inputting the seed phrase on the phone/tablet.
🚨SCAM Alert🚨 Reminder if you missed to read the welcome message! - There are no free giveaways/airdrops! - If you receive a DM, assume it is scam! - Do not participate in give-aways, send funds or enter your keys after following some links! - There are impersonators across the crypto ecosystem. Kindly familiarise with safety guidelines as per here, note that YOU are your OWN bank when it comes to crypto!
Yoroi’s top priorityHigh-quality code, thoroughly tested, security audited and more to make sure that Yoroi works flawlessly. Private keys are encrypted and never shared with their servers or third party providers. In order to preserve your privacy, Yoroi wallet does not even implement analytics.
I know that. Could there be any Android spyware that could compromise the security, for example?
None that I know of.
Then there would be no point in having a hardware wallet. The only point of a hardware wallet is that you don't input the seed phrase on your device.
Why have one when yoroi supports the ledger hardware wallet?
So it's not as secure on its own?
In one sentence, they’re just as safe as if you were managing your coins directly on ledger live. In both cases your private keys never leave your ledger device
I am talking about using Yoroi without a Ledger.
Like I said, it is safe to.
So why you use Ledger then, if it's safe to not use it?
A ledger, or other hardware wallet simply keeps your private keys on a device that never accesses the Internet. You only ever put your seed words directly into your hardware device as well, nowhere else. So when you use hardware, you connect it to the device with your wallet on to authorise a transaction from your wallet. Without a hardware device you need to enter your seed words into your Internet connected device. Your private keys are also saved (encrypted) on your device connected to the internet. You use a spending password to decrypt the private key to authorise a transaction. So if your device with your wallet gets a virus / key logger etc or compromised in any way. Then your funds would be highly vulnerable. That's the difference.
I knew that as soon as the first hardware wallet came out. Does anyone here know any actual attack vector that could be used on Android to compromise the seed phrase when it's being entered or stored? If I am using Yoroi on a clean Android, what should I do to have it compromised?
That's difficult to say.. compromised could be even losing your phone, or someone watching you type your spending password and then stealing your phone. Also remember people have unlimited attempts at spending password if someone gained access to your mobile. These days mobiles are genuinely quite secure. But I think the bigger question would be, is the cost of a hardware wallet to add security to your funds worth it. Private keys and seed words security are more important than the funds itself. Simply because access to them would give unconditional control over funds in that wallet.
What kind of malware should I install if I want someone to steal my seed phrase? Let's put it that way. I am not talking about losing my phone, I am only talking about software vulnerabilities to begin with.
Обсуждают сегодня