2985 lines
876 KiB
HTML
2985 lines
876 KiB
HTML
<html><body><style>
|
|
* {
|
|
font-family:sans-serif;
|
|
}
|
|
body {
|
|
text-align:center;
|
|
padding:1em;
|
|
}
|
|
.messages {
|
|
width:100%;
|
|
max-width:700px;
|
|
text-align:left;
|
|
display:inline-block;
|
|
}
|
|
.messages img {
|
|
background-color:rgb(248,244,240);
|
|
width:36px;
|
|
height:36px;
|
|
border-radius:0.2em;
|
|
display:inline-block;
|
|
vertical-align:top;
|
|
margin-right:0.65em;
|
|
}
|
|
.messages .time {
|
|
display:inline-block;
|
|
color:rgb(200,200,200);
|
|
margin-left:0.5em;
|
|
}
|
|
.messages .username {
|
|
display:inline-block;
|
|
font-weight:600;
|
|
line-height:1;
|
|
}
|
|
.messages .message {
|
|
display:inline-block;
|
|
vertical-align:top;
|
|
line-height:1;
|
|
width:calc(100% - 3em);
|
|
}
|
|
.messages .message .msg {
|
|
line-height:1.5;
|
|
}
|
|
</style><div class="messages"><div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2017-11-15 21:48</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2017-11-15 21:48</div><div class="msg">@hutch set the channel purpose: Discussion of implementation and progress of Status Hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-15 22:00</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-05/310886360359_5346fd4529b6d0a8ed28_72.jpg" /><div class="message"><div class="username">jason</div><div class="time">2017-11-15 23:42</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-16 00:13</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-11-16 00:13</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-11-16 08:43</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-01-09/125597416918_4b7b095b4e695e7a8be1_72.jpg" /><div class="message"><div class="username">carl</div><div class="time">2017-11-16 19:06</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-11-17 13:22</div><div class="msg">Hi all, I am the one working on the Status Hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-11-17 13:23</div><div class="msg">for any question/feedback/proposal I am here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 06:10</div><div class="msg">thanks @micheleb hey, how's the pairing spec going?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-19 06:20</div><div class="msg">hey guys what is the planned form factor for the hardwallet? the graphics i saw in some of the marketing material show a credit card sized object with a chip, and i saw the some JavaCard code in the repo.
|
|
|
|
is the idea here to interface with traditional chip and pin systems but talk to ethereum or is there going to be an nfc component that does signing with the phone app?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 06:29</div><div class="msg">@noman it's a credit card form factor</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 06:30</div><div class="msg">no it's not, at least not for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-19 06:32</div><div class="msg">so what is the chip interacting with?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-11-19 07:38</div><div class="msg">@jarradhope The pairing spec is complete, implementation is also complete but I need to write some more tests. I am also considering adding a MAC (message authentication code) in each APDU and response. It makes things more complex but guarantees integrity.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 09:35</div><div class="msg">the phone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-19 09:35</div><div class="msg">so it's an nfc thing for offline signing of transactions?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 09:47</div><div class="msg">have you had a chance to read <a href="https://hardwallet.status.im/">https://hardwallet.status.im/</a> /</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 09:48</div><div class="msg">sorry @noman I'm not super clear how you're involved in the hardware wallet project?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2017-11-19 09:51</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-19 10:46</div><div class="msg">i'm not really involved, was just reading through code trying to understand the project. i was confused seeing the physical, gold, chip on the cards in the marketing materials. wasn't sure how that piece fit in</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2017-11-19 10:49</div><div class="msg">the site says contactless but the graphics imply both contactless and contactful</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 11:01</div><div class="msg">ah right, so yes the cards can be what they call 'dual interface' so it looks and behaves just like a card with physical contact but it also has NFC</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-19 11:01</div><div class="msg">yes that's the case</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-11-21 13:52</div><div class="msg">I have added AES CBC-MAC to the SecureChannel. As I had thought, it makes the secure channel much more complex and slower, especially since the card unexpectedly does not implement AES CBC-MAC natively so I had to implement it in software, wasting some RAM and possibly some performance too. However if real usage performance is found to be acceptable, then there is nothing to worry about. If anybody wants to review the updated specs and the code, you are welcome</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-22 04:49</div><div class="msg">thanks @micheleb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-11-22 04:50</div><div class="msg">Will review later today</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2017-11-23 17:56</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2017-11-29 11:14</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2017-12-01 15:03</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-04 09:37</div><div class="msg">@jarradhope did you already have a chance to review? also, is there anybody working on the client side of the project yet?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2017-12-04 09:43</div><div class="msg">Re client side, not that I know of. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-05 03:35</div><div class="msg">i haven't had a chance to review sorry @micheleb will find some time today, at the moment the client side there isn't, </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-05 03:35</div><div class="msg">it's unclear best integration point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-05 03:36</div><div class="msg">ie if we do it in Go or in react native, and both have different design decisions involved</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-05 03:36</div><div class="msg">@naghdy there was some talk supporting multiple wallets and this would be related to that discussion</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-05 03:37</div><div class="msg">@janherich @jeluard started thinking about it,. but these are related but also separate discussions</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-12-05 07:31</div><div class="msg">@micheleb Maybe you can share some details about the integration workflow?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-05 09:08</div><div class="msg">@jarradhope @jeluard I will write a document about how the client should comunicate with the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-05 09:11</div><div class="msg">the way I have made the applet and all related protocols a wallet can support pairing with multiple clients and a client can support pairing with multiple wallets. Each wallet has an UUID.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-05 14:04</div><div class="msg">I have finished the document I promised</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-05 14:04</div><div class="msg"><a href="https://github.com/status-im/hardware-wallet/blob/master/CLIENT_NOTES.md">https://github.com/status-im/hardware-wallet/blob/master/CLIENT_NOTES.md</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-05 14:04</div><div class="msg">for any clarification I remain available, but this should provide most of the information needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-06 12:38</div><div class="msg">@jeluard @naghdy @chad ^</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-12-06 14:48</div><div class="msg">@micheleb Thanks for the detailed document I will have a deeper look at it.
|
|
I may lack some context but how do you foresee hardwallet being integrated with status running on a mobile?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-06 15:02</div><div class="msg">@jeluard I think the idea was to use the NFC reader of the mobile. Since at the moment I am not involved with application development, I do not know which mobiles provide NFC smart-card readers and through which API</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-06 15:03</div><div class="msg">there are certainly external card readers made for Android however</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-12-07 07:40</div><div class="msg">@micheleb Thanks! Looks like we have all that we need in Android.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-12-11 07:33</div><div class="msg">@micheleb I finally spent some time reading the documentation. Great work! It looks like in combination with unit tests we have everything to implement the client.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-11 15:03</div><div class="msg">```
|
|
Nick Johnson @Arachnid Dec 08 23:20
|
|
Hey, do you have a build of Status that supports the smartcard hardware wallet?
|
|
Or, is there something else you've been using to test?
|
|
```
|
|
@micheleb @naghdy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-12 00:56</div><div class="msg">@jeluard? anyone?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2017-12-12 06:56</div><div class="msg">I understand @micheleb has been developing / testing using an internal fork of jCardsim (<a href="https://github.com/status-im/jcardsim">https://github.com/status-im/jcardsim</a>)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-12 07:28</div><div class="msg">@jarradhope @jeluard I have been testing with jCardSim but also on a real card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-12 07:29</div><div class="msg">there is an automated test suite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-12 09:50</div><div class="msg">I believe Nick was asking about automated test suite for real card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-13 08:58</div><div class="msg">yes there is one, it is the one started with the ./gradlew test command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-13 09:01</div><div class="msg">@jeluard here are some mobile smartcard card readers: <a href="https://www.acs.com.hk/en/product-lines/54/mobile-card-readers/">https://www.acs.com.hk/en/product-lines/54/mobile-card-readers/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-13 09:01</div><div class="msg">surprisingly, some claim to work even on iOS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2017-12-17 13:10</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2017-12-31 06:00</div><div class="msg">@micheleb Nick Johnson from MyEthercards is having problems getting the tests to run, could I trouble you to contact him on <a href="http://Gitter.im">http://Gitter.im</a> and help him out ? <a href="https://gitter.im/Arachnid">https://gitter.im/Arachnid</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2017-12-31 13:47</div><div class="msg">@jarradhope ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:21</div><div class="msg">@jarradhope we got the tests running at Nick?s side, both on card and simulator</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:22</div><div class="msg">fantastic thanks @micheleb thanks for update</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:22</div><div class="msg">what was the blocker?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:22</div><div class="msg">he did not have the JCE Unlimited Security policy installed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:22</div><div class="msg">I added that requirement and a link to the instructions in the README</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:23</div><div class="msg">I have also extended the Gradle build script a bit to also support testing on simulator, since before this would only work by running JUnit manually or through an IDE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:24</div><div class="msg">great thank-you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:24</div><div class="msg">:smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:24</div><div class="msg">I have also forwarded you quotes from ACS for the plain cards and cheap card readers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:25</div><div class="msg">in volumes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:25</div><div class="msg">yes I saw thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:25</div><div class="msg">We probably won't do it in-house I think, its a fair bit of overhead</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:25</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:25</div><div class="msg">So Nick and his team runs <a href="https://ether.cards/">https://ether.cards/</a> so we can work with them for the time being</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:26</div><div class="msg">actually are you familiar with the card in this company uses <a href="https://www.coolbitx.com/">https://www.coolbitx.com/</a> ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:27</div><div class="msg">its a bluetooth card with screen for bitcoin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:27</div><div class="msg">cool stuff. No, not familiar</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:28</div><div class="msg">unfortunately their API page is under construction</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-05 13:30</div><div class="msg">if I understand correctly from their code examples on Github, it is not being sold as a platform where you can developer your on-card applets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:32</div><div class="msg">no its not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:32</div><div class="msg">its being sold as a product</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-05 13:32</div><div class="msg">trying to decipher who their vendor is</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-14/287020633316_325ce7b3b08263f4a62a_72.png" /><div class="message"><div class="username">eduardo780</div><div class="time">2018-01-06 19:53</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-08-30/234480040247_f5d20e9a30823e58ae4a_72.png" /><div class="message"><div class="username">deodatus</div><div class="time">2018-01-12 03:41</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-28/292166928837_80716616e1b9d7917b1b_72.jpg" /><div class="message"><div class="username">alexander249</div><div class="time">2018-01-13 18:13</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-01-16 16:29</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-19 12:24</div><div class="msg">Hi @jarradhope, I am doing some improvements/fixes to the hw wallet as requested by Nick. I was wondering if there is any advancement regarding the security audit. It would be nice to have in order to validate, strengthen or simplify the security model</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-01-19 13:19</div><div class="msg">There hasn't but I can arrange it if you would like</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-01-23 10:47</div><div class="msg">well in case the audit is still something that is planned for the project, I think this would be the right time to do so, since Nick has submitted the PR for go-ethereum (<a href="https://github.com/ethereum/go-ethereum/pull/15925">https://github.com/ethereum/go-ethereum/pull/15925</a>)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-03-02 00:29</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-01/308563433637_bac31bc179bd2f35cf1e_72.jpg" /><div class="message"><div class="username">martin487</div><div class="time">2018-04-09 12:48</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-01/308563433637_bac31bc179bd2f35cf1e_72.jpg" /><div class="message"><div class="username">martin487</div><div class="time">2018-04-09 12:51</div><div class="msg">I?m friends with Andrew Pantyukhin of <a href="https://tangem.com/">https://tangem.com/</a> ? maybe they would be worth considering as partner for the hardwallet stuff. Don?t know. Can intro if wanted.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-04-16 07:22</div><div class="msg">I am learning about "hardwallet logic". I read WalletApplet.java, and seems clear and simple, good work.
|
|
Seems like we will be able to use exactly the same method for `ethereum signed transaction` and `ethereum signed message` ?
|
|
<a href="https://github.com/status-im/hardware-wallet/blob/9224471670da713be2bcec971b6446af45532e04/src/main/java/im/status/wallet/WalletApplet.java#L240">https://github.com/status-im/hardware-wallet/blob/9224471670da713be2bcec971b6446af45532e04/src/main/java/im/status/wallet/WalletApplet.java#L240</a>
|
|
I`m not sure if is important to take them separatedly as standerd specific for safely separating the signed messages from signed transactions as <a href="https://github.com/ethereum/EIPs/issues/191">https://github.com/ethereum/EIPs/issues/191</a> (and referenced EIPs & PR). Right now wallets, such as Mist/MetaMask sign messages by including a prefix `keccak256("\x19Ethereum Signed Message:\n" + msg.length + msg")`. This can be handled by software interacting with javacard, and if a malicious "app" wanted to fake a transaction from a message it would probably also fake a transaction from a transaction.
|
|
|
|
I didnt verified any parameters and I don't have technical background to audit this wallet, but the architecture of WalletApplet.java sgtm
|
|
|
|
As suggestions I think would be good to cards behave genericly to pin/puk behavior even if never configured or already burned out the pik/puk and keys...
|
|
And for safety, when pik retrys run out, it should lock card for a long period after accepting retrys of PUK, and each PUK retry should have a big delay. I'm thinking in a case where some "children" hand a status hardwallet card and mobile phone and start playing with the pin because tried to buy random stuff, so parents could have more time to prevent wipe out of their keys.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-04-16 07:23</div><div class="msg">I see great potential of this cards together with #145-identity</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-04-16 07:26</div><div class="msg">I assume I can always rewrite a new WalletApplet.java code from my mobile device? Or that reset the pin/puk requires rewrite of WalletApplet.java :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-04-16 07:33</div><div class="msg">Also I imagine we can use contactless javacard for running this WalletApplet.java?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-04-20 14:49</div><div class="msg">@3esmit regarding the dealys in the PUK retry, javacard has not time-keeping abilities and platforms run at different frequencies so using an empty for loop would create unpredictable behavior</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-04-20 14:49</div><div class="msg">there is no ?sleep"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-04-20 14:50</div><div class="msg">and yes the applet works regardless of contacted or contactless interface</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-10/345048961478_60c5a0cb079da69aa25c_72.jpg" /><div class="message"><div class="username">ericmastro</div><div class="time">2018-04-23 13:53</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-04/448613224960_1172d54b59bd12529087_72.jpg" /><div class="message"><div class="username">rramos</div><div class="time">2018-05-05 14:21</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-06 08:36</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-08 07:53</div><div class="msg">nothing too exciting yet, but the toolchain works :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 08:47</div><div class="msg"><!channel> Hi all, I am working on the memory layout and bootloader of the hardware wallet. I have written this file which documents the entire procedure, but there are some open question inside I would like to get feedback on. I want to start a repository for this and the code, but I still need to know which license we can use. I would got for GPLv3 since it would allow us to reuse similarly licensed code from other projects. If there is no objection I will go for that.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 08:51</div><div class="msg"><!channel> comments on the above?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-11 12:30</div><div class="msg">hey @micheleb we typically dual license Apache and MIT but GPL can be fine as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 12:31</div><div class="msg">ok I can license our code as Apache/MIT, then if there are GPL dependencies the project as a whole will be considered to be GPL</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 12:31</div><div class="msg">it should work like this when mixing, if my understanding is correct :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-11 12:35</div><div class="msg">yes exactly</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-11 12:36</div><div class="msg">the problem with gpl is we might block ourselves from adoption in hardware</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-11 12:36</div><div class="msg">not by us but some other kind of partner</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-11 12:37</div><div class="msg">and you can't protect against Tivoization anyway <a href="https://en.m.wikipedia.org/wiki/Tivoization">https://en.m.wikipedia.org/wiki/Tivoization</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 13:06</div><div class="msg">ok. I will avoid GPL altogether if possible then</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 14:22</div><div class="msg"><a href="https://github.com/status-im/hardwallet-bootloader">https://github.com/status-im/hardwallet-bootloader</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-11 14:22</div><div class="msg">very much work in progress :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-14 11:12</div><div class="msg">awesome!!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-14 11:12</div><div class="msg">@ericmastro ^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-18 10:49</div><div class="msg"><!channel> another document regarding the production details/firmware upgrade procedure. If you have any feedback let me know: <a href="https://github.com/status-im/hardwallet-bootloader/blob/master/PRODUCTION.md">https://github.com/status-im/hardwallet-bootloader/blob/master/PRODUCTION.md</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-18 10:51</div><div class="msg">from next week work on the actual firmware will start</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-18 14:00</div><div class="msg">Looks good to me, it seems the discussion on how to sign and the signatories needs to take place</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-18 15:22</div><div class="msg">good. Yeah that discussion needs to take place, of course there is still time for this. The boot time @24mhz and low voltage with 4 signatures is around 2 seconds. With 1 signature is almost instantaneous. But the chip I have can go up to 80mhz and the one we are looking to get can go up to 64mhz, so we have a lot of headroom for improving this. I can (and will) manage the frequency dynamically in the firmware to get the optimal performance/power usage balance. With the size we are aiming at our battery will be very small, so this is a concern I will keep in mind from the very beginning</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-19 11:46</div><div class="msg">Good stuff</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 14:40</div><div class="msg"><!channel> as always I request some feedback. Here is the repo for the hardwallet firmware <a href="https://github.com/status-im/hardwallet-firmware">https://github.com/status-im/hardwallet-firmware</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 14:43</div><div class="msg">the README file is quite small, but in the docs/UI.md document there are a lot of open point where I really need feedback on. Until we clear these point up I can work on the internal components in an isolated way (implementing needed algorithms, transaction decoding, BLE etc) but not on the ?whole"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 14:51</div><div class="msg">@micheleb the proposal for 2 buttons makes alot of sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 14:52</div><div class="msg">i would highly recommend against scrollwhell, the mooltipass has one and it's the worst</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 14:52</div><div class="msg">Ledger Nano S also has a two button config and works really well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 14:53</div><div class="msg">yeah I also tend for the two buttons variant</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 14:54</div><div class="msg">the scrollwheel I envisioned was more like the old iPod one, but I still do not think it is worth the PCB space and I think people already un-learned using the iPod scrollwheel</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 14:56</div><div class="msg">i think moving parts is going to increase the fragility of the device</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 14:57</div><div class="msg">yeah, it was a touch-capacitative one, so no moving part. But it would need to be rather large to be remotely useful. We can settle for the two buttons variant and I will describe that one more in details</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 14:58</div><div class="msg">ah cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:14</div><div class="msg">> currency icon (ETH, SNT),
|
|
might be a rabbit's hole, as there is many, many ERC20 tokens, do we support them all?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:15</div><div class="msg">somewhat related, do we support Bitcoin?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:15</div><div class="msg">yeah that is the question. If we are doing it only for status then it is ok to include the SNT icon</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:15</div><div class="msg">Bitcoin and other coin support was not planned, but we can add it actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-21 15:16</div><div class="msg">waterproof?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:16</div><div class="msg">waterproof would be ideal :neutral_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:17</div><div class="msg">Bitcoin and Ethereum is the only ones we really need to support, ERC20 tokens maybe its better to stsore 3 letter alpha-numerics</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:17</div><div class="msg">instead of icons</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:18</div><div class="msg">> 5. How we display the destination address
|
|
I would truncate end and show begin and end as static, then scroll through it
|
|
0xasd332...adsdasad</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:19</div><div class="msg">ok so we need bitcoins too, I did not know. Then we we will need either extra space for the token 3 letters or to display it sequentially</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:20</div><div class="msg">ok so each key press scrolls by one ?page? the address?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:24</div><div class="msg">@arnetheduck.slack if we need it waterproof then we must use capacitative buttons or resisitive ones but covered by a dome (like very simple pocket calculators). We also need to seal everything. But this is not really a challenge, it can be done</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:25</div><div class="msg">especially if we are not too strict on keeping thickness to the ISO standard for credit cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-05-21 15:28</div><div class="msg">Playing devils advocate, wouldn't keeping the thickness to the ISO CC standard be more important than being waterproof. Both would be ideal, but if we had to choose the convenience of being carried around in your wallet would outweigh the waterproof-ness</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:29</div><div class="msg">well, a credit-card slot of a regular wallet can usually keep up to 3 credit cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:29</div><div class="msg">at least 2 is always possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:33</div><div class="msg">another thing about waterproofness is that is better to use wireless charge (instead of exposing two contacts on the body like the current Coolwallet does). For that we need a separate layer with a coil, when time comes I will have to check the thickness of this solution</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:34</div><div class="msg">a smaller on-PCB coil is not really an option, it wouldn't have the surface area to pick enough of a field</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-21 15:37</div><div class="msg">what about splash/rain-proofness? does that make a difference? ie IP68 vs IP53</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-05-21 15:38</div><div class="msg">I've taken my phone out for a swim more than once by accident, and if we imagine this thing being carried around in a wallet on a "daily" basis..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:38</div><div class="msg">coolwallet does wireless charge</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:39</div><div class="msg">@jarradhope I have seen they have two models, one is wireless the one if contacted</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:39</div><div class="msg">but on the current site I can only see the one with contacts, from the wireless one I see an old manual only</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:40</div><div class="msg">the one he demo'd me was wireless, but maybe just trying to be fancy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:40</div><div class="msg">I have seen some videos. There is one with a black screen and wireless. Then on the site is white screen and two contacts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:40</div><div class="msg"><a href="https://coolwallet.io/wp-content/uploads/2018/02/DSCF3513.png">https://coolwallet.io/wp-content/uploads/2018/02/DSCF3513.png</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:41</div><div class="msg">the silver squares are positioned as to go in the charging dock, so I guess these are contacts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 15:43</div><div class="msg">hmm i see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:44</div><div class="msg">the charger question I think is mainly a cost question</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:44</div><div class="msg">we can use Qi standard and not bundle the charger at all (but then you already need a compatible charger)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:44</div><div class="msg">or bundle one, but it is going to be more expensive than a simple usb charger</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:51</div><div class="msg">anyway it is relatively early for these details. It is more important to decide how we display things</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:51</div><div class="msg">so what I get from today discussion is that we need bitcoin support and generic ERC20 token support</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:52</div><div class="msg">what about the input wallet? do we display the input wallet address too?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 15:53</div><div class="msg">since we are going for HD, the device can manage several wallets? for bitcoins it is a little different because you can use multiple inputs for a single transaction, but Ethereum is account based..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 16:30</div><div class="msg">bitcoin was mostly a question, i think uxto is going to be alot harder to manage</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 16:30</div><div class="msg">ah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 16:31</div><div class="msg">i haven't really put the thought into managing bitcoin keys, having Eth only might be more feasible instead of expanding scope</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 16:31</div><div class="msg">although i can certainly see almost everyone owning eth will own btc</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2018-05-21 16:31</div><div class="msg">The old coolwallet charging was wireless, the new one must be physically inserted into a device. I suspect reliability issues.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 16:35</div><div class="msg">ok I will study the possibility of handling BTC, but it is not a strict requirement for the product for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 16:39</div><div class="msg">@jeluard I will check the reliability and costs aspects of wireless charging</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 16:45</div><div class="msg">too bad betavoltaic cells are not mainstream, otherwise we wouldn't really need a charger</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-05-21 17:20</div><div class="msg">So, Im kind of out of sync here.
|
|
Hardware wallet is about a Javacard that holds one or more private keys, which can sign ethereum transactions or sign ethereum messages.
|
|
So, we are going to have one more thing beside that hardware? I imagined it would be all in the smartphone nfc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 17:22</div><div class="msg">the JavaCard hardware wallet indeed does not require other components (except a card reader but these are standards)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 17:23</div><div class="msg">we are now discussing another hardware wallet we are developing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 17:23</div><div class="msg">it is not a JavaCard is an embedded device with its own screen, button and connects to the phone via bluetooth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 17:23</div><div class="msg">BLE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-05-21 17:35</div><div class="msg">would be nice if this other device be able to use the javacard</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-05-21 17:35</div><div class="msg">or its a replacement?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-21 17:37</div><div class="msg">it is a parallel project, let?s call it a pro version</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 18:30</div><div class="msg">@3esmit security model of the javacard still requires a one-time trust decision with the phone/app, the pro version aims to improve the security model by displaying transaction and physical signing (by button) on card, as well as enable bluetooth, which is kind of the only option we have for iPhone communication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-21 18:30</div><div class="msg">so their will be a "Lite" version and a "Pro" version</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:06</div><div class="msg"><!channel> I have been working (with the help of a designer, my wife) on the digits/letters for the hardware wallet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:07</div><div class="msg">?standard? solutions are 7-segment and 14-segments, like this.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:08</div><div class="msg">as you can see, letters in the 7-segment version require a lot of imagination to understand, they are mostly unreadable. The 14-segment is very readable but is twice the amount of segments, meaning we require a lot more pins to drive it and hence we will have to either use more PCB space or be able to show less digits</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:09</div><div class="msg">then, we also developed a very custom 9-segment display. Everything is very readable in my opinion</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:09</div><div class="msg">from a readability/amount of segment point of view it is a good compromise. The downsides are</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:10</div><div class="msg">1) the numbers are not similar to those used in regular 7-segment display which people already know</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:11</div><div class="msg">2) 4, 5 and B are not that good looking, although readable imho. Maybe they can be made a little nicer by making the center segment shorter.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:13</div><div class="msg">3) 2/Z and 5/S pair are similar. We have used the central segment on Z because many people write the crossed Z when handwriting. Also we have used it for the 5 because well, it looks a little more like a 5.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:13</div><div class="msg">the compromise here is that we have more diagonals than a 7-segment but the vertical bars are one-piece and not separated</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 09:15</div><div class="msg">so once again, I am asking for feedback. If there are no objections, I will go with the custom 9-segment digits. Otherwise the choice is between 7 and 14, keeping in mind that 14 costs more in term orf PCB space, MCU pins and possibly component count</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-22 09:58</div><div class="msg">I cant say 9 segmemts is inherently more readable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 10:00</div><div class="msg">there are less problem letters than with 7 segments, where the k, m, u, v, w are quite unreadable to me</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 10:03</div><div class="msg">3 and 8 could actually be made look like classic digits also with 9-segments, it was a choice to make it that way to keep the font more uniform</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 10:04</div><div class="msg">but yeah, there are compromises</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-22 10:16</div><div class="msg">another intermediate step between 7 and 14 is 11, which means all numerals would look as usual and the letters mostly as with 9-segment, except B, P, R which can be improved</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-31 10:51</div><div class="msg">thanks for being on the call @micheleb , when i mentioned the possibility to change featureset, i wanted to ask you that if the specific pinless address in HD tree, also doesnt require the secure channel?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-31 10:51</div><div class="msg">the usecase im imagning is payment at point of sale terminals</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 10:51</div><div class="msg">the secure channel is always required at the moment, but that can be changed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-05-31 10:52</div><div class="msg">i think if we can change it to allow for this use-case we greatly increase the versatility of the product, what do you think?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 10:54</div><div class="msg">I would like to analyze the possibility to at least keep a secure channel as in the very first version, where no secret is shared and just encrypts communication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 10:54</div><div class="msg">but this is surely possible, a sort of paypass application would be great</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 10:54</div><div class="msg">or paywave or whatever the cc companies call it :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 10:56</div><div class="msg">so basically make a difference between authenticated and not-authenticated secure channel, where non-authenticated can only use the pinless address</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:12</div><div class="msg">@jarradhope I have had a look at the code and the document to refresh my memory. I confirm that it can be done in a backward compatible way. The possible solutions in decreasing order of security but increasing order of client-side simplicity are</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:13</div><div class="msg">1) use a pre-shared secret for the secure channel, so the cards are pre-paired with all terminals. This pre-shared secret must be protected by NDAs etc and be shared with terminal manufacturers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:13</div><div class="msg">2) use a secure channel but with no shared secret so no authentication. It just defends against traffic snooping</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:14</div><div class="msg">3) use no secure channel at all</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:14</div><div class="msg">I would really like the first solution, because if the keys are kept secret then unauthorized terminals would not be able to perform transactions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-05-31 11:16</div><div class="msg">we can also pre-allocate n different keys so different manufacturers would get different keys, allowing us to somehow react on a leak</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:03</div><div class="msg">@jarradhope do you see any obstacle if I implement that solution? Because I could start to work on it on Monday already</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:03</div><div class="msg">or any of the three really</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-01 08:03</div><div class="msg">Sorry I forgot to respond</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-01 08:04</div><div class="msg">So the issue with a preshared key is it might not be doable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-01 08:04</div><div class="msg">Because it would be in the Status app and reversible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-01 08:05</div><div class="msg">What we *could* do is only allow to sign transactions automatically to a specific contract address</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-01 08:06</div><div class="msg">And this can do advanced logic on chain</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:07</div><div class="msg">but the problem is for the javacard app that it does not get the transaction</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:07</div><div class="msg">it only gets the hash</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:08</div><div class="msg">since it cannot do SHA3</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:10</div><div class="msg">how do you envision the possibility to use payment terminals? I thought you wanted to use the card directly with a payment terminal, so communicating with the javacard applet without the mobile phone (or at least, not with a paired one). I wanted to use a preshared key only instead of the pairing process and allowing only to use the pinless key to sign</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:13</div><div class="msg">aaaaa I think I see, the payment terminal would still be an app, not a dedicated device, so the preshared key can be read from device memory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-01 08:13</div><div class="msg">ok, but still would provide a little more snooping protection than disabling the secure channel altogether</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-05 08:08</div><div class="msg">Ah that's right</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-05 08:08</div><div class="msg">No worries</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 08:11</div><div class="msg">So do we want to implement just an unauthenticated secure channel? Or leave it as is for now?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 08:13</div><div class="msg">The security issue is the same as with nfc credit cards, but with the difference that you do not need a bank-issued terminal to process transactions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 08:13</div><div class="msg">So it is much easier to be an attacker</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-05 10:34</div><div class="msg">Yeah without inspecting the transaction on device what I was proposing is impossible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 10:35</div><div class="msg">But we can keep this in mind for the pro version</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 10:35</div><div class="msg">A pairingless BLE connection</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 10:36</div><div class="msg">Since PIN entry happens on the device it is possible to even keep PIN security if needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 10:37</div><div class="msg">In later stage I will try to model and document this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-05 10:37</div><div class="msg">And of course in the pro version we can inspect the transaction</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-05 10:44</div><div class="msg">Sounds good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-15 12:14</div><div class="msg">Just an update to the channel, now the communication protocol and data storage are documented. You find everything here: <a href="https://github.com/status-im/hardwallet-firmware/tree/master/docs">https://github.com/status-im/hardwallet-firmware/tree/master/docs</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-15 12:14</div><div class="msg">as always I am open to any feedback, questions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-15 12:16</div><div class="msg">and yes, we are going to have the only open source hardware wallet with proper documentation. Should help for interoperability and for maintenance :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-15 13:24</div><div class="msg">Haha awesome, will do my best to review</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-19 14:01</div><div class="msg">@micheleb Peter (@karalabe on GitHub/gitter) thinks he found a large security hole in the light hardware walllet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-19 14:02</div><div class="msg">That's all the info I know but worth reaching out to him</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-19 14:03</div><div class="msg">oh, I will reach out to him immediately, let's see what it is about</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-21 07:47</div><div class="msg">@jarradhope I managed to contact Peter. It turned out to be a misunderstanding about the role of the secure channel.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-21 07:49</div><div class="msg">However, he had a point that we could erase the private key as soon as the PUK is blocked. It does not really increase security since any operation with the key is blocked anyway. Nonetheless erasing the key reinforces the statement that the wallet is lost forever :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-21 07:50</div><div class="msg">Long story short, there was no security issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-21 07:54</div><div class="msg">thanks for following up @micheleb !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-21 08:11</div><div class="msg">I am also thinking of using a pairing code separate from the PUK because it generates confusion. The PUK is not really being used for its functions, it was only to avoid having too many separate codes. But it created the misconception that the PUK and pairing code are the same thing (instead of just happening to match)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-25 09:14</div><div class="msg">update on the javacard applet. I have decoupled the pairing secret from the PUK</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-25 09:17</div><div class="msg">the applet now accepts the pairing secret as an installation parameter and does not care how it has been generated. It can still be a password (of any length), maybe hashed with PBKDF2 or scrypt or it can even be random data printed as QRCode on the card itself (since pairing is only needed to create a secure channel)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-25 09:19</div><div class="msg">for this reason, the PUK retry count is not output anymore in the SELECT command. But you get a number of remaining pairing slots instead, so the client can issue a warning about all pairing slots being full.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-28 14:43</div><div class="msg">Thanks @micheleb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-28 14:43</div><div class="msg">how many pairing slots do we allow for ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-06-28 14:45</div><div class="msg">5 at the moment but is easily increased</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-06-28 14:47</div><div class="msg">okay thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 11:40</div><div class="msg">hey @micheleb how are things going you way? How is the audit coming along and pro hw wallet?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:44</div><div class="msg">hey @jarradhope. There has been no reply from Matthew about the audit, I even got no reply to the email I sent about the last updates...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:46</div><div class="msg">regarding the pro hw wallet I am developing the firmware. I have already implemented BIP32, BIP39, Ethereum transaction parsing/signing and all the data storage, caching, PIN. I have written unit tests for each component</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:47</div><div class="msg">today I am starting with the actual command processing (implementing what I have defined in the PROTOCOL.md file).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 11:48</div><div class="msg">Hmm will follow up</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:48</div><div class="msg">I am quite positive that the deadlines for the milestones will be met</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 11:48</div><div class="msg">on audit?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:48</div><div class="msg">no, hw pro wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 11:48</div><div class="msg">the dev progress sounds amazing btw</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 11:48</div><div class="msg">great</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:49</div><div class="msg">for audit if Matt doesn't give any feedback I really cannot say when it will be done</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-10 11:49</div><div class="msg">since he had no questions so far, I am wondering if he started</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-10 18:35</div><div class="msg">i am wondering the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-11 07:53</div><div class="msg">@andreaf how familiar are you with the hardware wallet project and the go-ethereum client implementation?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-11 08:29</div><div class="msg">I'm familiar with go-ethereum but not with the hardware wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-11 09:27</div><div class="msg">no i mean, that in go-ethereum they implemented our hardware wallet, but nobody has done so for Status</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-11 09:28</div><div class="msg"><a href="https://twitter.com/nicksdjohnson/status/954387116636758016">https://twitter.com/nicksdjohnson/status/954387116636758016</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-11 09:53</div><div class="msg">ah I see! It's an old PR but still not merged, does it make sense starting looking at it if we want to implement it and maybe import/merge it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-11 11:40</div><div class="msg">there weren't a lot of changes in the hardware wallet since the PR was created. I think the only change was that the PUK is now separate from the pairing code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-07-13 12:22</div><div class="msg">Any thoughts on this? <a href="https://keystone-enclave.org/">https://keystone-enclave.org/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-13 12:26</div><div class="msg">The goals sound great, it would be an open source solution secure element. There are currently no open source secure elements at all. They are closed to the point that you are not allowed to open source even your own firmware if it exposes their API, since they are all under NDA</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-13 12:29</div><div class="msg">But the site is very light on details so far. Companies focusing on secure elements invest millions in developing countermeasures to hardware attacks, and since much of this research is a trade secret I do not know what they have as foundation </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-14 21:13</div><div class="msg">@andreaf yes it makes sense since it's literally our work :joy: someone else, Nick Johnson who is a very prominent person is doing our work for us with that PR :joy: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-16 08:12</div><div class="msg">@micheleb <a href="https://status-im.slack.com/archives/C9R0TSTM2/p1531613045000007">https://status-im.slack.com/archives/C9R0TSTM2/p1531613045000007</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-20 14:12</div><div class="msg">Ah ok I understand :) I never looked at that code before, but I'll do it!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-20 19:53</div><div class="msg">I'll be back online next week and I'll do it </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-23 21:01</div><div class="msg">hey @micheleb I saw you already had a call last week to talk about the hardware wallet. I can help with the integration with the status app, would you like to have another quick call in the next days? it would be helpful for me to understand what we need</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-23 21:01</div><div class="msg">tomorrow as well if you can </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 06:21</div><div class="msg">hey @andreaf works for me, in the morning or in the early afternoon</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 06:31</div><div class="msg">Thank you! I sent you a calendar invite </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 06:36</div><div class="msg">In the meantime you can have a look at <a href="https://github.com/status-im/hardware-wallet/blob/master/CLIENT_NOTES.md">https://github.com/status-im/hardware-wallet/blob/master/CLIENT_NOTES.md</a> and <a href="https://github.com/status-im/hardware-wallet/blob/master/UX_NOTES.md">https://github.com/status-im/hardware-wallet/blob/master/UX_NOTES.md</a> this will give a starting point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 08:26</div><div class="msg">Awesome communication guys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:41</div><div class="msg">as a follow up from our call with @andreaf I send a couple of links of the hardware which can be used for the light wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:41</div><div class="msg">Card: <a href="https://www.smartcardfocus.com/shop/ilp/id~790/acosj-dual-interface-java-card/p/index.shtml">https://www.smartcardfocus.com/shop/ilp/id~790/acosj-dual-interface-java-card/p/index.shtml</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:42</div><div class="msg">Desktop card reader (this is the best card reader on the consumer market): <a href="https://www.smartcardfocus.com/shop/ilp/id~54/omnikey-3121/p/index.shtml">https://www.smartcardfocus.com/shop/ilp/id~54/omnikey-3121/p/index.shtml</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:43</div><div class="msg">Smaller card reader (this is the one I have): <a href="https://www.smartcardfocus.com/shop/ilp/id~564/acr38u-n1-pocketmate-reader/p/index.shtml">https://www.smartcardfocus.com/shop/ilp/id~564/acr38u-n1-pocketmate-reader/p/index.shtml</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 10:45</div><div class="msg">awesome @micheleb thank you for the call! really helpful! and interesting! I'm starting right now studying more about it and looking at that PR and the hardware needed!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:46</div><div class="msg">Mobile card reader (bluetooth + microusb) (I have never tried this): <a href="https://www.smartcardfocus.com/shop/ilp/id~683/feitian-br301-bluetooth-reader/p/index.shtml">https://www.smartcardfocus.com/shop/ilp/id~683/feitian-br301-bluetooth-reader/p/index.shtml</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:46</div><div class="msg">then there many others iPhone/iPad specifics which I won't link here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:47</div><div class="msg">In theory the mobile one should work with on PC too if you connect it through USB but I do not know this brand</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:47</div><div class="msg">I usually trust OmniKey and ACS. ACS is also the card supplier</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 10:48</div><div class="msg">yeah I think at the beginning the reader for computer is enough</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 10:49</div><div class="msg">just to understand one thing. to develop it I need the reader, but when we finish, and we only need to sign transactions, is the phone nfc enough?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:50</div><div class="msg">no, we still need the reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 10:50</div><div class="msg">ok I see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:59</div><div class="msg">(i have deleted all the mess I have written) - so, I stand corrected, it actually works</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 10:59</div><div class="msg">but to be useful it needs something to hold the card still while you type on your phone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 11:00</div><div class="msg">works on android, I do not think the iPhone exposes this interface, but I have none to test so do not take my word for it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 11:37</div><div class="msg">Ah interesting!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 12:44</div><div class="msg">@micheleb @andreaf I have a set of 9 (8 minus mine) of the ACOSJ cards, if someone can help me write/test them, I can get them setup and then send to @erin to send to the relevant people in the organisation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 12:45</div><div class="msg">i have no idea what i'm doing but i have the reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 12:49</div><div class="msg">@jarradhope I can help writing the tests for sure. I'm studying the protocol just to understand better that pr and be able to write some tests from status-go or in general from go-ethereum</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 12:57</div><div class="msg">@jarradhope yes I can help loading the app, I have wrote a script for that </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:01</div><div class="msg">you need to download and copy somewhere <a href="https://sourceforge.net/p/globalplatform/wiki/GPShell/">https://sourceforge.net/p/globalplatform/wiki/GPShell/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:02</div><div class="msg">and javacard 3.0.4. Do you use a mac or windows?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:02</div><div class="msg">if you use a mac it is simpler if I send you the archive of the javacard jdk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:04</div><div class="msg">linux</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:05</div><div class="msg">yeah that would be the same as for the mac</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:05</div><div class="msg">I will prepare the archive and an example configuration file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:05</div><div class="msg">thanks :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:06</div><div class="msg">gpshell might be already packaged by your distro, otherwise you will have to compile it from scratch probably</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:10</div><div class="msg">later in the evening or tomorrow morning I will send everything with instructions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:11</div><div class="msg"><a href="https://aur.archlinux.org/packages/gpshell/">https://aur.archlinux.org/packages/gpshell/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:11</div><div class="msg">great, that's the one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:12</div><div class="msg">I have ACR38U-N1 drivers installed and gpshell</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:13</div><div class="msg">mm in theory if I send you the cap file and a gpshell script you do not even need the jdk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:13</div><div class="msg">it will be easier</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:13</div><div class="msg">then I will prepare the package this way. The cards are new, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:14</div><div class="msg">yep!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:17</div><div class="msg">latest wallet cap file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:17</div><div class="msg">I send it to the channel, others might want to play with it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:18</div><div class="msg">script to install</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:18</div><div class="msg">so all you have to do is download the script and wallet file in the same directory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:18</div><div class="msg">cd to that directory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:18</div><div class="msg">and run gpshell < status_hw_install.gpshell</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:18</div><div class="msg">make sure the only card reader attached is the one with the card to personalize</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:19</div><div class="msg">the procedure can be repeated if needed (if the cap file changes)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 13:19</div><div class="msg">I know I said I will send it by tomorrow but it was easier than I initially thought :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:55</div><div class="msg">champion @micheleb ! :weight_lifter: :heart:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 13:56</div><div class="msg">i'll give that a go, I lied about installing gpshell, i got globalplatform going but gpshell giving me some sass</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-07-24 16:06</div><div class="msg">@jarradhope commented on @micheleb?s file <a href="https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell">https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell</a>: so i tried `gpshell status_hw_install.gpshell` and `gpshell < status_hw_install.gpshell` but in both cases i got ```
|
|
mode_211
|
|
Unknown command mode_211
|
|
```</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-07-24 16:06</div><div class="msg">@jarradhope commented on @micheleb?s file <a href="https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell">https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell</a>: however when i entered the commands manually it seemed to work just fine</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-07-24 16:07</div><div class="msg">@jarradhope commented on @micheleb?s file <a href="https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell">https://status-im.slack.com/files/U7D2EJ44B/FBVUQ8R7C/status_hw_install.gpshell</a>: is the output <a href="https://gist.github.com/jarradh/d57eb01fef1b9f67f748e87c3475b80a">https://gist.github.com/jarradh/d57eb01fef1b9f67f748e87c3475b80a</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:08</div><div class="msg">Strange, it should be literally the same with input redirection </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:08</div><div class="msg">Ahh maybe the newlines are crlf</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:09</div><div class="msg">Because I was on a windows machine </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:28</div><div class="msg">ah yeah seems like it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:29</div><div class="msg">okay so now i have the card setup, ... now what? :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:29</div><div class="msg">I guess we wait for Andreas</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:29</div><div class="msg">we have the java client right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:30</div><div class="msg">Now we need to implement a client :smile: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:30</div><div class="msg">sorry been away from the project for awhile and haven't put my head into it all</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:30</div><div class="msg">I'm Java we have automated tests</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:30</div><div class="msg">In java</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:32</div><div class="msg">So it only sends a specific sequence of apdus and evaluates responses. But it doesn't allow an user to play with the thing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:32</div><div class="msg">the closest thing we have to a client is <a href="https://github.com/ethereum/go-ethereum/pull/15925">https://github.com/ethereum/go-ethereum/pull/15925</a> i believe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:34</div><div class="msg">Yes that is a client, I think Nick tested it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:34</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:35</div><div class="msg">the only problem is that we need to update the pairing code, because the PUK is not used anymore. There is a 256-bit key now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:35</div><div class="msg">it is passed as installation parameter. The script I sent you sets it to a fixed value</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:35</div><div class="msg">@andreaf ^^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:35</div><div class="msg">but of course it should be random :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:36</div><div class="msg">but now for testing it is easier to reason with fixed values. It is now indeed the same as before, the SHA-256 of the PUK (unless you change the PUK in the script)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:40</div><div class="msg">pretty exciting :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:43</div><div class="msg">if you wanted to send the cards out for actual use, we can do a script which first randomizes PUK and pairing code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:44</div><div class="msg">we must also decide what the pairing code should look like. The card stores it as 256-bit, but of course we must decide how the user will input that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:45</div><div class="msg">i have 8 cards to send out to people involved in development</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:45</div><div class="msg">it can either be PBKDF2 of a password or we could print the raw key as a QRCode</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:45</div><div class="msg">pairing with the card alone does not allow to perform any restricted action, so the secrecy of this code is not life-or-death matter</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:46</div><div class="msg">of course it is better if random strangers cannot pair :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:48</div><div class="msg">hmmm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:49</div><div class="msg">QR is a nice idea for Status, and we could probably assume a webcam on desktop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:50</div><div class="msg">i'm not sure i like the idea of prying eyes when trying to use a pinless signing at a Status payment terminal</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:51</div><div class="msg">maybe if it was a sticker you could peel off</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:51</div><div class="msg">there is also the edge case of a device you want to pair with and has no camera</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:52</div><div class="msg">we can do both things. It can password processed with PBKDF2 and then we could also print it as QRcode in the package</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:53</div><div class="msg">I mean in the leaflet or something like that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:53</div><div class="msg">we must print the PUK and the password somewhere too anyway</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:53</div><div class="msg">yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:53</div><div class="msg">speaking of packaging, i realize ACS does the personalization and printing, but probably not packaging right ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:54</div><div class="msg">so need to find a vendor for it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:54</div><div class="msg">we must ask them that. Last time we spoke you mentioned that production would be through other partners</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:54</div><div class="msg">so I didn't continue my contact with ACS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:55</div><div class="msg">@guylouis will be handling that, perhaps @josh109 (business dev) can begin engagement</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-07-24 16:55</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-07-24 16:55</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:55</div><div class="msg">oh ok, great</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 16:56</div><div class="msg">yeah it would be, but that relationship seemed to have not gone anywhere unfortunately</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:57</div><div class="msg">I see. One thing to check with ACS is if they plan a JavaCard 3.0.5 (instead of 3.0.4) anytime soon... that would enable loading a BIP-39 binary seed directly on card (instead of full keys) and would allow for a less intricate key derivation procedure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:58</div><div class="msg">the applet already implements that path of code, if it detects that the needed functions exist it will use them (and the client can also ask the card if it supports that or not)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 16:58</div><div class="msg">I have tested that on our branch of jCardSIM, where I implemented the needed JC3.0.5 functions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 17:00</div><div class="msg">oh neat</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 17:02</div><div class="msg">@micheleb so 3.0.5 can derive keys complete independently without part of the computation in the client?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 17:03</div><div class="msg">correct</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 17:03</div><div class="msg">but I couldn't found any card on the market which is sold in small quantities supporting 3.0.5</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-24 17:04</div><div class="msg">I see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 17:04</div><div class="msg">the ACS card is indeed the only card supporting at least 3.0.4. The vast majority are at 2.2.2</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-24 17:05</div><div class="msg">I love how technology at every level is just hacked together house of cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-24 17:05</div><div class="msg">but I know they exist somewhere. I have got contacted by a guy who asked a few question and he had a 3.0.5. I asked where he got the card but claimed to be under NDA</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-25 14:01</div><div class="msg"><a href="http://KPN.nl">http://KPN.nl</a> reached out today interested in our work :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-25 14:02</div><div class="msg">Cool, are they an ISP? What do they want to do with the hardware wallet? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-25 14:16</div><div class="msg">yeah they are, and i have no idea, will jump on a call with them soon*</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-29 09:51</div><div class="msg"><a href="https://spectrum.ieee.org/semiconductors/devices/riscvs-opensource-architecture-shakes-up-chip-design.html">https://spectrum.ieee.org/semiconductors/devices/riscvs-opensource-architecture-shakes-up-chip-design.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-29 09:52</div><div class="msg">can be very interesting for future hardware wallet versions, especially since it is a better match for our principles</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-29 09:52</div><div class="msg">of course is too early to talk about that, but I will try to keep the code as portable as possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-07-29 20:40</div><div class="msg">I've wanted to get my hands on a risc-v dev board.. any recommendations?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 05:46</div><div class="msg">@arnetheduck.slack I do not know any native MCU, but if you get an FPGA dev board you can download a RISC-V core to it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-07-30 08:49</div><div class="msg">I couldn't wait so I bought a couple :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 08:50</div><div class="msg">ok, you can use the files I have sent on the channel here earlier</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 08:50</div><div class="msg">if you are not on windows you have to convert the newlines from crlf to lf for the script, as I have mistakenly saved it this way and gpshell apparently does not handle that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-07-30 08:55</div><div class="msg">@micheleb would you be willing to do an update on the hardwallet in our Town Hall later today? (3 hours from now)
|
|
|
|
<a href="https://docs.google.com/presentation/d/1_iepVD0r76Aw9PZ7JrsP94wR3YYgHcBNmGCkqx1I2b8/edit#slide=id.g3e5fea2218_4_4">https://docs.google.com/presentation/d/1_iepVD0r76Aw9PZ7JrsP94wR3YYgHcBNmGCkqx1I2b8/edit#slide=id.g3e5fea2218_4_4</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 08:57</div><div class="msg">that's a bit sudden, but I can do it... do I have to add a slide there?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-07-30 09:02</div><div class="msg">Yeah, I see it got added for this week, sorry for the rush. It's slide 50 :+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 09:11</div><div class="msg">ok I have written the slide, I hope it is enough information</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-30 11:34</div><div class="msg">The KPN guys metnioned this, might be an interesting hardware platform <a href="https://www.youtube.com/watch?v=lX2nta9221Y">https://www.youtube.com/watch?v=lX2nta9221Y</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 13:23</div><div class="msg">- A cell phone chip and cell phone antenna so data can be transferred between Wallet Card and the bank anywhere in the world and at any time of the day.
