Review of the Digital BitBox crypto bitcoin hardware wallet, made in Switzerland.
Bitcoin donations appreciated: 12gVrtZg75SWQFKhQ512DjPKpSFt3sK218
http://www.MyWallet.ch
https://kit.com/EEVblog/crypto-hardware'>https://kit.com/EEVblog/crypto-hardware
https://shiftcrypto.ch/
Forum: http://www.eevblog.com/forum/blog/eevblog-1075-digital-bitbox-hardware-wallet-review/'>http://www.eevblog.com/forum/blog/eevblog-1075-digital-bitbox-hardware-wallet-review/
EEVblog Main Web Site: http://www.eevblog.com
The 2nd EEVblog Channel: http://www.youtube.com/EEVblog2
Support the EEVblog through Patreon!
http://www.patreon.com/eevblog
Stuff I recommend:
https://kit.com/EEVblog/
Donate With Bitcoin & Other Crypto Currencies!
https://www.eevblog.com/crypto-currency/
T-Shirts: http://teespring.com/stores/eevblog
💗 Likecoin – Coins for Likes: https://likecoin.pro/ @eevblog/dil9/hcq3

Hi, It's time for another review of a cryptocurrency. Hardware Wallet Today we've got the digital a Bit box from shifted devices made in. Switzerland Why do all my Swiss viewers and this is a simple low-cost Bitcoin How We Are wallet And as I've said in many previous videos which I'll link in at the end of this video in down below because I've reviewed the new Traceur Model T the original traceur and the ledger as well and I've done tear downs of the traceur as well. If you're in the crypto space, you Must have a hardware wallet to store your crypto.

Zin Do Not store them on the exchanges or anything like that. It's I Understand, you have to do that if you you know, like day or week trade in your cryptos or something like that. But when you're not using them and keep them when you're not trading them, keep them stored on a cryptocurrency hardware wallet. It just makes it so much harder, if not almost impossible.

I Never say impossible for people to steal your coins because you're physically in possession of the actual wallet itself. So I they need the physical wallet itself before they can get access to it because the keys are stored inside these hardware wallets and that's the key no pun intended. So thank you Shift Devices for sending this one in. This is a slightly different to the other hardware waltz we've looked at because these have all had screens on them so that you can.

The new Model T actually even has a touchscreen so that you can actually type your PIN number into this to actually log into the thing and enable it. Whereas the digital bit box let's open it up there it is. It's just a little hardware key like that, fully potted by the way which is really nice. Sells for 59 euros with 19 euros shipping.

It's a little bit pricey for just a basically just the secure crypto chip on there that generates the true hardware random Keys plus a micro plus a USB micro in there. but hey, it is fully potted which was one of my sort of I guess a huge complaint, but I was just surprised that the ledger and the traceur they didn't come fully potted. This one does and that's nice. It just means it's more secure from a physical hardware attack.

and it's different again in that it comes with a microSD cards into the side of the thing and it allows you to backup your key so you when you set this up, backs it up onto the micro Sd. You go put your micro Sd card in your safe-deposit box or whatever. Hide it. you know, in your bottom of your shoe or wherever you want to hide the thing and that's how you store the backup for this thing.

Um, I don't know. It doesn't look like it has a paper password. there's nothing in else in the box. Nothing up my sleeve to backup the key in this thing because these ledger entries all ones actually have a paper backup.

So yet when you set them up, they give you the seed keys and you write down the twelve or twenty four seed word keys. This one looks like it just backs it up under micro Sd card. So I I Don't recommend you stall that on your cloud or whatever cuz if somebody's got that, they can steal your coins. So like keep it on multiple SD cards in multiple locations, physically separate from the interwebs.
But I like the fact that it's fully potted with look at this, the same material used in bulletproof glass? The beauty? huh? There you go. Handy touch button and LED indicator to physically confirm your intention. so there must be like a capacitive touch thing. I Guess it lights up when we plug it in.

We'll find out and it has a true random number generator on there. I Don't I can't do a teardown on this I Have no idea what chips are used so it looks like it doesn't use a secure micro. It looks like it just uses a dual chip system. It's got a regular USB micro like an arm or you know, something like that.

and in this, the keys I kept inside a secure memory chip and that will have a physical attack security with that like wire mesh over the die and all sorts of other anti tampering mechanisms in this thing. because well, technically, if you've got possession of this, ultimately if you got enough time and enough resources, you can probably get the key out of it. but it's gonna be incredibly difficult if not destructive to do so. and they claim that their app is native so it avoids security attacks our front light which is different of a browser based wallets, but unlike the ledger and the traceur which actually have screens on them and when you boot them up, especially the ledger, you actually enter your PIN number onto this so there's no way that you know any malware on your computer or anything else can intercept this sort of stuff.

And the ledger and this one's got a touch screen on it. and the original ledger had a randomized keypad. so to show you a keypad when you boot it on and be random each time, so you would actually click the keys on your computer into the web browser based thing, but they were randomized so they couldn't get your pin number on there. So without having used it yet, that would be my first concern is that when you there's a PIN number or password for this thing and that has to be entered on the computer which then travels over the USB and well, technically less secure than this screen based ones.

but it's still gonna be much more secure order of magnitude more secure than leaving your crypto on an exchange or in a software-based wallet unless you set the software base wallet up on a completely clean machine. and most people have really no idea how to do that. or worst of all, using your damn phone to set up your software wallets and do Not do crypto on your phone. trust me.

