Krippenreiter Profile picture
May 21 โ€ข 25 tweets โ€ข 22 min read Twitter logo Read on Twitter
[1/๐Ÿงต] You've heard of @XummWallet but aren't sure if you can #trust its #security?

You'll learn about @cossacklabs' most recent security assessment and why the #XUMM #wallet strives to maintain the highest security standards.

Follow along in this "all-in-one security ๐Ÿงต" ๐Ÿ‘‡ Source: https://dev.to/wiet...
[2/24] โ€” Outline โ€”
๐Ÿ”ธ Basic Introduction
๐Ÿ”ธ Hot #Wallet Fundamentals
๐Ÿ”ธ #XUMM Wallet Security
๐Ÿ”ธ #Security Audit (18.05.2023)
๐Ÿ”ธ XUMM @Tangem Cards
๐Ÿ”ธ #Tangem Card Facts Source: https://www.gagan.p...
[3/24] โ€” Basic Introduction โ€”

After hearing the news of #Ledger willingly integrating a ๐Ÿ”‘-extraction mechanism into their FW if opted-in, I decided it was time to review #XUMM + @Tangem

This ๐Ÿงต is not sponsored in any way, & all of my praise comes from the bottom of my โค๏ธ Source: https://www.ledger....
[4/24] โ€” 1โƒฃ Hot Wallet Fundamentals โ€”

โ–ถ๏ธ #XUMM is a hot, self-custodial ("unhosted") mobile-only #cryptocurrency wallet designed exclusively for the XRPL ecosystem, allowing users to securely store their private keys, make payments, and engage with the #XRPL via #xApps. Source: https://coingate.co...
[5/24] โ€” 2โƒฃ Hot Wallet Fundamentals โ€”

Regardless of how secure the app is, "hot" desktop & mobile apps have access to the internet & are only as secure as their weakest link.

Keep the following in mind:
๐Ÿ”ธ Update your smartphone
๐Ÿ”ธ Don't use public WiFis
๐Ÿ”ธ Use strong passwords Source: https://www.techtar...
[6/24] โ€” #XUMM Wallet Security โ€”

โ“ How long would it take an attacker to successfully exploit the app?

๐Ÿ”ธ ~99 quadrillion years โ†’ secret number
๐Ÿ”ธ ~228 years โ†’ 6 digit passcode
๐Ÿ”ธ There is basically no pw-length restriction for the signing password โ†’ 200+ years (16 chars) Source: https://www.forex.a...
[7/24] โ€” 1โƒฃ #Security Audit โ€”

@XRPLLabs had a security assessment performed by #Cossacklabs that required over 240 person-hours of work and was publicly disclosed on 18.05.2023

The main takeaway was:
โ˜‘๏ธ "No critical vulnerabilities or immediate exploits were identified" Source: https://xrpl-labs.c...
[8/24] โ€” 2โƒฃ #Security Audit โ€” BEFORE โ€”

During the 1st evaluation, #Cossacklabs noticed that "only" 28 of the relevant 65 standards had been met.

Sounds worse than it is since #XUMM users were never at risk as long as their ๐Ÿ“ฑ were updated and their passwords were kept safe. ๐Ÿซก Source: https://xrpl-labs.c...
[9/24] โ€” 3โƒฃ #Security Audit โ€” AFTER โ€”

Following the implementation of the solutions, #Cossacklabs verified that 58 of the necessary 65 criteria were met, significantly reducing the number of unresolved issues.

Consider how much effort went into resolving all of that. ๐Ÿ”ฅ Source: https://xrpl-labs.c...
[10/24] โ€” 4โƒฃ #Security Audit โ€”

Many cryptographic flaws and weaknesses, according to #Cossacklabs, were caused by insufficient security controls that were already in place but did not meet the highest criteria. Source: https://xrpl-labs.c...
[11/24] โ€” 5โƒฃ #Security Audit โ€”

As a result, @XRPLLabs opted to re-implement the whole cryptographic layer, thereby building on existing solid foundations to combat certain sophisticated edge cases. Source: https://blog.xumm.a...
[12/24] โ€” 6โƒฃ #Security Audit โ€”

Key takeaways:
๐Ÿ”ธ Even #XUMM is not foolproof
๐Ÿ”ธ No secrets were ever compromised
๐Ÿ”ธ Security has been upgraded based on WASP MASVS v1.5
๐Ÿ”ธ @XRPLLabs team is capable of fixing code related security issues
๐Ÿ”ธ Hot wallets will inevitably be attacked Source: https://itnext.io/b...
[13/24] โ€” 1โƒฃ XUMM Tangem โ€” Firmware โ€”

There are @Tangem cards and #XUMM branded Tangem cards that both use one firmware that has been reviewed by #Kudelskisecurity with one exception:

The XUMM-branded #Tangem cards are not designed to sync the keys ๐Ÿ‘‡
[14/24] โ€” 2โƒฃ XUMM Tangem โ€” Firmware โ€”