|
|
- A battery and organic recharging chip so that the card charges itself through normal operation. Wallet Card can last indefinitely without the need for the consumer to perform any physical action.
|
|
- A card-programmable magnetic stripe, card-programmable EMV chip, and a card-programmable contactless chip. At any time a new card profile can be downloaded to the card so that when that card is selected, the card?s magnetic stripe, EMV, and contactless data is written to the associated components.
|
|
- A 65,000 pixel display and user interface so that a cardholder can change between different cards and informational screens.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 13:23</div><div class="msg">does this thing actually exist?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-07-30 13:25</div><div class="msg">I mean if it does, it is very good. But I do not see how such a battery can power "a 65,000 pixel display" display and "a cell phone chip and cell phone antenna" and recharge itself "organically" whatever that means</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-07-30 14:07</div><div class="msg">@micheleb @jarradhope do we plan also integrate status with other hardwallets (like ledger for ex)? sorry if this was already said and i missed that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-30 14:19</div><div class="msg">it might be hard with Whisper for example</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-30 14:19</div><div class="msg">it wouldn't be able to work the same way</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-30 14:20</div><div class="msg">but our Wallet itself could have a hardware wallet in it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-07-30 14:20</div><div class="msg">so yes, but only for wallet transactions and not for logging into Status</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-07-30 14:20</div><div class="msg">ah okay i see. thanks! Yep asking because people ask in status channel from time to time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-02 00:23</div><div class="msg">Pretty interesting tech. the presentation is pretty masturbatory but I guess it's a marketing presentation so what can you expect. I love how all they could come up with for this device was "visa/tim hortons". Seems so small in comparison to connecting it to blockchain/crypto/p2p.
|
|
|
|
At one point he boils down the one of the biggest problems in finance to one of data collection: "how can you give someone a coupon if you don't know what they purchased??". i almost vommed. so small!
|
|
|
|
there's a segment where they beam a $5 off birthday coupon directly to the card which felt particularly dystopian. gamified spending is wack.
|
|
|
|
however, it proves that it's possible to make such a device which is a neat sign. i'd love to get my hands on an open source software/hardware version of one of these. connecting it to ethereum would be wild. smart contract events directly to the card!
|
|
|
|
he said an interesting slogan in there somewhere "swipe, insert, and tap". This little device can pay in any of the modern digital formats we have globally. you could walk around the world owning just a little piece of plastic and if it's connected to the collective swarm, you'll retain your whole life's worth of data _and access_. they talking about beaming hotel keys onto it, which is :mindblown:
|
|
|
|
the cell phone connected card is a completely different device however. it's not the same as a "cold" signing key thingy
|
|
|
|
also, wtf is "organic charging". i know there are watch batteries which get charged by the movement of your arm but that just doesn't seem like enough electricity to power all that stuff, tho i am an electricity noob so maybe i'm wrong
|
|
|
|
(i just watched another video of this thing and it uses a micro usb charger :scream:)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 11:40</div><div class="msg">@micheleb are you fine with me running that gm script over these cards and sending them out to people to implement the UX flows? we don't really need to do personalization right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 11:41</div><div class="msg">otherwise can you send over a script that'll program 10 cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 11:47</div><div class="msg">and open source one is pretty much @micheleb and @guylouis goal</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 11:47</div><div class="msg">@jarradhope yes you can use it to create cards, the important things is to point out that they shouldn't be used for real wallets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 11:48</div><div class="msg">perhaps we should treat it as real wallets, since we cannot guarantee how people will use them in the future, even if we explain that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 11:49</div><div class="msg">ok then I have to modify the script to at least randomize PUK and pairing key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 11:50</div><div class="msg">thank-you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 12:33</div><div class="msg">my only concern is if I should change the global platform keys as well. If I do, it is not possible to replace the applet anymore (which is not really welcome during development). But if I don't, anybody can replace the applet. In any case there is no access to the wallet keys though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 12:33</div><div class="msg">so the funds remain safe either way</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 12:33</div><div class="msg">i think replacing the applet on these versions is okay</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 12:33</div><div class="msg">as we may encounter an issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:37</div><div class="msg">This is a personalization script which generates a random password and PUK (which is printed at the end of the installation). Requires Python 3 and gpshell to be in PATH.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:39</div><div class="msg">the important thing to know for developers is that the pairing password must be converted to a 32-bytes key by running the PBKDF2 algorithm with SHA-256, 50000 iterations and "Status Hardware Wallet Lite" as salt</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 13:44</div><div class="msg">> the important thing to know for developers
|
|
|
|
@micheleb is it already in some document? it will be useful to have it written somewhere</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:46</div><div class="msg">no, and I also do not know where it makes sense to write it. Because the applet does not really care how you generate those 32 bytes so it is not really applet-specific</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 13:47</div><div class="msg">right I understand. maybe we can add the Idea also for the java card? I see you already create one for the hardware wallet pro</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:47</div><div class="msg">on the other hand, since this happens on personalization phase, maybe I should also commit this script</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:49</div><div class="msg">do you already have something working to establish a secure channel with the card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:49</div><div class="msg">it would be good if you could test with client-side code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 13:50</div><div class="msg">@micheleb me?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:50</div><div class="msg">@andreaf yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 13:51</div><div class="msg">not yet, I waited for the cards to start and this week I had to finish a work for mailservers. I think I will start next week, but it would be cool if we can have a quick call tomorrow if you want so that I can setup everything quickly and start maybe also in the weekend</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 13:51</div><div class="msg">tomorrow OK, in the morning... 11 italian time?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 14:07</div><div class="msg">thank you! I sent a calendar invite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 14:17</div><div class="msg"><a href="https://status-im.slack.com/archives/C5Z5NRYKS/p1533219421000151">https://status-im.slack.com/archives/C5Z5NRYKS/p1533219421000151</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 14:18</div><div class="msg">I was too excited so I bought 2 last week :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 14:18</div><div class="msg">Good stuff!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 14:53</div><div class="msg">BTW, anyone would be able to burn its own Status Card?
|
|
I mean like: I could buy like just any clean java card and install the status wallet in the javacard through smartphone NFC?
|
|
Also, is possible for reading a fingerprint of what is running inside Status Card? My concern would be fake cards being selled, I imagine we can implement many redundancy checks in this part, such as checking for valid fingerprint, checking if signed transaction/messages returned is actually from what was requested, etc.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 14:57</div><div class="msg">@3esmit Installing the applet is quite easy, the script I have sent above takes care of everything, you just need the cap file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 14:59</div><div class="msg">there is no fingerprinting however. We could add it however... then we need to add a warning when someone tries to use a self-installed applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:01</div><div class="msg">would be possible for smartphone app reprogram a javacard, or to simply program a blank javacard? I imagine that reprograming wipes the keys inside of it, so it wont be an attack vector</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:01</div><div class="msg">it would, but it would need to implement part of global platform. Again, if we do this then fingerprinting makes no sense anymore</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:02</div><div class="msg">fingerprinting needs to be supported by Java Card platform, otherwise it seems always fakeable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:02</div><div class="msg">it is not supported. But if the applets know a certain private key it can send a signature verified by a well-known public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:03</div><div class="msg">the private key must not be in code of course, but supplied as part of personalization process</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:03</div><div class="msg">but then it must be kept secret and only applets with that signature should be considered safe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:03</div><div class="msg">Interesting, so the cards would need a validator?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:03</div><div class="msg">Like those "signed apps"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:04</div><div class="msg">so, there is no concept of signed app. You could just send a command to the card with random data to sign and get it back signed. If the signature verifies it means the card has the right private key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:05</div><div class="msg">I see, but at end it works like the concept of "signed apps", right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:05</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:06</div><div class="msg">yes exactly, all of its open source, our pro version will have physical button , screen, bluetooth and recharable battery and we'll open source the hardware designs on that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:06</div><div class="msg">This is a problem for a decentralized company, because then we need to hire a signer to validate, or maybe its pretty plausible: independent auditors can validate a sign together an application</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:06</div><div class="msg">thing is that making fake cards is not really useful. The card has no I/O capability. To do something nefarious it would need to come with a malicious client as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:07</div><div class="msg">I agree, the other protection side would be in the Status Wallet in Smartphone, which would verify the output from the card, instead of just broadcasting anything it shots out</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:08</div><div class="msg">the way the commands are designed, the card cannot even try to shout something malicious. The only thing is that one could add a secret APDU which allows exporting all keys. But then you need to steal the card too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:09</div><div class="msg">I see, the attack vector sums up to make a backdoor to download the keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:10</div><div class="msg">So maybe the best product to be shipped to final users would be a "Status Card Wallet" that would only come with an installer, which then Status Wallet in smartphone will grab the latest version from a smart contract and download from swarm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:10</div><div class="msg">Anyway, status wallet client can always check for updates and install them as needed.
|
|
When you update the "software", it wipes the private data?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:11</div><div class="msg">yes, it is not designed for being updated</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:11</div><div class="msg">This is good..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:11</div><div class="msg">if you updated then you must restore from mnemonic</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:12</div><div class="msg">Yes, when status client updates the applet it also reprograms the key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:12</div><div class="msg">it is an interesting idea. It would save us even personalization costs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:12</div><div class="msg">and custom printing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:12</div><div class="msg">because PUK and pairing code would be generated during installation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:13</div><div class="msg">I think that the best way would be if I could buy a totally empty javacard (assuming is the correct version) from any distributor in world and just tap with status and install on it...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:14</div><div class="msg">from a "product" point of view not really. Also the problem is that we need a specific set of algorithms supported, a regular user is probably unable to select the correct card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:14</div><div class="msg">This is better because it removes one actor, which is the first card programmer.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:15</div><div class="msg">I would still package branded cards, even if empty, but that are certain to run the applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:16</div><div class="msg">sourcing them is really not easy, it would thwart adoption seriously</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:16</div><div class="msg">If you think as a traditional company it is bad to just "give away the magic to anyone do it", but we are about to decentralize everything.
|
|
I think if is not possible, we can build a market on top of it.. and assert the security of card in the Smartphone by Status Wallet.. Unless you brought a fake javacard chip that contains 3G communication and would leak your data, you should be safe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:17</div><div class="msg">At end, Oracle stills the first manufacturer and could put a lowest level backdoor there?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:17</div><div class="msg">Oracle is not involved, they do not implement JavaCard, only write the specs and official test suite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:17</div><div class="msg">Great!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:18</div><div class="msg">the chip producer and final-card producer are also usually separate entities</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:18</div><div class="msg">only Infineon does both</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:18</div><div class="msg">and NXP actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:18</div><div class="msg">Gemalto, G&D, Oberthur, etc they buy the chip from Samsung, ST, Infineon and write the OS, JavaCard environment and so on</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:19</div><div class="msg">I see, the attack vector seems very very generic and is very unlikely that we get backdoor in those chips if we buy from good reputation companies (or not? :disappointed: )</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:19</div><div class="msg">well I have worked for G&D 5 years and I cannot say anything bad about them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:19</div><div class="msg">Sorry for the paranoia, but it's part of the process of security.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:20</div><div class="msg">it makes sense, of course</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:20</div><div class="msg">because you are under gag order? :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:20</div><div class="msg">jk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:20</div><div class="msg">The good thing is that I can see that Status card is far more safe in all aspects then other hardware wallets like ledger and other</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:21</div><div class="msg">aahahaha exactly! No, actually they had good practices</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:21</div><div class="msg">I imagined as this stuff is usually used for finance security</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:21</div><div class="msg">as I say, my only issue is that if we let the user select and source a blank white javacard by themselves, we kill adaption. It is really hard to get hold of the correct card and they are not even sold in all countries</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:22</div><div class="msg">for that we can marketing the product and people sell it with free marketing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:22</div><div class="msg">i think in this case we just open source what we are doing and give card recommendations and requirements of card platform</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:22</div><div class="msg">its up to users, but of course most adoption will be driven by our own sales</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:23</div><div class="msg">and this is what we already do, more or less, although I notice we don't make our card suggestion in GH yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:23</div><div class="msg">yes I mean, we can allow using any card that is for sure. But we should also provide our own card... that's the only way to make sure anybody can get hold of one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:23</div><div class="msg">For a second version of card wallet, would be possible for me to setup many different accounts in many differnt passwords?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:24</div><div class="msg">My idea is that if I enter an invalid password it does not say is invalid, it just opens another account, that always that same wrong account for that same wrong password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:24</div><div class="msg">yes that is the plan, we do an upsell from the Status app saying "hey you should totally get a hardware wallet, buy one now"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:24</div><div class="msg">Underhood, if hardware wallet see that user tries too much different accounts at short period of time, then it kills the data</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:25</div><div class="msg">the idea is that you could have 2 accounts in the same card, one with more money, and other with lower money.. if you thretened to give your password you can give this other password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:26</div><div class="msg">mmmmm in one way, this could be done without even modifying the applet, with some support for the client</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:26</div><div class="msg">you see, on Javacard you can install the card n times with a different instance id</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:26</div><div class="msg">when you select the applet, you select a specific instance id</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:26</div><div class="msg">well, you can think about it, but in my opinion we should protect people from being "forced" to give them their "status card wallet" funds</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:26</div><div class="msg">so a card can have as many instances in parallel as they fit on the flash</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:28</div><div class="msg">My idea was that
|
|
user set mnemonic + password: -> this points to the correct default account... the other passwords would always derive from this mnemonic + password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:28</div><div class="msg">@micheleb i've finished running this script and given a CSV of the card_num, pairing_password, PUK to the person delivering them to the implementers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:29</div><div class="msg">is there anyway I can test/verify one , i imagine it's not necessary as all were successful and the .cap is correct</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:29</div><div class="msg">This is what I had in Status originally, but we moved away from this scheme to be more compatible with MyCrypto and Metamask</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:29</div><div class="msg">I live in Brazil, here the criminals are pretty smart aswell, and I bet they would figure out how to use Status, as is just easy like most apps.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:30</div><div class="msg">@jarradhope there is no easy way at the moment, until we have a skeleton of the client. If there are no errors then the applet is installed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:30</div><div class="msg">aight</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:30</div><div class="msg">well i will be on holiday so it won't be my problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:31</div><div class="msg">ahaha good.. in any case, anyone can run the script so the important thing is to physically have a card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:31</div><div class="msg">Well, if we have a better solution then they might support us, however we can have this security feature only for hardware wallets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:31</div><div class="msg">everything else can be sorted out later</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:32</div><div class="msg">@3esmit but the mnemonic + password thing is done during initialization. What you need to access the card is just the PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:33</div><div class="msg">Also, we can support this feature again while keeping this compability, maybe we let user create hidden accounts with different passwords?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:34</div><div class="msg">This new hidden accounts dont need mnemonic, they can be derived from a signature of the main account or something like that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:34</div><div class="msg">yeah it's trivial to implement imo, and we need it for dapp privacy as we plan to introduce `hostname.eth` to create a hidden account from the dapp</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:34</div><div class="msg">@andreaf is our resident key genius these days :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:34</div><div class="msg">Yes, so the PIN could select different accounts?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:35</div><div class="msg">he's best to get involved</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:35</div><div class="msg">I guess this is not a planned feature in the PIN/PUK scheme :confused:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:35</div><div class="msg">not directly, because verifying the wrong PIN brings it one step closer to being blocked</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:35</div><div class="msg">Yeah, I've read the wallet applet :slightly_smiling_face: , learned a lot doing it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:36</div><div class="msg">I just remembered checking it, and figuring out this you just said. Perhaps we need to request this feature to Javacard?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:37</div><div class="msg">even if oracle were to specify something like that, it would be at least 5 years until we get a card supporting this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:37</div><div class="msg">I think is an interesting topic to keep in mind, however seems like javacard have a limitation in PIN/PUK verification</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:37</div><div class="msg">it is a very slow ecosystem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:38</div><div class="msg">For the Pro version this would be possible?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:38</div><div class="msg">yup</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:38</div><div class="msg">we are in full control of the hardware</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:38</div><div class="msg">Well, then if you want this feature, for now only Pro... and then we suggest to oracle and wait 10 years to be implemented</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:40</div><div class="msg">thank you, was great discussing this. I am really excited by this project because its amazing. anytime need feedback or brainstorming, just ping me that I would love to participate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 15:40</div><div class="msg">sure, thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:44</div><div class="msg">BTW for sake of curiosity, the first time I saw this concept was in TrueCrypt software.
|
|
This software was so good that NSA shut them down by giving the devs loads of money to stop developing it (rumours), not sure if was a bad joke, but the TrueCrypt devs suggesting use Microsoft or Apple solutions for hardware encryption :laughing:
|
|
Now VeraCrypt forked and continued the work :shrug: not sure if is really safe as TrueCrypt was claimed to be.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 15:45</div><div class="msg">we can easily re-introduce an optional password to add entropy to the mnemonic phrase. is that what we need? I read this thread but not the other messages in this channels yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 15:47</div><div class="msg">and actually having an optional password is a good thing against the 5$ wrench attack <a href="https://xkcd.com/538/">https://xkcd.com/538/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:47</div><div class="msg">We need "plausable deniablity"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:48</div><div class="msg">A simillar concept from this <a href="https://www.truecrypt71a.com/documentation/plausible-deniability/hidden-volume/">https://www.truecrypt71a.com/documentation/plausible-deniability/hidden-volume/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:50</div><div class="msg">So I think it would be possible to decrypt a different private key of every any password, and just the right password would decrypt the right account, so it would not be just a second password, but an any password.. (Maybe this would only work after user saves mnemonic)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:52</div><div class="msg">well we can do that in Status without having to change javacard applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:52</div><div class="msg">It needs to be done right, to actually make accessible "plausable deniability" to anyone and that is not possible to tell if the password was wrong.
|
|
|
|
Although this is questionable, maybe having 2 passwords only is better</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:53</div><div class="msg">The javacard applet would bypass this account system as login would be done by tapping the card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:53</div><div class="msg">only 1 specific leaf is pinless</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:54</div><div class="msg">and other exports whisper keypair leaf</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 15:54</div><div class="msg">I see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:58</div><div class="msg">the idea is that you can pay-and-pay with that account, and you should only ever store the amount you're willing to lose in it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-02 15:59</div><div class="msg">the pro version we're working on now will offer more security for this, screen can show tx and physical button to sign</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 18:03</div><div class="msg">Also the status wallet should always confirm what was signed before submitting to network, just in case something goes "wrong" in hardware wallet, status wallet would present what was signed.
|
|
For users typing password nothing changes for now, but for when a status card signs a transaction by tapping and entering pin, the response should be compared to what was actually requested, otherwise inform an error and open a chat in #status-support, or throug the bug report? so any attempt of modifing the "blackbox" to change whats being signed would fail</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-02 18:06</div><div class="msg">Actually, the "blackbox" (hardware wallet) could response only the signature, not the transaction payload, as the payload is already known by the wallet, and thus making the check mandatory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 20:12</div><div class="msg">the card already responses only the signature</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-02 20:13</div><div class="msg">this will also be true for the Pro version, the only difference that the Javacard version outputs a standard-formatted ECDSA signature whereas the Pro version already gives V, R and S in RLP format</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 22:34</div><div class="msg">> My idea is that if I enter an invalid password it does not say is invalid, it just opens another account, that always that same wrong account for that same wrong password
|
|
|
|
that's a good idea @3esmit! though the 12 mnemonic words + optional password is only used during the setup, then the card will have stored the key derived at `m/44'/60'/0'/0/0` from a seed generated with 12 mnemonic words or 12 mnemonic words + password. so I think with the current implementation the only way would be saving multiple keys with different pins, but that would be unrelated from the 12 words + password or not. but I think we should continue thinking about it and we can find a solution!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-02 22:39</div><div class="msg">unless we have that key, and then we derive on the fly a child key based in the pin/password every time we use the card.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 06:14</div><div class="msg">I think there are many ways we can do plausible deniability. The thing to understand is if we assume the attacker sees the APDUs or not.. if not it is easier to implement</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 06:17</div><div class="msg">but even if it can, the card could have two PINs and two sets of keys. When you enter a PIN it first tries to verify the "fake" account. If it verifies, it uses that. If not, it tries to real one. If it verifies, it also resets the retry counter of the fake one, otherwise it just gives failure. Then depending on which of the two PINs is verified it will use one or the other set of keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 06:17</div><div class="msg">of course, this is a huge change in the app, but is transparent (an attacker has no clue of what is happening)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 06:19</div><div class="msg">if the APDU are not being sniffed then the "fake" PIN could be recognized on the client itself and it could select a second instance (that must be previously installed) of the applet. It would work exactly the same, but in this case the applet does not need to be changed.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:00</div><div class="msg">@micheleb I installed everything and I'm interacting with the card from `go-ethereum`. I'm pairing and I get a `Error: Invalid card cryptogram`. is that related to what we said about using `pbkdf2`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:01</div><div class="msg">@andreaf most probably, because the patch must be simply doing a SHA-256 (that was the old way) </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:01</div><div class="msg">exactly, ok I'm going to start changing that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:03</div><div class="msg">so the initial part of the pairing is: they both path the PUK to `pbkdf2` and then check that the result is the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:03</div><div class="msg">is that correct?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:03</div><div class="msg">instead of the PUK you must use the pairing key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:03</div><div class="msg">pass it to pbkdf2</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:03</div><div class="msg">then the rest i sthe same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:04</div><div class="msg">ok cool I try now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:36</div><div class="msg">@micheleb I see the first step is sending a challenge (random number)
|
|
then I get back a response
|
|
shall I pass `pairingPassword + response` to `pbkdf2`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:38</div><div class="msg">only the pairing password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:39</div><div class="msg">PBKDF2(pairing password) replaces SHA256(PUK), everything else remained as-is</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:41</div><div class="msg">but to verify you need the SHA256 of the pairing key and challenge</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:41</div><div class="msg">their code now is this one:
|
|
<a href="https://github.com/ethereum/go-ethereum/pull/15925/files#diff-6dcf5f4b48f767ce8075cfc851b2cf2aR87">https://github.com/ethereum/go-ethereum/pull/15925/files#diff-6dcf5f4b48f767ce8075cfc851b2cf2aR87</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:41</div><div class="msg">so something along the lines of SHA256(PBKDF2(pairing password) + challenge)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:41</div><div class="msg">I replaced `secretHash := sha256.Sum256(sharedSecret)` with `secretHash := pbkdf2.Key(norm.NFKD.Bytes(pairingPassword), norm.NFKD.Bytes([]byte("Status Hardware Wallet Lite")), 50000, 32, sha256.New)`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:42</div><div class="msg">correct, everything else should be exactly the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:42</div><div class="msg">if it worked, which I think it did</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:43</div><div class="msg">I am away from keyboard for about 1-2 hours</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:44</div><div class="msg">don't worry, thank you! I'll tell you later, for now it doesn't pair but maybe it's something else</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:44</div><div class="msg">my first advice, check that the output of the PBKDF2 of the Python script and the one of the Go code are the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:45</div><div class="msg">because if there is any difference in that, of course it won't work :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:49</div><div class="msg">cool I'l do it!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:55</div><div class="msg">yeah that works, same output using same pass and salt</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:57</div><div class="msg">that's cool. I would also assume that the arguments are passed correctly to the app since the command would fail otherwise</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:57</div><div class="msg">it works now!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:57</div><div class="msg">oh, cool :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:57</div><div class="msg">now I'll continue with the next error which is `Error: smartcard: pin needed`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:57</div><div class="msg">what was the problem?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 13:57</div><div class="msg">I don't know, I rewrote it from scratch :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:58</div><div class="msg">the default PIN is 000000</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 13:58</div><div class="msg">ah, good stuff :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 14:46</div><div class="msg">I am back if you need my help</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 14:54</div><div class="msg">I think everything works. I paired it and unlocked it with the PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 14:54</div><div class="msg">now I need to initialise it and I'm looking at the code already implemented there because I'm playing with the `geth` console, but maybe we can just initialise it from our code the way we want without using that implementation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 15:00</div><div class="msg">I don't know, if this gets merged to geth then maybe it would not be bad to use it and eventually extend it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-03 15:00</div><div class="msg">but I am not aware of whatever limitation this brings</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-03 15:00</div><div class="msg">I'm going to explore that part to know more about it for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-08-03 16:43</div><div class="msg">this is _so_ cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-04 22:46</div><div class="msg">sent first PR to update the pairing with `pairing password` and using `pbkdf2` <a href="https://github.com/Arachnid/go-ethereum/pull/2">https://github.com/Arachnid/go-ethereum/pull/2</a>. it goes to the same branch of the PR that goes to `go-ethereum`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-04 22:47</div><div class="msg">2 questions:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-04 22:48</div><div class="msg">1 - in the `initializeWallet` method, the call to the card returns `0x9000`, which is success, and not `0x6A81` for "public key derivation is not supported". is that correct? because the status of the wallet then says anyway: "public key derivation is not supported"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-04 22:48</div><div class="msg">2 - `initializeWallet` generates mnemonic and key and then uploads the key. it doesn't use the card to generate the mnemonic. shall we change it to use the card function?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-05 11:46</div><div class="msg">@andreaf 1 - can you point me to the code in question? You need public key derivation only if you attempt to load the binary seed instead of the full keyset</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-05 11:46</div><div class="msg">2 - It would be much better to use the card's RNG, so yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-05 11:46</div><div class="msg">the phone's RNG might be compromised</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 09:50</div><div class="msg">ah ok. the part of the code is this one:
|
|
|
|
<a href="https://github.com/Arachnid/go-ethereum/blob/7f0a28e7cf84d7b6026408aac610d7b98b215bb3/accounts/scwallet/wallet.go#L869">https://github.com/Arachnid/go-ethereum/blob/7f0a28e7cf84d7b6026408aac610d7b98b215bb3/accounts/scwallet/wallet.go#L869</a>
|
|
|
|
And the response is not even checked. I was wondering if we need to check it. because the wallet structure has a `SupportsPKDerivation` field that is never used, so it's always false</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 09:52</div><div class="msg">the response should be checked of course, it must be 0x9000</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 09:53</div><div class="msg">the `SupportsPKDerivation` field should be populated with the response from the GET STATUS command, and used for key derivation to understand if assisted derivation is needed or not. Maybe Nick did not implement the part where public key derivation is supported, since we have no card where this happens</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 09:54</div><div class="msg">the initialisation function is a generic one in the API exposed by geth. for now it works only if the wallet is a `scwallet.Wallet`, but the mnemonic is generated in go <a href="https://github.com/Arachnid/go-ethereum/blob/7f0a28e7cf84d7b6026408aac610d7b98b215bb3/internal/ethapi/api.go#L480">https://github.com/Arachnid/go-ethereum/blob/7f0a28e7cf84d7b6026408aac610d7b98b215bb3/internal/ethapi/api.go#L480</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 09:54</div><div class="msg">to maximize compatibility, I have made it so that assisted key derivation always works, even if the card supports derivation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 09:55</div><div class="msg">yeah I see, that is not the best idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 09:56</div><div class="msg">maybe there it should call `wallet.Initialize` and each type can have its own implementation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 09:56</div><div class="msg">yup. I know it is more work just to get some random bytes. But really random bytes is what makes the algorithms actually secure :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 09:57</div><div class="msg">yeah exactly! I will work on that too!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-06 09:57</div><div class="msg">I need to get in touch with them during these days to understand if they are still working on that or not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-06 10:01</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/411838218004_c7eba2c8e4f6b1a5ba77_72.png" /><div class="message"><div class="username">graeme</div><div class="time">2018-08-06 10:32</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-10 07:43</div><div class="msg">Hey @micheleb I'd love to understand how #hardwallet will integrate with Status from a users point of view, as well as getting a sense for the work and teams needed to make it happen on the product side. Do you have any docs to point me to?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-10 07:44</div><div class="msg">And perhaps we can jump on a hangout today to go over in greater detail?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-10 08:13</div><div class="msg">Hi @chad, the repo is <a href="https://github.com/status-im/hardware-wallet">https://github.com/status-im/hardware-wallet</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-10 08:13</div><div class="msg">CLIENT_NOTES.md and UX_NOTES.md are the most relevant and high-level docs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-10 08:16</div><div class="msg">I have time for a call right now or at 16:00 moscow time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-12 16:15</div><div class="msg">@micheleb are you familiar with <a href="https://firefly.city">https://firefly.city</a> ? Super intelligent guy, great hardware wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:21</div><div class="msg">@jarradhope, not familiar with that, I am looking at that now </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-12 16:22</div><div class="msg">Look at his ble broadcast packet scheme :joy: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:28</div><div class="msg">:rolling_on_the_floor_laughing: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:29</div><div class="msg">It's clever</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:30</div><div class="msg">But the security is really bad, because the same key is reused with AES in ECB mode. I understand the reason (he can only send a single block) but patterns will appear across several packets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:35</div><div class="msg">I am talking about this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-12 16:35</div><div class="msg"><a href="http://jbcdn2.b0.upaiyun.com/2016/04/3ead0c84b14c3462837c1ee846fac2181.png">http://jbcdn2.b0.upaiyun.com/2016/04/3ead0c84b14c3462837c1ee846fac2181.png</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-19/383973012787_48836a48c36759f221b2_72.png" /><div class="message"><div class="username">statushero</div><div class="time">2018-08-13 08:18</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/344d33df5b96cf58d66c3ec84521ac2e.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0008-72.png" /><div class="message"><div class="username">work_directory</div><div class="time">2018-08-13 08:18</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-13 09:46</div><div class="msg">Ohshi! That's crazy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-13 11:18</div><div class="msg">Hi hardwallet team ! I am joining as product manager for the hardwallets and want to get hands on asap. A quick update on where I am standing for now :
|
|
* took as a goal to secure supply asap for a manufacturer for 3.0.5 javacard. Goal is to have a first batch for Devcon 30/10 in Prague.
|
|
* will synchronize with Michele online tomorrow and face-to-face next monday to understand the javacard and hardwallet pro projects in details.
|
|
|
|
My goal for this week is to get familiar with the project, understand who does what, have one and ones, understand where I can fit in and help, and progress on the manufacturing side since there is some clear urgency here.
|
|
|
|
Your suggestions/ideas are most welcomed. Please ping me for a quick chat so that we know each other better.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-13 16:20</div><div class="msg">welcome @guylouis</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 07:13</div><div class="msg">Thanks @andreaf !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-14 10:15</div><div class="msg">Welcome!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-14 10:18</div><div class="msg"><!here> So happy to see the great progress with #hardwallet! I?m especially excited by the prospect of hardwallets being distributed at Devcon. @micheleb @guylouis What do you think about taking some time during the next Status Devs Meeting on Monday to go over the app changes that need to happen for Devcon? cc @oskarth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-14 10:20</div><div class="msg">@chad I started working on the `status-go` part for the javacard but only a few hours a week. we don't have any okr for that I think. do you think we should think about it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-14 10:21</div><div class="msg">Perhaps this could be a great OKR as it spans many teams and requires quite a bit of coordination cc @jarradhope</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-14 10:33</div><div class="msg">Agree</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-14 10:42</div><div class="msg">@chad sounds like a good idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 11:29</div><div class="msg">I am still trying to understand how OKR are defined/used, but I will be happy to synchronize the effort for hardwallet OKR</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 13:59</div><div class="msg">I just posted a thread in discuss to align on the hardwallet user stories we want to implement and prioritize them and outline the UX and technical consequences these scenarios can have.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 13:59</div><div class="msg"><a href="https://discuss.status.im/t/javacard-hardwallet-user-stories/307">https://discuss.status.im/t/javacard-hardwallet-user-stories/307</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 14:12</div><div class="msg">Also on the manufacturing side, some updates :
|
|
* ACS answered that they do not have plans to support 3.0.5 (or EC end point multiplication, what we are really looking at). Still, I will continue the discussion with them to get quotes. Even if we don't work wth them it will be helpful to benchmark prices.
|
|
* got in touch with some contacts in the 3 main javacard technology providers : Gemalto, Idemia, NXP. Not much feedback for now but if anyone here has some contacts in these companies, it could help too.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-14 14:18</div><div class="msg">3.0.4 is fine and the audit and testing cards are all on their 3.0.4 platform</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-14 14:18</div><div class="msg">Thanks for update!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-14 16:27</div><div class="msg">One question for you all : who has javacard with them to integrate/test ? anyone else than @micheleb (of course :slightly_smiling_face:) @andreaf and @jarradhope ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-26/320279260448_ec6cae0dd4f9145858b4_72.jpg" /><div class="message"><div class="username">chad</div><div class="time">2018-08-14 17:24</div><div class="msg">@oskarth Any dev meeting tips for @micheleb and @guylouis? An agenda or docs to add to for the meeting?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-14 17:29</div><div class="msg">@carl has 7 of them, for @rajanie to pickup and deliver to whoever will be implementing the flow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-14 17:30</div><div class="msg">I don't have any as I gave mine to Matt who is doing the audit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-14 19:26</div><div class="msg">any ideas about how much hardwallet cards will cost once they're mass produced?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 06:18</div><div class="msg">@noman we still need to get a quote. Depending on quantities a javacard costs from 1 to 7 dollars a piece from my experience. Then there is the printing, packaging, etc.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-15 06:19</div><div class="msg">very cool, thank you. do you any schematics or photos of your prototypes up anywhere? i'd love to get a look at them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 06:20</div><div class="msg">the javacard is an off-the-shelves device, it is the same as your regular credit card or sim card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 06:21</div><div class="msg">if you are talking about the wallet pro, there is no schematics yet. I am prototyping using the STM32 Nucleo boards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-15 06:21</div><div class="msg">ah okay, i thought i saw you posted about screens</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 06:21</div><div class="msg">correct, that's the pro wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-15 06:21</div><div class="msg">gotcha, didn't realize there was two devices</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-15 14:08</div><div class="msg">Since I am engaging with manufacturers to source our javacard hardwallet, we need to decide if we ask them or not to load the applet since there?s been some discussion about that earlier here. At least for the first batch to be delivered before 10/2018.
|
|
|
|
*(base line) option 1:* the factory loads the applet (and they hold GlobalPlatform keys used to load the applet). The factory will need to print : PUK (used by the user to recover the pin when lost/forgot) + pairing code as explained by Michele in his documentation. If the user blocks his card (3 false pins + 5 false PUKs) then the card cannot be reprogrammed since GlobalPlatform keys are hold at the factory.
|
|
|
|
*option 2* :the card is delivered blank to the end user. At first use, Status client, who holds GlobalPlatform keys, downloads applet to the card with NFC. The card comes only with its PUK, no need for a pairing secret in this case.
|
|
_Advantages:_ less work by the factory (faster cooperation, cheaper prices), if card is blocked (3 pins + 5 puks) the user doesn?t have to throw it away and can reprogram it.
|
|
_Disadvantages_ :Global Platform keys are in the client (risk of compromission, and thus that Status branded javacard be reprogrammed with a different applet), longer and more complex card set-up for the user (@micheleb btw how long would you estimate it will take to download the applet), less straight forward client integration.
|
|
|
|
Thanks for your feedbacks/correction to my assumptions there.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 14:17</div><div class="msg">@guylouis the applet loading process does not take long, a few seconds. If we want this kind of provisioning, we must do something with the GlobalPlatform key. My proposal is as follows:
|
|
|
|
1) The Status client checks if the card has the default (also called VISA) keys. This can be done by sending an INITIALIZE UPDATE and check if the card cryptogram matches
|
|
2) If it is, load the applet, change the keys to random ones
|
|
|
|
and here comes the decision: we can either
|
|
1) save those keys to allow erase/reload of the applet if needed (then applet reload must be implemented too)
|
|
2) destroy the keys, then the applet cannot be replaced anymore
|
|
|
|
each approach has advantages and disadvantages. But to be fair, I quite like the idea to have the applet loaded at the client side, because we will save a lot of hassle with printing, personalization, etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 14:20</div><div class="msg">of course this means more client-side development. I think I will have to take active part in this development, because it involves implementing (part of) the GlobalPlatform specifications, and they are not clear at all, but I am extremely familiar with them (I have worked on implementing GlobalPlatform compliance test among other things)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-15 14:27</div><div class="msg">In this approach, what can prevent a malicious user developing an alternate version of our (open source) applet (adding some backdoors), downloading it on some javacards, providing it to some users, and getting back some secret either by getting physically the card or using a compromised client ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 14:31</div><div class="msg">nothing. But nothing prevents a distributor to do the same thing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-15 14:34</div><div class="msg">actually, if the cards are known to be empty, and you download Status from a known source, it is safer than a pre-personalized card, because a distributor might forge cards and distribute their own compromised one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-16 03:33</div><div class="msg">Thanks guys, exciting stuff.
|
|
|
|
@micheleb @guylouis Here: <a href="https://github.com/status-im/pm/issues/2">https://github.com/status-im/pm/issues/2</a> - added placeholder, please feel free to add more to it about what we want to have discussed/decided
|
|
|
|
Invited you to . We also have: #core-dev-meetings</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-16 03:36</div><div class="msg">Since this will be a very tight and uncertain thing (not part of our initial OKRs, HW/SW integration, huge security impact, etc), I'd want to make sure we don't over promise on this one. Can we ensure this doesn't happen from an event/marketing POV?
|
|
|
|
cc @jonny.z @naghdy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-16 13:19</div><div class="msg">Client side loading is nice, but it needs to be super easy and convenient to do</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-16 13:20</div><div class="msg">As a consumer I think I would prefer to trust the manufacturer on this... Not sure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-16 13:22</div><div class="msg">I am checking with ACS for both options, and outlining the ux user flow in both options to help with the decision</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-16 13:23</div><div class="msg">I think if we manage to do something easy enough, from a customer perspective nothing strange happens. Ideally, they open their new card, put it near to the device and after waiting a bit they see their PUK and pairing code to write down, more or less</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-16 13:26</div><div class="msg">yes and on the advantages of option 2 from a ux point of view, we spare them to manually enter the pairing code at setup (in option 1 they need to look for it in the packaging and enter it manually)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-16 14:01</div><div class="msg">the hardware wallet should act like a tool that provides functionality, but not be the end all storage. The root is the seed phrase, which is stored securely offline, and ported to other things if necessary ( 0-layer backup and recover). I'd hate for someone to have to buy a new device because they can't wipe their card and start fresh with a new seed phrase. This also allows for current account transport (we'll need education around not spreading your seed over many devices, which removes security guarantees around hardware wallets)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-16 17:20</div><div class="msg">What's that in reference to ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-16 18:40</div><div class="msg">these 2 options.. it feels as though one of the options bricks the card if they forget something or want to change accounts (seed phrase). Am I wrong on that?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-16 18:58</div><div class="msg">I'll share tomorrow a document I am writing with some ( high level at this stage) ux flow with the two options. This should help.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-16 19:03</div><div class="msg">but on the principle you're right : if the card is bricked (in the meaning that 3 wrong PIN + 5 wrong PUK have been input by the user) then in option 1 the card can be thrown away, and in option 2 the user can get it in a factory reset mode and reload the applet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-16 19:21</div><div class="msg">@corey122 if you just want to change the account you can do that even with option 1, the card is only bricked if the PIN and PUK are blocked</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-16 19:24</div><div class="msg">ah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-16 19:24</div><div class="msg">thank you for that clarification</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 08:42</div><div class="msg">hey before I start to work on low level UI and UX flows in the app, please clarify a couple things to me
|
|
|
|
*A.* Do you need to touch (tap) a smartphone with the card (1). Or it may be just close enough (2) ?
