After hearing the news of #Ledger willingly integrating a ๐-extraction mechanism into their FW if opted-in, I decided it was time to review #XUMM + @Tangem
This ๐งต is not sponsored in any way, & all of my praise comes from the bottom of my โค๏ธ
[4/24] โ 1โฃ Hot Wallet Fundamentals โ
โถ๏ธ #XUMM is a hot, self-custodial ("unhosted") mobile-only #cryptocurrency wallet designed exclusively for the XRPL ecosystem, allowing users to securely store their private keys, make payments, and engage with the #XRPL via #xApps.
[5/24] โ 2โฃ Hot Wallet Fundamentals โ
Regardless of how secure the app is, "hot" desktop & mobile apps have access to the internet & are only as secure as their weakest link.
Keep the following in mind:
๐ธ Update your smartphone
๐ธ Don't use public WiFis
๐ธ Use strong passwords
โ How long would it take an attacker to successfully exploit the app?
๐ธ ~99 quadrillion years โ secret number
๐ธ ~228 years โ 6 digit passcode
๐ธ There is basically no pw-length restriction for the signing password โ 200+ years (16 chars)
Following the implementation of the solutions, #Cossacklabs verified that 58 of the necessary 65 criteria were met, significantly reducing the number of unresolved issues.
Consider how much effort went into resolving all of that. ๐ฅ
Many cryptographic flaws and weaknesses, according to #Cossacklabs, were caused by insufficient security controls that were already in place but did not meet the highest criteria.
As a result, @XRPLLabs opted to re-implement the whole cryptographic layer, thereby building on existing solid foundations to combat certain sophisticated edge cases.
Key takeaways:
๐ธ Even #XUMM is not foolproof
๐ธ No secrets were ever compromised
๐ธ Security has been upgraded based on WASP MASVS v1.5
๐ธ @XRPLLabs team is capable of fixing code related security issues
๐ธ Hot wallets will inevitably be attacked
[13/24] โ 1โฃ XUMM Tangem โ Firmware โ
There are @Tangem cards and #XUMM branded Tangem cards that both use one firmware that has been reviewed by #Kudelskisecurity with one exception:
The XUMM-branded #Tangem cards are not designed to sync the keys ๐
Not only can the firmware not be upgraded by design, but the #firmware can never give out your #privatekey because it is physically only feasible to communicate through #NFC while keeping the secret truly offline at all times.
[15/24] โ 1โฃ XUMM Tangem โ Best Practice โ
Here are some guidelines to make your cold storage genuinely secure:
๐ธ Create a #PIN / Password on your card using #XUMM
๐ธ Purchase 2 cards and configure your "Plan B" using the "Tangem Backup" #xApp within XUMM
[16/24] โ 2โฃ XUMM Tangem โ Best Practice โ
Additional suggestions:
๐ธ Use 4 cards (2 #XRPL accounts) to separate your hot & cold wallets
๐ธ Do not 'root' or jailbreak your phone and use your cards on it
๐ธ Less is more, so use your cold storage to save your funds in the long run
Here are some mind-blowing #Tangem facts:
๐ธ Tangem offers a 25+ year replacement warranty
๐ธ Withstands environmental extremes
๐ธ Withstands occasional mechanical deformation
๐ธ Withstands electromagnetic pulse (#EMP)
. . .
[21/24] โ 2โฃ Tangem Card โ Facts โ
. . .
๐ธ Withstands electrostatic discharge (#ESD)
๐ธ Withstands X-rays
๐ Within limits defined in #ISO7810.
Further:
๐ธ #Tangem App, an open-source in-house development, is capable of verifying the installed firmware on the card
. . .
[22/24] โ 3โฃ Tangem Card โ Facts โ
. . .
๐ธ Works from -25ยฐC up to 85ยฐC
๐ธ Works even underwater ๐
๐ธ #IP68 certified
๐ธ An Access Code may be set and even adjusted to prevent it from being removed from the card after it is set.
๐ If you lose this code, you lose everything.
[2/13] Browser extensions in and of themselves can easily be the source of #exploits.
So, rather than securing your #browser session, increasing your #privacy, or acting as a warning tool before signing transactions, it may turn out to be your worst enemy.
[3/13] โ Attack Vectors โ
๐ง There are merely two malicious concepts that will be exploited by #hackers to harm you while using #browser extensions:
To learn more, keep on reading and complete the steps. (๐ Warning: paranoia ahead.) ๐งต๐
[2/20] โ What is the primary goal? โ
The basic purpose of an executor address is to claim rewards on your behalf in order to save time, max. compound interest, & reduce unwanted exposure of a cold wallet.
Executors will then use auto. claiming to route rewards to your acc. ๐
[3/20] โ 1โฃ Is it safe to assign the task to an executor? โ
The executor cannot claim to any address other than the one provided by the user, therefore automatic claiming is secure. ๐ช
. . .
Let's look through the website and conduct some research before leaping to conclusions. ๐ง
๐ธ Did the #IMF make any comments regarding #DCMA?
๐ธ Will this be the end of #XRP?
Let's find out in this ๐งต๐
[2/16] The Digital Currency Monetary Authority is making moves and expanding its reach through Twitter with its Unicoin network and #UMU, the native Unicoin.
โน๏ธ Who are they and what do they offer?
[3/16] โ โน๏ธ โ 1โฃ #DCMA & #Unicoin โ
๐ธ Founder working on Unicoin since 2013, yet LinkedIn says 2018
๐ธ Just 2 employees
๐ธ They refer to themselves as a business, yet there is no registered corporate structure
2/ Assume I develop a #decentralized gaming app (L2-Smart Contract) with 10 nodes hosted all over the world to be redundant and reliable while processing #smartcontract data in the #network.
โก๏ธ The purpose of this #game is to walk from the starting point to the finish line.
3/ On the players route to the finish line, there are rocks to leap over.
After successfully leaping over a rock, a #transaction on the #dApp gets crafted, granting the player 1 issued #Token labeled "JUMP".
[1/๐งต] A short synopsis of Joachim Nagel's most recent speech on the future of #economic and #monetary union, presented and released by @OMFIF (@OMFIFDMI). ๐