-
Hello, I have just heard about this https://gofetch.fail/ vulnerability on Apple M chips which could pose serious secruity issues for bitcoin wallets. Can you please tell us what should we do? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 5 replies
-
Thank you for your report. I am not an expert in this but tried to look around for an answer. From the site https://gofetch.fail/
👍
Unfortunately, I am not aware of any possibility we can set this bit. Wasabi is using .NET which is developed by Microsoft. The control of that is in their hands. Wasabi immediately upgrades to the new .NET when it is released. Usually in every November.
I think this is the most important point. Do not share your hardware and make sure nobody can access it remotely either. |
Beta Was this translation helpful? Give feedback.
Köszönöm a gyors választ Dávid! :)
I have also read these recommendations, but it's not reassuring.
To my understanding, any other application running on your Mac can try to fish in the memory and get unencrypted data. Wasabi (and other apps) can flip this bit when encryption/decryption is running to prevent other apps from accessing what's happening at that time. I understand .NET is not exposing this functionality at the moment, so Wasabi can't do anything.
At this point, to be bulletproof, I'd actually recommend people to not use it on Macs with M chips and if they have, move their stash to a new wallet.
To mitigate risk and keep using it on Macs, one could just say "only install softw…