|
|
|
|
*B.* When do you need to enter PIN code, while touching device with card ( keeping card close to smartphone)? Or once you have touched a device it prompts you asking to enter a pin code and you can keep away your card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 08:44</div><div class="msg">@denis-sharypin The card must touch the phone (on my phone, the reader is on the back btw). The card must be touching the phone the entire time, tapping is not really enough.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 08:45</div><div class="msg">because as soon as one removes the card from the field, the PIN verification is reset</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 08:49</div><div class="msg">as a technical note, NFC is not a radio technology, communication does not happen through radio waves. The reader and tag are respectively the primary and secondary windings of a transformer and communication happens by high-frequency modulation on the power line itself. So the range of NFC is very short</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 08:50</div><div class="msg">okay got it. thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 09:13</div><div class="msg"><!channel> following my different discussions with @micheleb @chad @goranjovic @patrick771 @andreaf @corey122 about the hardwallet light, here?s a document to help
|
|
- align on the hardwallet ux with high level wireframes of the wallet setup, transaction signing, and user login,
|
|
- start further discussions with you guys about the implications on the client (no more password, no more ?3 words? checking for transactions, whisper key decoupling for instance) of this ux.
|
|
|
|
You will see we still have to decide how the applet is loaded on the card (either at the factory, or by Status client), it has some ux, manufacturing and security implications. I did wrote down in Annex a basic decision matrix, but it needs to be completed (in particular discus security implications) and discussed.
|
|
|
|
<a href="https://docs.google.com/presentation/d/1r27RoYKQ1TQtxByGKyFGlLWcb5AtDziXi_1qIqzuQH8/edit?usp=sharing">https://docs.google.com/presentation/d/1r27RoYKQ1TQtxByGKyFGlLWcb5AtDziXi_1qIqzuQH8/edit?usp=sharing</a>
|
|
|
|
@oskarth this doc could facilitate Devs meeting on monday. Given time constraints of the meeting, your suggestion on how to discuss this on monday are welcomed. I guess we?ll have to set-up a team to work and discuss this in further detail, but still need help to understand who should be part of it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 09:45</div><div class="msg">@guylouis can you give a comment access to this doc? or it's better to talk here?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 10:23</div><div class="msg">oups - sure will do in approx. 30 min when back on the keyboard</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-08-17 10:34</div><div class="msg">re `no more three words in ux`:
|
|
|
|
1. We are planning on changing these to emojis, for better memorability afaik
|
|
2. Can't we still show these on the screen to tap your card and sign the tx?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-17 10:36</div><div class="msg">same question here, we still need 3 words (or emojis), because they're not related to hardwallet, we need them to protect from spoofed UI</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 10:42</div><div class="msg">i strongly suggest keeping the signing phrase, it should be emoji's though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 10:44</div><div class="msg">@guylouis please understand that the 3 words is to guard against the screen being spoofed, and has nothing to do with signing the transaction itself</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 10:45</div><div class="msg">actually why hasn't it been turned into emoji's</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 10:45</div><div class="msg">that's pretty low hanging fruit, no?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-08-17 10:48</div><div class="msg">@goranjovic would likely know...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 10:50</div><div class="msg">I can't seem to comment either</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 10:53</div><div class="msg">hey, we are still testing the copy and design around it. Here is last designs (last column) that are going to be tested by @philipwu next week. If everything goes well we implement it <a href="https://www.figma.com/file/Xg0hHWg7Ngqrly2syl4MAM/Transaction-phrase-UXR?node-id=0%3A1">https://www.figma.com/file/Xg0hHWg7Ngqrly2syl4MAM/Transaction-phrase-UXR?node-id=0%3A1</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 10:58</div><div class="msg">feel free to add comments (figma :raised_hands:)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:07</div><div class="msg">I changed the link (original doc was on a wrong google doc domain) and now you can all comment/edit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:07</div><div class="msg"><a href="https://docs.google.com/presentation/d/1r27RoYKQ1TQtxByGKyFGlLWcb5AtDziXi_1qIqzuQH8/edit?usp=sharing">https://docs.google.com/presentation/d/1r27RoYKQ1TQtxByGKyFGlLWcb5AtDziXi_1qIqzuQH8/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-17 11:11</div><div class="msg">Many thanks for putting this together @guylouis! Took a spin through and jotted some notes that I can transfer to the deck now but copying some main points here:
|
|
|
|
- Generally, from a UX point of view, would prefer to not have user have to pair anything so am in favor of option 1. Forcing users to pair increases chances of errors through NFC pairing failures and increases overall steps to getting set up which is not a great first impression.
|
|
|
|
- We seem to be substituting PUK for a user-decided password? Would it be possible to let users select one of the two or default to their password in the future?
|
|
|
|
- How will this work with touch/faceID which is currently being worked on? cc? @chad</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 11:20</div><div class="msg">yeah, joining to the question about defaulting to a simple account password. Should we consider this usecase?
|
|
?
|
|
How can you get the access to your account if you lost your card? Only using mnemonic?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-17 11:26</div><div class="msg">@denis-sharypin `Uh oh... we can't open that file`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 11:27</div><div class="msg">@andrey try again please, worked for me and other two users I saw there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:30</div><div class="msg">I edited the document and removed any mention to not need 3 words/emojis check when using hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-17 11:31</div><div class="msg">oh sorry, didn't read description `We can't open this file because WebGL isn't supported, or is disabled, in your browser. If your browser supports WebGL, check out this help article to find out how to enable it.`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 11:32</div><div class="msg">enable WebGL, Andrey :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-17 11:33</div><div class="msg">:neckbeard:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-28/338213459126_9a2080e57364819a4d87_72.jpg" /><div class="message"><div class="username">andrey</div><div class="time">2018-08-17 11:33</div><div class="msg">is it safe? :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 11:33</div><div class="msg">logout from Metamask</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:42</div><div class="msg">about option 1 vs option 2 for the user experience : actually both options have exactly the same number of NFC ?taps? (however in option 2, the first tap has to be longer than in option 1, we?ll have to warn the user to make it 5 seconds), and in option 2 you don't have to type the pairing code in the client, and is thus simpler in this respect.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:43</div><div class="msg">about PUK : in both option there is a PUK the user needs to have written down somewhere, this is usedif he blocks his PIN. In option 1, the PUK is printed on a paper delivered with the card, in option 2 is show to the user on the client during set-up</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:45</div><div class="msg">about pairing code, same thing : it exists in both options, and needs to be known by the user in the case he changes his phone for instance and wants to use his already setup hardwallet on his new phone. in option 1 it's printed on a paper, in option 2 it's displayed by the client at set-up. In option 2, one advantage is that the user does not need to type it in manually.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:48</div><div class="msg">touch/face ID : to be studied and discussed but we could think about replacing the hardwallet PIN by touch/face ID. In this case we would need to securely store the hardwallet PIN in the phone, secured by touch/face ID.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 11:49</div><div class="msg">If you lose the card, yes recovering is only with mnemonic</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 12:10</div><div class="msg">From a manufacturing standpoint: got an answer from our preferred short term supplier of javacards (ACS). They can't support us for a personalized setup of the card (Option 1 in the discussion above) for the October time frame. However for later deliveries they could propose this for 0.5$ per card. Card cost for 2k-5k batch is 2.12$. I think this should really push us to investigate Option 2 and load the applet on the card through our client.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 12:11</div><div class="msg">I also would tend for option 2. Of course another possibility is to handle applet loading on our side after getting the cards from ACS (from what I understood, they do not really do packaging?)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 12:13</div><div class="msg">Do these prices and timeframe include some printing on them?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 12:13</div><div class="msg">yes 2.12$ per card with printing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-17 12:17</div><div class="msg">and for packaging, they usually do not provide it and is not included in the price. But we can ask them for some quotations. They probably work with some packaging vendors. Your opinions on the packaging definition are thus also welcomed ! I was my self thinking about something really flat design to facilitate shipping in a standard letter (just like Visa cards). Here is an example of packaging I liked from Yubikey.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 12:18</div><div class="msg">cc @ned</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 12:20</div><div class="msg">yeah simple packaging with a seal looks cool. Did they give any timeframe to get the cards with print but without applet? Because if the earliest date is October 15 then we really MUST implement option 2, because we would not have the time to handle packaging and custom print ourself (in option 2 the print will be the same for all cards, since all custom data is generated during applet installation)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 12:49</div><div class="msg">Design isn't aware of doing the layout or packaging but we should get them started asap</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-17 13:31</div><div class="msg">Btw, my opinion is based on the skimming the deck for 5 min and re-reviewing these GH notes: <a href="https://github.com/status-im/hardware-wallet/blob/master/UX_NOTES.md">https://github.com/status-im/hardware-wallet/blob/master/UX_NOTES.md</a>
|
|
? so not strongly held and see the need for urgency and go with option 2. We can aim for fewer taps in V2 :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:41</div><div class="msg">Will our numeric keyboard for PIN randomize where the numbers are? @denis-sharypin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 13:42</div><div class="msg">@3esmit :thinking_face: do you think its needed?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:42</div><div class="msg">Banks like it...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:42</div><div class="msg">Most touchscreen ATMs do that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:44</div><div class="msg">The risk that it mitigates is someone trying to look what digits you are typing when unlock your password, lets say a "friend" at a bar looks when you pay the account, later he only needs to steal your card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:44</div><div class="msg">It's also a remember to the user its dealing with "secret here"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 13:45</div><div class="msg">I've never seen that anywhere personally. By default I was going to use a native keyboard (easy to implement and maintain) But if there a consensus on the idea implementing a custom one we could do it probably</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-07/237395147762_41041c5be71b2b3bc1d1_72.jpg" /><div class="message"><div class="username">3esmit</div><div class="time">2018-08-17 13:48</div><div class="msg">The case of friend is an example, but even a survillance camera could easy guess what numbers you are typing in a big predictable numeric keyboard.
|
|
I imagined this was a common feature because I've seen it so many time in brazilian banks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 14:42</div><div class="msg">native keyboard is not the best idea IMHO, on Android the keyboard could be malicious</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-17 15:04</div><div class="msg"><!here> So I quickly created wireframes for UX flows that were outlined by @guylouis above. I have added only my thinking on how import account could be done using our current flows. Please create accounts in Figma and leave comments.
|
|
|
|
<a href="https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1">https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-08-17 15:04</div><div class="msg">just was asking about this @goranjovic . How come you are reading my mind @denis-sharypin? :scream:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 16:11</div><div class="msg">this was mentioned to us by gluk256 that we use a native keyboard for password fields also (though we should move to faceid/fingerprint anyway)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-17 16:11</div><div class="msg">@guylouis @denis-sharypin @patrick771 btw the pin entry could be done with faceid/fingerprint</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 18:26</div><div class="msg">to make PIN entry with fingerprint we would need a Javacard implementing the biometric API, but these are really hard to come by.. and also the applet would need to be changed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-17 18:27</div><div class="msg">if we cache the PIN on the client, even encrypted, and decrypt it with faceid/fingerprint we defeat the point of using smartcard-side authentication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-08-17 19:23</div><div class="msg">This is amAzing </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-17 22:00</div><div class="msg"><a href="https://twitter.com/peterktodd/status/1030529279484878848?s=12">https://twitter.com/peterktodd/status/1030529279484878848?s=12</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-18 08:43</div><div class="msg">Vertical card design is quite a trend right now <a href="https://www.acorns.com/spend/">https://www.acorns.com/spend/</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-18 12:19</div><div class="msg">The problem with emojis IMO is that they have more individual connotation than words. Could it be possible that if I have positive/negative emojis in my signing phrase it influences my mood and usage of transaction feature</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-18 12:22</div><div class="msg">it is inspiring</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-18 15:39</div><div class="msg">@denis-sharypin left a few comments on the ux flows, i think we can simplify it by
|
|
1) using faceid/fingerprint which eliminates pin/password
|
|
2) enabling NFC on certain screens and allowing a tap of card vs tap on screen</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-18 17:31</div><div class="msg">@micheleb I stumbled upon this <a href="https://www.fi.muni.cz/~xsvenda/jcalgtest/">https://www.fi.muni.cz/~xsvenda/jcalgtest/</a>
|
|
would this be of interest to further qualify ACS card, and other cards if we source other models ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-18 17:35</div><div class="msg">@guylouis I am aware of that site, but the results for the ACOSJ card are incomplete</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-18 18:51</div><div class="msg">I feel like that can be largely mitigated by choosing a subset and letting the user roll the dice until they are happy with it at setup</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-18 19:58</div><div class="msg">> same question here, we still need 3 words (or emojis), because they're not related to hardwallet, we need them to protect from spoofed UI
|
|
|
|
@andrey is there any doc explaining how it does that ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-18 20:37</div><div class="msg">@yenda it's pretty straight forward, if the user remembers the 3 symbols and the set of those symbols is large enough, if the phisher does not know the symbols at time of generation or individual, then they cannot reliably create a spoofed sign transaction screen</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-18 20:37</div><div class="msg"><a href="https://status-im.slack.com/archives/C8QP8S5UH/p1534624372000100">https://status-im.slack.com/archives/C8QP8S5UH/p1534624372000100</a></div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-18 21:05</div><div class="msg">@jarradhope correct me if I am wrong but spoofing the transaction screen should only give away the password right ? Is the password what we are protecting here ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 10:01</div><div class="msg">the tx signing screen is the most trusted screen, we don't want a phisher capable of falsifying any of the tx details or creating an alternate flow that convinces the user to give up his private keys or sign a bogus transaction, or type their password into an input field the attacker controls (granted we need to remove this using faceid/fingerprint scan on mobile which helps mitigates this further)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 10:18</div><div class="msg">@micheleb @guylouis what prevents an attacker from ovewriting the card software?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 10:19</div><div class="msg">@jarradhope In which case? You mean when we ship an empty card? The way I see it, after installing the applet the client must change the Global Platform key to random ones, so nobody can personalize it anymore</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 10:20</div><div class="msg">okay sgtm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 10:20</div><div class="msg">then the question is if we want those keys to be saved/kept for eventual upgrades or just destroyed</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-19 10:28</div><div class="msg">but I don't understand how the attacker could create an alternate flow leading the user to give up his private keys or signing a bogus transaction because the private key isn't known to status-react and a dapp doesn't have any control passed .sendTransaction call which triggers this flow. If the risk of password phishing is mitigated by using faceid/fingerprint the utility of the emojis seems very limited</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-19 10:33</div><div class="msg">If that's the case I would just educate the user with a message like this: "The transaction screen will never ask you for any key or password. If it does in the future, ask for help". (at least the first part)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:28</div><div class="msg">@micheleb if we don't change the key after programming: anyone with this key will be able to delete/rewrite my Status javacard without knowing my PIN right ? and our key will be part of our source code (open source) and thus very easily accessible by anyone ? If yes, then it's quite clear we have to randomize them after programmation, other wise the card can be attacked even remotely when sitting in my bag/wallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:30</div><div class="msg">From a user experience standpoint I don't find it really shocking to brick totally the card if 3 PINs + 5 PUKs have been wrongly typed in</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:31</div><div class="msg">@guylouis of course we must randomize that, I was wondering if these randomized key can be saved somewhere for recovery or just destroyed afterwards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:31</div><div class="msg">ok clear</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:32</div><div class="msg">If someone replaces the app somehow, the pairing is broken, so the client would detect that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:32</div><div class="msg">So keeping the random keys safe is important but is not a critical secret </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:33</div><div class="msg">The way pairing is done, there is no way to simulate a working pairing card-side or client-side. It is a mutual authentication </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:35</div><div class="msg">I mean interest of keeping the new keys is to 1/ allow upgrades of the card 2/ allow reinitialization from the card if it's blocked after 3 pin + 5 puk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:36</div><div class="msg">Yeah, exactly that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:37</div><div class="msg">one consideration for this choice : if we save the new keys, I imagine it will be saved locally in the client. If the user changes phone, he will lose the keys.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:38</div><div class="msg">Correct. One could device a mnemonic-like system of course to allow paper backup, but it makes things more complex</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:39</div><div class="msg">Since you would have too many codes to write down and confusion will arise</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 12:39</div><div class="msg">fully agree !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 12:39</div><div class="msg">That's why I cannot really say what I would prefer. If we destroy the keys, we are safe, that's for sure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 13:10</div><div class="msg">One other case to tackle : we will ship empty cards, and our keys will be easily accessible (open source code for the client), so some our cards can be reprogrammed by a malicious attacker before first use by the real user. The attacker can brick our cards for sure. He can also download a malicious app on the card. In this case what mechanisms could we put in place to prevent the (authentic) Status client to interact with this malicious card : signing the applet firmware with a status key ? I see there is a unique identifier of the app AID used in your SELECT command, can it play this role or on the contrary can a malicious applet fake the AID ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 13:36</div><div class="msg">@jarradhope out of curiosity, did they mention an interest to have our javacard hardwallet implementation running on their SIMs ? This would be a cool ISP/Status type of partnership.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 13:52</div><div class="msg">well I think this is actually much easier. Applet cannot do anything unless they are selected. Even if they are, they can only access their own memory. If an applet is installed with an AID different from our own, then it would be pointless, it cannot do anything</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 13:52</div><div class="msg">if an applet is installed with our AID is also no problem. The algorithm in my mind is as follow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-19 13:56</div><div class="msg">When a card is near:
|
|
|
|
1) Try to authenticate with INITIALIZE UPDATE using the default keys
|
|
2) If this fails, try to select the applet and ask for pairing code (unless it has been paired already). If an applet has been installed maliciously it is extremely easy to detect: you get asked for a pairing code, but you do not have one :smile:
|
|
3) If this succeed, erase the applet and package with our AIDs (if this fails, ignore the failure, it is actually a good sign).
|
|
4) Load the verified package, install the applet (show pairing and PUK)
|
|
5) Change the GlobalPlatform key to random ones, put the card in OP_SECURED
|
|
6) Destroy the keys
|
|
7) go on with the setup</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 15:35</div><div class="msg">Awesome ! We have a workshop with @micheleb tomorrow and we will study the flows in more detail (in particular we?ll discuss what we can do about these taps and PIN entries), we will provide more detailed feedback right after !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:13</div><div class="msg">They were looking at doing that yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:13</div><div class="msg">They were abit secretive, it was unclear if they would want to partner with us or just take our code :joy:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:20</div><div class="msg">While upgrade-ability would be one of the bigger features for option 2, I'm not a fan of storing the globalkeys on device. Thats kind of the whole point of the hardware wallet in the first place is to get sensitive information off the phone, and it just makes Status the app a larger target for attack</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:30</div><div class="msg">I bet I could create a webpage that looks identical to the tx you want to sign and I could create an address that even has the same start and end hex and you would tap it and the real tx screen would come up, and you will assume you just didn't tap correctly and I will take your eth and take a pic of your dumb face doing faceid</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:31</div><div class="msg">we're trying to give a simple, easy visual signal to the end user that's hard for the attacker to visually replicate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:32</div><div class="msg">faceid/fingerprint is only making password entry more convenient, it does not solve the problem at all, it just makes it quicker for me to steal your eth</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/fcc4675bd0ade27de9baefb82098e500.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0002-72.png" /><div class="message"><div class="username">yenda</div><div class="time">2018-08-19 18:47</div><div class="msg">I hope status would have at least asked me to give your phishing site permission to take my picture :D</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-19 18:50</div><div class="msg">me too :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-19 20:47</div><div class="msg">That?s not an easy choice indeed, and it's an important one. My feeling is that we risk to rush into option 2 because it makes our sourcing job easier & cheaper, and because it's probably be the only way to get a large (let?s say 1k+) batch for Devcon. But if we look at the big picture and stick to our principles (� we don't compromise on security �) to take our decisions, we should consider as a blocker the fact that option 2 allows a malicious attacker to brick completely our cards while they are still in their packaging. @micheleb could you confirm that my understanding about this is 100% correct (meaning : in option 2 a malicious attacker with our keys - they are easy to get from our source code-, can change the keys of the card to a random one, and thus brick them, before the card has been programmed by our client).
|
|
|
|
We spend the day tomorrow with @micheleb and we can summarize the pros and cons of the three options (features + security), share them with the team, to help with the decision:
|
|
* option 1
|
|
* option 2 with keys being randomized and stored in client after programmation
|
|
* option 2 with keys being randomized and deleted in client after programmation
|
|
|
|
Also, and as @micheleb proposed, we could also prepare a smaller batch ourselves for Devcon following option 1 methodology. For instance source 100-200 cards, have them printed somewhere, source separately the packaging, the seal, a welcome card or quick start guide, program the cards ourselves (we?ll need some printer to print the PUK and paring code during this process). We might not be able to use the same suppliers for packaging etc. than the factory will for further batches but would allow to give cards at Devcon, and would be a good beta test for the whole user experience.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-20 05:05</div><div class="msg">if an attacker has physical access to the card, bricking it is just matter of using scissors or applying a bit of force :smile: If we really are paranoid about bricking without opening the envelope, we can use RFID-shielding packaging. I do not feel option 2 is a compromise on security if done correctly, but we have to discuss that in details. As I said, GlobalPlatform keys allow loading/deleting applets, yet they give no access to any part of the applet's memory, so the thing we are trying to keep safe (the master key) remains safe no matter what.
|
|
|
|
Furthermore, even in the SIM-card industry they are finally arriving at the conclusion that over-the-air provisioning is a good idea. These systems are being actively worked on. I do not think we should remain "in the past" unless we have a good reason to do so. Today we will discuss everything.
|
|
|
|
Another point to consider, if we do option 1 and yet delegate the personalization to ACS, we are trusting ACS to load the correct applet, we are trusting them not to keep a copy of: GlobalPlatform keys, PUK, pairing code. I have no reason to distrust them in principle, but we are basically placing all our security eggs in ACS's basket :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-20 05:29</div><div class="msg">Added to agenda: <a href="https://github.com/status-im/pm/issues/2">https://github.com/status-im/pm/issues/2</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-20 05:30</div><div class="msg">```
|
|
3. Hardware wallet (Javacard, light)
|
|
Context: We want to support hardwallet for Devcon. This requires a lot of coordination across HW/dev/security/ux. This is not captured in current OKRs or priorities among teams. Additionally, we also have a HW wallet pro.
|
|
Goal: Discuss roughly what we need, unknowns, and figure out team and point person to this. Rough timeline. Understand relationship with HW pro wallet.
|
|
```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-08-20 08:58</div><div class="msg">Thats reasonable @oskarth. Let's not do anything pre-announce, and if it happens before our summit (i.e. <25th Oct), then we can put together something last minute. cc @shawn678 as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 09:02</div><div class="msg">Yeah I don't think we will be able to make it in time for devcon</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-20 15:48</div><div class="msg">Today we went with @micheleb on all Pros & Cons of the different options we have to load the applet on our Hardwallet Light (javacard). This choice needs to be done urgently because it structures our sourcing relationship with the manufacturer, the development of the client, and the ux work.
|
|
|
|
The document below is quite factual. Our own conclusion is the best choice is option 2a mostly because it has better security. But also : simpler logistics, lower product cost ($). Downside being that it implies additional client side development, and an extra step in the user setup ux.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 16:28</div><div class="msg">doesn't 2a have a "bricking card before open" problem ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 16:29</div><div class="msg">i guess it's not a big deal unless they want to grief us</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-20 17:19</div><div class="msg">yes, we considered that this problem exists with all options. Because you can still brick an option 1 card before opening too, using a large coil instead of a regular nfc reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-20 17:20</div><div class="msg">I mean, it would be an act of vandalism more than a security issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 17:28</div><div class="msg">gotcha</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 17:40</div><div class="msg">have we successfully programmed a card using .cap with Status on Android yet? @andreaf ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 17:40</div><div class="msg">> The two secrets of the cards (PUK and Pairing code) will be displayed to the user on the client while setting up the card for the first time.
|
|
|
|
This is abit of a concern</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-20 17:41</div><div class="msg">Unless the card can have some writable surface on it for the user to write it on or something</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-20 20:37</div><div class="msg">We were thinking of putting a quick start guide and paper where you can write in the packaging, like ledger does </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-20 21:42</div><div class="msg">As for your question on upgrade of a card from android, we need at least to implement GlobalPlatform (upgrade procedure in javacard environment) in the app, it's not well documented but luckily @micheleb is an expert at this :grinning: @micheleb could you also comment on what else we need to port to the app ? any ISO7816-4 android libraries needed and existing to send APDU to the cards ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-20 21:44</div><div class="msg">We have went through hardwallet today at devs meeting and are putting up a swarm team for the client integration. I will suggest OKRs.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-21 06:01</div><div class="msg">Yes the android API does not support APDU sending directly, the NFC api is lower-level than that. I think there are some open source libraries which can be used. Of course this is something we will need regardless of options 1 or 2</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-21 09:19</div><div class="msg">> have we successfully programmed a card using .cap with Status on Android yet? @andreaf ?
|
|
|
|
not yet but I can try these days</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-21 09:20</div><div class="msg">@micheleb what about iOS? I remember nfc is less open in iOS but I don't know a lot</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-21 09:23</div><div class="msg">I have no idea, I don't think you can implement a card reader using iOS NFC, needs to be checked on client side</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-21 09:23</div><div class="msg">there are Bluetooth based NFC readers, but of course the API is not standard, so we can only support specific readers if we were to do that on iOS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-21 11:04</div><div class="msg">- Natively iOS (since iOS 11 in 10/2017) can read NFC tags. There is however no writing capabilities. Contrarily to the rumors, iOS 12 which just launched did not change that, and writing is not possible. Thus impossible for us to implement APDU send/response model.
|
|
- I don't believe in a Status business model where we would supply a battery powered nfc-bluetooth adapter. These kind of devices are expensive and as @micheleb wrote will need custom SDK implementation in our client.
|
|
- I would stick to Android compatibility only for now (and desktop, a USB adapter might make more sense here, much cheaper, I will investigate) for our hardwallet light. Hopefully iOS will evolve towards nfc read/write capability.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-21 11:34</div><div class="msg">yeah the card won't be for iOS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-21 11:35</div><div class="msg">the pro version will be with ble</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-21 15:52</div><div class="msg">Sharing UXR plan for Hardware Wallet plan here put together earlier today. Edits / comments welcome: <a href="https://docs.google.com/document/d/1h8X_VKNGOKMA91CmyM97spNlPcfmupFwLYKx400MBY0/edit">https://docs.google.com/document/d/1h8X_VKNGOKMA91CmyM97spNlPcfmupFwLYKx400MBY0/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-21 16:03</div><div class="msg">I agree with the conclusion of the document with regards to security and usability. The trade-off of additional client side dev is well worth it. Furthermore, from a production standpoint, it
|
|
Doesn't pin us to additional requirements if we need to change or if someone wants to port this from our open-sourceness. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-21 21:09</div><div class="msg">We had a full day of discussion about hardwallet light and pro with @micheleb yesterday. Here?s a transcript of the take aways of this discussion. I will provide tomorrow further high level diagrams of the user experience for patrick/denis to review and discuss. This diagrams will also help read and understand this transcript.
|
|
|
|
<a href="https://docs.google.com/document/d/1uDbdAGkqcGBm9CxmUKtPQc8T8e03CU8cw8yMrfXZVk8/edit?usp=sharing">https://docs.google.com/document/d/1uDbdAGkqcGBm9CxmUKtPQc8T8e03CU8cw8yMrfXZVk8/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-21 22:44</div><div class="msg">looks like this is behind google login. can it be made public?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 05:26</div><div class="msg">Will the light hardwallet work with iOS? If yes, how?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 05:31</div><div class="msg">@corey122 forgot if this has been talked about, but do you have any thoughts re the options listed in <a href="https://docs.google.com/document/d/1h8X_VKNGOKMA91CmyM97spNlPcfmupFwLYKx400MBY0/edit">https://docs.google.com/document/d/1h8X_VKNGOKMA91CmyM97spNlPcfmupFwLYKx400MBY0/edit</a>?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 05:49</div><div class="msg">ok that's odd, I checked again, let me know if it is still not ok to access it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 05:50</div><div class="msg">@oskarth as per the question on iOS, see <a href="https://status-im.slack.com/archives/C813TET52/p1534849489000100?thread_ts=1534780127.000100&cid=C813TET52">https://status-im.slack.com/archives/C813TET52/p1534849489000100?thread_ts=1534780127.000100&cid=C813TET52</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 06:11</div><div class="msg">and in the same thread @corey122 gave a feedback about the options also</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 11:03</div><div class="msg">Cheers!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 11:09</div><div class="msg">@goranjovic @andreaf @micheleb Action points I wrote down after our discussion
|
|
* @goranjovic: check with Roman how password is generated/managed also when several accounts in the client. What we need to evaluate is if the account password for the account on a card can be a BIP32 derivation of our master secret, if not some development in the card might be needed to store the password there.
|
|
* @andreaf + @micheleb : check further support of APDU send/receive and GlobalPlatform minimum requirements for the applet loading
|
|
* @guylouis : write down a first draft flow charts of user steps + states of the card
|
|
* @guylouis : write okr/swarm
|
|
* @andreaf / @goranjovic : whisper key decoupling in the client is a hard dependency for the hardwallet project, we need to understand implications/time line to do this decoupling.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 12:00</div><div class="msg">With @dmitryn also helping out (Clojure/client), do we need any more resources for this @guylouis? How are we on UX front?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 12:03</div><div class="msg">@guylouis Also, would you mind if I talk a bit about HW wallet at ETHIS talk in a few weeks? Doing trial run on Friday. If OK, what are the main takeaways you think I should impart?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-22 12:05</div><div class="msg">@oskarth, @denis-sharypin has already spun up some work on the UX flows (<a href="https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1">https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1</a>) and I'd like to try an get started with both preliminary user research + usability testing. And @andmironov along with @hester are also keeping tabs as they are interested as well.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-22 12:05</div><div class="msg">@denis-sharypin is on vacation this week, back next</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 12:05</div><div class="msg">I should probably get better at reading chat history :sweat_smile: Cheers!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-22 12:07</div><div class="msg">@goranjovic @dmitryn A lot of these screens looks mockable, i.e. parallel work. WDYT about creating issues for them and possibly bounties (can try Gitcoin, @cryptowanderer might be able to help)?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-05-11/181684552369_66f21f8981bdb0f83bdd_72.jpg" /><div class="message"><div class="username">cryptowanderer</div><div class="time">2018-08-22 12:41</div><div class="msg">Not yet ready on the Gitcoin front and SOB is non-functional. Can definitely create bounties though, just need another 1-2 weeks likely to straighten it all out with them.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 13:27</div><div class="msg">Hi, I think we're good ! I'll formalize a swarm but it looks like this for the bees :slightly_smiling_face: : @micheleb (applet), @andreaf (goeth), @goranjovic & @dmitryn (clojure/client), @patrick771 (ux), @denis-sharypin (design) and myself for pm.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 13:28</div><div class="msg">we need also to finalise the swarm on decoupling the keys (which is needed for the hardware wallet), and understand who can work also there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 13:28</div><div class="msg">I can help with go but there will be a lot of clojure work I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 13:36</div><div class="msg">Mockups for the ux will definitely help a lot. After all the discussion of the past two days with @micheleb @goranjovic & @andreaf, I think we need at least an other iteration of the diagrams/screens before we engage here. Next step is for me to provide @patrick771 &@denis-sharypin with some inputs.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 15:35</div><div class="msg">@micheleb in the installation script, what's the last command after loading the file?
|
|
` send_apdu -sc 1 -APDU 80E60C005F0C53746174757357616C6C65740F53746174757357616C6C65744170700F53746174757357616C6C657441707001002EC92C{:s}{:s}00`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 15:36</div><div class="msg">is it calling a function of the applet to set the secrets?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:36</div><div class="msg">That's the actual installation command </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:36</div><div class="msg">The secrets are installation parameters </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 15:36</div><div class="msg">ah ok thank you!!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:37</div><div class="msg">So installation is a 4 step (2 of which can be combined) procedure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:37</div><div class="msg">Install for load command which says about the cap file being loaded</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:38</div><div class="msg">Then load command (split in several pieces) to load the cap</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:38</div><div class="msg">The install for install which installs an instance of the applet from the cap file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:39</div><div class="msg">and install for make selectable, which makes the applet install selectable, so usable </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:39</div><div class="msg">Usually install for install and make selectable is combined in a single command, which I do here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-22 15:40</div><div class="msg">And yes install for install is a stupid name but is what is written in the specs:rolling_on_the_floor_laughing: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-22 15:40</div><div class="msg">:slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-22 19:01</div><div class="msg">Sure this would be awesome ! Not sure how much you want to detail and the angle you wanted to take. Anyway, here are the main takeaways. Let me know how I can adapt if you had something else in mind. I did not mention any date of availability since I am not sure we publicly give this kind of indication. The reality is that light version will be available in Q42108 , and planning for PRO version is not secured for now.
|
|
|
|
*CONTEXT*
|
|
- Status is a caretaker of value, in the form of crypto assets : eth, erc20 tokens, erc721 tokens etc.
|
|
- These assets can be stored in Status client
|
|
- or in hardwallets, which are physically separated security devices
|
|
|
|
*STATUS HARDWALLETS*
|
|
* True to our principles: open software, hardware, mechanics
|
|
* two products in development, both allow the same use cases:
|
|
- secure off-client signing of transactions
|
|
- secure and easy authentification with Status mobile client
|
|
* Light version
|
|
- contactless (nfc) javacard
|
|
- no screen, buttons
|
|
- natively compatible with android phones
|
|
*Pro version
|
|
- battery powered, card size form factor, BLE, screen, buttons
|
|
- natively compatible with iOS & android mobile phones
|
|
- improved security towards client spoofing : transactions details, confirmation, and PIN entry are done fully on device with no interaction with the client</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-22 21:32</div><div class="msg">Coldcard Wallet is available now for 70 bux
|
|
<a href="https://coldcardwallet.com/">https://coldcardwallet.com/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-23 01:17</div><div class="msg">This is great, thank you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-23 01:20</div><div class="msg">For pro, what's the reason we don't leverage something like Ledger? This question might come up. I feel like this has been touched on but I forgot the details</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-23 02:39</div><div class="msg">Ledger: I know there's the SGX stuff.
|
|
|
|
Light: Are we using ACOSJ card? Is this open in some form?
|
|
Pro: are we planning on using open hardware in some form?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-08-23 05:58</div><div class="msg">while they are highlighting `ultra-cheap` i was expecting something like 1.99 USD but not $69.99:joy:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-23 06:02</div><div class="msg">their production runs are in the hundreds at the moment</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 06:52</div><div class="msg">cool stuff actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-08-23 07:06</div><div class="msg">early adopter hacker aesthetic</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 07:30</div><div class="msg">Ledger: apart from the SGX stuff, some considerations:
|
|
- we enable iOS. Ledger is USB only so would work with PC, maybe android through the USB port, but not iOS, that's the first thing we tackle with our Pro. Actually Ledger API is integrated in goeth already.
|
|
- So Ledger could sign our wallet transactions, but we use our hardwallets for other Status client features : login with Status client, and derive the whisper key, not sure (not studied ledger API yet) this would be feasible with Ledger.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 07:31</div><div class="msg">Light : the model of card we will source is most probably ACOSJ card.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 07:32</div><div class="msg">ACOSJ is just the reference of one model of card of one specific chinese manufacturer called ACS. It?s not open in any way. It?s impementing javacard specifications. We might source other references too from other manufacturers e.g Gemalto, Idemia, NXP etc.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 07:33</div><div class="msg">Pro : the hardware we will design will be open sourced. We haven't identified an existing open source project we could use and join however.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 08:16</div><div class="msg">Very interesting ! I ordered one for review and will share my feedback as soon as I am able to test it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 08:37</div><div class="msg">I note they have interesting security features, like second PIN for plausible deniabilty, 3rd PIN to brick the hardwallet, a very open source approach (despite the use of a secure element), and a specific visual indication wether the uploaded code used is the original one or an other one (either open source project or malveillant).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 08:39</div><div class="msg">we certainly can think about implementing these things in our wallet too. The secure element is not "smartcard-grade" like the ledger nano is using but if it does not require closed source code it becomes interesting</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 08:40</div><div class="msg">of course our priority remains to understand if the STM32WB is going to integrate a sort-of secure element too or what they mean when they say that it will have a "key storage" area</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:10</div><div class="msg">no</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:10</div><div class="msg">iOS won't support NFC writes (calling commands), the hardware can, Apple just...doesn't :troll:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:10</div><div class="msg">that's why we're working on the Pro version with BLE etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:11</div><div class="msg">oh this has already been answered :slowmo-parrot:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:12</div><div class="msg">@nastya unit price will most likely be $40 or so last time I checked for something like this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-08-23 09:13</div><div class="msg">sounds good! anyway they created interesting stuff!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-23 09:13</div><div class="msg">totally</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 11:03</div><div class="msg">@micheleb I'm playing with the `GlobalPlatformPro` java project to see better how the protocol works and what we can implement. I see that if I use the wrong key it says: `DO NOT RE-TRY THE SAME COMMAND/KEYS OR YOU MAY BRICK YOUR CARD`. am I going to block the card if I send wrong keys while testing/debugging?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:05</div><div class="msg">you might, depends on the card... the library can send INITIALIZE UPDATE (which does not reveal if the client has correct keys or not) and receive a response from the card. From that response, the library can determine if the keys you are using are correct or not. If they are not, it can refrain from sending EXTERNAL AUTHENTICATE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:06</div><div class="msg">there are a few cards (very few), which have velocity check on INITIALIZE UPDATE (so, they slow down an attempt to send many INITIALIZE UPDATE commands) but I know none which blocks at repeated INITIALIZE UPDATE without EXTERNAL AUTHENTICATE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 11:06</div><div class="msg">so there's a maximum number of attempts? is there a way to know it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:07</div><div class="msg">there is a maximum number of EXTERNAL AUTHENTICATE, so you do not need to send that command with wrong keys... it is usually 3 to 5</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:07</div><div class="msg">some have no limit though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 11:08</div><div class="msg">ah ok so I can play with other commands like listing the apps installed maybe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:10</div><div class="msg">you cannot do almost anything before authenticating :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:10</div><div class="msg">but you have the correct key, they are in the script</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:10</div><div class="msg">is the 4041...4f ones</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 11:11</div><div class="msg">ahahh yeah I know, I was trying to understand how many bugs I can write before I lock the card :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:11</div><div class="msg">ahahah try to get the authentication right, anything else you can do without problems</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 11:12</div><div class="msg">I mean start with INITIALIZE UPDATE, that one is safe, once you are confident that you can check the card cryptogram then it also means you can generate a correct EXTERNAL AUTHENTICATE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-23 12:04</div><div class="msg">cheers!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-23 12:05</div><div class="msg">> We haven't identified an existing open source project we could use and join however.
|
|
|
|
this might be something worth plugging at ETHIS then? already fishing for HW vendors to collab with Nimbus for points of sale etc :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 13:49</div><div class="msg">Here?s a wireframe designed to help us better understand how the user experience (which screens to show, when tap to have on the nfc) and the client-card exchanges (command exchanges imposing us to have card close to the phone?s nfc) are related. This example is for the case of an account creation and not importation.
|
|
|
|
In *bold* are when client-card exchanges are happening in the user flow.
