking, and soldering, making it a difficult and detectable process.
- Caution Light Indicator: The red caution light indicates that the firmware has been modified, alerting users to potential compromise.
Notable Quotes:
- "The bootloader only runs signed firmware, which is a very important security feature."
- "If you get a Coldcard from the factory and you don't set a main PIN, anyone can load arbitrary code onto it."
- "The red caution light is a visible indicator that something is not right."
People/Bitcoin Prices:
- No specific people were mentioned by name.
- No Bitcoin prices were mentioned.
---
Here's a summary of part 5/5 of the Coldcard PIN Design and Operation podcast transcript:
Key Topics & Design Philosophy
- PIN Length and Complexity: The Coldcard allows for PINs up to 32 characters, but encourages users to choose strong, complex PINs for enhanced security.
- PIN Hashing and Security: PINs are hashed using a complex process involving a pairing secret and a purpose solved value, making them resistant to brute-force attacks.
- Secure Element Protection: The secure element is the core of the Coldcard's security, protecting PINs and other sensitive data.
- Lost PIN Recovery: There is no recovery mechanism for lost PINs. Users must securely store their seed phrase as the only means of recovering their funds.
- Duress PIN Considerations: The duress PIN provides a safety net for emergency situations but is detectable through bus monitoring.
- Firmware Updates and User Responsibility: Users are responsible for verifying the authenticity of firmware updates and ensuring that they are signed by trusted keys.
- Physical Security and Tamper Evidence: The Coldcard's physical design incorporates tamper-evident features to deter unauthorized modification.
Notable Quotes:
- "The secure element is the heart of the Coldcard's security."
- "There is no recovery mechanism for lost PINs."
- "You should probably have a brick me pin as well [if relying on the duress pin]."
People/Bitcoin Prices:
- No specific people were mentioned by name.
- No Bitcoin prices were mentioned.
---