Not only can the firmware not be upgraded by design, but the #firmware can never give out your #privatekey because it is physically only feasible to communicate through #NFC while keeping the secret truly offline at all times. Source: https://xumm.app/
[15/24] โ€” 1โƒฃ XUMM Tangem โ€” Best Practice โ€”

Here are some guidelines to make your cold storage genuinely secure:
๐Ÿ”ธ Create a #PIN / Password on your card using #XUMM
๐Ÿ”ธ Purchase 2 cards and configure your "Plan B" using the "Tangem Backup" #xApp within XUMM Source: https://support.xum...
[16/24] โ€” 2โƒฃ XUMM Tangem โ€” Best Practice โ€”

Additional suggestions:
๐Ÿ”ธ Use 4 cards (2 #XRPL accounts) to separate your hot & cold wallets
๐Ÿ”ธ Do not 'root' or jailbreak your phone and use your cards on it
๐Ÿ”ธ Less is more, so use your cold storage to save your funds in the long run Source: https://xrpl-labs.c...
[17/24] โ€” 1โƒฃ XUMM Tangem โ€” Hardware Chip โ€”

The "SE" within the card, which is practically indestructible, is the #S3D350A microchip from #Samsung

Entropy is created from the chip's inherent physical noise source via thermal noise amplification ๐Ÿ‘‡
[18/24] โ€” 2โƒฃ XUMM Tangem โ€” Hardware Chip โ€”

Now that we know the source of genuine randomness utilized to generate the secrets, what about the #CPU? ๐Ÿค”

#Tangem employs the "#Arm #SecurCore SC000 Core," one of the most extensively licensed 32-bit smartcard processors in the world Source: https://developer.a...
[19/24] โ€” 3โƒฃ XUMM Tangem โ€” Hardware Chip โ€”

The #Tangem microchip passed the "Common Criteria #EAL6+ Assurance Level," which is required if your chips are to be used in passports.

Fun fact: #Ledger also reached that level. Source: https://excormedia....
[20/24] โ€” 1โƒฃ Tangem Card โ€” Facts โ€”

Here are some mind-blowing #Tangem facts:
๐Ÿ”ธ Tangem offers a 25+ year replacement warranty
๐Ÿ”ธ Withstands environmental extremes
๐Ÿ”ธ Withstands occasional mechanical deformation
๐Ÿ”ธ Withstands electromagnetic pulse (#EMP)
. . . Source: https://tangem.com/en/
[21/24] โ€” 2โƒฃ Tangem Card โ€” Facts โ€”
. . .
๐Ÿ”ธ Withstands electrostatic discharge (#ESD)
๐Ÿ”ธ Withstands X-rays
๐Ÿ“ Within limits defined in #ISO7810.

Further:
๐Ÿ”ธ #Tangem App, an open-source in-house development, is capable of verifying the installed firmware on the card
. . . Source: https://tangem.com/en/
[22/24] โ€” 3โƒฃ Tangem Card โ€” Facts โ€”
. . .
๐Ÿ”ธ Works from -25ยฐC up to 85ยฐC
๐Ÿ”ธ Works even underwater ๐Ÿ˜…
๐Ÿ”ธ #IP68 certified
๐Ÿ”ธ An Access Code may be set and even adjusted to prevent it from being removed from the card after it is set.
๐Ÿ“ If you lose this code, you lose everything. Source: https://tangem.com/en/
[23/24] โ€” TL;DR โ€”

๐Ÿ”ธ XUMM security upgraded (MASVS v1.5)
๐Ÿ”ธ XUMM Tangem account backup via xApp
๐Ÿ”ธ Tangem cards โ€” simple secure offline cold wallet
๐Ÿ”ธ Literally indestructible
๐Ÿ”ธ XUMM branded cards w/o key-sync
๐Ÿ”ธ Cutting-edge certified hardware security
๐Ÿ”ธ @XRPLLabs rocks! Source: https://www.csmonit...
[24/24] Hopefully, this gave you a solid introduction of #XUMM and #Tangem cards in terms of security.
Rest assured, there is more to come. ๐Ÿ”ฅ

Please follow me here:
@krippenreiter ๐Ÿ™

Feel free to contribute by sharing here: ๐Ÿ‘‡

โ€ข โ€ข โ€ข

Missing some Tweet in this thread? You can try to force a refresh
ใ€€

Keep Current with Krippenreiter

Krippenreiter Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @krippenreiter

May 6
[1/๐Ÿงต] Ah, #XRPL, the #blockchain of choice for tech-savvy investors looking to make a quick buck in the world of #Web3 domains.

Why bother with @ICANN when you can just get an NFT? Isn't it practically the same?