|
|
|
|
The diagram helps to understand that for a first set-up we have to encourage the user to find a way to have his card tighted up with the phone for the whole process, that will last > 1-2 minutes overall (initialization is 1 min, and then account needs to be prepared), and this is why we shoudl include some kind of sticker in our packaging to facilitate that....</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 13:49</div><div class="msg">Here?s the <a href="http://draw.io">http://draw.io</a> file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 13:51</div><div class="msg">Given everyone?s feedback, let?s consider for now (unless further feedback in the coming days) we chose option 2a for the applet loading.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 14:02</div><div class="msg">I think that one of the main thing to tackle from a ux point of view is what we *in terms of perception from the user* associate the PIN to : either the account, or the card. One of the main difference is that when the user changes his account, if PIN is associated to the account, we will reset his card to a PIN 000000, and he will have to define a new PIN when creating or importing a new account. I do prefer this option, but it really is a ux question. It gives the user the perception he is starting from a 100% fresh card set-up when he change the account on the card. It?s very similar to the current Ledger or Tresor user experience, where device is reseted when you want to change the account.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-23 14:40</div><div class="msg">Yes definitely, we are quite advanced on the software side for our pro version, but identifying an open source hardware to merge efforts with would be excellent !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 15:16</div><div class="msg">@micheleb is that ok if I implement only scp 2 for now or it depends on the card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 15:17</div><div class="msg">Yes they all have scp2</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-23 15:19</div><div class="msg">ok cool! I studied the secure channel implementation in that library and the data sent and received for the INITIALIZE UPDATE. javax.smartcardio is not in android but I don't think we need all those classes so I'm sending bytes directly. the javax.crypto is in android so the same algorithm should work. I'm doing now an android test app to test it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-23 15:23</div><div class="msg">yeah porting that library is mostly matter of replacing the javax.smartcardio. Unfortunately they have not wrapped it to make it easier to port to other frameworks but it can be done</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 07:15</div><div class="msg">Here's a Q3 OKR draft for the hardwallets (the document includes also hardwallet pro). Feedbacks welcomed !!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-24 07:53</div><div class="msg"><a href="https://status-im.slack.com/archives/C846J9HTJ/p1535066890000100">https://status-im.slack.com/archives/C846J9HTJ/p1535066890000100</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-24 07:53</div><div class="msg">^ please read that thread</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 09:24</div><div class="msg">And also submitted and made a PR for a swarm for the hardwallet light integration and sourcing effort :
|
|
<a href="https://github.com/status-im/ideas/commit/dbb859a4cd5be64fc354b4f14019a56b407a7a9d">https://github.com/status-im/ideas/commit/dbb859a4cd5be64fc354b4f14019a56b407a7a9d</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 09:24</div><div class="msg">There is an existing swarm for the hardwallet pro here :</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 09:25</div><div class="msg"><a href="https://github.com/status-im/ideas/blob/master/ideas/229-hardware-wallet-pro.md">https://github.com/status-im/ideas/blob/master/ideas/229-hardware-wallet-pro.md</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 16:17</div><div class="msg">Feedback from Gemalto (#1 ww supplier of javacards): they will have a 3.0.4 card (IDCore 3140), and 3.0.5 card (IDCore 3130) only in Q4 2018. They say neither of the two are available. I have some doubts on the quality of this feedback so I will find other entries in Gemalto to double confirm.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-24 16:34</div><div class="msg">IDCore is probably a Global Platform ID Configuration card from the name. I was working on IDConfig 3-4 years ago. It might be, that they make it for some specific customers and then they commercialize as "standard" products only in a few years. The smart card market is slow from this point of view, requirements for newer technologies come seldom and mostly from R&D departments of large companies or pilot tests of public institutions...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 16:35</div><div class="msg">Yes it's crazy slow:disappointed_relieved:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-24 16:37</div><div class="msg">But Q4 2018 is already good news. If we want to get our second batch from them, or even have a second supplier it already means something.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-24 19:30</div><div class="msg">With the pro version, are we familiar with what electronics certifications or approvals we're going to need? And what's involved with those processes?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 19:58</div><div class="msg">I have done that quite a few times. The list of certifications we need depends on two things: the definition of the product (mainly its interfaces : which radios, here also the magnetic part of the wireless charging) and the countries we want to distribute. CE and FCC are usually covering most of the technical needs (what needs to be actually respected), but some countries impose specific certifications (e.g Canada, Japan etc.) to sell on the territory. I will work on this and come with a list with the current product definition. I will base that on three things : 1/ some reference documents I have about tests per countries 2/ I will consult some testing labs, that's part of their job to be able to answer this kind of question 3/ my network of ex-colleagues in the field. The certification process usually implies test houses (like BACL or STS) either in Asia or Europe that go through the testings (for instance to get FCC you can't do the tests yourself and provide your test report, it has to be done in an accredited test house). CE can however be declarative but all serious industrials pass a test in a external test house.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-24 20:03</div><div class="msg">Before the certification, we'll have to qualify our product, meaning that we'll have to test ourselves or more realistically at the factory (since we are not equipped for now with testing equipment) that our hardware design qualifies with 1/the certfication tests it will take (we don't want to discover we have significant issues while in the test house) 2/the characteristics we will have defined for the product and that can of course go further than 1/ (either by being more stringent, or for things that are not part of certifications like IPxx tests for dust/water proofness etc.).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-23/422058362675_dc3e307b6e9052d90b4c_72.jpg" /><div class="message"><div class="username">kim196</div><div class="time">2018-08-24 22:44</div><div class="msg"><!here> our incubatee pixura /superrare inquired about integration with the hard wallet. not sure what they have in mind exactly. is there anyone on the hardwallet team who might be able to chat with them and answer some questions? for reference <a href="https://pixura.io/">https://pixura.io/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-25 13:08</div><div class="msg">I'll be happy to</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-25 13:10</div><div class="msg">@guylouis if needed you can ping me any time to jump in the call</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-23/422058362675_dc3e307b6e9052d90b4c_72.jpg" /><div class="message"><div class="username">kim196</div><div class="time">2018-08-25 22:35</div><div class="msg">Great thank you so much! I will set up a 30 min chat. Does this coming week work for you- any day and time preference? The Pixura team is pretty flexible.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 08:11</div><div class="msg">About hw light set-up user experience: we know now that the user will have to leave his card in close contact to nfc for a long period of time (>1minute) and he will have to grab a pen to write down his secrets on a piece of paper, and that if the card gets away from the nfc during this, he has to start again. We came to the conclusion that we should help the user sticking the card to his phone for the whole set-up. There are number of accessories on the market to help with that we could put a simple sticker in packaging or put this kind of accessories: <a href="https://www.amazon.com/s/ref=nb_sb_noss_2?url=search-alias%3Daps&field-keywords=stick+on+card+holder+">https://www.amazon.com/s/ref=nb_sb_noss_2?url=search-alias%3Daps&field-keywords=stick+on+card+holder+</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:10</div><div class="msg">the other option is to source the right removable double sided tape (would look something like below) and provide such a pad in the packaging.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:20</div><div class="msg">hmmm, are you sure this is good UX?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:20</div><div class="msg">@patrick771 @hester ^^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:22</div><div class="msg">We have to find the best possible ux that allows the card to remain close to the nfc reader during the whole setup. Will brainstorm with UX team for sure !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:24</div><div class="msg">Shipping with a cardholder thing is kind of cool, but I do worry that there's alot of steps here, where it might be easier and more enjoyable experience just going down personalization route if we introduce too many hurdles</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:33</div><div class="msg">yep, we're inline, we want to go for the no personalization route for security reasons, but have to make sure we build a good enough UX experience.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-27 09:33</div><div class="msg">The thing I worry about here is that we're suggesting people augment their phones / devices with some double-sided tape which in the grand scheme is probably not a big deal but agree it's not a great experience. I can see the memes now of people trying to peel sticky tape off their phones after pairing.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-27 09:37</div><div class="msg">Is it worse than suggesting at the start of unboxing/unwrapping to have a place where the phone lays on top of the card on a flat surface? I.e. don't try to do this on a subway on the way home from work?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:39</div><div class="msg">I think it's going to cause alot of frustration with people</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-27 09:41</div><div class="msg">Wework uses such card case for their cards for opening doors and it's quite handy actually. Concern that I have here is will it eliminate the initial idea to store this HW in a private place? And how it will work with ux flows that are triggering when HW is presented to the flow.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:42</div><div class="msg">@denis-sharypin did you have to program the card with your phone for a minute ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:42</div><div class="msg">afaik wework just hands it to you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-27 09:43</div><div class="msg">Yep, that's correct. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-27 09:43</div><div class="msg">Okay, just for set up this case is too much imo</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-27 09:44</div><div class="msg">And what do you do with the case afterwards?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:44</div><div class="msg">yes too much, because it will look like something here to stay on the back of the phone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:44</div><div class="msg">i used to just have my card in my cow wallet and tapped through doors by pressing my wallet up to sensor</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-27 09:45</div><div class="msg">Yep, it has really sticky surface</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-27 09:45</div><div class="msg">good morning, quick update on the applet installation from android: last week I created a test app for android and implemented the first commands and generation of the keys for the secure channel. today I'm trying to use the secure channel and then to upload/install the applet. @micheleb I'm always confused with scp versions. I see my card has 2.15, are we going to always have this exact version or can it change? in the docs I don't see a lot of things related to that but following the gpj code I see a lot of checks for version 2.x</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:45</div><div class="msg">i think moving your physical wallet to your device is also an interesting experience and association for people to make</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 09:46</div><div class="msg">your card SCP02 with i=15</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-27 09:46</div><div class="msg">How i picture the set up is like saying to user something like: put your card on the table and place phone on top of it, prepare pen and paper</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:48</div><div class="msg">I agree that we should at least try this with real users to see if it creates frustration or not.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-27 09:48</div><div class="msg">@denis-sharypin This is what I was thinking in my earlier comment. Btw, are the prototypes shipped? Has anyone tried for themselves?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 09:48</div><div class="msg">i=55 is common in telco environment. With i=55 the challenge generation is deterministic so you can pregenerated both initialize update and external authenticate so you can transfer an entire GP session through sms without waiting for response. I think GPJ also supports SCP03 and SCP01 but the first is unlikely to replace SCP02 in the following years (we can always add SCP03 if and when needed later) and SCP01 is dead since long</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:48</div><div class="msg">@rajanie</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-08-27 09:49</div><div class="msg">i don't even know who they should have been shipped to</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:50</div><div class="msg">I asked @rajanie to send to Goran for now because I was sure he would need one. For the rest I have to tell her who needs how many (and I'll buy more). Anyway there is not integration working at all for now, so nothing to test.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-27 09:50</div><div class="msg">cool thank you @micheleb!! :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 09:51</div><div class="msg">basically, I'm centralizing needs for samples</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-27 09:52</div><div class="msg">Happy to get started on organizing user studies for unboxing as soon as we have a working prototype.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 09:54</div><div class="msg">@andreaf from your side you actually do not care if it is i=55 or i=15, because it only affects how the *card* challenge (not host) is generated. Since you do not need to predict it, the same code for i=15 works just as well.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 18:07</div><div class="msg">@micheleb Gemalto finally sent to me the datasheet about their 3.0.4 card. It will be only available in samples in november (yes, samples !) and they don't want to communicate prices before then (they say their price list has not beed fixed yet). About Ec end point multiplication, I see in the data sheet "on card asymetric key pair generation", that could be it isn't it ? what do you think ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:10</div><div class="msg">So is like ACS but with more flash memory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:11</div><div class="msg">No, key generation is not related
|
|
Unless they allow setting the private key and only derive the public one but that wouldn't be a standard feature </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:12</div><div class="msg">I mean I agree with you that key generation does technically all we need, again is a limit in the specs in that I cannot set a privatr key and say "OK now give me the public one". The card always generates the entire pair</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:13</div><div class="msg">Which would be fine but since we cannot feed it a seed would make the wallet not BIP39 compatible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 18:14</div><div class="msg">ok, so I'll ask them if they support any ec end point multiplication, to be sure if yes or no, and do you see anything else ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:15</div><div class="msg">No. As I say the best way to ask is if they support that algorithm I have mentioned in the Readme or something equivalent </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:15</div><div class="msg">It is easier to explain to them than to say point multiplication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:16</div><div class="msg">Because if the person is not intimate with EC they might not know that internally it is point multiplication </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-27 18:17</div><div class="msg">ok KeyAgreement.ALG_EC_SVDP_DH_PLAIN_XY then</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-27 18:17</div><div class="msg">:+1: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-08-28 02:29</div><div class="msg">FWIW as a user i'd much rather lay the card on a table and the phone on top instead of messing with any double stick tape. I would never apply double stick tape to my phone.
|
|
|
|
the cool thing about laying everything on a table is that it's kinda like a little security ritual, which could be fun for some users (nerds like me)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-28 12:40</div><div class="msg">@guylouis looks good! couple questions that I have:
|
|
1. from your opinion on which screen from the current app onboadring we should communicate to user about HW?
|
|
2. what?s the reason to have two PUK codes?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 12:49</div><div class="msg">@denis-sharypin, so for 1. I personally liked it the way you put it in your first flow, the user first chose if he wants to create an account or import one, and then chose if it he will have it on the card or on the phone.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 12:50</div><div class="msg">for 2: there is only one PUK. I might have something wrong that leads to think there are two. Could you point to me where so that I correct it ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-28 12:51</div><div class="msg">Ah sorry, it's me. Got it wrong. Thanks for clarifying!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 13:21</div><div class="msg">@patrick771 we need ux team input about PIN user experience. The PIN format is 6 numbers. During the first setup of his card+account, the user will be asked to define a a PIN, we should not accept 000000 as an acceptable PIN by the way.
|
|
The question is what we want to build : the perception that the PIN is associated with the card, or the account. It?s a different user experience especially when he decides to change his account.
|
|
|
|
If PIN is linked with ACCOUNT : when changing account, the PIN is automatically reset to 000000, the user starts fresh with fresh card can either crate or import a new account, and create a PIN again to protect his account.
|
|
|
|
If PIN is linked with CARD : when changing account, the PIN remains the same on the card even after the decision to change account.
|
|
|
|
I am personally for the first option (link with ACCOUNT) because:
|
|
* It?s very similar to the current experience of the password in Status client : anytime the user creates/import an account he is asked to define a password.
|
|
* When deciding to change account on the card, it gives a fresh start to the card. It?s just like Ledger or Trezor ux, if you want to change the wallet on the hard wallet then you first clean the hard wallet, like a factory reset, making clear that your wallet is wiped out of everything from before, and then restart the user experience and define mnemonic + PIN.
|
|
|
|
What?s your opinion on this ? It affects the screen flows that Denis is about to create.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 13:23</div><div class="msg">I second this preference... are there technical differences in each of the options?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 13:29</div><div class="msg">I think it's purely ux, since it only involves that PIN is reset to 0 when the user decides to change the account on its card. cc @goranjovic @dmitryn in case they think differently</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-08-28 13:32</div><div class="msg">There shouldn't be a difference on the impl side. I agree with linking with account, as that's the only option that allows us to have both hw and non-hw accounts in the same client app.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-28 13:34</div><div class="msg">Can you remind, if a user selects to set up the PIN would this substitute for an account password as we currently have for the normal onboarding flow?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-28 13:37</div><div class="msg">And in the ACCOUNT flow, if a user has multiple accounts / wallets wouldn't they need to have a different PIN for each account?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 13:40</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-28 13:41</div><div class="msg">and that segmentation is appropriate for securing multiple different types of accounts and good password management.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-08-28 13:59</div><div class="msg">Yeah, agree, I think it makes sense to link to an account vs. the card. @guylouis My only concern is with my first question, as it's not entirely clear if a user has to keep track of both a password + PIN with HW or if the PIN substitutes as the password during setup. It just becomes a lot of elements to keep track of if that's the case (but I suspect not).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 14:00</div><div class="msg">It's clear that we want to remove the password, because yes it would be too much to ask the user to remember PIN and password.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 14:45</div><div class="msg">Following discussion with Denis, here's an update of wireframe (v1.1 now) with mentions (see at the bottom of the file) of two other screens:
|
|
- unpair cards
|
|
- change PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-28 14:46</div><div class="msg">@denis-sharypin it seems everyone involved is happy with this chart, you can thus use it for the screens flow :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-08-29 07:39</div><div class="msg">More of a random FYI, but if haven't heard of Ecomi check it out: <a href="http://www.ecomi.com">http://www.ecomi.com</a> Mentioned on my call with Guy today as I came across them in Asia and they are only card wallet I?m aware of with NFT?s.
|
|
|
|
No idea on feasibility, but is this something we might consider with having NFT functionality? Could help us standout as well since Ecomi is unknown and new (not to mention security concerns I had when they demo?d to me)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 07:43</div><div class="msg">oh, their wallet is either a perfect copy or a rebranded <a href="https://coolwallet.io">https://coolwallet.io</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 07:44</div><div class="msg">yes, same remark, they must have a partnership with coolwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 07:46</div><div class="msg">NFT are ERC-721 tokens, right? What would be needed to support them from a user point of view? The hardware wallet (both pro and lite) can sign transaction of 0 ETH and non-empty data field. The HW Pro will also recognize ERC20 tokens</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 07:47</div><div class="msg">but I am not familiar with ERC721, I have read what it is, but it would be nice to hear from a user point of view how should the wallet behave in a transaction involving ERC721 tokens</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 08:28</div><div class="msg">actually it's for sure : the ecomi support page to set-up the hard wallet points out to coolwallet screens <a href="https://orbishelp.freshdesk.com/support/solutions/articles/36000014638-how-to-setup-the-orbis-secure-wallet">https://orbishelp.freshdesk.com/support/solutions/articles/36000014638-how-to-setup-the-orbis-secure-wallet</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 08:39</div><div class="msg">Actually ecomi white paper gives interesting insight about coolwallet hardware (based on NXP secure element), and even some infos about how pairing & session are done : <a href="http://digitalusdedicated.com/ecomi/files/ECOMI%20Whitepaper.pdf">http://digitalusdedicated.com/ecomi/files/ECOMI%20Whitepaper.pdf</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 08:39</div><div class="msg">also, one point I note is that the mnemonic is shown on the phone and not the coolwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:40</div><div class="msg">yeah I had noted that, it is a bad idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:41</div><div class="msg">if there is a piece of information that you can mark as "most sensitive" in the entire chain, that would be the mnemonic :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:45</div><div class="msg">also, there is a point which makes me wonder... help me understand, if I am missing something important in this sentence</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:45</div><div class="msg">The mechanism has been designed for the wallet to register the hosts in a secure way. When a host device (Android
|
|
or Apple smartphone) sends a request to the Secure Wallet, it provides a UUID (Universally Unique Identifier) with
|
|
description to the card. The card will generate a UUID which is pushed to the host device so it can generate the
|
|
device key (which is SHA256 value of UUID). The Secure Wallet will generate the same device key following the same
|
|
protocol. Both the device and Secure Wallet will then confirm the key by challenge-response mechanism. If passed,
|
|
the device will be registered as a host of the Secure Wallet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:45</div><div class="msg">that is about pairing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:45</div><div class="msg">how in the world is this pairing secure, if the key is simply the SHA256 value of the UUID which can be retrieved in plaintext</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 08:47</div><div class="msg">I mean it is extremely easy to make this secure, by displaying a pairing code on the screen, but the way they describe this they basically send the encryption key plain as the very first thing...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 09:32</div><div class="msg">I haven't checked in details but isn't the pairing code of step 3 here to secure that ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 09:32</div><div class="msg"><a href="https://orbishelp.freshdesk.com/support/solutions/articles/36000014638-how-to-setup-the-orbis-secure-wallet">https://orbishelp.freshdesk.com/support/solutions/articles/36000014638-how-to-setup-the-orbis-secure-wallet</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 09:35</div><div class="msg">but the whitepaper does not mention this at all</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-29 09:37</div><div class="msg">either the whitepaper is not up to date, or the mechanism described there is in addition to the BLE pairing, no idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-24/304281668629_99d09ae86c8e0a04b52d_72.png" /><div class="message"><div class="username">growbot</div><div class="time">2018-08-29 13:23</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-29 13:23</div><div class="msg">/kudos @micheleb for helping me with all these APDU commands :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 15:35</div><div class="msg">@goranjovic have you had by chance the opportunity to check with roman (? not sure I got the name right - sorry about that), what constraints on the password on the client could possibly affect the hardwallet integration ? one thing at stake is for us to evaluate if the current applet software needs to evolve to store the password or not, especially because an external company will start a security audit of our applet code.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-29 15:53</div><div class="msg">@corey122 there is a security audit of our javacard software that is starting now by a swiss company called Zklabs. For sure you'll be in copy of the exchanges with them (they haven't started, I am pushing them to provide some visibilty). I was wondering if we have any process to assess the security on the client side, and if yes if this is some kind of permanent process or we have some planning and deliveries for this.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-29 15:58</div><div class="msg">we're currently in the process of looking at what modules to start the auditing process on. there has been a previous audit of the client, but some of it has been nullified due to updates and changes, while other parts are still relevant. I can link you that doc if you'd like.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-29 15:58</div><div class="msg">also +1 on including me on the process for this audit.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 09:52</div><div class="msg">Hi swarm team ! @micheleb @goranjovic @dmitryn @andreaf @patrick771 @denis-sharypin here?s the draft swarm for the javacard integration (note that I'll update it asap with some remarks I got). For now we have quite high level objectives setup (a beta release in Q3, and a product release in Q4).
|
|
We should now work on a more granular project plan with iterations (e.g two weeks iterations). I see the following main trails of work for the project : uxr, ux, clojure, goeth, sourcing. Once these will be better planned, we?ll include also QA and security audit on the planning. Let?s set-up a kickoff call to discuss: what steps you see (for each trail uxr, ux, clojure, go, sourcing) to reach our objective, and let?s identify dependencies. From there I'll compile an overall project plan with iterations for the whole project.</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-08-30 09:52</div><div class="msg">@guylouis has a poll for you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 09:53</div><div class="msg">Thanks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 09:55</div><div class="msg">oups, here's the swarm : <a href="https://github.com/status-im/ideas/pull/301/files">https://github.com/status-im/ideas/pull/301/files</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-08-30 10:09</div><div class="msg">Do we need to include to this activities marketing and branding people?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 10:37</div><div class="msg">Great point - I'd suggest to first outline a development planning, and it will be a good basis to have marketing + branding in the loop and include their needs + inputs. For branding, packaging is actually on the critical path for sourcing (!), I talked about it with @ned and will definitely include his feedback in the planning.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 10:37</div><div class="msg">michele can tomorrow only at 9am or 6pm, here's a new poll</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-08-30 10:38</div><div class="msg">@guylouis has a poll for you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 10:39</div><div class="msg">pff sorry I realize this is not a multi-choice poll :disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 10:42</div><div class="msg">sorry for the mess, here's the good one :</div></div></div><br/>
|
|
<div><img src="" /><div class="message"><div class="username"></div><div class="time">2018-08-30 10:43</div><div class="msg">@guylouis has a poll for you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 10:57</div><div class="msg">i see it's been added by @oskarth to next Devs meeting agenda on monday</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-30 12:27</div><div class="msg">probably last week, feel free to add it again here: <a href="https://github.com/status-im/pm/issues/3">https://github.com/status-im/pm/issues/3</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 13:05</div><div class="msg">ok, what about monday 4 pm (cest) then ? any one who cannot ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 13:10</div><div class="msg">oups ! I add it for next monday then !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 13:11</div><div class="msg">I see it there "292 Decouple Whisper key from Wallet (status-im/ideas#292)"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-30 13:12</div><div class="msg">when it's confirmed can you send the calendar invite please?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-30 13:16</div><div class="msg">oh my bad, I was thinking of HW</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-08-30 13:16</div><div class="msg">can we add the context / goal / reading?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-08-30 13:17</div><div class="msg">pls loop me in as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 15:07</div><div class="msg">we're on for monday 4pm CEST, I'll send an invite to you guys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-30 15:53</div><div class="msg">@micheleb I used today to write more tests to avoid blocking the second card :slightly_smiling_face: I finished and run init update, ext auth, status, and everything works on a real device + real card. so I think it's almost ready for the final installation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-30 16:39</div><div class="msg">I created the repo for the test app <a href="https://github.com/status-im/smartcard-cap-installer-test">https://github.com/status-im/smartcard-cap-installer-test</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-30 16:41</div><div class="msg">@micheleb when you have time can you start reviewing the code? especially the Crypt class. I tried to follow the gp docs but for some algorithms I had to look at gpj to understand them, the docs aren't very complete. <a href="https://github.com/status-im/smartcard-cap-installer-test/tree/master/app/src/main/java/im/status/applet_installer_test/appletinstaller">https://github.com/status-im/smartcard-cap-installer-test/tree/master/app/src/main/java/im/status/applet_installer_test/appletinstaller</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-30 16:46</div><div class="msg">@andreaf I will start right now. Yeah I know the specs are incomplete, to really understand them you need the VISA part of the specs (which can be had only under NDA) which gives concrete examples on how to use things... that's why you need a reference implementation, or someone who knows what's written there :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 19:27</div><div class="msg"><!channel> I created a new slack channel called #hardwallet-pro to host discussion about the second version of our hardwallet. Please join it should you be interested and/or want to contribute. Current main objective as described in the swarm is to discuss *the hardware architecture* (which MCU to use, with a focus on open source and security, should we use a Secure Element), exact *hardware definition* (which screen ? can we really embed wireless charging ? etc.) and *feature definitions* (brainstorming on use cases we could enable with it, benchmark of other hardwallets).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-30 19:30</div><div class="msg"><a href="https://github.com/status-im/ideas/blob/master/ideas/229-hardware-wallet-pro.md">https://github.com/status-im/ideas/blob/master/ideas/229-hardware-wallet-pro.md</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-08-30 19:42</div><div class="msg">Is this your weekly sync? I'd like to a few if not regularly so I can be well-informed for copy suggestions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 07:03</div><div class="msg">@micheleb I am writing a design brief for the packaging what do you suggest we consider as a format for the pairing password ? can you also remind me of the PUK lenght ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:04</div><div class="msg">PUK is 12 digits</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:06</div><div class="msg">the password - I have no specific suggestions. We either use some dictionary words (<a href="https://xkpasswd.net/s/">https://xkpasswd.net/s/</a>) or just random characters, but then I would restrict the alphabet to exclude easily confused symbols</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:07</div><div class="msg">like 1, lowercase L and uppercase i</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:07</div><div class="msg">0 and uppercase o</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:07</div><div class="msg">etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 07:07</div><div class="msg">ok - should it have a minimum number of characters ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 07:08</div><div class="msg">at least 8 characters, but more importantly, it must be a variable number of characters</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 07:09</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 07:38</div><div class="msg">@ned I did put up in writing a design brief for the packaging, inline with what we discussed earlier this week
|
|
cc @patrick771 @obi @jonny.z
|
|
all feedbacks welcomed !!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 07:38</div><div class="msg"><a href="https://docs.google.com/document/d/1Eeb1TaQ5VU3bitEKAc8kyNps_KiXC5oc28vxP2Q8Nyw/edit?usp=sharing">https://docs.google.com/document/d/1Eeb1TaQ5VU3bitEKAc8kyNps_KiXC5oc28vxP2Q8Nyw/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 10:12</div><div class="msg">:+1: this monday it's our first meeting with dev + uxr + ux, it's a kick off with goal to outline a first development plan. You can join with pleasure, actually Patrick & Denis will join from Berlin, and you might be there too.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 10:23</div><div class="msg">@andreaf for you ? (for hwallet the only point is that its a dependency for launch)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-31 10:31</div><div class="msg">yeah I think we just need to say it's a dependency, but we haven't finalize it yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-31 12:27</div><div class="msg">@micheleb if I understood correctly, `A000000151000000` is the AID and we can choose it following some rules, but how do we generate the `53746174757357616C6C6574[417070]`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 12:33</div><div class="msg">sourcing update/ *Gemalto* confirmed today that their 3.0.5 card (with ec end point mutliplication thus), called idcore 3130, will be available in samples in dec. 2018 only (I have some doubts though, since for memo their 3.0.4 card is not yet available in samples ...) & they confirmed their 3.0.4 card has no alternative ec end point multiplication scheme. *Conclusion* : we can't realistically consider them for our product launch. I will of course keep a relationship ongoing with them though.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-08-31 12:39</div><div class="msg">ok, I added some context in comments to the agenda</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-31 12:39</div><div class="msg">thank you @guylouis!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-08-31 12:46</div><div class="msg">so `A000000151000000` is the card manager AID and the other one is ours I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 15:15</div><div class="msg">oh, it is a nice card however, we should definitely keep them in mind for next year</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 15:17</div><div class="msg">it is likely that they will release 3.0.4 and 3.0.5 cards roughly at the same time. It is not a technology problem, I am sure they have them since years and now they are only making a product out of them (instead of a customer-specific project).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-08-31 15:18</div><div class="msg">I mean I have worked on a 3.0.4 card (3.0.5 wasn't yet out as spec) 3 years ago and Gemalto is usually ahead of the other companies</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-01 20:31</div><div class="msg">sorry for the late reply, I have seen only now. Yes this is correct A000000151000000 is the card manager, but it might have another ID. The only way to be sure is to send an empty select command, it always selects the default application, which is the card manager</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-01 20:32</div><div class="msg">and it answers with its own AID</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-01 20:32</div><div class="msg">only SIM cards have the USIM application as default instead of the card manager, but that will not be our case regardless of the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-01 20:33</div><div class="msg">for your information A000000003000000 is the other possible AID for the card manager, although it comes from an older spec many cards use that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-03 03:57</div><div class="msg">> Status lauched its hardwallet last year. Users can store, send & receive Eth and ERC-20 tokens with it. Comparing to other hardwallets, what are the advantages of Status Hardwallet? Will you introduce more tokens in the future?
|
|
|
|
@graeme @micheleb et al?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-07/411838218004_c7eba2c8e4f6b1a5ba77_72.png" /><div class="message"><div class="username">graeme</div><div class="time">2018-09-03 08:06</div><div class="msg">@oskarth you mean @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-03 08:09</div><div class="msg">sorry, yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-03 08:50</div><div class="msg">@oskarth, the hardwallet (javacard-based) can be actually used with any token, since it signs any 256-bit hash, so on the client side you have maximum freedom</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-03 08:51</div><div class="msg">you could use it not only for ETH actually, anything where the signature is calculated across a 256-bit hash (so anything using SHA-256 or SHA-3/Kekkac)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-03 09:00</div><div class="msg">the only thing confusing me, you say "Status launched its hardwallet last year"... do you mean another? because I always assumed that <a href="https://hardwallet.status.im">https://hardwallet.status.im</a> is our</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-03 09:03</div><div class="msg">to clarify, that question is not from me but from an upcoming q&a that I'll have with wechat community - I'm sourcing answers to make sure I represent Status accurately :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-03 09:03</div><div class="msg">ok now I understand the way it is formulated :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-03 09:04</div><div class="msg">I guess another advantage is that it requires no batteries, it is very cheap, yet secure and opensource. @guylouis any other points?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-03 09:11</div><div class="msg">The question about how we compare to other hardwallets is going to come often, especially since a market for hardwallets is emerging and more & more products come to life. I will keep up to date a file with a comparison of different hardwallets, so that we can be all up to date on this.
|
|
|
|
As per the current question, I'd say that as already outlined by michele, what we share with other hardwallets :
|
|
- we support ETH, ERC20 tokens, ERC721 tokens (as long as they are supported by our client actually)
|
|
- very strong security
|
|
|
|
Differentiators:
|
|
- Much cheaper than most hardwallets (let's not communicate prices for now,but we will most probably be <20$ easy)
|
|
- Open source
|
|
- size of a credit card, very convenient to carry.
|
|
- integrated with Status mobile experience (that might be the most important actually ...)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-03 14:58</div><div class="msg">@denis-sharypin set the channel topic: UI/UX Mockups <a href="https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1">https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-03 14:59</div><div class="msg">The constant link to latest design mockups, feel free to comment
|
|
<a href="https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1">https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardware-wallet-flows?node-id=0%3A1</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-03 15:01</div><div class="msg">@denis-sharypin set the channel topic: UI/UX Mockups ? <a href="https://bit.ly/2NdxoUB">https://bit.ly/2NdxoUB</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-03 15:24</div><div class="msg">If anyone need cards for development, please let me know. We still have some samples available to dispatch.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-03 17:59</div><div class="msg">Here are the meeting notes from the kick-off earlier this afternoon. I will propose by tomorrow a phased approach for the overall project. Please amend/correct/provide remarks in the doc.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-03 17:59</div><div class="msg"><a href="https://docs.google.com/document/d/1T5H8wy79RBb8jeI7NJgf9qBVUGMZ08_vJLM8t_eV5ZE/edit?usp=sharing">https://docs.google.com/document/d/1T5H8wy79RBb8jeI7NJgf9qBVUGMZ08_vJLM8t_eV5ZE/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-04 05:01</div><div class="msg">cheers!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-04 05:01</div><div class="msg">added here <a href="https://docs.google.com/document/d/114ArwstxOeA7WgIizmdj0RB3uvHa6ZfhD5W9L4QQLIY/edit#">https://docs.google.com/document/d/114ArwstxOeA7WgIizmdj0RB3uvHa6ZfhD5W9L4QQLIY/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-04 05:01</div><div class="msg">can we quantify "very strong security" if they ask? what do we mean more precisely?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 06:21</div><div class="msg">So the hardwallet actually doesn't offer the maximum security in every aspect, that is the reason we also develop the pro version. The good things are that the keys are stored in a secure element and never transmitted to the client. The PIN verification is like for credit cards, so you cannot really brute force it (the card is blocked). The Secure Element has a True Random Number Generator to make sure we generate strong keys. The Secure Element is very resilient against physical attacks so attacking the card directly is unfeasible. Of course it also offers 2FA since you need to have the card and know the PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 06:22</div><div class="msg">It also cannot be backdoored, we will block applet loading after personalization. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 06:23</div><div class="msg">The bad part is that the card, being a regular smartcard, doesn't have a screen or keyboard, so the user must trust the client program to display the right info regarding transactions and not to store the PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 06:29</div><div class="msg">In our case it means that the Status client must be the real one, and not a backdoored version that somehow came to the phone. Since we do pairing on first usage we can try to mitigate the issue of an attacker replacing the Status app afterwards by having the client destroy this key on deletion or something similar (I am not familiar with Android's security features), since this way the user would be unexpectedly prompted to pair with the card, which would allow detection of attack</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 08:46</div><div class="msg">Hey, I am out of a meeting with NXP for the supply of Javacard. Below my notes. Very interesting since they have a 3.0.4 card ready, roadmap to 3.0.5, and can help with identifying manufacturers that can produce small batches (in this industry a 10k batch is a small batch). Our applet being open source seems not to be blocker. @anna see the remark about NFC performances on android phones, it's someting to keep in mind when we will be at that stage of testing !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 08:51</div><div class="msg">great news! I am working on the performance test right now, and having a couple of different cards will be very useful to compare and understand the actual performance. From my experience with desktop-based NFC readers (usb), they tend to be faster than wired ones in T=0 mode, but for mobile it might be different</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 09:32</div><div class="msg">hey Swarm team ! Hope you could check-out my meeting notes of our kick off yesterday. Here's a phased planning approach for the swarm. You can make remarks/correction directly in the doc. This is a high level view with goal to define the main phases. I can easily make a graphical version of this, let me know if usefull !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 09:32</div><div class="msg"><a href="https://docs.google.com/document/d/1QY0S4cPdrWN0LPPh2K6oA5XYEqcDcFhrhRP1oJf7L-k/edit?usp=sharing">https://docs.google.com/document/d/1QY0S4cPdrWN0LPPh2K6oA5XYEqcDcFhrhRP1oJf7L-k/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 12:11</div><div class="msg"><a href="https://hackmd.io/s/BJhWIlnv7">https://hackmd.io/s/BJhWIlnv7</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 12:12</div><div class="msg">I have written a test to measure performance of our applet with regards to key derivation on the ACOSJ card. Each value is measured 10 times and the average is taken, it is pretty consistent, also across different runs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 12:18</div><div class="msg">My conclusions are
|
|
|
|
1) Key derivation is not fast
|
|
2) If we had EC Point multiplication, derivation would probably take 700ms per level (but we have to measure that)
|
|
3) The Whisper/Database keys are better stored as siblings of the first account, because there is a relatively fast way to switch between siblings (derive from parent command, I had forgot I implemented that)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 12:19</div><div class="msg">Another action point, I will check if I can boost performance by changing with the terminal parameters. Since the clock comes from the terminal, it might make a lot if different, since the terminal might be using conservative values... but we have to check how that is translated to NFC.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:42</div><div class="msg">@micheleb from a security prospective, if the whisper key is `m/n'`, so with `n` hardened, do we have any other thing to think about?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 13:45</div><div class="msg">@micheleb @andreaf just so that we are on the same page, could you precise what paths are (will be): our transaction key, the whisper key, and our future database encryption key ? thanks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:49</div><div class="msg">transaction key: `m/44'/60'/0'/0/0`, which is the only key we already have and use also for whisper.
|
|
for the other 2 we still don't know but as @micheleb said maybe having just 1 step in the depth would be faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:50</div><div class="msg">@andreaf I am yet to explore that, but it is better if we use a sibling of the main account, this way switching back to signature key is going to be much faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:51</div><div class="msg">ah ok so children of `m/44'/60'/0'/0/0` ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:51</div><div class="msg">No, a sibling</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:51</div><div class="msg">ah `m/44'/60'/0'/0/1` ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:51</div><div class="msg">In the result file I have given an example </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:52</div><div class="msg">Yeah, or hardened</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:52</div><div class="msg">m/44'/60'/0'/0/0' for example</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:53</div><div class="msg">I'm just thinking that in the future we could allow accounts to have multiple wallets, so the second one could be `m/44'/60'/0'/0/1` etc.. that's why I was thinking to use a complete different path</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:54</div><div class="msg">Yeah I know, but each part is 32-bit number, we can reserve 2 combinations for us</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:54</div><div class="msg">@micheleb
|
|
> Derivation time (1 level, non-hardened, from master): 916. Without overhead: 893
|
|
here you mean master as `m/` or the main account key as `m/44'/60'/0'/0/0`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:55</div><div class="msg">Master is m/</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 13:55</div><div class="msg">ah ok cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:57</div><div class="msg">On the last level, we could reserve the second most significant bit for our use, and everything else for accounts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 13:59</div><div class="msg">So we can expand if we need more internal keys.. Nobody needs more than 1 billion accounts I think, even if they use them as disposable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 14:03</div><div class="msg">yes you are right!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 14:10</div><div class="msg">@micheleb I am trying to understand how long the login process will take given the fact we need to derive both the whisper key and database one at login. Does it mean that for now (ACS key in 3.0.4, no further improvement) if we use m/44?/60?/0?/0/0' for whisper key, and m/44?/60?/0?/0/1' (not sure if this what you have in mind), once m/44?/60?/0?/0/0 is calculated (set-up), when we login we will have to derive whisper key and come back to transaction key (1200ms * 2 = 2,4s) and then derive database key and comeback to transaction key (2,4s) = 4,8 s login ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:12</div><div class="msg">@guylouis almost, but we do not need to come back to transaction key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:12</div><div class="msg">So is "just" 2,4s</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:13</div><div class="msg">The we can go back to transaction key only when needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-04 14:14</div><div class="msg">Yeah it's a bit long, however might be acceptable. It's another thing to try to make faster (other card, other magic tricks you could find etc.) and monitor closely from a UX point of view .....</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:16</div><div class="msg">Yes, I have to check the terminal settings for sure, I know Java smartcard I/O is not the best in this regard. I will try to source an NFC USB card reader, too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:31</div><div class="msg">Actually, I should measure a login scenario, since our timer starts with the begin of the tap. We must also select the applet, open secure channel, verify pin and export the keys (besides generating them) </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:33</div><div class="msg">If we all agree, at least for now, that transaction and whisper and db keys are siblings, I can write a test login scenario.. Actually, I will probably try to run it on Android directly to have a real feeling of how it is going to work</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-04 14:42</div><div class="msg">if you want we can use the same test project for Android </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-04 14:43</div><div class="msg">That would be good, at least the APDU classes are in common</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 07:32</div><div class="msg"><!channel> please review denis work (UI screens for hwallet) pined on top of the channel :slightly_smiling_face: I also made comments directly on the doc. For memo, the goal is to have this reviewed by uxr, development team, security (at the least) to reach (objective next monday) a v1 of the flow to do some user testing especially for the set-up phase. Also @obi welcome onboard ! a first review of the wording before then would be awesome too. Happy to chat with you anytime, to guide you through the product.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-05 08:54</div><div class="msg">Just want to confirm it one more time: ```Card can have only one Status account on it and it can be paired up to 5 phones (to same Status account)``` Is it correct?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 08:55</div><div class="msg">Yes it is 100% correct</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-05 09:00</div><div class="msg">I received other 5 cards. I can send them to other people after we finished the development but I needed more just in case. given that I blocked one at the first test :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:04</div><div class="msg">great, however I have 6 left to be shipped to whoever needs them for development. Don't hesitate to ask !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-05 09:05</div><div class="msg">ah right sorry, I ordered them last week just after I blocked the first one. so I started panicking :slightly_smiling_face: but then everything woorked with the second one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:08</div><div class="msg">@ned some notes from Trezor about their tamperproof packaging. I note that on top of having the seals, it's of course key to be sure the glue (if any) used for the pack can't be unglued/reglued.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:08</div><div class="msg"><a href="https://blog.trezor.io/trezor-one-tamper-evident-packaging-f98d3f63569d">https://blog.trezor.io/trezor-one-tamper-evident-packaging-f98d3f63569d</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:09</div><div class="msg">for the hardwallet do we need tamper-proof packaging?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:10</div><div class="msg">since tamper can be detected in software, maybe it not as critical?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:21</div><div class="msg">True ... and actually the card could be reprogrammed without opening the box if we don't make the pack able to isolate the card from nfc. I guess there's also the ux experience to take into account, 100% of hardwallets on the market today have a seal, it's quite re-insuring for users ot know their product has not been opened and played with ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:22</div><div class="msg">Actually could you re-state, which security strategy we could have on the client side for products that have been tampered with through nfc while still in their box ?</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/2674ec9e762bcd011c9542c1b787ce13.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0019-72.png" /><div class="message"><div class="username">jeluard</div><div class="time">2018-09-05 09:24</div><div class="msg">AFAIK LedgerS does not have a seal? They used to but it's been removed to improve user confidence.
|
|
There were issues with people being able to open the LedgerS package without breaking the seal .. :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-09-05 09:27</div><div class="msg">Noted! Thanks for the heads up</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:30</div><div class="msg">very interesting. Good read about this here too : <a href="https://www.reddit.com/r/ledgerwallet/comments/695iit/ledger_wallet_nano_s_came_with_no_tamper_proof/">https://www.reddit.com/r/ledgerwallet/comments/695iit/ledger_wallet_nano_s_came_with_no_tamper_proof/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:31</div><div class="msg">@guylouis our strategy is to just delete the applet if it exists but global platform keys are unchanged and eventually warn the user </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:31</div><div class="msg">if we don't put a seal, we shoudl at least like Ledger did, put in writing in the packaging somewhere that this is normal, and explain shortly why (like Ledger says 'we check integrity of the software every time it is plugged')</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:37</div><div class="msg">just pushing in the corners, since it's an important topic. In the case a hacker downloaded (through nfc) a counterfeit applet with some backdoors, and changed the GPkeys to random one. What coul d happen ? I guess the protection comes from pairing secret, right ? in this case if the packaging is not tamperproof, the user could put a paper in the pack, with being written "your pairing code (and PUK) are (right values being written her)", and in this case we have a security risk right ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:37</div><div class="msg">if yes, in this case we can consider tamperproofing and/or specific content in the ui screens to warn against presence of any pairing code and PUK written already in the pack.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:38</div><div class="msg">Yeah, if that happens you do not have PUK and pairing key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:54</div><div class="msg">can the hacker generate a 'valid' pairing code while he programs the card and write it down on a piece of paper that he leaves in the packaging ? In this case we have a security issue to tackle.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:55</div><div class="msg">Yes, he can. So we should instruct the user accordingly </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:55</div><div class="msg">clear</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:56</div><div class="msg">I mean, cards are cheap enough that an attacker can replace our card with another, so no amount of sealing will work</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:56</div><div class="msg">the thing is that the user, with such a hacked card +packaging, will not go through our initialization screens anymore. So our UI warning has to be placed somewhere else !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:58</div><div class="msg">Yeah in the screen where we ask pairing code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 09:58</div><div class="msg">you're rigth, forgot about this one :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 09:59</div><div class="msg">It is also a dubious attack venue, because to make use of the backdoor you would need to acquire the card again</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 10:00</div><div class="msg">The card is unable to initiate any communication</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 10:03</div><div class="msg">So you would need to convince a lot of users in a certain area to use tampered cards, wait until they possibly have funds and go on stealing all cards you can, in the hope of some fat accounts on tampered cards. I would not overthink that, as long as we put the warnings at the right place, we are safe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 10:07</div><div class="msg">:ok_hand: but it was a very interesting discussion, since it shows we must add a warning message in pairing code screen. About the seal, we can either put one, or not (and if not, we should write down in the packaging, that it's normal there is no seal and explain why). I will summarize the two cases for the uxr/ux/team to have feedbacks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 10:22</div><div class="msg"><!here> I have had an idea. An idea with a lot of potential issues to resolve, but I will put it here for discussion just in case. What if in the Status Client we had a sort of security bar that warns you need a more secure storage for your keys as you approach a certain threshold? Because we always talk about security, but maybe we can somehow estimate some amounts by estimating the cost/feasibility of the attacks. So for example you get adviced to get a hard wallet when your account reaches a certain amount and warned to get a pro if it reaches another amount (then eventually, suggests to create multiple accounts). Is this something that has been proposed before? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-05 10:23</div><div class="msg">100%. Same would be useful for backing up your seed phrase pestering.
|
|
|
|
cc @chad @goranjovic</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-05 10:33</div><div class="msg">cheers!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-05 11:23</div><div class="msg">Currently, we show an extra notification to backup mnemonic (it's non-mandatory) on the wallet screen once user has some amount of crypto. Sure it could be customizable and text could reflect the amount</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 11:59</div><div class="msg">@denis-sharypin just answered your comments in the figma (great tool by the way :)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 12:00</div><div class="msg">@micheleb would be great if you could take a look at it. There is especially for you one question about the ability for the client to check if a card (initialized & paired) has a secret in it (an account) or not without entering the PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 12:00</div><div class="msg">I'll be afk for 2h-3h (meeting in ST office)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 12:03</div><div class="msg"> @guylouis I will look as soon as I get internet access working again at home. But yes, the GET STATUS command returns this info, you only need to be paired</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-06/310412231971_aab33885aa55d16e4740_72.jpg" /><div class="message"><div class="username">arnetheduck.slack</div><div class="time">2018-09-05 13:15</div><div class="msg">very nice!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-05 14:16</div><div class="msg">That's for you @micheleb </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 14:33</div><div class="msg">Thanks :grin:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-05 16:02</div><div class="msg">Very good news for the GET STATUS command !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-05 17:10</div><div class="msg">I have added my comments to the document on Figma</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-04-24/173180126768_7f6060168aa29f44babc_72.png" /><div class="message"><div class="username">noman</div><div class="time">2018-09-06 05:11</div><div class="msg">love the idea. i hate the pestering. not only because it's annoying, but also because it doesn't work. People constantly ignore it and also feel shamed by it.
|
|
|
|
if instead of ordering someone to back up their phrase, you explain to them why it might be in their best interest to, _how to do it and what to do with it_, then hopefully it brings them one step closer to actually putting in the work.
|
|
|
|
no one likes losing their money, but nearly everyone is kind of lazy sometimes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-06 08:30</div><div class="msg">:eyes:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:25</div><div class="msg">I'm testing the final installation with all the commands, but I can't arrive at the end because the tag disconnects. I'm not sure if it's related to something I'm sending or to my phone hardware but it looks random</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:28</div><div class="msg">It does not disconnect always at the same place? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:28</div><div class="msg">ah right there's a default timeout for the connection</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:29</div><div class="msg">not always at the same step</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:29</div><div class="msg">no still the same even increasing the timeout</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:30</div><div class="msg">Strange. Try limiting the rate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:31</div><div class="msg">Wait a bit before sending each command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:32</div><div class="msg">ok it worked now, but I had to keep the card and phone in my hands without moving not even a millimeter</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:33</div><div class="msg">I'm testing now to see if I installed correctly with a right pair pass and puk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:37</div><div class="msg">Mmm it means the card is consuming more energy than the reader is supplying I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:37</div><div class="msg">Or is very close at the limit - you move a bit and its over</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-06 13:38</div><div class="msg">Is there a way to increase the reader's field strength? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-06 13:47</div><div class="msg">I'm going to search for it, there must be something</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-07 08:49</div><div class="msg">@andreaf @micheleb We need to define the derivation paths we use for the whisper key and database keys, since it affects both the applet code (and we need to freeze it as much as possible, since there is a security audit ongoing) and also the ux (which derivation path we use affects time needed by the card at login to provide to the client the two keys). Could you summarize here (or in a discuss thread if you prefer) your suggestion of paths to use ? cc @goranjovic @oskarth , and please add whoever needed in cc, to help with the discussion/agreement on these paths</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 08:55</div><div class="msg">my suggestion for Whisper path is m/44'/60'/0'/0/?1073741824?' and m/44'/60'/0'/0/?1073741825' for Database. I know the last number looks strange in decimal, but in hex it is 0xC0000000 and 0xC0000001 respectively. The idea was to reserve the second most significant bit for our internal use and the rest for accounts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 08:56</div><div class="msg">the most significant bit is the hardened/non hardened flag</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 09:03</div><div class="msg">I like the idea! I don't think we can have problems with these indexes. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-07 09:11</div><div class="msg">This seems like a big decision that is hard to reverse. Mind if we open it up as a Discuss thread to get as much input as possible? We should make sure we have an extensible design for future things, like many wallet/Whisper key/swarm stuff, etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 09:19</div><div class="msg">yes it makes sense! @micheleb do you want to start the thread on discuss so that you can explain better why are those paths better for the hardware wallet?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 09:20</div><div class="msg">ok I can do it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 09:22</div><div class="msg">just one question. the wallet key will be normal and the whisper key hardened. they have the same parent that is not hardened. is there a problem if one of the 2 is compromised? I don't know in this specific case but maybe it's not a problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 09:28</div><div class="msg">the ones which are more at risk of being compromised are the hardened ones (because we send them to the client)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 09:29</div><div class="msg">mmm I have to check if there is any way to go back, I do not think so</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 09:48</div><div class="msg"><a href="https://discuss.status.im/t/whisper-and-database-keys-on-the-hardware-wallet/381">https://discuss.status.im/t/whisper-and-database-keys-on-the-hardware-wallet/381</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-07 10:50</div><div class="msg">Here are the notes of today's meeting with Idemia, possible javacard supplier for our hw lite.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-07 11:01</div><div class="msg">@micheleb could you share our applet size + the RAM/EEPROM size we expect for the card ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:03</div><div class="msg">@guylouis I have to check, unfortunately it is not as easy as it might seem to get this info, I will have to check all GET STATUS options and see if there is something that tells me free volatile and non volatile memory (and run it before and after installing the applet), I do not remember</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:03</div><div class="msg">but the applet is very small, I do not believe there are cards on the market unable to host it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:03</div><div class="msg">from the memory/size point of view</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:05</div><div class="msg">but this card sounds very interesting, if they optimize key derivation in hardware or at least by implementing it in C and exposing that to Javacard it will be MUCH faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:06</div><div class="msg">coincidentally, I have just managed to get my test work on my OnePlus 6 + ACOSJ card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:06</div><div class="msg">D/installer-debug: Total time for m/44'/60'/0'/0/0 derivation: 7382ms</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:06</div><div class="msg">D/installer-debug: Total login time: 4282ms</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:07</div><div class="msg">this includes the time spent by the client. There is also the debugger attached and some log info, I have to check if disabling this greatly affects performance, although I wouldn't expect drastic differences</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:08</div><div class="msg">login time is measured from selecting the applet all the way to exporting the database key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-07 11:21</div><div class="msg">Is my understanding correct : at first set-up we'll need 7,3s to derive the transaction key from master. And then at login time, we 'll need about 4,2s to get whisper + database key ? Once set-up is done we don't have to go through the whole 7,3s derivation anymore ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:22</div><div class="msg">yeah, this is correct. Assuming the debugger did not introduce such a big overhead that significantly inflates the measured time. I will modify the app to not make use of the logger and to instead show the results in the interface at the end of the process. This way I will not need a debugger to let it run</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:24</div><div class="msg">but in any case the 7,3 was once and 4,2 each time. But 4,2 is really long, this is why I want to make sure I am not artificially inflating that number</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-07 11:58</div><div class="msg">How usually quick client can understand the state of the card and show the next step that depends on it? seconds or immediately? Asking if I need to provide a screen for this with loading state for instance</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 11:59</div><div class="msg">it should be under a second, but this can be measured if needed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-07 12:01</div><div class="msg">1 second is fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 12:39</div><div class="msg">if we save the master key in the card, don't we need to derive the account key every time we start a new session?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 12:40</div><div class="msg">No, before the first transaction after login we just need to switch to the transaction key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 12:41</div><div class="msg">ah ok so when we derive/select a key, then does it stay in memory until you switch to another one?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 12:41</div><div class="msg">Yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 12:41</div><div class="msg">Even after a card reset</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 12:41</div><div class="msg">So you only need to switch if you need to retrieve Whisper and Databases keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 12:43</div><div class="msg">ah right, I thought it was resetting at each session. ok so that's much better!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 17:49</div><div class="msg">@micheleb I created a branch called `card-watcher`. it would be nice if you can try it with your device. I removed the install actions and it's just logging when the tag connect and disconnect. with my device I can find some position where I can move it a little bit and it's still connected, while in other positions it disconnect with a small movement</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 17:50</div><div class="msg">Ok I will try it and let you know </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 17:50</div><div class="msg">yeah when you have time, thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 18:01</div><div class="msg">@andreaf I have tried. It does not beep continously, it works really nice. I can move the phone a lot without having it disconnect</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 18:01</div><div class="msg">I can even lift it quite a bit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-07 18:32</div><div class="msg">ok so maybe there's something with the commands we send. But it's strange because if I leave it still I'm able to run the installation to the end</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 20:50</div><div class="msg">when you load the applet, it writes to flash. This requires more power than just "connecting" to the card. During this phase it might be more sensible to changes in field strength</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-07 20:51</div><div class="msg">same will happen during crypto operations, since the various crypto co-processors are active</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-08 09:13</div><div class="msg">I notice it often fails at the beginning before loading so I'm not sure why. I'm going to try sending other commands. If I send only select commands I shouldn't block it right? I can also use the already blocked one </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-08 09:14</div><div class="msg">Yes select is safe</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-09-10 09:34</div><div class="msg">@patrick771 and I discussed something similar last week. We were considering that a user might have gone through the seed backup flow but then lost the phrase (maybe because they only had a trivial amount and weren't careful). At this point they still have access to the wallet and can take an action, if a reminder is triggered by activity or an ETH value threshold of some sort</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:07</div><div class="msg">@micheleb @guylouis I updated the installer to start only after 2 seconds of good connection with the card. The way I use it now is:
|
|
- I put the javacard on the table
|
|
- I click the Install button
|
|
- I put the phone on the table on top of the card
|
|
- the app discovers to the card and connects to it and start a timer
|
|
- after 2 seconds, if the card connection is not lost, it starts the installation
|
|
At this point if I don't move the phone, the installation finishes correctly.
|
|
|
|
Previously I was starting the installation at the button click. The problem was that I was able to connect to the card, but the connection was lost clicking the button, because I was moving the phone. what do you think about this way of using it? @micheleb when you have time can you try it again to see if it's better with your phone? /cc @denis-sharypin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:11</div><div class="msg">@andreaf I will try and let you know </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:52</div><div class="msg">@micheleb @guylouis I think I broke a card while testing. If I try to connect with gpj it says: `Could not connect to ACS ACR 38U-CCID: SCARD_E_NO_SMARTCARD`, so it's not saying it's blocked, like with the first one. do you think they are so fragile? I swiped it a lot under my phone near the camera flash so I guess I ruined the chip. is that possible?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:55</div><div class="msg">No I think I did it with another one </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:55</div><div class="msg">That's really weird. If they are so fragile we need to delay the order and wait for a better supplier. They are not supposed to break and go mute</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:55</div><div class="msg">No I think I did it with another one </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:55</div><div class="msg">So it might be blocked </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:56</div><div class="msg">Ok blocked is possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:56</div><div class="msg">I think I lost the connection n times before arriving to the ext auth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:56</div><div class="msg">which is a big problem I think isn't it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:57</div><div class="msg">If you lost the connection between Initialize update and ext Auth it is normal</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:57</div><div class="msg">But it is really strange that it happened so many times in a row at that point </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 14:58</div><div class="msg">Because as soon as you send a valid ext Auth the counter resets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 14:59</div><div class="msg">it looks blocked in a different way though. Because gpj can't even see it. Instead with the first one I blocked it sees it and the card return a code that explains it blocked </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:15</div><div class="msg">There is in theory a card mute state in the old open platform specs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:15</div><div class="msg">But it shouldn't be so easy to trigger</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:15</div><div class="msg">You say you put the card near to the camera flash... Was it flashing? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:16</div><div class="msg">Because that could indeed trigger and attack detection routine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:16</div><div class="msg">no, but I thought it was ruining it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:16</div><div class="msg">but actually I blocked another one just after 20 seconds so it's not that the problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:17</div><div class="msg">Oh that's very strange </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:17</div><div class="msg">I mean they could be detecting some hardware attacks based on supplying low voltage etc </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:18</div><div class="msg">I tried with another one from scratch and I was able to install correctly. with the previous one I was playing at connecting/disconnecting it. so something triggered it. but I'm not sure how</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:18</div><div class="msg">But they should cope with NFC being unstable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:18</div><div class="msg">Yeah that's not to be expected. We should probably arrange to send the card(s) to ACS for investigation </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:18</div><div class="msg">I would like to try to reproduce it, but it means blocking another one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:19</div><div class="msg">ACS?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:19</div><div class="msg">ACS is the card manufacturer </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:19</div><div class="msg">ah right!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:19</div><div class="msg">@guylouis do you think ACS can help us with this? Because if it is so easy to mute a card, it is a show stopper</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:20</div><div class="msg">I do not think it is physically broken, I know card mute state is used when detecting physical attacks and the likes. But that should be extremely rare</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:22</div><div class="msg">I have seen it a couple of times when doing tear tests.. Tearing is what happens when the card unexpectedly loses powers..but these were considered serious bugs to be fixed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 15:23</div><div class="msg">absolutely, we have to react and ask ACS. Do you have a suggestion on how to present the problem and our question ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:26</div><div class="msg">We can say that we are testing the card using NFC and that the card (I understand two of them) muted. If @andreaf can provide the logs it will be helpful</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:26</div><div class="msg">The question is what happened with these cards, if they have an idea of what mechanisms could have triggered this behavior </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:27</div><div class="msg">which logs can I provide? the only thing I see is that using gpj it fails at `reader.connect` with message `Could not connect to ACS ACR 38U-CCID: SCARD_E_NO_SMARTCARD`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:27</div><div class="msg">The logs of what you have done before that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:28</div><div class="msg">The last APDU which was sent to the card </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:28</div><div class="msg">Or the last event you have </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:28</div><div class="msg">unfortunately I don't have them because I only saw tag lost, so I thought it was just disconnecting. so I tried multiple times and in the end I tried with the sub on the computer</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:28</div><div class="msg">The more data the better, because if we just send a muted card and ask why it might not be possible unless they have some backdoor to revive it or at least extract diagnostic data </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:30</div><div class="msg">Since the cards are in OP_READY and not secured, it could be that some backdoors are still active</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:30</div><div class="msg">the only thing I know is that today I added the dele command before sending the install for load command. I don't know if it can help but the other day without this command I didn't have problems. but it's still strange because now I was able to install multiple times</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:31</div><div class="msg">the problem is that from android I wasn't able to see the error. it was connecting fine, and then disconnecting after sending the first command (select).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:32</div><div class="msg">so it looked just a normal disconnection, but for several times, that's why I tried on the computer usb and found out it was "blocked"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:32</div><div class="msg">Yeah you might have triggered some security measures, but to have such measures on NFC interface and in OP_READY is a design flaw </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:33</div><div class="msg">Because NFC connection in the real world is not so stable, it can happen to need several attempts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:35</div><div class="msg">I mean, the only way to get an answer is to send them as much info as possible and the cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:35</div><div class="msg">yes of course</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:35</div><div class="msg">I'm trying to see if I can find more</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:35</div><div class="msg">Yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:35</div><div class="msg">In any case, if you muted the card, it is a bug in the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:36</div><div class="msg">ok so maybe we can start asking why and when it can be muted? just to start a conversation @guylouis</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:42</div><div class="msg">We also need to check in parallel if we can get NXP 3.0.4 samples already</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:44</div><div class="msg">Because I am afraid this will be a major issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:45</div><div class="msg">ok I could reproduce it and I have the logs. now I don't know what to do though, because I have only other 2 cards.
|
|
the logs are basically:
|
|
- sending command select
|
|
- sending command init update
|
|
- sending command external auth
|
|
- sending command delete
|
|
- remove card from phone, so a "tag lost" is thrown</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:45</div><div class="msg">now trying again the installation is disconnecting after sending `00A4040000`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:46</div><div class="msg">and gpj says `Could not connect to ACS ACR 38U-CCID: SCARD_E_NO_SMARTCARD`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:46</div><div class="msg">Wow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:47</div><div class="msg">They are probably not handling transactions very well and then on next select the ISD detects inconsistency in the registry and mutes the cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:47</div><div class="msg">and in fact, last week I lost the connection thousands of times, but never during a `remove` command because it wasn't implemented. and I never had this problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:47</div><div class="msg">But that's a very good report</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:48</div><div class="msg">/kudos @andreaf for finding a bug in the ACS card before we ordered thousands :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:51</div><div class="msg">another strange things. with 2 cards I'm always able to install in 14/15 seconds. with another one, always around 110 seconds</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:54</div><div class="msg">Wow that's an order of magnitude </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:54</div><div class="msg">Is a particular APDU taking longer? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:54</div><div class="msg">Or the entire sequence? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:55</div><div class="msg">normally each "load" command of the file upload is super quick except for the 24th. with that card (now blocked), each one was taking at least one second</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:56</div><div class="msg">24th is the last? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:56</div><div class="msg">no they are 31</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 15:57</div><div class="msg">I don't know if after that one it does something specific</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:58</div><div class="msg">No idea, it might be the end of a cap component and the other parts might contain the ancillary components and after each full component it commits something to flash</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 15:59</div><div class="msg">Because the cap file consists of several components, the main one being the program code of course </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:02</div><div class="msg">it might also be my phone. now the same cards that took 15 seconds is taking 100</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:06</div><div class="msg">Mm we definitely need another card to check </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 16:07</div><div class="msg">I will get 5 JCOP card from NXP</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 16:08</div><div class="msg">but it might take some days, so maybe we can buy some JCOP card directly from the internet. Let me check if there are any sellers online.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:08</div><div class="msg">The newest JCOP I have found online were 3.0.1</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:08</div><div class="msg">And this misses some of the methods we are using</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:09</div><div class="msg">> Mm we definitely need another card to check
|
|
do you mean another model just to compare ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:09</div><div class="msg">Yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:10</div><div class="msg">Because we need to see if these issues are to be attributed to the phone or the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-10 16:10</div><div class="msg">And also I really want to measure performance on NXP and discover that 4,8 seconds login was a bad dream and it never happened :joy: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 16:12</div><div class="msg">ok, so I'll ask to my contact in NXP to speed up sending the 5 cards with 3.0.4 and also tell us if there is any place where we can order more</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:35</div><div class="msg">@guylouis are we going to contact ACS for this error? if you want here there you can find the log: <a href="https://gist.github.com/pilu/317b8ff6bf83de15f71079f7e8566b75">https://gist.github.com/pilu/317b8ff6bf83de15f71079f7e8566b75</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:35</div><div class="msg">with some comments</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 16:36</div><div class="msg">yes, I'll contact them tonight, thanks a lot for the log</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:37</div><div class="msg">cool! I'll be on holiday tomorrow but I'll try to read here if you need something feel free to write me!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:37</div><div class="msg">can you put me in CC please?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 16:37</div><div class="msg">it would be interesting to read their comments</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 16:48</div><div class="msg">@patrick771 @corey122 @obi @micheleb @ned @denis-sharypin
|
|
We have to decide if hardwallet lite packaging is tamperproof or not. This choice needs to be done now since @ned is currently designing the packaging. I have summarized in the doc below some considerations for this choice. It should be driven mostly by the security level we actually provide but also the whole user experience to understand the level of security he's getting.
|
|
Please provide your feedback either in the slack or the doc directly !
|
|
<a href="https://docs.google.com/document/d/1QY0S4cPdrWN0LPPh2K6oA5XYEqcDcFhrhRP1oJf7L-k/edit?usp=sharing">https://docs.google.com/document/d/1QY0S4cPdrWN0LPPh2K6oA5XYEqcDcFhrhRP1oJf7L-k/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-10 16:51</div><div class="msg">:heavy_check_mark: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 17:06</div><div class="msg">is the following ok/clear for you two ?
|
|
"We have had two cases of ACOSJ card that got muted in a strange manner, the message we get is the following : "Could not connect to ACS ACR 38U-CCID: SCARD_E_NO_SMARTCARD � which is different from other blocked cards that return 0x69825 (Security condition not satisfied).
|
|
|
|
Find here a log of what we did (we just reproduced it following this exact chain of commands, and blocked the card). Please note we use NFC interface here with an android phone.
|
|
|
|
<a href="https://gist.github.com/pilu/317b8ff6bf83de15f71079f7e8566b75">https://gist.github.com/pilu/317b8ff6bf83de15f71079f7e8566b75</a>
|
|
|
|
Can you please provide your insight about this ?
|
|
Are there specific counter measures we should know about that can mute ACOSJ card ?
|
|
Is there any specific procedure we can try to unmute card ?
|
|
Should we send the cards to you for evaluation of their state ?
|
|
"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-10 17:24</div><div class="msg">I'm fine with the lack of a tamperproof seal because we do not depend on it. It is there only as an additional level of perceived security, and not actual security. All other reasoning as well, but mostly that.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-10 17:31</div><div class="msg">well I sent it - if you have further questions, let me know I'll send them too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 17:39</div><div class="msg">I think it's good!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 21:50</div><div class="msg">@micheleb I found out that on my p10 the NFC reader must be at the very top of the phone. If I put the card chip at the top of the phone I can move it a lot and even leave it almost 1cm from the card without losing connection. But I think this would be different on each device /cc @guylouis @denis-sharypin </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-10 22:25</div><div class="msg">yeah I can confirm I can install it without putting card and phone on the table. If I take the chip at the top of the phone I can easily install it even if I move it, leaving the card at 0.5cm from the phone. And installation took 15 seconds </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 05:53</div><div class="msg">@andreaf mine is also at the top (OnePlus 6), near the cameras</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 05:56</div><div class="msg">I have read the document now. I am also for option 2. The only thing we might want to formulate differently, is the phrase about the authenticity is checked...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 05:57</div><div class="msg">because what we actually do is not check authenticity of the card itself. We just personalize it on the client side and then make it impossible to have further personalization</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 05:58</div><div class="msg">I would not want someone taking our phrasing too literally and than claim we lied. We do not have a signature/hash/checksum to match against.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 07:20</div><div class="msg">@andreaf @guylouis I have tried the applet installation and performance tests again with the latest changes to the installer app. The connection is much more stable than it used to be, but connection is still lost some times. Performance tests with logging and debugging disabled are indeed faster, 6,5s and 3,8s respectively. Not a huge difference but still worth noting.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 07:25</div><div class="msg">ok thanks for the update !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-11 07:45</div><div class="msg">Do you need to push some button to turn on the nfc? Or it works on the background all the time?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 07:45</div><div class="msg">I will add other measurements today so that we have a full understanding of what we can expect</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 07:52</div><div class="msg">Very interesting thanks. From a ux point of view, what we should try to assess is if it works with most phones (independently from where the nfc chip is actually) when card is left under the phone centered. Let's keep that as hypothesis, if we see performances with some phones are not good like this, we will have to add an extra message to the user explaining him to check if it works better with card near its nfc reader (but it's a pain because it depends on his phone model ....)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:15</div><div class="msg">I have measured it, 816ms so under 1 second</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 08:23</div><div class="msg">ACS answer : "Please ask try to delete through contact interface by ACR38 (not by NFC phone) and see if same problem occurs.
|
|
|
|
Also, you can send us ?53746174757357616C6C6574?cap file to test Install and Delete from our end?"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:24</div><div class="msg">the problem is that we cannot simulate card tearing on the contacted interface with a regular PC/SC reader. The problem is about the card losing power during DELETE</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:25</div><div class="msg">I mean manually extracting the card at the right time requires too much coordination :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:27</div><div class="msg">we can send them the cap file and stress on the fact that the issue happens when the card loses power during a DELETE operation... maybe they have terminals where they can control Vcc independently</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-11 08:29</div><div class="msg">:star-struck: thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:31</div><div class="msg">@guylouis on another note: I have measured some parameters, I think the most interesting result is that OPEN SECURE CHANNEL (which is needed for all other commands) takes 630ms. This means 630ms is the baseline for any our commands. I think a big role is played by the first step of OPEN SECURE CHANNEL which uses EC-DH to add some randomness to the generated session keys. In theory, we could do without that step since we do pairing (the very first version had no pairing so EC-DH was needed for confidentiality, but there was no authentication)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:31</div><div class="msg">that is something that should be discussed in the context of the security audit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 08:33</div><div class="msg">ok clear, do we have the cap fie ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:36</div><div class="msg">the cap file is the regular wallet.cap</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:36</div><div class="msg">they said this name because it is the package AID and they do not know how we named the file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-11 08:36</div><div class="msg">:point_up_2: maybe you know @guylouis</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:37</div><div class="msg">if you do not have it, it is here: <a href="https://github.com/status-im/smartcard-cap-installer-test/tree/master/app/src/main/assets">https://github.com/status-im/smartcard-cap-installer-test/tree/master/app/src/main/assets</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 08:38</div><div class="msg">It's android system level setting, it's either disable (in this case we will need to ask the user to go himself turn it on, once for all)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 08:38</div><div class="msg">or it's enable and then it's in background all the time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-11 08:38</div><div class="msg">okay got it thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 08:48</div><div class="msg">If we do not use ec-dh : do we need to change applet software or is that already an option ? have you got any idea how much ms we would gain (we can find this out later) ? any idea on how we can quantify the security downside ? yes let's discuss that with security auditor ....</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:50</div><div class="msg">we have to change the applet for sure. I cannot measure the improvements without modifying the applet or writing an applet that only this and measure the time it takes. But I think it will be quite large, since the only other time-expensive thing being done there is calculating SHA-512</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 08:51</div><div class="msg">so I think we can cut the time to half... about security implications. From my point of view, it wouldn't compromise anything, but I would really like to get a second opinion on this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-11 09:24</div><div class="msg">@micheleb I used to lose the connection often until I discovered a position where I can move a lot and I never lose it. In fact now I'm able to run the installation keeping everything in my hand instead of leaving them on the table. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-11 09:28</div><div class="msg">I used to keep the card under the phone in the middle and connection was always lost. If I keep the card at the very top it works very good</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 10:04</div><div class="msg">@micheleb @naghdy So I finally managed to get Matthew Ferrante on the phone (Zklab, security audit for the applet code). He said he's been really busy in the past weeks and that's why he did not came back to us. However one of his auditor has been auditing the code, and they plan to provide a security report end of this week. I am a bit surprised they had no question to us about the code to run the audit, but let's see what they come up with. Do you guys know if there was any meeting report, or document they shared with us before starting that would state the scope of what they would audit ? Just would like to make sure they deliver what we scoped them and paid them for.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 10:24</div><div class="msg">good to hear we will have a report. I am also very surprised they had no questions at all... I mean, I have documented everything, but there are always some unclear points</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 11:31</div><div class="msg">sourcing update : JCOP NXP card is getting more & more interesting : NXP confirmed this morning it supports KeyAgreement.ALG_EC_SVDP_DH_PLAIN_XY !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 11:31</div><div class="msg">:grinning:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-11 11:31</div><div class="msg">Wow! </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 11:31</div><div class="msg">I will now get in touch with two european factories that personalize JCOP cards. I hope their price will not be too high.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 11:32</div><div class="msg">one is in France, the other in Austria</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-11 11:39</div><div class="msg">@guylouis if you need me to pick anything up personally or shepherd things with the company in austria, i'm in vienna to help you expedite anything!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 11:41</div><div class="msg">:+1::thanks::flag-at:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 12:38</div><div class="msg">Hi swarm team @micheleb @goranjovic @dmitryn @andreaf @patrick771 @denis-sharypin @obi I guess we should set-up a weekly stand up for the hardwallet lite integration work. The goal is to remain in sync on where the swarm stands. I suggest that this weekly goes through 1st/a quick update from everyone on where he stands 2nd/items to dicuss (listed and shared as much as possible before the call).
|
|
|
|
I did set-it up for Tuesdays at 11:00am CEST, and sent an invite. If this is a blocker for any of you, let me know, I'll move it (and make some fun little surveys :slightly_smiling_face: )
|
|
|
|
Next one is Tuesday 18/09</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 12:43</div><div class="msg">we'll get 20 from them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-11 12:43</div><div class="msg">might take a couple of days though, even probably next week ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-11 15:51</div><div class="msg">thanks for the update. I haven't seen a doc myself. If you think there is a need for me to go visit him in person, just let me know</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-12 04:35</div><div class="msg">I met someone at ETHIS who was quite knowledgable and experienced about HW wallets and Crypto. They might be able to help out with Pro version, etc. Who should I introduce them to? @micheleb or @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-12 05:02</div><div class="msg">There was another guy Marco who seems like a possible HW partner. Unfortunately I forgot exactly where he was working or what he was offering :sweat_smile: but the conversation was good and he seemed to have something in the HW department, both HW wallet and Nimbus. I have his WeChat right now - either if we have a specific ask re e.g. HW pro stuff I can send this, or I can intro him to @micheleb @guylouis or someone else.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-12 06:47</div><div class="msg">I'll be happy to have discussion with both to see if we have synergies</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 06:48</div><div class="msg">I can also join the discussion</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 07:07</div><div class="msg">can we also plan an audit for the final code that we will use to interact with the javacard? like the installer/initializer and the part that we'll use to sign data?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-12 07:10</div><div class="msg">This would definitely make sense ! cc @corey122
|
|
I tend to think we should do that when we will be feature complete on a first beta version, since security will be seen as a whole on the full integration of the javacard.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 08:22</div><div class="msg">@micheleb today during a test installation I had a response 0x6985 "Conditions of use not satisfied". when does this happen usually?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 08:24</div><div class="msg">you need to delete the applet most likely</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 08:24</div><div class="msg">6985 is very frequent... but usually it means you forgot a step :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 08:25</div><div class="msg">ah ok!! cool thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 08:28</div><div class="msg">example installation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 08:29</div><div class="msg">I uploaded a video where I install the applet moving the card. just to show you what I meant yesterday. that's the only position where I can move the card. if I keep the card on the back of the phone, it loses the connection if I move it even a little bit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 08:30</div><div class="msg">ok, I think this is going to change on each phone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 08:31</div><div class="msg">yeah :disappointed: I think it will be difficult to explain to users</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 08:31</div><div class="msg">"you are holding it wrong" is already an Apple's trademark :joy:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 12:04</div><div class="msg">@guylouis I saw their reply, the card I have is this one:
|
|
<a href="https://www.smartcardfocus.com/shop/ilp/id~790/acosj-dual-interface-java-card/p/index.shtml">https://www.smartcardfocus.com/shop/ilp/id~790/acosj-dual-interface-java-card/p/index.shtml</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 15:17</div><div class="msg">@micheleb I added the puk/pairing generation to the installer. what do you think about using something like base58 so that we don't have similar characters? I had an uppercase i and lowercase L and I couldn't understand what was the real password</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 15:46</div><div class="msg">Yeah the algorithm for the password generation is not fixed at all</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 15:47</div><div class="msg">I only fixed the PBKDF2 algo, but how the password is generated must be changed </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 15:47</div><div class="msg">I would prefer a word-based password or passphrase</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-12 15:47</div><div class="msg">I have done it this way in the script just to have it done quickly </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-12 15:48</div><div class="msg">ah ok cool! yeah for me it's the same, I just noticed that and for now I used the same implementation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 08:15</div><div class="msg">well they are really good, received them this morning already.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 08:16</div><div class="msg">@micheleb@andreaf How many shoud I send to you and can you send me (mp maybe) the adresses I should use ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 08:16</div><div class="msg">I have received 20</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 08:27</div><div class="msg">as many as you want :slightly_smiling_face: what do you think about 5? just because I know I'll block a couple in the testing. actually, shall I try the same "bug" we had with the other one?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 08:36</div><div class="msg">ok I got your two adresses, I'll ship them this afternoon or max tomorrow morning in express</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 08:37</div><div class="msg">awesome thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 08:37</div><div class="msg">@micheleb as far as I know these have the same spec. is it correct? also for the future, would the installer code always work or depending on the card we might need changes?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 09:04</div><div class="msg">It should always work </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 09:16</div><div class="msg">the card should support unassisted key derivation (ec point multiplication) so that should greatly improve performance... but for installation it makes no difference</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 09:27</div><div class="msg">There have been some discussion initiated by @patrick771 in the google doc above, and we might not even need to put a paper to explain why there is no seal. Let's decide on that, and if we put a paper, then we will work on the good content.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 09:31</div><div class="msg">I think a paper explaining that this card comes with no PUK and pairing code and that it will be generated on first install wouldn't hurt... usually cards are shipped with a PIN (ok, that is shipped separately, but still)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 09:31</div><div class="msg">but the explaination of why there is no seal is redundant I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 12:17</div><div class="msg">@guylouis now that the installer works, I think we can use it for UX and performance testing before integrating it with status-react. and also it would be interesting to start using the go-ethereum branch for status desktop, because the usb connection with the card already works. do you @patrick771 and @denis-sharypin have a javacard? I think it would be interesting for you to start playing with it. (it's a good idea to buy a usb reader too, so that you can run "dangerous" commands from there).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-13 13:09</div><div class="msg">I have one USB reader and one ACS card so I'm good to go. @denis-sharypin I can ask Rajanie to send one ACS card to you, ok for you ? as per the USB reader, if you need one, maybe the easiest would be to buyit online. I ordered mine on amazon. <a href="https://amzn.to/2xfThsC">https://amzn.to/2xfThsC</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 13:10</div><div class="msg">yes that's the same I bought!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 13:11</div><div class="msg">Sure, sounds good!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-13 15:03</div><div class="msg">Hey, apologies I've been traveling most of the day today. I'd love to try it out and have a friend with a USB reader. Are there any spare ACS cards? Am also fine to try it out after someone else has.
|
|
|
|
Also, I was planning to run user tests towards the end of next week in Zurich but can also postpone or change up the study style if we are close to a working demo. That would be preferable to requiring faking the pairing actions, etc. in a study. Either method is fine but was just curious about the time line.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 15:05</div><div class="msg">hey @patrick771 I don't know yet about the final integration with status and signing transaction, maybe we need to talk also with @dmitryn and @goranjovic, but for now we can start testing the initialization/installation of the card. which is maybe the most difficult because it takes a lot of times where the user should keep the card without moving it too much etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-13 15:10</div><div class="msg">@denis-sharypin, @dmitryn or @goranjovic any guesses as to how long it might take to start building a UI for initialization/installation? Again, no pressure as we can figure out another way to user test. Just thought it might be interesting to do with a real card + installer.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-24/320320314756_fe0f3ce0bb820f1aa8e3_72.jpg" /><div class="message"><div class="username">dmitryn</div><div class="time">2018-09-13 15:11</div><div class="msg">Integration with status-react is not started yet. But i saw @andreaf has sample android app where you can try card pairing/installation
|
|
upd: <a href="https://status-im.slack.com/archives/C813TET52/p1536740894000100">https://status-im.slack.com/archives/C813TET52/p1536740894000100</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 15:12</div><div class="msg">From the design side this part is ready to be implemented. But it may require some iterations in the future</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 15:19</div><div class="msg">Also a quick update on it. So a card can be in a different state to application at any moment of time. It could be
|
|
? completely blank
|
|
? could have an applet but no paired
|
|
? already has a Status account on it
|
|
And to decide what path to show to a user I created such flow.
|
|
Does it make sense?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 15:32</div><div class="msg">I think it can also be paired but without account yet, does it make sense?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 15:33</div><div class="msg">in case pairing started but the account has not been created yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 15:36</div><div class="msg">I think so, good catch!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-13 15:50</div><div class="msg">@andreaf in the event say that you?ve ordered the hardware wallet and have just downloaded Status app and haven't created an account?
|
|
|
|
@denis-sharypin were you thinking of including the color-coded messages e.g. `Card is blank` or is this just to clarify the designs were looking at? If the ladder then the only thing I'd say is we could consider keeping these messages a neutral color, maybe?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 15:52</div><div class="msg">@patrick771 yep I considered to make them colorful but yeah it doesn?t make sense actually. Good idea, thanks!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 15:52</div><div class="msg">> @andreaf in the event say that you?ve ordered the hardware wallet and have just downloaded Status app and haven't created an account?
|
|
|
|
"paired but without account yet" state can be when user enters the pairing code and then "remove" the card without creating or importing an account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-13 15:53</div><div class="msg">@patrick771 ^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-13 15:56</div><div class="msg">@denis-sharypin sorry, meant the ?former? not the ?ladder?. I.e. if it's user -facing. Was just thinking that `Card is blank` in bright green was a bit of a mismatch in expectations.
|
|
|
|
@andreaf ah, got it!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-13 15:57</div><div class="msg">@patrick771 yeah completely agree on that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 18:27</div><div class="msg">I think there is a distinction to make: paired does not mean that there is an account, it only means that you paired the card with the device. Up to 5 devices can be paired at the same time, so the last message should only be shown if all pairing slots are full (conveniently, the SELECT command already gives the number of free slots)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 18:28</div><div class="msg">also the suggestion would be to unpair one device to further pair with this device</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-13 18:29</div><div class="msg">if the card already has an account that the device is not aware of then maybe it should give a warning with the ability to confirm that they want to use that account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 07:31</div><div class="msg">@micheleb @naghdy some thoughs on hwallet security audit with zk labs. Since:
|
|
- our feeling is that the security of the javacard applet only (what we have now) is quite clear and robust (even though, of course, they can find some issues, and we need an external audit in any case)
|
|
- we will have to audit in any way the client side also,
|
|
- the scope of the audit with zk labs is unclear (nothing written down, from any side)
|
|
- we're paying a good amount of money for this audit (50k$)
|
|
I propose that I push zk labs to also include the client side audit in the service they will provide. They might not accept, and be reluctant to it but I will try, and I think it would be overall quite fair. Are you ok with that ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-14 07:33</div><div class="msg">`Up to 5 devices can be paired at the same time` but all of these devices have the same Status account on it. Is it correct?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 07:33</div><div class="msg">@guylouis of course it would make sense from my point of view, the only problem is that we do not have an implementation yet... Although it is taking so long that maybe we will have one by the time they finish audit on the applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 07:34</div><div class="msg">Yes, correct </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 07:36</div><div class="msg">The concept of pairing and account are separate. Pairing only allows establishing a secure channel with MITM protection and mutual authentication that the counterpart is one of those you are supposed to communicate with </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 07:36</div><div class="msg">So the card can refuse talking to an unauthorized device and the device refuses to talk to an unauthorized card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 07:37</div><div class="msg">:100: Ideally they could deliver their conclusion on the applet side short term (Mathew told me they would in the coming days, eventhough I have some doubts) and when we have a client side integration they will complete the audit with the client side part.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 08:03</div><div class="msg">do we have a decision about the database/whisper keys?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 08:03</div><div class="msg">I would like to deliver the modified applet while it is still being audited</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-14 08:19</div><div class="msg">probably worth checking with @corey122 if you haven't already</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-14 08:44</div><div class="msg">Agree that we should ask for that as well. Please loop in Corey as Oskar mentioned</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:04</div><div class="msg">after some discussion with Michele to clarify things and be inline :
|
|
- for your second screen (this screen is the case where a card is presented that has an account, and is not paired with the current device), then we should mention that we will provide a warning message if the slots are full (either on device or card). Wanring message to be written, we can discuss the exact text in a separate discussion.
|
|
- for the third screen, this one is for a card that has an account and is paired with the device. So you are right to tell the user to login to his account, but he shouldn'"t unpair (as written in the message) since he's already paired.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:24</div><div class="msg">Following the discussion on the flows, I draw what I think are the only states of a card in its life time with regards to: an applet is loaded (y/n), the card is paired (y/n), an account is loaded (y/n), and the only possible transition behind those states. These 4 states are what a user can perceive of its card (well apart from bricked after false PINS and false PUK), and there's actually a real question of how we name them, and how call the transition.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:26</div><div class="msg">another remark, when account=no then pin is 0000, when account=yes then pin is <>0000</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 09:32</div><div class="msg">@micheleb I have a question again about the keys derivation on the card. why switching from `m/44?/60?/0?/0/0` to `m/44?/60?/0?/0/X` is faster then a complete different path with the same depth? I understand deriving a child is faster, but I thought deriving a sibling is the same as deriving from scratch</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 09:33</div><div class="msg">@guylouis is nice to have a flowchart to make this clear. There are few things to clarify imho
|
|
|
|
1) Changing account does not pass for the "INITIALIZED" state, the keys are replaced with new ones, but there is no explicit delete command
|
|
2) Between OUT OF FACTORY and INITIALIZED, there is the state in which the applet is loaded but the globalplatform keys have not been changed yet. Of course, this state only appears if connection is lost at the wrong time, but still it exists
|
|
3) what do you mean about ACCOUNT LOADED + NOT PAIRED with "account: NO"? Do you mean that the device is not aware of the account which is stored on card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:34</div><div class="msg">3/ : is a typo, let me correct it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 09:34</div><div class="msg">@andreaf because the applet keeps the master key, the current key and the parent of the current key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 09:34</div><div class="msg">so the parent is already there :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 09:34</div><div class="msg">ah ok, I didn't know about the parent! :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 09:34</div><div class="msg">ok it makes sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 09:34</div><div class="msg">yeah I forgot I had added that optimization. Is a minimalistic cache.. I thought it made sense because accounts would most likely all be at the same depth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:45</div><div class="msg">so 3 -> corrected
|
|
2-> 100%. I'll add a remark, but in any case this state will not really be seen by the user.
|
|
1-> ok. Let me propose a new version. By the way, I guess the use should be able to reset it's card and make it free of any account also, I'll add it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 09:49</div><div class="msg">We need to modify the applet to remove the account and revert to uninitialized state. Do we really need it? To resell the wallet or what other reason? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 09:58</div><div class="msg">understood. let's loop in @patrick771 @corey122, even though the secrets are really secure in the javacard, I thought that the user might want to have the possibility to wipe everything from the card at some point, just so that he'll be sure that his secrets have disappeared from the card, and not providing him this possibility could be frustrating. What do you think ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 10:00</div><div class="msg">cc @denis-sharypin too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 13:53</div><div class="msg">@andreaf I have a card and a android phone, where should I start to play around with installation of our card ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-14 14:24</div><div class="msg">Got the card! Thanks to @rajanie. What?s next?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 14:24</div><div class="msg">@andreaf could you guide us to how we can test the init. with the cards and a android phone ? Thanks so much !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 14:25</div><div class="msg">awesome! yes give me half an hour, I'm in the #282-deterministic meeting. after that I'll create an apk you can download and I'll tell you how to do it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 14:29</div><div class="msg">@guylouis @denis-sharypin do you also have the usb reader? just for one reason. I removed the `delete` command from the android app because it mutes the card if the connection is lost before the ned of the command. this means you can install it just once. from usb, where you don't lose connection easily, you can delete the applet to be able to install it again</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-14 14:35</div><div class="msg">Ah, I ordered it yesterday. I will get it next week.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 14:35</div><div class="msg">ok so I can still prepare a build but then you'll be able to try it just once :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 14:36</div><div class="msg">we are still waiting for their reply about what we think can be a bug on the delete command. they didn't reply yet right @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 14:47</div><div class="msg">yes: no answer from them yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 14:48</div><div class="msg">I have a usb reader already</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 14:48</div><div class="msg">perfect! so better if you try it first, so that if something doesn't work, you can use another tool just to fix it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 15:21</div><div class="msg">ok I can create an apk or you can download the source code and compile it.
|
|
I need to be afk a couple of hours so I can prepare it later or in the WE and I'll write more documentation on how to use it if it's ok for you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 15:22</div><div class="msg">I also started today the go part, so that we can play with the test android app to understand more things about UX and maybe start using it in desktop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 15:23</div><div class="msg">great - I'd rather wait. I haven't compiled anything for a very long time :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 15:23</div><div class="msg">:slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-14 16:43</div><div class="msg">@oskarth what would you suggest ? should we consider this point closed and go further with @micheleb's suggested paths (there was a discuss thread where everyone could voice concerns) or should it be discussed at devs meeting on monday ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 16:53</div><div class="msg">@micheleb with the acosj the first command I send is an empty select to get the aid of the card manager. I use a cla 0x00. I see the jcop3 tells me the class is not supported. Should I always use 0x80?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 16:54</div><div class="msg">I like the background</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 16:57</div><div class="msg">No, select is with cla 00 </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 16:58</div><div class="msg">You could try 80 I guess but that contradicts the ISO7816?4 specs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-14 16:59</div><div class="msg">Try gpj shell first to check what is says</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 19:19</div><div class="msg">with gpj it says the same (command sent: `00a4040000`): `Could not SELECT default selected: 0x6D00 (Invalid INStruction)`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-14 19:21</div><div class="msg">also with our python script</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-15 06:43</div><div class="msg">@andreaf that's very strange. Try selecting expliclity A000000003000000 or A0000001510000.. it must work with one of these</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-15 06:43</div><div class="msg">the second is most likely if the card GP2.2.1</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-15 06:47</div><div class="msg">or you could omit the SELECT command altogether, the ISD is most likely already selected on reset</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-15 06:50</div><div class="msg">the strange error message is because SELECT is dispatched a little differently to other commands. SELECT is first processed by the JCRE, if it finds a match it performs the SELECT of the application. If it does not find a match it forwards the command to the currently active application, which might not have an internal SELECT command (like the Global Platform ISD) and then you get invalid INS. Some applications (like GSM and UICC) have internal SELECT command because they have a sort of filesystem and you can SELECT file. That's the reason of the strange dispatch mechanism</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-15 17:18</div><div class="msg">I tried skipping the select command and it still has the same error. I also tried changing the code in gpj and it's the same. I'll try later selecting the aid you said but as I understand the error is in the cla isn't it? Are you also going to receive the same card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-15 17:19</div><div class="msg">6D00 is invalid INS, not CLA (that would be 6E00). Yes I am going to receive the same card. I am afraid we have been sent "unfused" card (a JCOP specific thing) without the instructions to "fuse" them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-15 17:22</div><div class="msg">Ah right, I think I read the class not supported message but it was a different error code </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 08:46</div><div class="msg">I tried both but I still have the same error :disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-17 08:47</div><div class="msg">cc @guylouis. On the card there should be some markings. Try to use some of those number (those compatible with hexadecimal encoding) as AID. If that works, it means we have an unfused card and the transport key is printed on the card itself</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 08:48</div><div class="msg">ok let me see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-17 08:48</div><div class="msg">but even if you manage to do this, it does not help us very much because the "fusing" commands are proprietary and I do not have the manual :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-17 08:48</div><div class="msg">but at least we know what is wrong</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-17 09:09</div><div class="msg">I am asking to NXP now how about to 'unfuse' the cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 10:35</div><div class="msg">I added an apk in the release section of the repo:
|
|
|
|
<a href="https://github.com/status-im/smartcard-cap-installer-test/releases">https://github.com/status-im/smartcard-cap-installer-test/releases</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:22</div><div class="msg">I'll be afk for 2/3 hours</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-17 13:22</div><div class="msg">got my card reader btw today!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:24</div><div class="msg">nice! the first thing you can do is trying it with the java implementation of globalplatform</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:25</div><div class="msg">you can download it from here:
|
|
<a href="https://sourceforge.net/projects/gpj/">https://sourceforge.net/projects/gpj/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:25</div><div class="msg">you need to have java installed but maybe you already have it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:25</div><div class="msg">afterdownload it you should have a globalplatformpro.jar file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:27</div><div class="msg">actually gpj.jar</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:28</div><div class="msg">and you can run it from your terminal with:
|
|
|
|
`java -jar gpj.jar -list`
|
|
|
|
you need the card in your reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:28</div><div class="msg">that's just to see if you get errors from the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-17 13:29</div><div class="msg">after that you can try the android app</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-17 16:38</div><div class="msg">Hey team ! here's the weekly sync doc where you can add items to the agenda. Talk to you tomorrow at 11:00 am CEST !