WRONG! ๐Ÿงต๐Ÿ‘‡ Source: https://web3domains...
[2/22] โ€” Outline โ€”
๐Ÿ”ธ Fundamentals and Definitions
๐Ÿ”ธ #Web2 vs. #Web3
๐Ÿ”ธ "Domain" Projects
๐Ÿ”ธ @fynbosdev and #ILP
๐Ÿ”ธ A Better Approach (#XRPL)
๐Ÿ”ธ Standardization Source: https://www.gagan.p...
[3/22] โ€” 1โƒฃ Fundamentals โ€” Domain โ€”

#Domains are #namespaces that are used for coupling #IP-addresses to human-readable names for ease of use.

They are also organized in a hierarchical structure for governance purposes. Source: https://www.compute...
Read 23 tweets
Apr 30
โš ๏ธ A browser extension is always a double-edged sword.

In general, there isn't much to disagree with in what @panosmek has written in this fantastic thread, but here are few additional thoughts:

๐Ÿงต๐Ÿ‘‡ [1/13]
[2/13] Browser extensions in and of themselves can easily be the source of #exploits.

So, rather than securing your #browser session, increasing your #privacy, or acting as a warning tool before signing transactions, it may turn out to be your worst enemy.
[3/13] โ€” Attack Vectors โ€”

๐Ÿง There are merely two malicious concepts that will be exploited by #hackers to harm you while using #browser extensions:

๐Ÿ”ธ Supply-Chain attack
๐Ÿ”ธ Man-in-the-middle attack
Read 14 tweets
Apr 24
[1/๐Ÿงต] An easy step-by-step guide for utilizing a #Ledger hardware wallet to configure @BifrostWallet as an #autoclaim executor on the #Songbird (#SGB) network.

To learn more, keep on reading and complete the steps. (๐Ÿ˜… Warning: paranoia ahead.) ๐Ÿงต๐Ÿ‘‡ Source: https://docs.flare....
[2/20] โ€” What is the primary goal? โ€”

The basic purpose of an executor address is to claim rewards on your behalf in order to save time, max. compound interest, & reduce unwanted exposure of a cold wallet.

Executors will then use auto. claiming to route rewards to your acc. ๐Ÿ‘ Source: https://docs.flare....
[3/20] โ€” 1โƒฃ Is it safe to assign the task to an executor? โ€”

The executor cannot claim to any address other than the one provided by the user, therefore automatic claiming is secure. ๐Ÿ’ช
. . .
Read 21 tweets
Apr 16
[1/๐Ÿงต] โ€” #DCMA / #Unicoin / #UMU & the future of #Crypto & #CBDC โ€”

Let's look through the website and conduct some research before leaping to conclusions. ๐Ÿง

๐Ÿ”ธ Did the #IMF make any comments regarding #DCMA?
๐Ÿ”ธ Will this be the end of #XRP?

Let's find out in this ๐Ÿงต๐Ÿ‘‡ Source: https://dcma.io/ima...
[2/16] The Digital Currency Monetary Authority is making moves and expanding its reach through Twitter with its Unicoin network and #UMU, the native Unicoin.

โ„น๏ธ Who are they and what do they offer? Source: https://dcma.io/ima...
[3/16] โ€” โ„น๏ธ โ€” 1โƒฃ #DCMA & #Unicoin โ€”
๐Ÿ”ธ Founder working on Unicoin since 2013, yet LinkedIn says 2018
๐Ÿ”ธ Just 2 employees
๐Ÿ”ธ They refer to themselves as a business, yet there is no registered corporate structure Source: https://unicoinnetw...Source: https://www.linkedi...Source: https://www.linkedi...
Read 17 tweets
Mar 28
1/ To be honest, I'm having a hard time comprehending this one, but I came up with a simple example that could help. ๐Ÿงต

@woj4ke Please correct me if I am incorrect.

I'll probably delete this later if it doesn't make sense.
2/ Assume I develop a #decentralized gaming app (L2-Smart Contract) with 10 nodes hosted all over the world to be redundant and reliable while processing #smartcontract data in the #network.

โžก๏ธ The purpose of this #game is to walk from the starting point to the finish line.
3/ On the players route to the finish line, there are rocks to leap over.

After successfully leaping over a rock, a #transaction on the #dApp gets crafted, granting the player 1 issued #Token labeled "JUMP".
Read 13 tweets
Mar 26
[1/๐Ÿงต] A short synopsis of Joachim Nagel's most recent speech on the future of #economic and #monetary union, presented and released by @OMFIF (@OMFIFDMI). ๐Ÿ‘‡

[2/7] Joachim Nagel, a member of the @bundesbank's Executive Board, discusses:
๐Ÿ”ธ #Inflation
๐Ÿ”ธ #Monetary policy
๐Ÿ”ธ #Fiscal development, ...

... among other topics.
[3/7] According to Nagel, the ongoing #energy #crisis in #Ukraine has resulted in:
๐Ÿ”ธ Greater #inflation
๐Ÿ”ธ Higher #energy prices ...

... influencing:
๐Ÿ”ธ #Industrial costs
๐Ÿ”ธ #Financial insecurity.
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(