|
|
|
|
<a href="https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit#">https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-17 16:38</div><div class="msg">Just a posting a usability study plan here for broadcasting and any feedback / comments / questions: <a href="https://docs.google.com/document/d/1ZpgpAYfHC57iEvalLMhpjOJPkfzLvjx309lBdjAlDjg/edit#">https://docs.google.com/document/d/1ZpgpAYfHC57iEvalLMhpjOJPkfzLvjx309lBdjAlDjg/edit#</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-17 17:01</div><div class="msg">I'm not happy with signing a contract of such a size with someone without a properly written scope. We should ask for that, as well as what @guylouis wants.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-17 17:01</div><div class="msg">also for some reason I didn't get this ping from @oskarth when he sent it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-17 17:20</div><div class="msg">:100: I asked Matthew to write down the scope too. I will call Matthew again tomorrow. I guess that if we don't have a clear answer from them (what's the scope ? what's the status and planning ?) this week we can consider we have an issue with them, and change strategy (to be discussed).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-17 21:43</div><div class="msg">Thanks @patrick771 that's really usefull. I added your main point about UX evaluation to tomorrow agenda : "To be decided : use static prototype (InVision) + fake card vs. early version of app + HW lite card"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-18 08:34</div><div class="msg">I have made the changes to EXPORT KEY. @andreaf I have also updated the wallet.cap file in the installer android app</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 08:34</div><div class="msg">awesome, thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 08:35</div><div class="msg">I saw the email from jcop, how does it work with these cards then?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-18 08:36</div><div class="msg">I still have to receive the docs and keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-18 08:37</div><div class="msg">but they indeed require to be initialized once. Note that this is not how we will receive the blank cards from distributor, from distributor they must come exactly as they came from ACS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-18 08:38</div><div class="msg">which is regular OP_READY state. No idea why they have a pre-OP_READY state, most likely to set some security switches and/or decide what AID we want for the ISD etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 10:15</div><div class="msg">added notes for today's meeting. Please amend/comment if needed !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 11:07</div><div class="msg">installation thread @denis-sharypin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 11:07</div><div class="msg">can you try downloading this gp.jar file? <a href="https://github.com/martinpaljak/GlobalPlatformPro/releases">https://github.com/martinpaljak/GlobalPlatformPro/releases</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-18 11:10</div><div class="msg">done, what?s next</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 11:10</div><div class="msg">if you open your terminal you should be able to check what is installed on the card:
|
|
|
|
`java -jar gp.jar -list`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 11:11</div><div class="msg">and you can delete the applet with:
|
|
|
|
`java -jar gp.jar -delete 53746174757357616C6C6574`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 11:11</div><div class="msg">so after that you can install it again from the phone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-18 11:44</div><div class="msg">@guylouis fyi
|
|
<a href="https://status-im.slack.com/archives/CAQSU50CQ/p1537268417000100">https://status-im.slack.com/archives/CAQSU50CQ/p1537268417000100</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:42</div><div class="msg">@denis-sharypin managed to install the applet in 10 seconds, which sounds good. I'm going to add an option to remove some logs to see if it can be faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-18 12:44</div><div class="msg">it's great that it is not 1-2 minutes as was mentioned before. Now not a big deal for user to wait</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 12:51</div><div class="msg">10 seconds to upload the applet in the javacard through nfc ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:51</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:52</div><div class="msg">I usually have around 15 seconds</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 12:52</div><div class="msg">with which card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:52</div><div class="msg">acosj</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:52</div><div class="msg">I guess...the one sent from Jarrad</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-18 12:52</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 12:54</div><div class="msg">that sounds very good ! there is some more time needed I imagine for the rest of the operations (open secure channel, pairing ...) but this is really encouraging</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 12:55</div><div class="msg">yes, but the can be different steps. in this 10 seconds connections cannot be lost. but then between this and the pairing the card can lose connection. they are kind of different "sessions"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:06</div><div class="msg">hey swarm team : do any of you plan to participate to the sharding event ? would be great to spend one hour together while in Prague on monday morning to have our weekly sync. face to face.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 13:08</div><div class="msg">are you staying other days? I'm staying until the 2nd of october. at the beginning we were saying during devcon we could have had team meetings, but I don't know if you are all staying more days</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:08</div><div class="msg">leaving tuesday morning early ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:18</div><div class="msg">I like it too, it could even be on the same paper where we leave some space for the user to write down his PUK and pairing, e.g on the front side an explanation (something like - of course can be made better ! - : "your card comes blank, at first set-up it will be uploaded with its unique secrets, it will happen once in the life of your card, and you need to write securely here "</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:19</div><div class="msg">So I propose that to move forward and let Alex progress on the packaging that we suppose we have :
|
|
- no seal
|
|
- one welcome paper (content to be defined)
|
|
- one paper with some indication about security and some space to write PUK and Pairing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:21</div><div class="msg">@patrick771 is it ok for you ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-18 13:25</div><div class="msg">ok we can do it on monday then!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:30</div><div class="msg">le me put something in the team agenda, and if it does not work, we'll figure something out</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-18 13:31</div><div class="msg">Yes, sounds good. Would push to have it all one piece of paper if possible :slightly_smiling_face: Looking at the Ledger Nano S paper now and they?ve printed on front and back. cc? @obi so she is aware of this thread when she returns.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 13:36</div><div class="msg">@denis-sharypin suggested we in fact set-up a "live" review of the UI flow. Indeed that could be very efficient. I think we need at least @denis-sharypin @patrick771 @micheleb, all other members of the swarm more than welcome of course. :slightly_smiling_face: Would tomorrow 4:30pm CEST work for you guys ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-18 13:44</div><div class="msg">tomorrow is fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-18 13:55</div><div class="msg">Have two other meeting conflicts from 4-5 pm but can join later.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-18 14:03</div><div class="msg">I'll move it to 5pm, so it might make things easier for you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-18 14:34</div><div class="msg">Sorry, thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 07:31</div><div class="msg">One scenario to investigate : user taps status javacard on its mobile when status app is in background. I am thinking about this since Apple just opened *background* nfc *reading* and redirect tags info to a specific app. Would be good if tapping the card on the mobile does the following
|
|
1/ if status app is not downloaded -> propose the user to download app in the app store
|
|
2/ if status app is already here, go to login screen and ask for PIN
|
|
@dmitryn do you think it's possible ? I found the following doc <a href="https://developer.android.com/guide/topics/connectivity/nfc/advanced-nfc">https://developer.android.com/guide/topics/connectivity/nfc/advanced-nfc</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 07:32</div><div class="msg">Must the card be seen as a NFC tag ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 07:32</div><div class="msg">@micheleb for this and also for the iOS case (see : <a href="https://developer.apple.com/videos/play/tech-talks/702/">https://developer.apple.com/videos/play/tech-talks/702/</a>) is it possible that our card is also seen as a NFC tag ? (iOS seems to necessarily process the NDEF message from a tag)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 08:30</div><div class="msg">*udate manufacturing SELP factory* / had a call yesterday with SELP, french factory that manufactures card with NXP chips. Briefed them about our need. They are quite professional it seems, understood perfectly the need for GPkey personalization, can handle printing and custom packaging (they will send some example of what they usually do). They work for loyalty cards, bank, transport cards, and government (IDs). They do big volumes (recently shipped a project of 600k cards in Malawi, mentioned an other 9m cards project they won) but are ok to accomodate with orders of 2k-5k too as I asked.
|
|
Next steps: get their quote end of this week/early next week + define a packaging</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-24/320320314756_fe0f3ce0bb820f1aa8e3_72.jpg" /><div class="message"><div class="username">dmitryn</div><div class="time">2018-09-19 08:33</div><div class="msg">Yes, both 1 and 2 are possible according to docs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-19 08:40</div><div class="msg">yes it should be seen as an NFC tag. But from the API it looks like you can only receive messages and not send any command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 09:06</div><div class="msg">for iOS, tapping our card will be pretty useless anyway (we could push a web page or a screen in our app saying that our hwallet can only be used with android, if it matters, if @patrick771 @denis-sharypin think it's a good idea)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-19 09:07</div><div class="msg">mmm how could we do this? The applet we write is not invoked automatically</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-19 09:07</div><div class="msg">so it would depend if the manufacturer supports some additional personalization steps to add this iOS-compatible message</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 09:13</div><div class="msg">cool ! so @micheleb what should we do/define to have our javacard showing like a nfc tag, is it some parameters including a NDEF sent at initialization ? do we need to declare as one particular technology ?
|
|
|
|
see in <a href="https://developer.android.com/guide/topics/connectivity/nfc/nfc#tech-disc<resources">https://developer.android.com/guide/topics/connectivity/nfc/nfc#tech-disc<resources</a> xmlns:xliff="urn:oasis:names:tc:xliff:document:1.2">
|
|
<tech-list>
|
|
<tech>android.nfc.tech.IsoDep</tech>
|
|
<tech>android.nfc.tech.NfcA</tech>
|
|
<tech>android.nfc.tech.NfcB</tech>
|
|
<tech>android.nfc.tech.NfcF</tech>
|
|
<tech>android.nfc.tech.NfcV</tech>
|
|
<tech>android.nfc.tech.Ndef</tech>
|
|
<tech>android.nfc.tech.NdefFormatable</tech>
|
|
<tech>android.nfc.tech.MifareClassic</tech>
|
|
<tech>android.nfc.tech.MifareUltralight</tech>
|
|
</tech-list>
|
|
</resources></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-19 09:15</div><div class="msg">the card is an NFC tag, but I do not think it communicates with Ndef commands. I have to check if the specific card we have support this technology in parallel to the ISO7816-4 messaging</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 09:15</div><div class="msg">do we need a another applet installed that behaves as a NFC tag maybe ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 09:15</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-19 09:16</div><div class="msg">I do no think this can be done applet-side, because it looks like the data is pushed to the device, and no applet can push data</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-19 14:39</div><div class="msg">Did a small thing on a train today. Screen transitions between screen asking to present card and screen where card is presented. Also 2 small animations telling users present card and maintain connection. Download the video and take a look at a bigger size</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-19 16:08</div><div class="msg">Kudos to @denis-sharypin for this awesome UI flows and presentation ! A couple of things I wrote down from our workshop :
|
|
* We need to use the right wording for the main states of the cards : � out of factory � , � Initialization �, � blank card �, � empty � card should be both clear to the user, and always used with the same meaning. We need @obi help here.
|
|
* In any case, we will propose the user to change his account, change his PIN (btw he can't change his PUK), but should we also add a ?remove account? meaning wipe secrets from the card and thats it. That?s a question for user testing. Not that it's high priority in terms of uxr, but it affects @micheleb code
|
|
* In the "sign-in" screen, if NFC is on, and a card is presented:
|
|
* If it's not paired with device, then we can propose to pair card with device. When it's paired, then if there is an account we can propose to sign in with this account
|
|
* If it's paired with device
|
|
* If there is no account: then we do nothing, or write please select ?create account or import account below? to set-up this card
|
|
* If there is an account, we can then login with this account
|
|
|
|
To clarify also : pairing is really a notion of being able to communicate between card and device, it's really like pairing to a wifi access point with your PC by typing a WEP key. Once it is done, it does not need to be redone, unless you unpair.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-19 16:21</div><div class="msg">What?s interesting is we should see what?s the best or most reliable way to hold the card to the back of the phone.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-19 16:21</div><div class="msg">And then see if we can make an approximate animation.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-19 20:10</div><div class="msg">I'll be on holiday tomorrow and on friday, I don't have updates since monday's meeting but I'm carrying on with the `go` implementation of the applet installer. see you on monday!
|
|
question for @micheleb I won't work tomorrow but I'll dream about it :slightly_smiling_face: are responses from the card always TLV or BER TLV? in the installer I use TLV (1 byte tag | 1 byte length | data) but maybe it's just a case</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-19 20:11</div><div class="msg">though I'll adjust the length to be 1 or 3 bytes if it starts with 0xFF</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-20 07:16</div><div class="msg">@andreaf most data is BER-TLV but the card does not send very longs responses so you do not have to worry about length encoded on more than 1 byte</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-20 07:17</div><div class="msg">tags encoded on multiple bytes are also not used in the main global platform spec</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 07:22</div><div class="msg">@alex118 welcome ! @ned told me you had to finish some stuff for the hackathon, and you could help us after on hardwallet packaging and artwork. This shared doc is a good intro. Let me know when you're available for a chat, it would be usefull that I walk you through it and give you the context !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-09-20 07:22</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-20 08:08</div><div class="msg">Yeah, I?m thinking to create a small poll among our team to find out the most popular position of NFC</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:33</div><div class="msg">some update about packaging, especially for you @alex118 and uxr/ux team. One of our preferred supplier (SELP, based in France) communicated the following document. It's interesting to understand their printing and packaging capacities. It's in french but overall :</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:33</div><div class="msg">p.3 they print cards in quadrichromy. Premium options: they can put a silver or gold element on the card, and they can color the edge of the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:34</div><div class="msg">p. 4 and 5 - packaging option 1 : their cardboard forming options with some examples.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:34</div><div class="msg">p. 6-7-8 - packaging option 2 : simple package (cheapest option possible) with only one additional paper</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:35</div><div class="msg">p9 : packaging option 3 : a box with some thickness</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:35</div><div class="msg">We can also ask for a fully custom solution, they seem to be quite flexible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-09-20 15:46</div><div class="msg">Thanks @guylouis I've had my head mainly in the hackathon space, whats the current timeline on this? It'd be good to get on a call next week with either yourself or whoever's keen to give me the LD on where we're at :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-20 15:56</div><div class="msg">Definitely we can have a talk next week, dm me with when is the best time for you. It's in fact important we start working on the packaging, doing a propal to the factory, checking with them if it's doable, getting a price, it's indeed pretty much on the critical path to get a first batch of the factory.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-09-20 16:29</div><div class="msg">Nice, how you set for Monday afternoon?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 05:35</div><div class="msg">@micheleb @andreaf I post here (attached in the thread) ACS feedback about the bug with their card so that we can discuss it easier than email</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 05:35</div><div class="msg">ACS feedback
|
|
"In brief, the card is dead if you pull out the card while deleting the APP and APP Data together in one-shot.
|
|
We has repeated the issue on ACOSJ.
|
|
Our team also tried to repeat the issue on NXP JCOP but the APP cannot be installed.
|
|
The team is still looking for complete solution.
|
|
To avoid having the issue, please do not pull out the card during Delete operation.
|
|
Alternative way is to delete the APP and APP Data one by one. Do not do it in one-shot, but you may need change their APP implementation."</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 06:12</div><div class="msg">Yeah I have read it. I could split the delete command in 2 (delete instance and delete package). My impression is that is more a mitigation than a solution </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 06:13</div><div class="msg">Actually no change is needed to the applet, it is a Global Platform command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 06:15</div><div class="msg">I do not know why they couldn't install to JCOP card, maybe they tried on an older card (not 3.0.4). I am still waiting for the transport key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 13:23</div><div class="msg">It would be perfect, right after town hall for instance ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 13:25</div><div class="msg">@micheleb @corey122 @naghdy here's zklabs feedback about security audit after their long silence</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 13:26</div><div class="msg">"Hey Guy,
|
|
I apologize for having been hard to reach, I've had a very hectic travel schedule the last two weeks and it's been hard to keep on top of emails/comms.
|
|
|
|
Regarding the scope : The audit was for the codebase that implements the status wallet and interacts with the smartcard found at: <a href="https://github.com/status-im/hardware-wallet">https://github.com/status-im/hardware-wallet</a>
|
|
|
|
We reviewed that the right interfaces were used and that the cryptographic primitives were used in a safe manner.
|
|
|
|
Also, within scope I endeavored to make sure to test that the important functions of the card behaved appropriately / as they do in jSim.
|
|
|
|
Regarding the "hardware" security testing, I meant testing the SmartCard itself and ensuring that it functions as expected and returns the right responses over the wire. Even though it's a SmartCard it is still "hardware", just passive and small form factor hardware. I had planned to go a bit deeper and analyze whether certain functions could leak side channel data via timing or power analysis attacks, however the hardware I normally use to test this is not appropriate for a SmartCard interface so that might have to come later as an extra while I figure out the best approach to get more consistent analysis.
|
|
|
|
On planning the audit I've had me, Dean and Harry do the testing independently for both the sim and the card and independent reviews on the code itself, the "physical" testing has taken a bit due to having to ship the card around as we're not all always in the same place and we only had one card.
|
|
|
|
I am putting together all the notes from everyone into a final report and will get it over shortly. Of course, we are happy to hear feedback and iterate on the report.
|
|
Regards,
|
|
Matthew Di Ferrante"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 13:27</div><div class="msg">I have seen it. I think we have to wait for the report. But I really expected their evaluation of the cryptographic schemes (not only primitives) I implemented, especially the SecureChannel. I mean auditing the "code" means nothing, it is Java, I am not going to have buffer overflow/underflow or similar issues</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 13:30</div><div class="msg">I will answer him to precise when he will provide the report ("shortly" is not really acceptable given our backlog with them), should I add any remark ? (like mentionning your remark about cryptographic scheme ?)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 13:30</div><div class="msg">yes please. A full evaluation of the Secure Channel protocol against MITM and similar attacks must be in scope</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-09-21 13:32</div><div class="msg">Sure, that works :+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 13:32</div><div class="msg">and also as an additional question is if the EC key agreement is still needed (it is a legacy of the older secure channel protocol) or if I can remove it since I have other sources of secrecy/randomness already to generate session keys. I wouldn't remove it, but the performances are not so good ATM so it would be great to know if we must live with this overhead or not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-21 13:33</div><div class="msg">I am still talking about the secure channel</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-21 13:38</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-09-21 19:46</div><div class="msg">Yes, MITM safety from them is very important and this came up A LOT during my time with KeepKey from companies/buyers. Many safety questions I never thought of. Zooko was asking me how I knew there wasn't inside people at the factory installing malware before shipped, amongst many other questions. My advice would be to be ready for any security questions no matter how weird or small they may seem to you. We should also have good comms/knowledge of the manufacturing process and not be a black hole where we can't really give examples of why we are safe. I am just thinking about this from potential enterprise deal level?s at some point and know these kind of questions will come up big time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-09-21 19:54</div><div class="msg">Just wanted to add that if it would be helpful to chat with Ken Hodler with KeepKey, I used to work with him and he?s considered a thought leader/truly an expert with hw wallets. He would totally be open to an hour chat (or more of an engagement if needed) to share his expertise and best practices. Security is at the forefront for him/good kind of crazy paranoid ha. He?s so nice he would probably take the time to chat just to help out, but if we did a little 1-2 hour consult and sent him some SNT/ETH, I think it would totally be worth it for barely any $, and you guys might think of something you otherwise wouldn't have. IMO it's good to be overly cautious and safe now, before you get way down the line and realize mistakes that can cost 3-6 months kinda stuff. No worries if not interested, but wanted to throw out there as a resource cc @guylouis @naghdy</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-24 06:54</div><div class="msg">That?s a cool idea. @guylouis I'll leave it to you to see if there?s much overlap. Thanks @josh109 ! </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:46</div><div class="msg">@guylouis @andreaf I have tested the applet on the NXP using my automated tests. Everything works fine, no errors. After lunch I will try the performance tests. I am quite confident we will get good results</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-24 09:48</div><div class="msg">ok so I can try to split the command in 2 commands and it should work. @micheleb do you think we can have other problems? For example if we loose the connection before external auth, if there's a counter can we block the card there as well?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-24 09:49</div><div class="msg">awesome! the jcop3? is there a way for me to unblock them?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:50</div><div class="msg">if the card has tearing issues they can happen everywhere. Of course with the external auth a little bit more difficult to block the card, because it would need to happen to many times in a row. With the latest version of the applet installer the connection is quite stable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:50</div><div class="msg">at least on my phone :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-24 09:51</div><div class="msg">btw, since JCOP 3 handles ec end point multiplication, does it mean you will have to change your applet code to take this into account or not ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:51</div><div class="msg">the applet already supported this code path, so I do not need to change it. I had tested it before with the simulator and now with the JCOP card and it works fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:52</div><div class="msg">the functional tests just test both mechanisms when the card supports ec point multplication, just to make sure everything works in the applet code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:53</div><div class="msg">the file I have been sent came with lot of warnings of highly confidential and only for my eyes. If you are in Italy, I'll be in Rome since tomorrow so probably the best way is that we send cards to each other. Otherwise we get authorized from NXP to give you the keys somehow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-24 09:55</div><div class="msg">@micheleb about this bug and the dialog with ACS, do you suggest we just wait for further feedbacks / solutions from them, or do you see questions/remarks for them at this stage ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 09:56</div><div class="msg">No remarks, they found the problem and confirmed my doubts. Their workaround is a bit doubtful though, I think it makes the bug less likely to happen but is not a fix </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 13:11</div><div class="msg">*************************************************
|
|
Opening Secure Channel: 319ms
|
|
Derivation of m/44'/60'/0'/0/0 from master: 2505ms
|
|
All following measurements are from application selection to the last needed APDU
|
|
GET STATUS: 542ms
|
|
Login: 2300ms
|
|
Transaction signature (after login): 1494ms
|
|
Transaction signature (subsequent): 813ms</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 13:11</div><div class="msg">all operations are much faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-24 13:12</div><div class="msg">if we can shave off 100/150ms from opening secure channel it would improve performance for all other operations as well. I mean by not doing the EC key agreement every time there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-24 13:15</div><div class="msg">nice!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-24 15:19</div><div class="msg">thanks @josh109 that's a great idea. A chat with him would definitely be interesting. How do you suggest we proceed ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-24 15:53</div><div class="msg">Reminder:we have our weekly sync. meeting tomorrow at 11:00 am CEST. If you have any subjects to discuss (especially if we need to review some material before hand), here's the place holder link :
|
|
<a href="https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit">https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-24 20:43</div><div class="msg">any reason this call can't be recorded like a core dev call, and posted to our.status along with the minutes?
|
|
|
|
if that's not up the team's alley, could we at least get a blogpost intro together with notes from the minutes, @andreaf?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-09-24 22:13</div><div class="msg">Let me give him a call and see his thoughts and circle back. He would love to chat i would imagine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-25 06:18</div><div class="msg">Sorry I can't make a call today. I have a doctor appointment. My progress so far: implementing a feedback from the our workshop session</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-25 07:03</div><div class="msg">yeah I think we can also record it and it would be easier (what do you think @guylouis) unless there's someone good at taking notes, I'm too slow :disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 07:51</div><div class="msg">@exiledsurfer I'd feel a bit uncomfortable to have it fully public since we are at a stage where we discuss a lot the choice of our suppliers (price proposals, issues we have with them) and there are indeed some competitive matters here. However I can share later today a proposal of blogpost with the status of the project !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-25 07:51</div><div class="msg">understand; awesome!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 09:37</div><div class="msg">@andreaf about your point on testing the NXP cards with the scenarios that caused ACS card to bug (delete issue, other scenarios you talked about) I suggest you check with @micheleb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 09:46</div><div class="msg">also @andreaf for the go part of the integration, what are your thoughts on how we should integrate in go-status the work you've done and/or the work been done by arachnid <a href="https://github.com/ethereum/go-ethereum/pull/15925">https://github.com/ethereum/go-ethereum/pull/15925</a> ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-25 09:59</div><div class="msg">I have just landed. Did you manage to unlock your cards too? It is a good idea to test the ACS scenario with NXP cards. My impression however is that NXP card do not lose connection to the terminal as often</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-25 10:00</div><div class="msg">So it should be a little more difficult to lose connection during delete</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 10:03</div><div class="msg">Not managed yet, we have a session this afternoon with andrea so that he helps me compile gpshell :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-25 10:06</div><div class="msg">yes we'll try this afternoon!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-25 10:06</div><div class="msg">I'll also try to reproduce the same "bug" with jcop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-25 10:07</div><div class="msg">the first implementation I'm doing is the installer and doesn't need that branch.
|
|
after that I will move those changes into our repo and continue with that. when we finish we can then open a PR upstream</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 12:12</div><div class="msg">Here's a proposal of text for the blog ! Let me know your feedbacks if I can post it first somewhere to have a draft.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 12:13</div><div class="msg">*Hardware wallet progress !*
|
|
|
|
Within Status we don't compromise on security ? It?s one of the core principles which guides all our architecture decisions, and the design of our user experience. We have a full team of core contributors working hard to develop a hardware wallet for those of our users that want the extra security of separating their mobile wallet and their secrets. This hardware wallet isolate the user private keys into the safety of the hardware wallet, which is kept offline by nature.
|
|
|
|
This hardwallet, which has the form of a NFC contactless card, offers state-of-the art physical security (CC EAL5+ criteria against physical attacks) to store the user crypto-assets (ETH, SNT, ERC-20 or ERC-721 tokens).
|
|
|
|
With a simple tap on the mobile, the hardware wallet (which is protected by a PIN code) allows an easy login into Status application and the signing of transactions to send crypto-assets or to interact with your favorite dApp.
|
|
|
|
This hardware wallet, that we qualify as our light version, is a fully open source project, and you can check our repos here <a href="https://github.com/status-im/hardware-wallet">https://github.com/status-im/hardware-wallet</a> , and our swarm here <a href="https://github.com/status-im/ideas/blob/master/ideas/291%20-%20hardware%20wallet%20light">https://github.com/status-im/ideas/blob/master/ideas/291%20-%20hardware%20wallet%20light</a> . It will be launched to be used with our Android Status application, since iOS has not opened (yet !) the full NFC capabilities on iPhones.
|
|
|
|
We are extremely excited to bring this product to life, and have tremendous work ongoing wether on auditing the security (we're working with an external company for this), designing the full user experience (see here <a href="https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardwallet-light-flows?node-id=0%3A1">https://www.figma.com/file/UfQjpWl1hmRchHIyY3Wvu2nW/Hardwallet-light-flows?node-id=0%3A1</a> for UI ), integrating the hard wallet experience with our android client, and sourcing the right card manufacturer !
|
|
|
|
See our weekly meeting wrap from 25/09 up here <a href="https://hackmd.io/g_D5r9XuS4qL-l6p9gypTA">https://hackmd.io/g_D5r9XuS4qL-l6p9gypTA</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 12:14</div><div class="msg">cc @exiledsurfer</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-25 12:17</div><div class="msg">thanks @guylouis, i'm going to send you an author invite to ghost; please just add a profile photo, a header image and a short bio to your profile upon logging in. I'll create, format, and publish the post under your and @andreaf's names, ok? please check your gmail for the invite.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-09-25 12:21</div><div class="msg">also, @guylouis is the figma link set to being public?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-25 12:23</div><div class="msg">awesome I like the post @guylouis! I'll try to prepare another one in the next days :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-25 12:24</div><div class="msg">yes the figma is public</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 06:54</div><div class="msg">@micheleb Here's NXP feedback on cards models. Austria cards is trying to push for some older JCOP3 models, but following NXP feedback I will answer to them we won't go that route. Also when you know it, let me know if you think the 40k JCOP3 is a possibility instead of the 80k one.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 06:54</div><div class="msg">"Hi Guy-Louis
|
|
If I understand well, AC is trying to propose you an old version of JCOP, and used for EMV/banking applications which to me doesn?t fit with your use case (EMV platform are not meant to be used for authentication or signature and are not as secure as the new one ? J3H082 ? where the OS is common criteria certified and maintained certified ? dit ?sous surveillance?);
|
|
SELP on his side has run the J3H082/J3H145 on many projects since 2017.
|
|
As for the memory size, please let us know when you test the samples. Maybe in the quotation we could all make an effort if everything fits in 40Ko.
|
|
Cheers,
|
|
Johann"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:09</div><div class="msg">I think it is, the ACS card is 40k. But I want to make exact measurements... maybe the JCOP3 card gives me some commands which can be used to determine available memory (so I can do a before/after installation). I will check the manual and let you know</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:10</div><div class="msg">because this topic is coming up often and since the applet will not change wildly (if at all) it is a good time to make some measurements</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 07:14</div><div class="msg">@andreaf finally I managed to have two android phones working with the javacards (both ACS and NXP). My surprise is how sensitive the way we apply the cards to the back affects the connection ! Samsung J5 : works pretty well, but the card has to be applied at the center of the phone other wise it does not work, Samsung A5 : works ok, but sometimes can't detect the card when holding phone in one hand and card in the other. What helps is to put the the card on the table, and the phone on the card.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 07:15</div><div class="msg"><!here> I really encourage you to try the cards you have with your android phones. @andreaf can you post here the apk link to download the app ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:22</div><div class="msg">is there any news regarding the tearing bug (mute after failed delete)?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:22</div><div class="msg">with NXP</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 07:32</div><div class="msg">@andreaf also I made this video, there is something wrong with the app with my samsung A5. It was working ten minutes ago, and now it cannot detect anything from our app.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:44</div><div class="msg">@guylouis so the applet (installed and initialized) uses 11k of EEPROM and 474 bytes of RAM on a JCOP3 card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 07:48</div><div class="msg">good news ! so I can confirm to NXP that 40k eeprom is good for us, right ? and I will mention the RAM we need to make sure their 40k cards has enough RAM too.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:48</div><div class="msg">yes, perfect</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 07:54</div><div class="msg">if I read the email correctly they would still give us the 80k version, they do not seem to have a 40k one... just a better quotation (for whatever reason), or do you read it differently?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 07:57</div><div class="msg">not sure actually, let's see ..</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:09</div><div class="msg">andrea will try to reproduce it with NXP</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 08:11</div><div class="msg">ok, really interesting to see the results. Because that bug on ACS is really nasty</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 08:37</div><div class="msg">yeah each phone is different. with mine I need to keep it on top, if I leave them on the table it loses connection easily </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 08:39</div><div class="msg">yeah there must be something in the app but it's really weird it works with other phones. I'll try to investigate on this today </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 08:40</div><div class="msg">yes I can try it today on the jcop3</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:44</div><div class="msg">@patrick771 @obi @denis-sharypin @alex118 as discussed yesterday, we're gonna have to precise what we write (content) on the card it self , and on the accompanying package & sheet of paper. Here's (in the tread) a very simple (wordings are not good) proposal to kick off the discussion</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:46</div><div class="msg">*Content of the packaging*
|
|
*- the card*
|
|
*- a recovery sheet* (piece of paper/cardboard designed for the user to write down two secrets :
|
|
The PUK : 12 numbers
|
|
A pairing password : 8-16 characters)
|
|
*- we should print somewhere* (to be decided the packaging it self, or the recovery sheet or an other piece of paper)
|
|
_Welcome message_
|
|
E.g. ?Welcome to Status?
|
|
_What is this ?_
|
|
E.g ? This is your hardwallet: store & send your assets with extra security?
|
|
_How to start_
|
|
1. ?Download <a href="http://status.im">http://status.im</a> app (how do we do that ? provide a link ? a QR code)?
|
|
2.? Follow app indications to set-up your card?
|
|
_Indications about security_
|
|
Something like : ?"Your card comes free of any software or secrets. It will be initialized the first time you use it with your mobile app. During this set-up you will be provided two secrets : the pairing code that you will need to pair the card with any new phone, and the PUK that you will need if you block your PIN after 3 wrong attempts. Please write down these two secrets on this sheet of paper, and store it securely."</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 08:47</div><div class="msg">@guylouis in the end did it work with the first phone? It looks like it didn't in the video</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:53</div><div class="msg">it's strange because this morning it worked ok !!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:53</div><div class="msg">and then i got in the state of the video</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 08:53</div><div class="msg">really really strange</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 09:09</div><div class="msg">"Thanks Guy-Louis for the feedback.
|
|
|
|
In that case, it will still be the J3H082 but with what we call a ?project price? for Status for a ?light memory usage?.
|
|
|
|
I'll make sure AC and SELP are aware of that: I'll liaise with my colleague who is their NXP account manager: Gilles de Rengerv�. So you can ask them for this project price and they should liaise with Gilles.
|
|
|
|
Cheers,
|
|
Johann"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 09:09</div><div class="msg">For now I :heart: NXP</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 09:50</div><div class="msg">@micheleb @guylouis I managed to block a jcop3 card in the same way I did for acosj cards:
|
|
|
|
1 - send command delete
|
|
2 - disconnect card before receiving the response
|
|
3 - the card now is blocked and `gpj` says: `could not connect to ACS ACR 38U-CCID: SCARD_E_NO_SMARTCARD`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 09:53</div><div class="msg">I'm going to implement the delete in 2 steps as they said.
|
|
one important thing is that we need the delete command only for debug, but in "production", there will be only 1 initialisation.
|
|
But I understand that it's a weird bug and it makes us thinking there could be more</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 09:55</div><div class="msg">Mmm that's strange that you get the same behavior...that's bad news </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 09:56</div><div class="msg">Yeah 2 steps should mitigate the issue, no idea if that really fixes it. But maybe NXP can give us more support on this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 09:57</div><div class="msg">@guylouis can we ask them the same question? maybe the discussion can be faster with them</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 09:58</div><div class="msg">ok, what do you think : how should I formulate it, and should I put some logs ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 09:59</div><div class="msg">The only that worries me is the no smartcard message </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 09:59</div><div class="msg">It should be card mute </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 10:00</div><div class="msg">Did you try a couple of times to connect with gpj? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 10:07</div><div class="msg">a lot of times. Only once I had: `Failed to communicate with card in JnaCardTerminal{scardHandle=SCardContext{2}, name=ACS ACR 38U-CCID}: SCardTransmit got response 0x80100016 (SCARD_E_NOT_TRANSACTED: An attempt was made to end a non-existent transaction.)`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 10:15</div><div class="msg">@micheleb if I want to split the command in 2, are these the 2 object IDs to remove?
|
|
- `53746174757357616C6C6574`
|
|
- `53746174757357616C6C6574417070`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 10:34</div><div class="msg">Yes correct </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 10:37</div><div class="msg">I see the `0x80100016` response happens when I remove the card from the reader during some operations. so I think I always have `SCARD_E_NO_SMARTCARD` with `gpj` and the jcop3 card I blocked today</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 11:16</div><div class="msg">yeah when you remove the card during some operation it is normal for that to happen (transmit fails), but then the card should work normally next time. If it does not, it is a bug in the card. It is strange because NXP mentions anti-tearing measures</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 11:40</div><div class="msg">I tried sending 2 delete commands but I always have a response `0x6985`. I tried deleting `53746174757357616C6C6574` and then `53746174757357616C6C6574417070` and vice-versa but I always have the same error. I tried passing `P1` with `80` (multiple commands but I'm not sure is used in this cases), but if the second one has `0x00` (last delete command), I get a `0x6F00`. I'm not sure if I need to delete a third file to be able to delete all?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 11:44</div><div class="msg">No you need to send P1 as 0x00, delete first the applet (longer ID) and then the package</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 11:44</div><div class="msg">Also I think in P2 you have to specify delete object.. I will have a look at the specs and let you know </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-09-26 11:58</div><div class="msg">@guylouis @rajanie i believe we need cards for all testteam members (more than 1, because of some negative scenarios, failures etc.) . So great to have 2-3 cards for each testteam member cc @anna. Is it possible?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:02</div><div class="msg">P2 should be 0x00 </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-09-26 12:03</div><div class="msg">I only have three left - so let me know who to send too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:04</div><div class="msg">yeah I tried everything. the orginal was P1 0 and P2 0</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:04</div><div class="msg">I'm also trying just with gpshell
|
|
|
|
```
|
|
mode_211
|
|
enable_trace
|
|
establish_context
|
|
card_connect
|
|
select -AID A000000151000000
|
|
open_sc -security 1 -keyind 0 -keyver 0 -mac_key 404142434445464748494a4b4c4d4e4f -enc_key 404142434445464748494a4b4c4d4e4f -kek_key 404142434445464748494a4b4c4d4e4f
|
|
send_apdu_nostop -sc 1 -APDU 80E40000114F0F53746174757357616C6C6574417070
|
|
send_apdu_nostop -sc 1 -APDU 80E400000E4F0C53746174757357616C6C6574
|
|
card_disconnect
|
|
release_context
|
|
|
|
```</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:05</div><div class="msg">but with both the commands I get `6985: Command not allowed - Conditions of use not satisfied.`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:05</div><div class="msg">Try with gshell but using the built-in delete command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:06</div><div class="msg">Mmm when you install, are you sure the installation aid is the correct one? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:06</div><div class="msg">ah, another thing is that in the data field I'm using for both the `4F` tag. the same I was using when deleting all together in 1 command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:07</div><div class="msg">yeah otherwise with wrong aid I get `0x6A88`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:07</div><div class="msg">4f is correct </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:08</div><div class="msg">I will try here too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-09-26 12:11</div><div class="msg">lets send them to @anna</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:11</div><div class="msg">ok with the builtin `delete -AID` it worked, let's see the command that it sends</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-09-26 12:12</div><div class="msg">does this work for you @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:12</div><div class="msg">ah byt default it sends `84 E4 00 80...` so it's a delete AID and all deps</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 12:12</div><div class="msg">yes this works ! thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:13</div><div class="msg">mm I mean, it is ok to send P2 80, but it shouldn't be necessary actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:15</div><div class="msg">the P2 with 80 is the one used in the version that blocks the card. so you only pass the aid and it also aid and it also delete all the dependency objects</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:15</div><div class="msg">now I was trying with the 2 command and if I understood correctly from the docs, p2 should be 00 to delete one at a time</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:16</div><div class="msg">well no, if you first delete the applet (long aid) even if p2 is 80 you do not delete the package</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:16</div><div class="msg">because with p2 `80`, I can just send the aid and it removes everything correctly (but we have the bug if the connection is lost)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:16</div><div class="msg">ah ok I understand</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:17</div><div class="msg">because it does it in the opposite order</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:17</div><div class="msg">mmm ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:17</div><div class="msg">let's try again</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:17</div><div class="msg">because the package is not a dependent object. The applet depends from the package but not viceversa</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-06/411178710468_720d28ab1ef2ed6c3c74_72.png" /><div class="message"><div class="username">rajanie</div><div class="time">2018-09-26 12:17</div><div class="msg">great @anna I will mail them to you this afternoon</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:18</div><div class="msg">yeah it makes sense now :slightly_smiling_face: thank you @micheleb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:18</div><div class="msg">it looks like it works</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:19</div><div class="msg">now I need to test losing connection in one of the 2. or in between</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:19</div><div class="msg">and if you manage to reproduce it, you are only left with 1 living card :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:19</div><div class="msg">or how many do you have?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:20</div><div class="msg">hahsahah, I will actually have 2 :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:20</div><div class="msg">oh ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:20</div><div class="msg">so now I still have 3 hahaha but you are right, I hope they don't fail this way</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:25</div><div class="msg">unfortunately I think it's not really working, not even in gpshell with the delete command. basically the first one (longer AID for the applet), fails with `6985`, so the second one with p2 80 successfully delete both</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:34</div><div class="msg">mmm I am trying, same results</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:34</div><div class="msg">I wonder if the ACS card works</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:34</div><div class="msg">I can try there, let's see</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:37</div><div class="msg">in the first delete, the acosj response is even different: `6448`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:39</div><div class="msg">both with p2 00 or 80</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:43</div><div class="msg">ok, I have found the issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:43</div><div class="msg">I use static references, which are only deleted when the package is deleted</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:44</div><div class="msg">ah ok, in the applet's code?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:44</div><div class="msg">yes</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:44</div><div class="msg">I will fix this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:44</div><div class="msg">well what do you think about it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:44</div><div class="msg">the thing is, that static objects are allocated once per package, not once per applet, I had forgot that detail</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:44</div><div class="msg">because we are trying this only for dev/debug, does it make sense or is it going to change a lot?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:45</div><div class="msg">I have to check when and where I use it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:45</div><div class="msg">ah ok so it would be good as a change?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 12:49</div><div class="msg">@micheleb @andreaf I wait for your final feedback before I ask anything to NXP, alright ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:49</div><div class="msg">well, I use static a lot but they are all final except one field</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:49</div><div class="msg">I think we can already ask the same question we asked for the acosj</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:50</div><div class="msg">I have to check if handling that one is enough.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 12:50</div><div class="msg">yeah I would also ask the same question for now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 12:51</div><div class="msg">ok, but without log ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:52</div><div class="msg">it's exactly the same of the other one so I think we could use exactly the same email</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 12:52</div><div class="msg">understood ! if it's exactly the same log then I can send it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:53</div><div class="msg">:thumbsup:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 12:53</div><div class="msg">I'll be afk for ~1h</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:01</div><div class="msg">@andreaf ok I have seen that constants are OK, but there are a few objects I marked as static that should be theoretically initialized in static initializers (but I think these do not exist in 3.0.4). I will rewrite it, it will be cleaner anyway</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:24</div><div class="msg">@andreaf ok, it is done. I have also updated the cap file in the smartcard-cap-installer-test repository. I have tested with GPShell and even with P2 00 it works fine now :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:25</div><div class="msg">this is better because we would have had problems the moment we decided that we want to have multiple instances on the same card or anything similar</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 13:40</div><div class="msg">awesome!! great job @micheleb thank you!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:43</div><div class="msg">it is also interesting to know if this change fixes the problem completely, since I removed any possible hanging referenced object which might trigger card mute state</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:44</div><div class="msg">I mean nothing for sure, because this shouldn't happen in any case</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 13:45</div><div class="msg">so meaning also the problem of losing connection during a delete with p2 80?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:45</div><div class="msg">I am not saying that it fixes it, but it surely changes the scenario enough to make it worth a try (in case 2 separate delete works fine)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 13:47</div><div class="msg">ok so, delete in 2 steps with p2 00 works!!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 13:49</div><div class="msg">losing connection during the delete (both first and second one), doesn't block the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 13:59</div><div class="msg">great, and what happens if deleting with a single command now? still blocks the card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 13:59</div><div class="msg">not tried yet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 14:00</div><div class="msg">shall I blocked another one :slightly_smiling_face: ? about acosj they replied the bug exists, and I don't think they used our specific applet, did they?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 14:01</div><div class="msg">mmmm no idea, we have provided them with the cap file</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 14:02</div><div class="msg">ok I can try now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 14:05</div><div class="msg">tried again with acosj, 1 delete command with p2 80, losing connection, card blocked</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-26 14:05</div><div class="msg">ok so no difference with acosj</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 14:26</div><div class="msg">/kudos @micheleb for fixing an "issue" in the applet, making the 2-steps delete command working</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 14:27</div><div class="msg">you can now all try the `test 3` release
|
|
|
|
<a href="https://github.com/status-im/smartcard-cap-installer-test/releases">https://github.com/status-im/smartcard-cap-installer-test/releases</a>
|
|
|
|
This test app deletes the current applet in the card before starting a new installation, so you don't need any other tool anymore</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 15:40</div><div class="msg">@patrick771 We had an interesting talk today with @obi and @denis-sharypin about wording content for the hardwallet. In particular we discussed naming of the product : should we call this product a hardwallet (blockchain word, for tech savvy people), or something else that's non-tech savvy (like a "Key to your Status account") ? To be in line with our goal to engage non-tech savvy users to Status, it would make sense to go to the latter. Obi will try to write something to answer to the question what is it ? what does it do ? with this kind of language.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-26 15:42</div><div class="msg"><!channel> any opinion on this welcomed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-26 15:42</div><div class="msg">My 2c. Getting away from a blockchain word is a good idea. I don't know if Key to your Status account is a good alternative, but I like the direction :+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-26 15:53</div><div class="msg">I also like the direction to move away from hardwallet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-26 15:54</div><div class="msg">i mean, calling it a keycard may be perfectly appropriate</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-26 15:54</div><div class="msg">its understandable, and that's what it does</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-09-26 15:56</div><div class="msg">Yeah, I?m all for exploring different options for a different term here. And taking the approach of first describing what a thing does for a user from their perspective and then generating ideas from what ever that description is. So am curious to hear what @obi can come up with and am happy to think of ways we can test those options with potential users.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-23/422058362675_dc3e307b6e9052d90b4c_72.jpg" /><div class="message"><div class="username">kim196</div><div class="time">2018-09-26 16:18</div><div class="msg">Agree with moving away from hard wallet And Patrick?s comment about the name
|
|
supporting the functionality. Look forward to seeing and weighing in on options. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-26 16:23</div><div class="msg">@guylouis what android versions do you have in your 2 phones?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-27 00:29</div><div class="msg">I'm fine with getting away from more technical terms, love the idea of rooting the name in its purpose. I would be wary of creating more levels of abstraction doesn't help a user understand what's going on when things go wrong and creates a dependency on us. As long as we carry the spirit of enabling the user to be responsible for their data and more importantly, maintaining their sovereignty it's better.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-27 00:31</div><div class="msg">Key for Status isn't that great to me because what about the use case of using this at a payment terminal? Are we vendor locking people into a Status payment network only? Or are we being more open, permissive with a wider ecosystem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-09-27 07:03</div><div class="msg">@jarradhope can you elaborate on a usecase with a payment terminal?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 07:34</div><div class="msg">samsung A5 (the one with issues with the app) : android 7.0</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 07:35</div><div class="msg">ok it might be related to the android version, I'm not sure. do you have os updates on that phone?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 07:37</div><div class="msg">samsung J7 (the one working well) : 7.0 also</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 07:37</div><div class="msg">I'll try</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 07:37</div><div class="msg">ah ok, I thought it was 8</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 07:37</div><div class="msg">so it's not related</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 07:40</div><div class="msg">yeah, anyway A5 says it can't be upgraded and has already up to date software updates ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 07:40</div><div class="msg">cool no problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 08:31</div><div class="msg">It?s the case where we have Nimbus running in payment terminals, or turnstiles in transport systems, and payment/access can be granted by tapping the card.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 09:43</div><div class="msg">@micheleb following our flow discussion yesterday with @denis-sharypin are you ok with this update of the state flows. I added 1bis and 1ter states (1 ter is quite rare but can happen right ? my understanding is that pairing is done after GP keys are randomized)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 09:45</div><div class="msg">the goal is really to have an exhaustive list of the states of the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:05</div><div class="msg">everything is correct. Pairing can be done either before or after randomizing. The important thing to know, is that the pairing key and PUK are generated before the actual installation (and can be actually shown while the installation is going if desired), not when doing the actual pairing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:13</div><div class="msg">Ok, great. As for when pairing is done, if it doesn't matter (before or fater GPkey randomization), i'll leave it like that then.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:14</div><div class="msg">:+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:23</div><div class="msg">I imagine at each tap of the card on the mobile, we'll first have to find out which state the card is in.
|
|
I drafted something here (sorry it's hand drawn for now - I'll formalize it after, if it is ok). Can you look at it @micheleb and tell if it's correct for you ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:25</div><div class="msg">Next question is the following : if the user is logged-in with a non card account (that's what we were discussing yesterday together with you and denis) and taps his card, and in the case the card is in state 3, then we need to figure out if the account in the card is the same as the one being logged in. Do we really need to ask the user to enter the PIN to check this - meaning can't we use the pinless path to make this check ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:28</div><div class="msg">this is an interesting question... can I answer: it depends? :smile: I wouldn't use the PIN-less path. There are several cases here however</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:29</div><div class="msg">maybe we can also add the state when the card is initialized (applet has been installed), but paired is still NO. does it make sense?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:29</div><div class="msg">when you pair with a card you need to memorize the card identifier. It is thinkable that you also remember on the phone which account was stored on that card. So you do not need to login, because you get this identifier as answer to the SELECT command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:30</div><div class="msg">it's state 4 actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:31</div><div class="msg">if the user is logged in with a non-card account, I think tapping with the card should do nothing. I think nfc listener should be activated only when we need it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:31</div><div class="msg">if however you are exporting an already logged in account (so the phone has no idea on which card this already exists or if it exists at all on a card) then you really need to enter the PIN.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:32</div><div class="msg">makes sense. I could have been more precise : it's in the case he's logged in with a non card account, but gets in the menu 'change account'</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:32</div><div class="msg">here we have to open nfc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:32</div><div class="msg">ah ok I understand!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:34</div><div class="msg">well.. and maybe it's a question for the wallet team, if the pin lesspath is the whisper key, can't we match the whisper key with the key in the app ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:35</div><div class="msg">this wouldn't help. The only thing we could do is return on select not a card-related id as we do now, but an id which can be derived by the master key's public key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:36</div><div class="msg">I mean the pinless path only allows signing without entering a PIN with a specific key, nothing more nothing less</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:37</div><div class="msg">> then we need to figure out if the account in the card is the same as the one being logged in
|
|
Let's say you have 2 accounts, 1 is a mobile account, 2 is a card account. if you click on account 1, we ask for a password, if I you click on 2, we wait for the card. so there should *not* be a state when we need to decide what to do no?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:38</div><div class="msg">Ok :100% clear</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:39</div><div class="msg">or am I missing something @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:39</div><div class="msg">I think we will need to make this change, but we have to check with the client development first how they want to handle it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:40</div><div class="msg">the card might be the wrong one, not the one you are expecting to login</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:41</div><div class="msg">ah ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 10:41</div><div class="msg">Let me write this diagram in a proper format then.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:43</div><div class="msg">in the keystore file we have the accounts list, and in clear we have the wallet address. so basically for now the "username" is the wallet address. can we just get the wallet pub key from the card and derive the address and compare it to the "username/address" the user selected?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:46</div><div class="msg">that's the problem... the only key which has a "special" meaning somehow for the card is the master key. There is no "wallet address", the wallet path is just one of the many you can derive</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:46</div><div class="msg">can the client select the wallet path and get the pub key?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:46</div><div class="msg">or is it slow?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:46</div><div class="msg">not without authenticating first</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:47</div><div class="msg">in my opinion, the client should keep an id generated from the pub key of the master key instead of the wallet key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:47</div><div class="msg">yeah I meant:
|
|
- user clicks on account XYZ (card account)
|
|
- tap with the card
|
|
- enter pin
|
|
- if pin is correct the client select wallet path, derive address and compare it to XYZ</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:47</div><div class="msg">it could be an ethereum address, or we could use a different algo, it makes no difference</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:48</div><div class="msg">ok that makes sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:48</div><div class="msg">then I could return this ID on select, so you do not require the PIN if the card is the wrong one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:48</div><div class="msg">I don't remember what the current implement does but I can check later (the smartcard PR on go-ethereum)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:48</div><div class="msg">I already return an ID, but is a random number generated during applet installation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:48</div><div class="msg">and that's also faster</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:49</div><div class="msg">if that is OK, then it is ok for me too.. the only thing is that if you change the account on card, the id stays the same</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:49</div><div class="msg">if you make it dependent from the master key, then you can detect that the account on card changed, even if it is the same card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:50</div><div class="msg">I didn't make it this way at the beginning, because I thought that changing account on card was not a desired scenario</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:53</div><div class="msg">yeah you are right! we shouldn't be able to change the account in the card. anyway when we log in we still need to download the whisper key, so we can double check that it's the same account maybe?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:57</div><div class="msg">as far as I understood it is foreseen that the account on card can be changed.. @guylouis is that correct? And yes we can double check, but it would be really useful if we could recognize an associated card already from the SELECT command. Especially because the user might not know they have taken the wrong card and might enter the PIN wrong twice (first time you think you mispressed a button, second time you realize something is wrong)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 10:57</div><div class="msg">and if you are like me, you enter it the third time again and you block it :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:58</div><div class="msg">yes you are right, I was confused between changing the account and "re-installing" the applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 10:59</div><div class="msg">so we would need a check on the card and then a check on the account</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:02</div><div class="msg">I think I must really change the answer to SELECT. At the moment I return: UID (this allows to recognize if you are paired or not). Public key for EC-DH (this also allows to recognize if you are paired or not). Application version and remaining pairing slots</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:03</div><div class="msg">if we remove EC-DH from secure channel, we can replace the public key with the master key address (if present, otherwise empty, so from select you even recognize if the card has an account or not, before pairing!). If we do not remove EC-DH, we can replace the UID with the master key address</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:04</div><div class="msg">keeping both the way it is now makes little sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 11:04</div><div class="msg">yes, the user must be able to change his account on the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 11:06</div><div class="msg">for `master key address` do you mean an ethereum address derived from `m`?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:06</div><div class="msg">to decide if EC-DH can be removed in the secure channel I would like to get a reply from the auditors... but if that is impossible and will block us for a long time we should take the decision ourselves... I have talked about this with Nick Johnson already a long time ago and he was also of the opinion that it can be removed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 11:07</div><div class="msg">I still don't know a lot about that but it makes sense if you already talked about it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:08</div><div class="msg">yes, possibly an ethereum address. We could also use a different algo if we do not want to create confusion and let the users/developers have the impression that this is an account where you can send ETH to</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:08</div><div class="msg">it must just be an ID which can be derived from master key, so it stays constant even when you make a new card from mnemonics</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:10</div><div class="msg">yeah because EC-DH was used before pairing was implemented to generate a shared secret between parties. However now the secret is preshared through different channels so the EC-DH secret only offers additional randomness.. it is actually redundant though</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:10</div><div class="msg">the preshared secret is the pairing password which is then used to generate a pairing key which is unique to every paired client</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-27 11:11</div><div class="msg">yeah it makes sense!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:15</div><div class="msg">actually, I cannot use an eth address, because I do not have SHA3 on card. I can use SHA-256 instead and take the full output</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 11:15</div><div class="msg">Well from everything you write, it seems it make sense to remove EC-DH. Since we can't rely much on zklabs, I'd propose we go this route, and just state to them clearly the change we are doing to avoid that they come back to us in 2-3 weeks with an audit that does not take this into account. Are you ok ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:15</div><div class="msg">this will make it a different length so it is not confused with an address</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 11:15</div><div class="msg">In this case, we'd just need to state them clearly the changes made.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:16</div><div class="msg">give mes this afternoon to evaluate all implications again and in the evening I will tell you if I am still of the same idea</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:16</div><div class="msg">because it is a really delicate topic, the secure channel protects communication and PIN transmission</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 11:17</div><div class="msg">I want to go again through all possible attacks and see if a secure channel without EC-DH resists to them in the same way as it does now</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 11:21</div><div class="msg">sure, take all the time necessary, we shouldn't feel rush to decide this kind of architecture decisions ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 13:51</div><div class="msg">ok I have thought of all the possible attacks and I have found 1 scenario where having EC-DH actually helps. Let's suppose that you can log all conversations between card and client. You cannot decrypt it because of the secure channel. You really cannot decrypt it, even if you somehow discover the pairing password (unless you have the log of the pairing). But let's suppose you somehow compromise the client and manage to read the pairing key. With EC-DH there is an ephemeral key which is lost forever and is used to generate the session key. This ephemeral key is not transmitted so it is not available in the logs and is not saved so you still cannot decrypt the old logs. If we do not use EC-DH instead, all the data needed to generate the session key is in the log (assuming you have the pairing secret)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 13:53</div><div class="msg">yes this scenario is very unlikely, however it is enough for me to keep the EC-DH where it is. This is because by decrypting the old logs you can read the PIN. If you do not have this ability, you can create your sessions with the same key, but you still cannot really perform any attack</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 13:53</div><div class="msg">do you agree with my conclusions? @guylouis</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 14:14</div><div class="msg">my proposal is: leave EC-DH as-is and even reinforce it, by having the card re-generate a new EC key set every x times a secure channel is opened (I would say every 100 times). This means the instance UID we have also must be left, because it is the only way to identify the card. Then I also add an account UID which is also returned in the SELECT command and can be used to determine if the card has an account or not and if yes which one without sending further commands/requiring auth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 14:15</div><div class="msg">and since I will be doing a lot of changes in the applet, maybe it is the right time to decide/implement a "remove key" command which removes the account from the card completely</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 14:17</div><div class="msg">@micheleb I read in detail, and it definitely makes sense. Eventhough the attack is very unlikely, we have to consider it. As josh said, the security of our system is going to be under a lot of scrutiny ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 14:19</div><div class="msg">Your analysis will probably be confirmed by Zklabs, since we stated we wanted their opinion if we could remove EC-DH. If they don't raise this attack it will be a good way to challenge their work.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 14:23</div><div class="msg">As for the delete account option, I am personally for it. I like the idea to be able to wipe any secret from the card if I decide to stop using it. This feature exist in all hardwallets that I tried, ledger, trezor, cool wallet S, keep key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 14:23</div><div class="msg"><a href="https://coolwallet.io/manual/">https://coolwallet.io/manual/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 14:23</div><div class="msg"><a href="https://www.keepkey.com/keepkey/faq/usage/">https://www.keepkey.com/keepkey/faq/usage/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 14:25</div><div class="msg">yeah I see. It could even simplify some UX flows, because we could disallow (client-side) to replace keys and give an option to delete the account instead</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 14:26</div><div class="msg">but only after logging in to the account. So we make it very explicit that you are losing the keys. And also we have less possibilities in the UX flows because if there is an account on card and it does not match you just refuse to proceed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 14:31</div><div class="msg">ok, I will do the changes by next Wed, maybe earlier. The applet will allow both removing and replacing, then client-side decision can be taken with UX concerns in mind</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 15:40</div><div class="msg">Just to be inline, here you're describing a case where the client UI (in the logged-in state of a card account ) does not say 'change account', but only 'delete account' ? or do you mean something else.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 15:42</div><div class="msg">Yes and not only. If you try to import an account on a card that already has an account or even create a new one we can refuse to go on until you delete the current account first</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-27 15:43</div><div class="msg">It is an option</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-27 15:44</div><div class="msg">Yep it's an option, and actually I :heart: it. For me it makes things quite clear and clean for the user.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-09-27 21:27</div><div class="msg">Here's what I've got so far re: naming of the product <a href="https://notes.status.im/vfvLRAulScCxlw88muHzdw">https://notes.status.im/vfvLRAulScCxlw88muHzdw</a> I'm going to switch gears now and work on updating copy in the design. The goal is for the design and 1 or 2 iterations of naming/messaging to be ready for testing next week. Please add your suggestions and feedback where you can</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-28 08:14</div><div class="msg">@guylouis I saw the reply from nxp. if I understood correctly there's a way to disable some protections, but I don't know anything about it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 08:15</div><div class="msg">I have not activated fast perso</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 08:16</div><div class="msg">I have seen it in the user manual and let it disabled (so anti-tearing is enabled) exactly because of our experience with ACS</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 08:17</div><div class="msg">That's why I expected NXP to work fine, since they go so far as giving a setting for anti-tearing :slightly_smiling_face: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 08:19</div><div class="msg">Just to clarify anti-tearing protection is protection from corruption due to tearing (so the card should work fine even after tearing in the middle of any operation). It is not a form of attack detection </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 08:23</div><div class="msg">ok, so I answer to them that we haven't disable anti-tearing protections</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 08:23</div><div class="msg">:+1: </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-28 14:07</div><div class="msg">I'll be afk for the rest of the day. I almost finished the go implementation of the installer so I think next week I can start working on the pairing/usage of the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 14:08</div><div class="msg">@andreaf all needed methods are already there, I have implemented them for my performance tests </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-28 14:09</div><div class="msg">you mean in go?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 14:09</div><div class="msg">No in Java</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-09-28 14:09</div><div class="msg">As a reference </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-09-28 14:09</div><div class="msg">ah ok cool! that is super helpful!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-28 14:43</div><div class="msg"><a href="https://twitter.com/kamescg/status/1045647028250972160?s=21">https://twitter.com/kamescg/status/1045647028250972160?s=21</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-28 14:43</div><div class="msg">Question for the hard wallet team. ^</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:06</div><div class="msg">can we define metrics for canceling our contract with zklabs.... this is getting ridiculous.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:10</div><div class="msg">we can answer that yes, our hardwallet is open source, our APIs are documented and we encourage any wallet to integrate it ! Full documentations and source are in the githubs repos that are in the blog post</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:11</div><div class="msg">what happened?
|
|
|
|
can we also debug how this audit got signed off? going forward we really need to make sure Corey is in on page 1 for these things</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:14</div><div class="msg">they have gone silent, and haven't answered any of the questions we've asked that should be standard issue points for a company performing an audit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:14</div><div class="msg">Contract was signed before Corey or I were here, I can't really comment except it's quite clear there clearly was a lack of written exchanges and agreement on the scope of the mission, the methodology to be used and the planning.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:15</div><div class="msg">^ @naghdy @carl @gdoly fyi</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-05/252830689991_12aab4b68577596e7564_72.png" /><div class="message"><div class="username">gdoly</div><div class="time">2018-09-28 15:15</div><div class="msg">has joined #hardwallet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:16</div><div class="msg">I'd rather we cancel it if it seems like a bad collab from the get go, assuming we legally can. We should be able to find a replacement, even if it doesn't fit as tight of a timeline (can still do alpha release with big disclaimer right?). Thoughts?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:18</div><div class="msg">we paid 25k$ as downpayment, 25k$ more to be paid when work is delivered</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-28 15:18</div><div class="msg">Awesome, thanks! do you want to or me from the status account with these details?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:18</div><div class="msg">what's their reputation in ETHSecurity?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:19</div><div class="msg">they were reffered to us by nick Johnson it seems, he's actually listed on their website as a contributor</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:19</div><div class="msg">It seems they usually audit smart contracts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:19</div><div class="msg">they have done a lot of audits</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:20</div><div class="msg">could it be just the contact we are using? do we have another person we can check with? if they aren't even replying to basics</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-17/348134203537_1bc2a6f28471cf6ec828_72.png" /><div class="message"><div class="username">hutch</div><div class="time">2018-09-28 15:22</div><div class="msg">i will respond through the status account for visibility :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:22</div><div class="msg">I know @jarradhope met with Dean in the UK in July/August. Dean seems to be the other auditor.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:24</div><div class="msg"><a href="https://zklabs.io/#team">https://zklabs.io/#team</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:25</div><div class="msg">The only time they answered something is when I told them that if they don't answer to our questions then they should cancel the contract and pay us back.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:26</div><div class="msg">@naghdy stepped in earlier today with a message to Matthew. If we don't get a reply before tuesday then I guess we should study how we can legally get our 25k$ back.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:27</div><div class="msg">It doesn?t sound great. How long have they not been answering for?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:28</div><div class="msg">For reference here's the contract signed, the scope makes not much sense since it's a smart contract security audit, and here we're auditing a javacard applet security scheme.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:28</div><div class="msg">Perhaps we should consider it a lost cost and find a new auditor, then do legal stuff in parallel </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:28</div><div class="msg">@oskarth I tend to agree we're close to lost cost</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:29</div><div class="msg">I can find a new auditor that is appropriate for this kidn of work quickly</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:30</div><div class="msg">Ok, unless @naghdy or someone objects I suggest we do this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:32</div><div class="msg">At least express interest and reach out </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:32</div><div class="msg">I will start that, but I agree that we give them until Tuesday to come up with a satisfactory response before initiating the cancellation process.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:33</div><div class="msg">Sounds good </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:33</div><div class="msg">And if they don't answer in a satisfactory way we should get another one in parallel of cancellation, so we don't let that process be a blocker. IMO anyway.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:35</div><div class="msg">I've reached out in other avenues to other contacts within zklabs, so maybe we can get someone else to discuss this with (could be a single person issue, and not an organizational one).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:36</div><div class="msg">Thanks </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:38</div><div class="msg">I will also let Matthew know explicitly that we put a deadline to tuesday to get a precise scope + planning + answers to our questions, and if we don't we will ask for our money back to them.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:39</div><div class="msg">:thumbsup:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:39</div><div class="msg">Sg</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 15:39</div><div class="msg">:ok_hand:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:48</div><div class="msg">I have contact with another rep from their company, and he is attempting to get in touch with matthew (our PoC).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-12-19/289021559940_764a5c704a5a99098d7a_72.jpg" /><div class="message"><div class="username">oskarth</div><div class="time">2018-09-28 15:51</div><div class="msg">If they do some kind of interference it might be worth pushing to get a proper contract in place </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:53</div><div class="msg">FWIW, Matt is a founder of zkLabs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 15:53</div><div class="msg">which doesn't speak well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-28 16:26</div><div class="msg">@carl and @jarradhope know him I believe. Our kick-off call went well, but thy have just gone MIA since then.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-10-04/251566892466_e37667e6064fe542e7d7_72.jpg" /><div class="message"><div class="username">naghdy</div><div class="time">2018-09-28 16:27</div><div class="msg">Let's see how they respond, but at this stage I think we should be trying to get our $25k back (cc @gdoly)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-28 20:09</div><div class="msg">@corey122 if you start discussions with other auditors it's a good time to consider that on top of the applet (and the security scheme associated with its design), we might want to have have client side code audited also (when it will be ready, so in a second step for sure).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 20:14</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-28 20:15</div><div class="msg">do we have a desired timeline for completion?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-29 02:48</div><div class="msg">hey in the blog post, are we comfortable saying "within Status we don't compromise on security" about the hw wallet? I mean the javacard is a compromise in itself isn't it? I do get a little worried about making claims like that.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-29 02:51</div><div class="msg">I'll let Dean and Nick know</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-29 02:54</div><div class="msg">I'm abit surprised because Matt comes highly recommended from both of them, ZK Labs has a pretty good rep and some reputable clients.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-29 06:32</div><div class="msg">@jarradhope they probably either don't have the bandwidth, or do not put it in priority, the subject being too far off what they usually do (smart contract audits).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-29 06:33</div><div class="msg">btw, one way to keep in mind to get out of this, could be they credit us of 25k$ for a future smart contract audit</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-29 06:34</div><div class="msg">@corey122 the goal was to have audit of the applet part (and security scheme associated) by end of october</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-09-29 07:24</div><div class="msg">For others to understand, you refer to the fact that a hardwallet need its own screen and buttons, for secrets (especially mnemonic & PIN) to never leave the card itself. "no compromise" is indeed perhaps a bit too strong in this context ... @exiledsurfer would this work, if we just remove this statement, and simply start the post by stating "Security is one of the core principles which guides all our architecture decisions, and the design of our user experience. ..." ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-29 09:34</div><div class="msg">Dean has been pretty apologetic and getting in contact with Matt, I'm fine with pulling the plug if need be. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-29 13:34</div><div class="msg">security and ease of use typically have a tradeoff. You have different practices based on how much money you store in a given place. For the purpose of this wallet and amount of money that should be stored in it, we are quite high on security.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-29 13:34</div><div class="msg">maybe we should start to have our narrative reflect that idea.... having the UI remind the user of various best practices based on how much money they have stored in their wallets.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-09-29 13:35</div><div class="msg">the javacard (in my opinion) is an escalation of security practices from chump change to something more substantial, but not life savings substantial.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-09-30 08:13</div><div class="msg">Agreed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-01 10:26</div><div class="msg">Matt sent over an email just now, and looks like he is presenting a report tomorrow ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-01 10:36</div><div class="msg">Yes, it seems he's committing to a report by tomorrow :thinking_face: ... it's actually the first time they have some technical comments and questions for us. @micheleb could you take a look at his comments/questions ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-01 10:37</div><div class="msg">:notsure:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-01 10:37</div><div class="msg">pretty basic questions even KPN asked us</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-01 11:08</div><div class="msg">@guylouis I have taken a look, should I just answer to the email or do you want us to discuss that first?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-01 11:12</div><div class="msg">my take on it is: softwared based kekkac-256 would be slow, even slower if we consider that we have to transfer the transaction block-wise. From a security point of view, it does not give anything since the card has no screen, except if we really want to limit the ETH amount transfered (which I am against). But then we would need to also check ERC20 tokens and check their amount too. But we do not know their value relative to ETH so we would open a pandora's box. About the brand of course we have NXP now too, the reason for ACOSJ was that it was the easiest to source with JC3.0.4. Regarding the pairing with 5 devices, indeed I could raise the limit to a much larger value if needed, we use a very little amount of EEPROM and RAM.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-01 11:12</div><div class="msg">but that last point has little to do with security :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-01 11:22</div><div class="msg">I'll answer then.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-01 11:28</div><div class="msg">Using little resources is a good thing, esp if we want to load this applet alongside some debit card applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-01 15:14</div><div class="msg"><!channel> We will be running our first user experience testing of our hardwallet this week! The goal is to evaluate the user understanding and feedback on the initial card set-up when the card is taken fresh out of the box.
|
|
|
|
We have seen during our team discussions last week, that to reach a complete definition of the user experience, we need to take into account a number of sub-cases depending mostly on the state of the card when it is tapped.
|
|
|
|
Here's a proposal to document that, and to break down the flows within logic blocks. It will allow us to share a better understanding of the product as a whole, and can be used by Denis & ux/uxr team to detail the exact UI screens and flows.
|
|
|
|
@micheleb @andreaf your confirmation that the state diagram and procedure to check the state of a card when tapped (I called that CCS procedure) are ok would be great.
|
|
|
|
Looking forward to your feedbacks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-01 16:08</div><div class="msg">I do not have edit access, but here are my comments:
|
|
|
|
1) UI WARNING MESSAGE 1BIS. In this case we must delete and reinstall the applet, not continue, because we do not know for sure that the applet is the official one
|
|
2) The RESET CARD scenario (5) misses PIN insertion, you must authenticate your PIN to reset the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-01 19:21</div><div class="msg">yall's diagraming is on point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-18/382994375376_59fd1c69cd3ef79dc859_72.jpg" /><div class="message"><div class="username">josh109</div><div class="time">2018-10-02 06:04</div><div class="msg">This is super awesome work @guylouis! Kudos! Would love to help with any user experience feedback if needed. Also Ken I referred to last week is getting back to me on his schedule</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-24/304281668629_99d09ae86c8e0a04b52d_72.png" /><div class="message"><div class="username">growbot</div><div class="time">2018-10-02 06:04</div><div class="msg">The Disco trial has ended.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 08:38</div><div class="msg">@guylouis does `GPKEY=STATUS` mean the card still have the initial "test" keys?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 08:39</div><div class="msg">yes, and it thus mean the initialization process has not gone to its end</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 08:39</div><div class="msg">:thumbsup:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 09:51</div><div class="msg">Weekly meeting notes here <a href="https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit">https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 09:52</div><div class="msg">@andreaf could you share (again) to the chain the link to your apk so that everyone can play with the card and go through applet installation with it ? thanks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 09:54</div><div class="msg">of course:
|
|
<a href="https://github.com/status-im/smartcard-cap-installer-test/releases/tag/0.0.3">https://github.com/status-im/smartcard-cap-installer-test/releases/tag/0.0.3</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 09:54</div><div class="msg">you can install the apk</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 12:44</div><div class="msg">@micheleb @andreaf what do you suggest I answer to Mehdi from NXP (on the thread, his email) ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 12:44</div><div class="msg">"Something I can recommend on this product is to *not* send any command to the product (a part Identify command) until you leave the transport mode
|
|
Deactivate the windows certificate propagation services to avoid unexpected commands to be sent to the card at insertion in PCSC reader).
|
|
Which smartphone\tablet are you using ? Can you share the NFC front end reference ?"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 12:46</div><div class="msg">I haven't really understood this one, what he means by transport mode, if he means OP_READY state maybe? Because we did not send any command beside authentication before bringing the card in OP_READY</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 13:49</div><div class="msg">Found this korean wallet. Apart from the ledger javacard project which never became a real product, this is the closest product to what we are doing with hw lite.
|
|
|
|
<a href="http://www.keywallet.co.kr/bbs/board.php?bo_table=Products&wr_id=4">http://www.keywallet.co.kr/bbs/board.php?bo_table=Products&wr_id=4</a>
|
|
|
|
@micheleb the card seems to be seen like a NFC tag and thus opens playstore (if app not downloaded), or the app (if app is installed already). That's actually neat, and since iOS manages that since last month too, it's definitely interesting for us to evaluate how we can configure our card to be seen as a NFC tag the same way. See : <a href="https://www.youtube.com/watch?v=rkjBlAbdPSM">https://www.youtube.com/watch?v=rkjBlAbdPSM</a>
|
|
|
|
@denis-sharypin some UI flows on their youtube channel for instance <a href="https://www.youtube.com/watch?v=crOQrPIFh1A">https://www.youtube.com/watch?v=crOQrPIFh1A</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-02 13:57</div><div class="msg">NFC tag that opens url if Status isn't installed is super cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-02 13:57</div><div class="msg">yeah just got the same thought</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-10-03/448433513781_35b198abdf960e874693_72.png" /><div class="message"><div class="username">jarradhope</div><div class="time">2018-10-02 13:57</div><div class="msg"><a href="https://www.youtube.com/watch?v=xhy7dXWjpAA">https://www.youtube.com/watch?v=xhy7dXWjpAA</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-02 13:59</div><div class="msg">some references from competitors</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 14:09</div><div class="msg">@micheleb about 1) ok understood. We can detect this case at different time in the flow (anytime a card is presented and we do the check actually) then shouldn't we decide that deletion+reinstallation of the applet will be done only if the user is currently taping his card in the context of an account creation or import?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 14:10</div><div class="msg">about 2) ok - I update the doc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:40</div><div class="msg">I would say the applet is reinstalled every time it is already installed and key = status</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:41</div><div class="msg">it shouldn't happen often anyway, it is only 2 more APDU after install to get it to the correct state</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:44</div><div class="msg">all we must do is ask NXP if the card we have supports that and which API it provides to Javacard applets. If there is any public one or only proprietary</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:44</div><div class="msg">it is for sure not part of the standard Javacard platform, but ETSI also specifies additional APIs which cards can implement and they are also open so it wouldn't be a problem to use them if supported by the card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:48</div><div class="msg">actually, I have found this <a href="https://github.com/OpenJavaCard/openjavacard-ndef">https://github.com/OpenJavaCard/openjavacard-ndef</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:49</div><div class="msg">it does not require any additional API but it is strange if it works with iOS. I will investigate that and let you know within the next few days</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:49</div><div class="msg">otherwise we query NXP about that, ok?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 14:49</div><div class="msg">I mean if this does not work</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 15:11</div><div class="msg">one remark about iOS : iOS NDEF tag reading from background will only be supported by iPhone X (r or s or max) . Stated here in the pres at 3:01 <a href="https://developer.apple.com/videos/play/tech-talks/702/">https://developer.apple.com/videos/play/tech-talks/702/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 15:13</div><div class="msg">Let's hope NXP have some native support for NDEF tags for that, otherwise we'll have to upload one applet at the factory ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 15:16</div><div class="msg">@micheleb @guylouis will the final applet be in the Status app? or fetched from somewhere?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 15:18</div><div class="msg">we will have for sure to implement that ourselves and upload it at the factory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 15:18</div><div class="msg">but it is an easy applet, no custom installation parameters, no secrets</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 15:18</div><div class="msg">we will of course separate it from the main applet</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 15:19</div><div class="msg">ok, got you !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-02 15:20</div><div class="msg">I think it should be bundled in the app, since it is not going to be updated unless there is a major upgrade, no?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 15:20</div><div class="msg">yes I think so, just wanted to see if there were other thoughts :wink:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-02 16:06</div><div class="msg">*SOURCING UPDATE HWlite@SELP/* SELP is a french factory recommended by NXP for our project. After some back and forth, I have a complete offer from them for HW lite. It's in french but here's a summary:
|
|
- *Product* : NXP JH082 card, contactless or dual interface, just change Gpkeys, not applet loading, side+front printing, mate finishing
|
|
- *Card price* : contactless card, _without packaging or shipment_, *1.72? for a 10k order, 1.46? for a 100k order*
|
|
- *Options* cost (for 10k order) : dual interface +0.48?, selective varnish (+0.05?), gold/silver printing (+0.2?), side printing (+0.22), packaging (the most simple one which is like a booklet with card glued + one paper glued, see pdf) : 1.05?, if we decide to have an applet loading (for NFC tag feature for instance) there will be a slight upcost too
|
|
- *lead times:* 10 weeks to supply NXP chips (will be shorter from second order onwards if we have recurring volumes) + 6 weeks for SELP to manufacture
|
|
- *payment terms:* 50% on order , 50% at delivery. I expect to negociate that from second order.
|
|
- for other qtities quotes, please check doc below
|
|
|
|
I am expecting a quote from Austria Cards in the coming days it will allow us to benchmark prices. Please note that Austria cards does not offer custom packaging capabilities,they only do standard letter, card is glued on a A4 paper, and they can insert a leaflet in the enveloppe.
|
|
|
|
*Conclusion for now:*
|
|
- NXP card has proven to be far superior (support for ec end point multiplication & overall faster) technically to ACS one, support from NXP is really good, this factory is very professional and flexible, and pricing is not much more expensive than ACS (2.12$ for 2k-5k order of card only).
|
|
- Let's wait for Austria cards quote, but for now, my opinion is that we have all reasons to proceed with SELP, what do you guys think ? SELP is sending to me packaging samples, plus card options sample. I'll take pictures and send the samples to you @alex118
|
|
- If we proceed with SELP next steps I see : I will go and visit them, lock an order asap (long lead times), and we will define the packaging (see if we look for something better than their current proposal, they have already provided a document with some other options), and a possible enveloppe.
|
|
- an other side remark: impressive to see packaging cost >50% of the card
|
|
- now that we have prices confirmed for this option, we can start to really brainstorm on how we will distribute this, I'll kick off some discussions.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-02 17:51</div><div class="msg">Hey, check out the prototype of the main card set up flow <a href="https://invis.io/PSOD2QGCADJ#/323086657_Signup">https://invis.io/PSOD2QGCADJ#/323086657_Signup</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-02 17:52</div><div class="msg">cc @obi we still have a chance to change some copy and test it out in this flow. Please leave comments in Figma</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-02 18:57</div><div class="msg">Merci @guylouis I?m looking forward to seeing them!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-02 20:21</div><div class="msg">I would like it to be usable both with NFC and a usb reader so that it could be used in go-ethereum and status desktop as well. What do you think @guylouis?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-02 20:35</div><div class="msg">nice work!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-02 22:52</div><div class="msg">Thanks, Denis. Only one small nit about the factory blank state. See my comments in Figma. Also, there's now a discrepancy between the landing page: `keycard` and the website, which still refers to it as a `hardwallet`. Will the website be shown during testing? cc @patrick771</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 06:55</div><div class="msg">thanks Obi, good catch! Maybe we should not include this into testing. For a context a tap on the Information icon in the top right corner opens a webpage <a href="https://invis.io/PSOD2QGCADJ#/323087309_Hardwallet_Product_Screen-3x">https://invis.io/PSOD2QGCADJ#/323087309_Hardwallet_Product_Screen-3x</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 07:14</div><div class="msg">@obi Yeah, good question. Was planning to leave this up to participants and see if they discover on their own. On the other hand, it could be a good mini exercise to have them review the content and see if matches their expectations after set up.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 07:19</div><div class="msg">So, it's possible that they will see website during set up flow but not likely.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 09:58</div><div class="msg">:man-lifting-weights: Denis ! some feedback (mainly about wording )
|
|
- step 1/5 : 'generating device pairing codes', well these are card (and not device) pairing code. I imagine it's itentional not to mention PUK to make it simple and not confusing for the user right ?
|
|
- step 2/5 : "Pairs the card to a different device with the same account on it" actually it's not necessary to say "with the same account on it".
|
|
- step 3/5 : @micheleb is this step really lasting 30s ? the client needs to randomize gp keys, pair the card, anything else ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 09:58</div><div class="msg">- step 3/5 : when the message displayed is "card is ready", don't we want to tell the user a bit where he is in the process and what's next ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-10-03 10:09</div><div class="msg">just a thought - if we have any important artifacts (pdfs, specifications, designs) - lets move it all to Google Shared drive, so it won't be lost when we move to Status Desktop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:17</div><div class="msg">yes - great idea. From now on, we can use this folder in Gdrive : Status Drive/Product/Hardware wallet lite/</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:17</div><div class="msg">I just sent to you guys an invite to use Gdrive</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-03 10:20</div><div class="msg">Depends where we generate and load keys, but is not 30 secs</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-03 10:20</div><div class="msg">Not with NXP card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:32</div><div class="msg">ok, for the CCS diagram I updated the following way</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:34</div><div class="msg">The file can be opened here :</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:34</div><div class="msg"><a href="https://drive.google.com/open?id=1e9voWqQP8WHcuh29X1oSPa0OlKEhdJWp">https://drive.google.com/open?id=1e9voWqQP8WHcuh29X1oSPa0OlKEhdJWp</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:35</div><div class="msg">and ask PIN added to in flow 5 too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:35</div><div class="msg">file here :<a href="https://drive.google.com/open?id=1Ch3Ab_evlxvqjokq447Ab77D7xz-NJyg">https://drive.google.com/open?id=1Ch3Ab_evlxvqjokq447Ab77D7xz-NJyg</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:36</div><div class="msg">@denis-sharypin should we have them in figma too to faciliate collaborating ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:40</div><div class="msg">wording on the blog post was changed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 10:44</div><div class="msg">As for naming, I like "Status keycard". "Key for status" sounded like it's for Status only, because of the 'for' actually, and yeah seemed to locked us in Status ecosystem. We can imagine nextgen payment terminals where you can pay with your Visa, your Apple pay etc. and your "Status keycard".</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-03 10:58</div><div class="msg">wat no kudos in the waning days of slack, @guylouis? lol</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-01-24/304281668629_99d09ae86c8e0a04b52d_72.png" /><div class="message"><div class="username">growbot</div><div class="time">2018-10-03 10:58</div><div class="msg">The Disco trial has ended.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 11:18</div><div class="msg">Yeah but we have right now such naming convention: Status Incubate, Status Studio and it doesn?t mean that these projects work for Status ecosystem only but they are part of it for sure. And nothing wrong with that from my pov</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 11:21</div><div class="msg">@guylouis good ones! cc @obi to think about</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 11:22</div><div class="msg">@micheleb shall I drop the mention of time estimations since it depends of different factors? wdyt?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-03 11:24</div><div class="msg">Since now there is no step which is supposed to take more than 15-20 secs you could just write "a few seconds"? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-03 11:24</div><div class="msg">And even there, only the applet installation will take that long, the other steps should be below 10s</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 11:25</div><div class="msg">Sounds good!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 11:26</div><div class="msg">my 2 cents. For desktop: this could make sense if 1-desktop is bound to become a wallet too. One can think it could remain linked (like wallet connect) with the mobile for signing. 2- we supply a usb-card reader. I consider they are very very far from being a commodity. We can buy some on amazon for sure (e.g. <a href="https://amzn.to/2NjEtih">https://amzn.to/2NjEtih</a>), but for geeks and not for a non-tech population which will get lost in descriptions.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 11:26</div><div class="msg">For go-eth I don't get your point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 11:29</div><div class="msg">Nick Johnson branch works on go-ethereum, so it will support smartcards via usb, but if ours doesn't wotk with the reader, it won't be usable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 11:50</div><div class="msg">the point is that we would miss compatibility with desktop wallets based on go-eth right ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 12:18</div><div class="msg">Hey <!here>. I?m doing some testing for tomorrow?s user study. Can anyone here help me out by clicking on this zoom link and tell me what you can see/hear?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 12:18</div><div class="msg"><a href="https://zoom.us/j/413808891">https://zoom.us/j/413808891</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 12:21</div><div class="msg">I'll keep this on until 2:30. But you should see a phone and card.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 12:22</div><div class="msg">more in general if that pull request will be merge on go-ethereum, it means that geth will be compatible with smartcards, so it would be nice if we can use our card. and also for our desktop at least to "download" the whisper key</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 12:23</div><div class="msg">@patrick771 I can see card and phone in your hands</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-03 12:23</div><div class="msg">I see your phone and can hear you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 12:24</div><div class="msg">what about audio?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 12:24</div><div class="msg">I hear "testing"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 12:24</div><div class="msg">yeah I can hear you fine</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 12:24</div><div class="msg">ok, thanks all!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 13:23</div><div class="msg">Got you about the whisper key for desktop.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 13:23</div><div class="msg">I have asked a couple chinese vendors for quotes about usb-contact reader and usb-nfc readers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 13:23</div><div class="msg">that will also help take a decision</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 13:25</div><div class="msg">do you mean shipping the card with the reader? I think we could ship only the card but an "advanced" user has the ability to buy a reader and use it with our card, what do you think?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 13:25</div><div class="msg">yes, but in this case this advance user can buy a usb-nfc reader already isn't it ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 13:27</div><div class="msg">like <a href="https://amzn.to/2P87jEj">https://amzn.to/2P87jEj</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 13:56</div><div class="msg">yeah it makes sense, I would like to try one to see if it's compatible with the cose already started by Nick Johnson</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 14:03</div><div class="msg">cool, yeah order one then, and let us know that will be interesting to know !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 14:03</div><div class="msg">I'll do it!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 14:28</div><div class="msg">I finished the go version of the installer and it works. I'm going to polish it today and tomorrow and then I'll open a PR</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-03 14:29</div><div class="msg">How about simply `Generating pairing codes` or `Generating unlocking & pairing codes` @guylouis Also, updated step 2 to `You?ll need this to pair the card
|
|
with another device.` fyi @denis-sharypin</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 14:31</div><div class="msg"><!channel> for those who feel ready (well dare would be more appropriate) to dive in to status desktop for group communications, I created a #hardwallet-lite channel in status dekstop.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 14:31</div><div class="msg">cool let's do it! we can also use `#status-hardwallet-lite` with the prefix like other channels</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 14:32</div><div class="msg">yep you're right let's use #status-hardwallet-lite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-03 14:32</div><div class="msg">and lite or light like in the idea repo title?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 14:32</div><div class="msg">For those I chat with in mp, feel confortable using status too, I now check it often :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 14:34</div><div class="msg">However for #status-hardwallet-lite please remember this is a public channel, so we should not share their competitive informations (prices for instance, or choice of supplier while we're chosing) or documents under NDA (not the case for hardware wallet lite for now) :warning:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 15:33</div><div class="msg">@andreaf I have downloaded your latest apk (v0.3), and here's a video where I try to install the app. First you see I struggle a bit to start the installation, then when I succeed to start it goes but ends up with a crash. I never managed to make it end without a crash. let me post the video :</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 15:37</div><div class="msg"><a href="https://photos.app.goo.gl/yzbQAhsPBSXQ3xnr5">https://photos.app.goo.gl/yzbQAhsPBSXQ3xnr5</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-03 16:03</div><div class="msg">Hey all. Heads up that we have 4 user study sessions tomorrow and 1 Friday on testing the onboarding flow.
|
|
|
|
I've linked the script below. Feel free to have a look and add comments or questions if necessary. Everyone on the HW-lite team has been invited into sessions but please do let me know if there is anyone that you think should be invited. For each session there will be a zoom link in the calendar invite that you can use to dial in and observe. All sessions will be recorded and distributed after the study.
|
|
|
|
Note that I?m testing out a set up for this study where stream a mobile camera to a zoom channel from a conference room I've rented out and I'll run through some testing in the morning before the first session to make sure things are running smoothly but do ping at any point if there is anything up with the video / audio. Thanks!
|
|
|
|
Plan / script link: <a href="https://docs.google.com/document/d/1ZpgpAYfHC57iEvalLMhpjOJPkfzLvjx309lBdjAlDjg/edit">https://docs.google.com/document/d/1ZpgpAYfHC57iEvalLMhpjOJPkfzLvjx309lBdjAlDjg/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 18:14</div><div class="msg">:eyes:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-03 18:17</div><div class="msg">sounds fine to me - it seems that any way at this stage, users won't understand what this is about very precisely ... so maybe the first one "Generating pairing codes" is better</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-03 18:21</div><div class="msg">I have added those changes to the prototype, thanks everyone</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-04 07:09</div><div class="msg">:eyes:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 07:32</div><div class="msg">does it work with the other phone?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 08:10</div><div class="msg">Ok, I have found more information and understood why the first time I looked into NDEF tags, it looked like we couldn't implement that. I was looking for the specs written about a different type of NFC tag.
|
|
|
|
All we need to do is implement an applet and install it with AID D2760000850101 and have it handle some standard commands. There are a few opensource implementations, I will find one with suitable license (I would avoid GPL), fork it and adapt to our needs. On iOS it still wouldn't help very much, all it could do is open an URL but it still wouldn't work as a wallet. On Android on the other hand it could be quite useful to get the app installed.
|
|
|
|
However, I was having a second thought about that. If we provide that, we invite the user to download the status client by tapping the card. It is all fine and dandy, but what if a fake card is shipped by an evil distributor and now the card points to a fake client? Is the convenience worth the risk? It is a "cool" feature, flashy and nice to show at demo, but how much time does it really save to the user?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 08:12</div><div class="msg">well the app (even v0.3) on the other phone can't detect my card. I guess the app is in a strange state (like the video I sent last week)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 08:13</div><div class="msg">I see the card was continuosly connecting and disconnecting. this happens to me when I keep the card in the wrong position so maybe there's another position where it works fine. but it shouldn't crash so I'll check it in the afternoon. this morning I'm doing the last things in the go version, and maybe we can start testing that one as well</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 08:17</div><div class="msg">I see you're copying the diagrams to figma, that's great and will be very helpfull in the long run for sure.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-04 08:25</div><div class="msg">@guylouis Yep I think it will help me and Obi keep on track all possible cases</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-04 08:25</div><div class="msg">thanks for this btw! really helpful!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 08:56</div><div class="msg">If you're observing the first user study session here is the zoom link: <a href="https://zoom.us/j/483395553">https://zoom.us/j/483395553</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 08:57</div><div class="msg">Just remember to mute your audio when you arrive in the meeting room</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 08:58</div><div class="msg">so do we want to proceed and do it?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:02</div><div class="msg">@corey122 what do you think about this ? convenience vs security risk :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:18</div><div class="msg">from a convenience point of view I find it really great. With Android @dmitryn had confirmed we could have the tag 1-show up <a href="http://status.im">http://status.im</a> in play store if it's not installed yet 2.launch status app if status is installed. Which is great. Now we have two questions more :slightly_smiling_face:
|
|
- can we have the same behaviour with iOS ? it seems the tag can trigger apps, but can it handle the same scenario as android (depending on if app is installed/not installed)
|
|
- if yes, can the same tag works with android and iOS with this beahviour ? if not can we have our card behave as two concurrent tags ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:19</div><div class="msg">for iOS <a href="https://developer.apple.com/videos/play/tech-talks/702/">https://developer.apple.com/videos/play/tech-talks/702/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:21</div><div class="msg">@guylouis but the card does not work with iOS as a wallet. Do you want to use it as a trigger only?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:24</div><div class="msg">regarding security, a compromise could be that the NDEF applet is also installed together with the wallet applet. Then it cannot be used to install the client but only to start it after the first setup.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:26</div><div class="msg">"but the card does not work with iOS as a wallet." I don't get that, would you elaborate please ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:28</div><div class="msg">we are developing the pro wallet also because apple at the moment does not support sending custom APDUs to NFC tags, so the hardwallet is not compatible with iOS. We discussed that already I think</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:28</div><div class="msg">God !! sorry I am out of my mind this morning</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:28</div><div class="msg">ok good, I thought I had missed the episode where Apple enabled this feature :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:28</div><div class="msg">was carried away by this nfc thing :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:30</div><div class="msg">I will develop the applet, it is a 1-2 days thing anyways. We will then decide if and how to use it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:30</div><div class="msg">I mean, as a trigger after initial setup is still useful and does not have the security issue I have mentioned before</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:31</div><div class="msg">cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:32</div><div class="msg">as for the security part, let's see what @corey122 thinks about it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:33</div><div class="msg">when I see that when I type "status" in play store, I don't get our app in the first screen, still it makes me think it would be quite cool to have that</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:34</div><div class="msg">do we want to fix a date when hardwallet and hardwallet-pro channels on Slack will be replaced by equivalents in Status? @guylouis already created a channel there, but having 2 parallel channels is not going to work until we shut this one down :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:36</div><div class="msg">yeah but you can do <a href="http://Status.in">http://Status.in</a> instead of <a href="http://Status.im">http://Status.im</a> and deliver such a card. I am aware that it is convenient, but I will not sleep good at nights :joy: But let's hear more opinions, of course</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:37</div><div class="msg">True, first off I think #hardwallet-pro really needs private group feature (currently in WIP in status) especially at this stage where we discuss competitive infos (what do you think ?), for #hardwallet we can probably live with a public channel.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:37</div><div class="msg">Still to decide for a date, I think we need more onboarding to Status, everyone needs to be ok with shutting down slack</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:38</div><div class="msg">Let's put that in the agenda of tuesday weekly sync</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:38</div><div class="msg">I will try to get the desktop client work on Windows... unfortunately many of the tools needed for the hardwallet-pro development are windows-only</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:38</div><div class="msg">ok</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 10:45</div><div class="msg">maybe some android emulator on windows ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:45</div><div class="msg">mmm I will just check if the compilation instructions happen to work for windows too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 10:46</div><div class="msg">with the usual cygwin or mingw environment addition... I mean it is a Qt + React app. Qt supports windows and react is Javascript so it should be possible</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 10:51</div><div class="msg">Heads up that if you're going to observe the second session in 10 minutes (1:00 CET) there is a new zoom link: <a href="https://zoom.us/j/673899697">https://zoom.us/j/673899697</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-04 12:02</div><div class="msg">I'm in a meeting, I will respond to this threat afterwards. Thanks for looping me in</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 12:19</div><div class="msg"><a href="https://zoom.us/j/629736708">https://zoom.us/j/629736708</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 12:20</div><div class="msg">Here is the link for the 2:30 session</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 12:49</div><div class="msg">Hi, we'll have to present hardwallet at next townhall on monday. We have about 8 minutes to present (which is in fact quite short) + QAs. Any inputs on what you want to present there ? I had in mind to do a general update like : intro (what it is we're trying to do and why), and then update on : product definition (flows, uxr), development, sourcing, and then elaborate on next steps.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 12:50</div><div class="msg">what you guys think ? any suggestion of things you want to stress on ? or demo ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 12:51</div><div class="msg">@guylouis I think I'll be able to open a pull request on status-go by monday, so we can also say that we have the "installation" part implemented in go</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 12:51</div><div class="msg">ok cool</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 12:51</div><div class="msg">we can share the results of the security audit :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 12:51</div><div class="msg">:sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 12:52</div><div class="msg">do we have the result?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 12:52</div><div class="msg">nope</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 12:52</div><div class="msg">ah ok :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 12:53</div><div class="msg">we should have got them yesterday.. that was the promise</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 12:54</div><div class="msg">the NDEF tag applet might be ready by monday</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-04 13:11</div><div class="msg">so if we use it it will be an applet preinstall when you receive the card right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 13:11</div><div class="msg">I think that having it preinstalled is a bad idea, because if a malicious card replaces the real one, a malicious client would be installed instead of ours, this is something we are discussing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 14:03</div><div class="msg">Thanks everyone for tuning in today! Last study session is on <a href="https://zoom.us/j/169107197">https://zoom.us/j/169107197</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 15:24</div><div class="msg">kudos @patrick771 for handling that, this was quite informative !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 15:28</div><div class="msg">ok, it is ready by today</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 15:29</div><div class="msg">check the channel on Status :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 15:33</div><div class="msg">there are a few decisions to take to make it final</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-04 15:34</div><div class="msg">1) Now we only have a single record, the AAR (Android Application Record). Do we need anything else?
|
|
2) If we install the applet together with the hardwallet applet, we might package them in a single package, otherwise it must be two separate packages
|
|
3) If we package them in the same package, the apps will be able to share some memory if we want. This means we could at least in theory change the tag value dynamically since the main applet could update the tag (without making the tag applet handle separately PIN, secure channel, etc)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 16:38</div><div class="msg">but it's a pull request on which branch ? go-status ? or go-eth ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-04 16:38</div><div class="msg">sorry if question is stupid, I wonder since there was some work done by nick johnson on go-eth</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-04 20:39</div><div class="msg">Here is the video file folder from today?s sessions sorted by participant and includes chat transcripts from Zoom for each session: <a href="https://drive.google.com/drive/folders/153CC6-v-Ivg9NW06KJKsi0Mz4LzCkZKK">https://drive.google.com/drive/folders/153CC6-v-Ivg9NW06KJKsi0Mz4LzCkZKK</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-05 07:55</div><div class="msg">Hey all! Last session for this week is starting at 10:00 CET. Here is the zoom link: <a href="https://zoom.us/j/116791568">https://zoom.us/j/116791568</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 08:08</div><div class="msg">awesome!! so that applet needs to have a specific aid so that it's automatically called right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 08:09</div><div class="msg">yes, correct</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 08:09</div><div class="msg">I will use he's branch on our status-go but eventually I hope to send a pull request to go-ethereum</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 08:10</div><div class="msg">in my opinion, if we install it together with the wallet applet, we can package them in the same cap file and then just issue one extra install command. I have tried this option already and it works</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 08:13</div><div class="msg">nice!! and then a user will use it to open automatically the app or to go to the store when using a new phone without status installed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 08:13</div><div class="msg">:+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-05 08:51</div><div class="msg">WOW</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-05 09:25</div><div class="msg">hey, hardwallet team, please remember to join <a href="http://get.status.im/chat/public/status-townhall-logistics">http://get.status.im/chat/public/status-townhall-logistics</a> today to participate in slidedeck updating for TH next week since you're scheduled to report ... looking forward to an overview of the test-results :-)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 12:14</div><div class="msg">ok thanks</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 14:31</div><div class="msg">Hi guys, here's a draft pres for Town Hall. 8-10 min is a real short time. I can present the whole thing of course, let me know if you prefer to present some part of it. I will replace the pictures by the real video for NFC tap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 14:31</div><div class="msg"><a href="https://docs.google.com/presentation/d/1Zuc8lUbHfOc27Fse2fL_Xyfv56MBCHOb6iyvtpXAYYA/edit?usp=sharing">https://docs.google.com/presentation/d/1Zuc8lUbHfOc27Fse2fL_Xyfv56MBCHOb6iyvtpXAYYA/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 14:32</div><div class="msg">Please let me know your feedback, if I forgot things, or some point do not matter to be precised</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 14:32</div><div class="msg">Thanks !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 14:33</div><div class="msg">For user sessions findings, what would you suggest @patrick771 ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-05 15:04</div><div class="msg">can you use this card designs please?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-05 15:04</div><div class="msg">that one in the deck has wrong color and logo</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:04</div><div class="msg">yep, great</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:09</div><div class="msg">FYI, first quote from a USB-contact reader : 3.8$ for 500 pcs (FOB China)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:12</div><div class="msg">nice! would it be for our users? or just for the team?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-05 15:12</div><div class="msg">looks so so</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-05 15:12</div><div class="msg">if it will be for users</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:13</div><div class="msg">If it is for the users, I would say it is rather large, ain't it? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:13</div><div class="msg">@micheleb for the secure channel the mac is generated using DES and our go linter of course fails saying "Use of weak cryptographic primitive". it should *not* be a problem in our case because we use a triple des for the mac but not for encrypting commands data, is that correct?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:13</div><div class="msg">yes for users</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-05 15:13</div><div class="msg">Thanks for pulling this together @guylouis I am putting in some high level findings now with some tweaks. Will refer to it as smthg like `Onboarding user study findings`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:13</div><div class="msg">yes it's big</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-05 15:13</div><div class="msg">also, do you mind giving edit access?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:13</div><div class="msg">but interesting to know the price range</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:13</div><div class="msg">:+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:14</div><div class="msg">Have we decided to bundle a desktop reader or is it just an option? </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:14</div><div class="msg">really just an option</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:15</div><div class="msg">we're not even sure desktop will have a wallet implemented actually</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:15</div><div class="msg">Oh, I really hope it does. I will use it</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:17</div><div class="msg">in any case, if we want to do that we'll need something nicer and take into account the desktop might me usbc only</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:17</div><div class="msg">Yeah, I mean we could just let the user buy it separately </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:18</div><div class="msg">The only universal option is Bluetooth reader, that works virtually on all modern computers</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:18</div><div class="msg">But it is more expensive </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:18</div><div class="msg">this one is nice (comes with cool wallet S) and has a USB-micro usb cable so a mac user with USBc can use a USBc to micro usb cable</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:19</div><div class="msg">Otherwise USB with detachable micro USB connector </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:19</div><div class="msg">Yeah</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:20</div><div class="msg">I think desktop should at least support the card for authentication and to download the whisper key. I would love to use it that way. Maybe we can say that in the town hall so that we can have some feedback</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:20</div><div class="msg">:+1:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:20</div><div class="msg">Yeah, the desktop has even weaker security </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:21</div><div class="msg">I really wouldn't want to store keys there</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:22</div><div class="msg">I mean the OS itself especially if we are talking about Windows </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:23</div><div class="msg">3DES is only for the applet installation</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:23</div><div class="msg">We could use SCP03 with the NXP cards in theory</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:24</div><div class="msg">That one is based on AES</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-05 15:25</div><div class="msg">Or I would recommend:
|
|
A) All participants successfully set up without critical usability issues
|
|
B) Need for more clear descriptions at each step
|
|
C) Key use cases are unclear. Is it a credit card? Security card?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:25</div><div class="msg">is DES a problem for the mac generation or is it good enough just for that? scp02 should anyway support AES for the encryption part if I understood correctly</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:26</div><div class="msg">sure</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:26</div><div class="msg">actually the real file is now here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 15:26</div><div class="msg"><a href="https://docs.google.com/presentation/d/1_krAv51BBPylbe1AhMwrgJbhpJA5DHvXWfv7hlkRe0M/edit?usp=sharing">https://docs.google.com/presentation/d/1_krAv51BBPylbe1AhMwrgJbhpJA5DHvXWfv7hlkRe0M/edit?usp=sharing</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:27</div><div class="msg">No it is 3DES all the way. Actually 3DES is not bad but it is slower. If we go for SCP03 then we cannot use the ACOSJ cards anymore..but it is not such a big issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:43</div><div class="msg">I see! what do you think? for the end version I think SCP03 would be better but for now some people only have acosj cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:44</div><div class="msg">Yeah I also vote for SCP03. The problem is that we must also replace gpshell with something else (maybe gpj has SCP03?) </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:44</div><div class="msg">I would say we must plan using SCP03 </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:45</div><div class="msg">what do we need gpj for? if it's only for install/delete the applet I finished today a command line executable in `status-go`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:45</div><div class="msg">here is a WIP pull request <a href="https://github.com/status-im/status-go/pull/1228">https://github.com/status-im/status-go/pull/1228</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:46</div><div class="msg">Yeah for the testing environment </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:47</div><div class="msg">next week if you want I can show you how to install it, it would be nice if you can try it for testing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:47</div><div class="msg">Ok, great! </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:51</div><div class="msg">I would need to implement the wrapper for scp03 though, but I don't think it will take too long. we can also support both since the scp02 one is already implemented</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:54</div><div class="msg">It is possible, yes. The important is using security level 3 to encrypt the APDUs since they carry the secrets. I think SCP02 is not less secure from this point of view.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:55</div><div class="msg">Actually thinking about it, since the keys are known it is possible to reconstruct the session keys from a log</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:56</div><div class="msg">This means installation is not safe from MITM </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 15:59</div><div class="msg">Of course MITM is not very easy to perform with NFC but still, if we want to secure this step we must think of something</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 15:59</div><div class="msg">yeah the only thing the changes in the session key derivation is the sequence number so it's very easy to try all the keys</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-05 16:06</div><div class="msg">well yeah not only that but if the keys are known it's easy </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:06</div><div class="msg">Yeah it is easy to decrypt the log. The log must exist for that to happen, of course</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:07</div><div class="msg">But basically is the same as no secure channel </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:09</div><div class="msg">Mmm I will think of something. I have a half-idea already which would protect at least from passive MITM and log decryption. Of course this will require a change in the installer</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:11</div><div class="msg">Good that you brought the topic up, the security audit did not take care of how we install the applet and we had ignored this aspect </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-05 16:21</div><div class="msg">great that you guys identified that :sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:21</div><div class="msg">yeah, it is not such a big issue actually, I mean try placing a packet sniffer between the card and the phone without the user noticing</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:22</div><div class="msg">if you compromised the phone already at that stage you have won anyways</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-05 16:22</div><div class="msg">so the only possible attack is physically placing something between the two devices :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:06</div><div class="msg">@alex118 I received some cards from SELP to illustrate their printing capabilities. I can send them to you, can you mp your adress ? . See pictures here <a href="https://photos.app.goo.gl/4axGVvJVmM97pjrw9">https://photos.app.goo.gl/4axGVvJVmM97pjrw9</a>
|
|
We can see in particular the cosmetic options : shiny varnish ( can be selective see GIFT card & fnac one), silver and gold printing (fnac, dior, gigi hadid), color side printing (decathlon)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-08 08:16</div><div class="msg">@guylouis :thanks: - GIFT is looking most on brand as an eg. The spot UV finish (clear ink) of the chameleon could be used nicely for some subtle detail. Sure, will send through my address. Did they send any external packaging?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:18</div><div class="msg">they did not send packaging, I will ask them today, it's important we got some ...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-08 08:21</div><div class="msg">Been thinking about card design as well. Would it be great to a have a transparent card with minimum branding? We can put a lot of thoughts in that design. The card is your secret, it should be hidden somewhere in you wallet and it's easy to do with the transparent design. Also in Status transparency vs privacy is a big topic and card design is somehow continue this discussion. Maybe everything above is my overthought, haha</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-08 08:22</div><div class="msg">Nice but we have a coil inside the card, so if you make the plastic transparent you see the copper NFC coil</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-08 08:24</div><div class="msg">yeah, I know, I have a transparent card from german bank and those copper coils look great</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-10-08 08:44</div><div class="msg">you should take a full-card picture @denis-sharypin also both sides and cvs code should be visible :sweat_smile::sweat_smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-08 08:45</div><div class="msg">almost got me! @nastya :grimacing:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-10-08 08:45</div><div class="msg">i like this idea personally! sounds great!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:46</div><div class="msg">@micheleb @corey122 let me share here the security audit draft provided by zklabs on friday. The document is amended by michele with remark/questions he has for zklabs.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:48</div><div class="msg">@corey122 for Town Hall, if you want to give an update on this, I guess you can say we finally received an audit draft. That is has some architecture suggestions, research points, and software audit results.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:49</div><div class="msg">That most of these points (some might be relevant, some are much less) will need to be discussed.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 08:50</div><div class="msg">One interesting/important point is on the sofwtare part, michele says that "basically wherever there is a potential problem with the platform, they prompt us to come up with test vectors and write tests. I think this is well within the scope of what they must do for the audit "</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-10-08 08:52</div><div class="msg">so it's both transparent and private? :mindblown:</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-10-08 08:53</div><div class="msg">what was your childhood pet name again? :evil:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-08 08:54</div><div class="msg">@guylouis BTW I want to implement a solution for the install parameters weaknesses. I will have it done by Wednesday, I already devised the scheme and discussed with @andreaf the client-side implementation </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-08 08:55</div><div class="msg">my macbook pro keyboard doesn't work anymore :( I'm going to buy an external one so I'll be afk a little bit </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-07-31/220671542518_0d49983291e646e395f0_72.jpg" /><div class="message"><div class="username">nastya</div><div class="time">2018-10-08 10:03</div><div class="msg">just received my card! thanks @rajanie :raised_hands:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-08 11:28</div><div class="msg">thank you</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-24/320320314756_fe0f3ce0bb820f1aa8e3_72.jpg" /><div class="message"><div class="username">dmitryn</div><div class="time">2018-10-08 11:40</div><div class="msg">Received my card today as well, thanks @rajanie</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-19/440171298119_1331b900dfbaec04dc89_72.jpg" /><div class="message"><div class="username">bruno412</div><div class="time">2018-10-08 12:28</div><div class="msg">I would love to play around with the card prototype. Also I volunteer <a href="http://Bitfalls.com">http://Bitfalls.com</a> to distribute the card in Croatia for just costs covered. I can also offer it on <a href="http://Coinvendor.io">http://Coinvendor.io</a> (my OTC desk crypto-onramp) as a direct purchase solution. If we can get it to an MVP of some kind by December, I would be happy to distribute the card in swag at <a href="http://Blockconf.io">http://Blockconf.io</a>. Anyway, let me know how I can help with this.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-01/375000796951_78d872be972af4441b52_72.jpg" /><div class="message"><div class="username">exiledsurfer</div><div class="time">2018-10-08 12:29</div><div class="msg">**That Marketing Guy** lol</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 13:56</div><div class="msg">Thanks for all this, pretty exciting ! as soon as we have a first app to test, we'll get you a card for sure.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-19/440171298119_1331b900dfbaec04dc89_72.jpg" /><div class="message"><div class="username">bruno412</div><div class="time">2018-10-08 14:14</div><div class="msg">cool, also would be nice to be able to play with it at devcon/cryptolife </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 14:58</div><div class="msg">@alex118@obi I had a talk with SELP (factory). As of the packaging, they proposed their simplest option because it's the only one that can be fully automated. I guess that's where there is a difference with Asia. In France and Austria, they really push to have packaging for the cards that can be 100% mechanically set-up. Sel can do anything but operations with manual work will be a problem (costly) when we reach high volumes per lot. So I suggest we check if wa can do a packaging that we like with their constraints. The type of packaging is the one on slides 6, 7, 8 here</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:00</div><div class="msg">the overall 'packaging' will be a 130mm*190mm (we can make it smaller if we wish)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:01</div><div class="msg">We can print content pretty much anywhere , on the packaging front , on the back of the cover when it's open for instance. Then we can stick our card on top, and stick another item below it.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:01</div><div class="msg">This item should be our booklet with secrets.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:02</div><div class="msg">Basically we should think about a first version of design where we see what we print where (artwork, wordings)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:02</div><div class="msg">and also what we print on the card it self</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:05</div><div class="msg">Please let me know if that is clear enough to work on this and come up with a full design porpal of the packging with this construction method.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:05</div><div class="msg">I'll get asap a couple samples of packaging based on this construction method.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:06</div><div class="msg">The open point I see is : should we add some space for the user to write down his mnemonic + PIN on the same paper where he wrote his pairing + PUK ?.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:07</div><div class="msg">the height of the booklet should be < than the eight of the card, which is approx. 0.8mm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-08 15:13</div><div class="msg">@denis-sharypin yeh these look cool, and the transparency/privacy visual metaphor works well but think we might be limited by the current manufacture. See samples <a href="https://photos.app.goo.gl/4axGVvJVmM97pjrw9">https://photos.app.goo.gl/4axGVvJVmM97pjrw9</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-08 15:46</div><div class="msg">@alex118 yeah, but probably we could ask if it's feasible or not</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-08 15:48</div><div class="msg">I guess it depends if the cards start off as solid white like the prototypes the team have been using or whether they?re clear. @guylouis would be best to advise on this</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-08 15:57</div><div class="msg">From a user perspective it's a nice convenience, but does it create security vulnerabilities. That is, encouraging them to store all of this together - does it make it more hackable? I recall one user in testing saying he wanted tips re: how to store these secrets. We could give brief idea and perhaps have a short link to more extensive information about security e.g. <a href="http://security.status.im">http://security.status.im</a> cc @corey122</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 15:57</div><div class="msg">I will ask to SELP if they can make the card transparent then !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-08 16:11</div><div class="msg">hey, I could not finish reading & working on the audit today, and must be afk now. I'll have a proposal of answers and maybe additional questions by tomorrow :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-08 16:32</div><div class="msg">:pray:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-08 17:06</div><div class="msg">this is a good idea.</div></div></div><br/>
|
|
<div><img src="https://secure.gravatar.com/avatar/a5f396eba057f6f6ce181fd462ff2b1a.jpg?s=72&d=https%3A%2F%2Fa.slack-edge.com%2F66f9%2Fimg%2Favatars%2Fava_0025-72.png" /><div class="message"><div class="username">goranjovic</div><div class="time">2018-10-09 07:10</div><div class="msg">Apologies everyone, can't make it for the call, got some emergency repairs.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 07:57</div><div class="msg">I wrote in status yesterday but after the update I don't even see my messages so I write it again here:
|
|
|
|
I received the usb contactless reader. with jcop3 it doesn't work, it doesn't see the card. with acosj everything works but it fails at the last command (install for install), and then the only way to use it again is disconnecting and connecting back the reader to the usb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 07:57</div><div class="msg">what reader is that?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 07:58</div><div class="msg">acs122u-a9. is it possible that it doesn't support iso7816?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 07:59</div><div class="msg">not really</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 07:59</div><div class="msg">or is that actually only for contact?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:00</div><div class="msg">ISO7816-4 is for all cards... but I would be surprised if it does not support that, since it claims to be a smartcard reader with PC/SC API</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:01</div><div class="msg">and with acosj it always works until the last command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:07</div><div class="msg">I know a very stable contactless reader was <a href="https://www.identiv.com/products/smart-card-readers/rfid-nfc-contactless/4711f-wsam/">https://www.identiv.com/products/smart-card-readers/rfid-nfc-contactless/4711f-wsam/</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:07</div><div class="msg">or anything from OmniKey</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:08</div><div class="msg">but it is strange the ACS one does not work properly... are you using it through a USB-hub?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:08</div><div class="msg">no without a hub</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:09</div><div class="msg">if you have a powered hub it might be worth a try, maybe it is not negotiating power properly</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:09</div><div class="msg">but powered hubs usually do not complain</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:10</div><div class="msg">I don't have a powered one, but I can see if I can find one</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:10</div><div class="msg">ok so let's consider we don't want to put PUK/PIN and account mnemonic on the same paper in any case. The next point is should we add a mnemonic paper in the packaging. The 'industrial' situation is that it's much easier to have only one booklet for SELP : if we decide to have two booklets, their automatic machine can't handle it and it will involve a specific 'human' work + a specific packaging. It is possible of course but will come at a cost for sure. So the easiest set-up is just card + one booklet.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:10</div><div class="msg">do you think that could be also the reason why it doesn't recognize the jcop3?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:11</div><div class="msg">oh... yeah it is not worth buying one just to try, without proper testing there is no way to know if that is the problem.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:11</div><div class="msg">Any thoughs on this guys ? the question is : do we need to have second booklet where the user will write down his 12 words mnemonic (maybe 24 words one day) + PIN</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:11</div><div class="msg">It could be, depending on how much the card consumes etc</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:12</div><div class="msg">if reader + card > 250mA then I think it should ask more power to the device</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:12</div><div class="msg">but you should see some glitches like blinking leds most likely</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:13</div><div class="msg">during the installation the light is always off</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:13</div><div class="msg">it's red with no card and green when I put the card on</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:13</div><div class="msg">and when you put jcop3 there is no reaction at all? Not even a blink of the red light?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:14</div><div class="msg">double beep blinking green and then red light on</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:15</div><div class="msg">well then in theory it could be that it recognizes the card, powers it, the system see the overload (because power was not negotiated properly) and shuts it down (reverting to red light)... but really it could be just a firmware bug, or some incompatibility... however in any case it is a bug in the reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:15</div><div class="msg">it must recognize the JCOP3 card, it is a valid card</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:16</div><div class="msg">yeah :disappointed:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:19</div><div class="msg">hi guys, for the weekly sync meeting at 11:00 here's our follow-up file. If you have any special item to discuss, you can add items to discuss there.
|
|
<a href="https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit">https://docs.google.com/document/d/13ns060aqzrp5nBK2QUDN81goO-mrSoR2LdWNMKZFqyk/edit</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:20</div><div class="msg">I listed a couple of open points, where we should discuss the next steps.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:23</div><div class="msg">I have found something interesting for @andreaf and maybe even a point in the contact/no-contact decision (if it works properly)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:23</div><div class="msg"><a href="https://frankmorgner.github.io/vsmartcard/index.html">https://frankmorgner.github.io/vsmartcard/index.html</a></div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:23</div><div class="msg">apparently it allows, among other things, using an Android phone as a contactless NFC reader for the desktop</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:25</div><div class="msg">waouh interesting. How does the desktop communicates with android phone then ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:26</div><div class="msg">I have no idea at the moment, I have literally just found it.. it has to be checked if it supports Bluetooth/USB and if it works on anything recent, since the docs mention Android 4.4...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 08:36</div><div class="msg"> interesting!</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:51</div><div class="msg">I finally read it completely. I'd like to answer to Matthew today. I read your remarks @micheleb in the pdf, and I haven't much to add. Here's a proposed reply, let me know if it's ok for you. One question though: should we ask more specific question about consequences (it's not what we're doing, but since we considered it, it's interesting) of not using EC keys for secure channel ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:52</div><div class="msg">"Hi Matthew,
|
|
|
|
Thanks for this draft.
|
|
|
|
We have studied the document and here si our feedback.
|
|
|
|
* Hashing on smartcard
|
|
The problem is not only implementing Kekkac-256. We also have to send the full transaction (which can be considerably large for data transactions) and parse the transaction. Since the card has no screen, this can only be used if we want to put hard limits on the transfered amount (which would be difficult for ERC-20 or other data transactions).
|
|
Additionally, the way it works now would actually allow supporting Bitcoins on the hardwallet, which is a point worth considering.
|
|
|
|
* Provide some ?Secure Default? schemes for pairing
|
|
|
|
In the CLIENT_NOTES.md we do suggest a scheme. The only point left open is how to generate the random password (if not selected by the user) but that is a UX concern.
|
|
|
|
* Badly implemented / malicious endpoint can wipe pairing history
|
|
This is the desired behaviour. A client should be able to unpair all other clients to allow unpair lost/sold/broken devices
|
|
|
|
* Ensure PIN length is at least 2x the # of allowed PIN attempts
|
|
PIN length is fixed at 6 digits and we only give 3 attempts. PUK length is fixed at 12 digits and we only give 5 attempts, so we already fully comply to this suggestion.
|
|
|
|
* Research / Possible Leaking Key via ECDH
|
|
The link <a href="https://github.com/licel/jcardsim/blob/master/src/main/java/com/licel/jcardsim/crypto/KeyAgreementImpl.java">https://github.com/licel/jcardsim/blob/master/src/main/java/com/licel/jcardsim/crypto/KeyAgreementImpl.java</a>
|
|
Is confusing us. That file is part of the simulator and is in no way part of the deliverable. The JavaCard is supposed to validate the supplied points internally. Please provide specific test vectors for testing this.
|
|
|
|
* Research / Possible secp256k1 implementation bug
|
|
These tests (and possibly those mentioned above) should be peformed as part of the audit on our two platforms of choice (ACS and N+XP). Please confirm where we should whip a NXP card, it can be done today.
|
|
|
|
* Code analysis / Secp256k1.java
|
|
As above, these are platform dependent and not applet dependent tests. Please perform the tests and share the results
|
|
|
|
* multiplyPoint
|
|
Since we use the KeyAgreement class for this step, the verification of the results should be performed by the platform already
|
|
|
|
* Crypto.java
|
|
Agreed, please provide test vectors
|
|
|
|
* SecureChannel.java
|
|
Yes, schemes other than CBC are not commonplace yet (not taking ECB into account of course)
|
|
|
|
* openSecureChannel
|
|
With regards to your suggestion :
|
|
Can you envision an attack scenario? The secret variable is a Clear-On-Reset array already
|
|
|
|
* verifyPIN
|
|
From our experience, the OwnerPIN.check method is possibly the most tested and hardened of the platform. There is no Java-code level implementation that could provide better security than the platform-provided one
|
|
|
|
We'll be looking forward to your feedback
|
|
|
|
Thanks, GL"</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:52</div><div class="msg">@micheleb should we be clearer on the fact we expect test codes / vectors from him ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 08:53</div><div class="msg">@corey122 from your experience, is this going in the right direction regarding the price we're paying / what we're getting ? I'd need your advice if we need to raise a concern here to him and when.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:55</div><div class="msg">the reply looks fine to me (except si instead of is and whip instead of ship :D). I think we already gave the question of what happens if we remove the EC</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 08:58</div><div class="msg">regarding the test/code vectors. I think for any claimed potential weakness they are supposed to demonstrate it in practice, otherwise it is just suppositions. The way they have formulated it so far really does not help us at all.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-09 10:38</div><div class="msg">Don?t need to read the whole thread but just pointing out that it sounds like the desktop team has wallet in the roadmap.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 10:52</div><div class="msg">@micheleb @guylouis I blocked another jcop3 card. I'm not sure how. the only thing I did was trying it with the nfc reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 10:53</div><div class="msg">but it wasn't recognized</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 10:57</div><div class="msg">now it does not work anymore with any reader, even usb?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 10:57</div><div class="msg">i mean contacted</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:03</div><div class="msg">yes not working. I'm not sure though I blocked it with the nfc reader, maybe it was during another installation but I don't remember</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:03</div><div class="msg">it might be blocked before though since I see now other jcop3 are recognized by the nfc reader</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:04</div><div class="msg">at least the reader is working then</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:06</div><div class="msg">yes, it's still failing at install-for-install for both cards</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:07</div><div class="msg">what happens in the install for install?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:07</div><div class="msg">I mean what error code do you get</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:07</div><div class="msg">it loses the connection: `scard: Transaction failed.`</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:09</div><div class="msg">oh... strange. I mean the install for install does not have any particular thing, it is not the longest apdu... maybe it takes a little more to process but I am not even sure.. in theory the card should keep communication active not to cause timeouts</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:10</div><div class="msg">yeah it weird, but it's always at the same moment, just after sending that command</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:10</div><div class="msg">what if you make the load procedure, disconnect the card, reconnect and perform only that command?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:10</div><div class="msg">I can try</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:11</div><div class="msg">or send a GET DATA after load... just to check if it is failing after load whatever you send or only on install for install</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:11</div><div class="msg">I do not know if it helps, though, you cannot really configure the reader much...</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:18</div><div class="msg">everything works except for the install-for-install, that fails even in a separate session</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:19</div><div class="msg">mmm what is your Le byte?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 11:19</div><div class="msg">the card should respond 00 in the data field, so you could try Le=1</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:20</div><div class="msg">it's empty for now, I can try setting it to 1</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 11:21</div><div class="msg">unfortunately it has the same problem</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:31</div><div class="msg">question for everybody, since I am now working on the installation/initialization phase I am thinking about some points:
|
|
|
|
1) the PIN is currently initialized at 000000 by default. Should it become an initialization parameter like the pairing key and PUK?
|
|
2) the PUK cannot be changed. Is this actually desired?
|
|
3) the pairing key cannot be changed. Is this actually desired? Changing the pairing key wouldn't break existing pairings.
|
|
Even if these features are not immediately exposed through the client, they would possibly make sense</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:44</div><div class="msg">my take
|
|
1/ it could make sense if we think of scenarios for the card (later) where we program the applet in the factory and want to provide a specific PIN. I have not though over how we could bundle some crypto in a status card (that's a discussion per say, and we're gonna need some identifier at the card level for sure ...), but in this case it makes even more sense.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:44</div><div class="msg">2/ a fixed PUK seems fine to me, it's how it works with mobile SIMs isn't it ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:47</div><div class="msg">3/ What it would allow is to show to the user how much flexibility he has to set-up his security (if someone sees is pairing secret written somewhere, and he decides he wants to change it). But personally (what do you guys think ?) I find it complexifies a bit more all options to the user.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:47</div><div class="msg">FYI, I posted on #status-desktop (in status :slightly_smiling_face: )a question about when history of chats will be permanent.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:49</div><div class="msg">yes PUK is usually fixed. Changing PUK/pairing password is only needed if you feel/know that they have been compromised or even lost (because knowing the PIN should allow changing them in my opinion)</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:49</div><div class="msg">but it is confusing. that's why I was wondering if I should implement all this in the applet (which cannot be really upgraded) for later decisions</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:51</div><div class="msg">if it only provides more flexibility for the future, isn't a huge work, and do not open security breaches , then we have all to gain to implement it actually !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 13:51</div><div class="msg">(but lot of ifs :))</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:53</div><div class="msg">the only "if" which needs to be evaluated is the "do not open security breaches". The other two ifs are affirmative, it is not a huge work and yeah it adds flexibility for sure :smile:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:54</div><div class="msg">for me, it is not a security issue, because you need PIN authentication for that to work. If PIN is broken you have lost your funds anyway</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 13:54</div><div class="msg">more than broken, revealed</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 14:14</div><div class="msg">True !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 14:14</div><div class="msg">Let's see if there are other feedback, but it seems a good idea to do it !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 14:21</div><div class="msg">another topic regarding the security issue in giving the secrets to the applet during installation, I am working on changes on how this procedure works. Basically the applet will not have any installation parameters anymore. Instead of this, the installed applet will be in a pre-initialized state where it accepts only SELECT and INIT command. In the SELECT command the card gives an EC public key which can be used with EC-DH + AES to generate a securely encrypted INIT command to bring the secrets on card. This is basically a one-shot Secure Channel without authentication (that is, the secrecy is assured, but the applet cannot know if the client is authorized.. but since the card is new it has no owner, so any client doing the INIT command becomes the owner). For the user this is transparent, it does not change the flow, it is only a change in the underlying installer code</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 14:24</div><div class="msg">I'm still in a meeting and I'll be afk for some hours after that but I'll read better the 2 discussions and reply as soon as I'm back</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 14:24</div><div class="msg">however it has an implication which might be interesting for @guylouis for the NFC stuff. We can install the applet at the factory but ship the card without any secrets because the secrets could still be generated on-client on first setup. From a logistic point of view it means that we "only" have to guarantee that the card reaching the user is not a fake one, but we do not have to ship and protect any secret. Also no custom printing per-item</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 14:26</div><div class="msg">I am still leaning more toward the do-all-in-Status approach we have taken now, but if we think come to the conclusion that having the NDEF applet (for triggering installation) preinstalled is vital, then there is this route too</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 14:46</div><div class="msg">Ok. I need to be baby-sitted on this a bit: should I ask for test vectors any where else than on the two points where you mentionned it above (* Research / Possible Leaking Key via ECDH and * Crypto.java) ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 14:48</div><div class="msg">@alex118 @obi I guess we should plan a discussion about the packaging, to move towards a first version of the content on the card, packaging and papers. when would that work out for you tomorrow or thursday ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 14:50</div><div class="msg">@patrick771 @denis-sharypin @obi (and of course anyone else is welcomed !) could we review the content (wording) of denis flows together to take into account feedback from user sessions ? would thursday 3pm or 4pm CEST work for you guys on thursday ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-16/346978770624_9e34aabb0e7c70909e09_72.jpg" /><div class="message"><div class="username">denis-sharypin</div><div class="time">2018-10-09 14:51</div><div class="msg">15.00</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 14:55</div><div class="msg">I have wrote it explicitly in the comments if the PDF in all instances, so I do not think it should be repeated in the email if you are sending the PDF, right?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 14:56</div><div class="msg">but yeah those are the places</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-09 14:56</div><div class="msg">Either day can work, prefer tomorrow</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-09 14:57</div><div class="msg">@patrick771 and I are in another meeting at 3pm</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-07-31/408248212533_6aab8328425c701a55ee_72.jpg" /><div class="message"><div class="username">corey122</div><div class="time">2018-10-09 14:59</div><div class="msg">I like all of these comments, and don't have anything to add to them. Great work on this @micheleb</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-09 15:06</div><div class="msg">Tomorrow also works for me but later in the day, say 4pm GMT?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 16:18</div><div class="msg">@obi @alex118 Thursday CEST 5pm-5:45pm (we might need less) would be ok for packaging discussion ?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-09 16:23</div><div class="msg">This is Thursday, correct? Works for me although I will not be able to join the package discussion unfortunately.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 16:49</div><div class="msg">Here's a usb-nfc reader I will get a quote for</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-09 20:08</div><div class="msg">this does not work before friday 2pm-5pm if we take denis & I constraints. @obi @patrick771 would 3pm cest or 4pm cest work out for you (on friday)?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-09-17/436371980657_7d78e921d5055bc47914_72.jpg" /><div class="message"><div class="username">alex118</div><div class="time">2018-10-09 20:10</div><div class="msg">Any chance of 7pm CEST I won't be about until 6pm GMT as I?m travelling</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-02-23/319521513136_d6db8eeb85a03cb7d705_72.png" /><div class="message"><div class="username">andreaf</div><div class="time">2018-10-09 20:16</div><div class="msg">@micheleb @guylouis I really like the NDEF applet, but I think that the example card we saw is different. if I got it correctly their product is the card, people receive the card, and they can get the companion app easily tapping the card to the phone. in our case I think people would get the card to add privacy/security to the app, so they should already have status. in other cases it would be nice to have a card already setup to give by hands to people that don't know the app yet, but maybe it's a special case that we can have. what do you think?</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-09 20:22</div><div class="msg">Sure, either works for me.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-09 21:45</div><div class="msg">I agree with you, it is the point I was making in the meeting too. But @guylouis came up with equally good points where the hardwallet could be the gateway to Status. However, I still think that security-wise it could be an issue</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-13/382065868838_3c9e05c4abd3cc1c0552_72.png" /><div class="message"><div class="username">obi</div><div class="time">2018-10-09 21:57</div><div class="msg">Yep, Friday works for me</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-08-14/416818628613_d7fb4e6d703678b4d1ef_72.jpg" /><div class="message"><div class="username">philipwu</div><div class="time">2018-10-10 02:38</div><div class="msg">Hey team, just had a quick question, will the wallet have multi-sig enabled from the get go or is that more of a future thing? Just curious as I've mentioned it to passing to interested users and they wanted to know.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 06:21</div><div class="msg">@philipwu the hardwallet itself is very flexible since it signs the hash of the transaction, so it doesn't care if ETH is being transferred or tokens or anything else having a data field, so it would support any scenario where it must sign a 256-bit hash using ECDSA. I do not know how the Status client handles multisig though. </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 06:27</div><div class="msg">@guylouis should we actually advertise this fact, maybe in less technical terms? I mean the way it is built it should be able to sign even Bitcoin transactions or any other cryptocurrency using ECDSA on secp256k1 and a 256-bit hash (does not even have to be kekkac) </div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-10 06:43</div><div class="msg">One way to see it, is that feature-wise users mainly see the bundle consisting of status app + our hwallet. If we look at at the relatively short term, and our first goals, we could say that Status offers before all a secure access to the ethereum ecosystem, eth and ethereum based tokens. That multi-sig is enabled by smart contracts in ETH, and is thus fully supported by Status. I think we can be clear that our wallet does not support bitcoin for now (might do it later on, of course is Status client supports it, or if our card is integrated with other clients).</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 08:02</div><div class="msg">yeah, on the other hand knowing that you could use the hardwallet for all your crypto assets could be a selling point</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 08:02</div><div class="msg">I mean most people having ETHs also have BTC</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-03-06/324554464353_18f48763243f656a4978_72.jpg" /><div class="message"><div class="username">patrick771</div><div class="time">2018-10-10 09:57</div><div class="msg">:point_up_2: agree this flexibility could really appeal to a lot of early adopters.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 11:01</div><div class="msg">@guylouis @andreaf bringing the discussion about the applet version for ZKLabs here, since I have Status only on my phone ATM. The changes I wanted to make are ready, they are now in a pull-request. We must update the installer accordingly, too. Should I do the changes in the Android-based installer? I think sending this latest version and prompting them to review that commit is the best option</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-01/236071010406_da0f3c0676319239cebe_72.png" /><div class="message"><div class="username">jacqueswww</div><div class="time">2018-10-10 11:41</div><div class="msg">Hey folks, just dropping in - after the feedback on Town Hall: Looking awesome! Really excited to seeing this being developed further and shipped :slightly_smiling_face:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2017-09-01/236071010406_da0f3c0676319239cebe_72.png" /><div class="message"><div class="username">jacqueswww</div><div class="time">2018-10-10 11:42</div><div class="msg">:rocket:</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-10 12:25</div><div class="msg">I agree this would be good, this is however something we should raise to the wallet team, since has said @micheleb hw lite is transparent regarding this.</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-04-23/350716208512_71705389d6fc8f978562_72.jpg" /><div class="message"><div class="username">micheleb</div><div class="time">2018-10-10 12:28</div><div class="msg">I hope eventually other clients will support our wallet as well, so maybe, with the right wording, it could be mentioned even if the Status client does not support it (yet). But I am not a marketing guy, the important thing for me is that at least internally we know that these options exist</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-10 12:38</div><div class="msg">ok let's say 3pm CEST then I'll send an invite</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-10 12:48</div><div class="msg">ok good let's do that then !</div></div></div><br/>
|
|
<div><img src="https://avatars.slack-edge.com/2018-06-06/376145814673_25fb6ff197e6a87c2368_72.jpg" /><div class="message"><div class="username">guylouis</div><div class="time">2018-10-10 12:49</div><div class="msg">:100:</div></div></div><br/>
|
|
</div></body></html> |