And it's also got a U2 F Authenticator thing for websites and other software that support you to eff authentication so you plug it in and you don't have to plug in typing your password. you physically got access to this. You can access all your Google accounts or whatnot. Um, I don't use that myself, but if you're going to do that, that could be handy.
One of the downsides is that only supports Bitcoin and Litecoin. By the sounds of it, does support Aetherium, but that's true my Ether wallet, but that's the same for both the ledger and the Azure as well. They both use my Ether wallet and it's a good system. It supports the AER 20 Gr C 20 smart Contract tokens and things like that.

So if you're buying into Icos initial coin offerings and things like that, they often use the ERC 20 system using the theorem and you can do that on my youth award. So that's how you can access your token. So technically, you should be able to store any ERC 20 token on here through the Etherium Smart contracts. Okay, installation should be easy.

Windows, Linux, Apple, and the source code as well. For those playing along at home, Excellent. A plug in the Bitna. So install software plug-in with a Micro SD card inserted and present little askest.

Set it up and we'll create a backup on that SD card and Bob's your uncle. But the good thing about this is when you're plugging your SD card into this, the keys are generated and stored inside here. They're immediately transferred to the micro SD card for backup. It never.

They never travel over the USB So even if your computer is infected with malware in theory, they should not be able to access any of this. That's in theory Anyway, if they've engineered it right. And by the way, if you're going to install the software for this, only get it from the official website. don't get it from any other file distribution server or anything like that.

They've got the 256 checksum there for it. so if you're super paranoid, you want to check the checksum and all that sort of jazz. But yeah, don't get fooled into downloading it from anywhere else cuz technically they could be some form of man in the middle attack. They're welcome, well guide you through, is recommending that you close all our verifications.

Bla bla bla bla bla Let's go 22 Me: That's pretty good. Let's go Complete Easy Peasy Lemon Squeezy Run Tada no device connected I'll have to connect it there. It is up close for those who want to see it. I Like that it has a little lanyard keyring attachment on it.

Looks really looks and feels. It's going to say looks and feels really robust but just put pressure on that and I just felt a crack. Guys heard a crack. Oh that's probably just the top shell.

I think it's just the top shell but the rest of it because they like that should be the PCB going all the way through. There should just be the 11.6 millimeter PCB right through and mmm. didn't like the sound of that. but yeah the potty and I don't think goes over the top of the SD card.

anyway. Anyway, it seems fairly robust. I mean that was pretty extreme Me you know, go on like that. I'm gonna play with it so it's alright.
So SD card plugged in and there you go. detected it. No workers at all. not on this device.

Driver rubbish and new wallet name, password and repeat password. Here's the problem. Technically like we're entering the password on the computer here. If your computer is infected with malware that is looking for this particular stuff or it has a keylogger screen, capture whatever it is, they're gonna get your password.

which is not good, but they still won't have physical access to your bit box so they still will need that to actually create another one and create a bit restore from a backup or whatever so they won't have that. But they could actually get your password. So technically this could be hacked by having some sort of malware keylogger or some other thing capturing your password when you install this on the computer and then they would need access to the backup file which is stored on that SD card. But as I said that the Bit box writes directly from its internal processor to the SD card.

It doesn't travel over the USB so there's no, in theory no way you can in infect your machine to actually capture that transfer. so they'd physically have to get hold of that backup file on your SD card. So if you're dumb enough to store that on your Dropbox or your cloud server or your email system and they could access it that way, then they could steal all your coins if they had the password and that file. So obviously don't do that.

Submit Saving password creating wallet and as always, choose a random password that you're not using elsewhere. There you go, we're in like Flynn password set wallet created backups saved to SD card, device connected okely-dokely Well that was really easy. I Was impressed by that. It's I Had a few issues with the traceur and the ledgers are setting up few little niggly things and stuff like that.

There you go, you can send me some Bitcoins I got no Bitcoins please Any Satoshi Appreciated I Do accept a cryptocurrency donations on the Eevblog website by the way. Thank you very much. It's also linked in in the comments down below so we can just send. Bitcoin Options Manage backup, change, password, creating your wallet and they will fall to if a Connect Mobile app.

Blink the lid. It blinked. one blink. That's right.

Next day. it's a big really bright white LED right next to the keyring port. There you go. This is handy.

Look, you can generate a random number. It did because it's got a true hardware random number generator or true ish random hub. That's a whole science in itself generating true random numbers. Um, it just generates this.

It's just because if you want to just like, if you've got an app and you want it, you've got a hardware random number generator. That's pretty cool. I like that being the nerd that I am I? Yep, that's impressive. Check for updates, upgrade firmware.
Oh the desktop app is up to date. There it is and upgrade expert settings. There we go: Wallet service Oh A bit Pay Ok digital bit box smart verification proxy Hidden wallet password as a security measure use a special password, open a hidden wallet. ah, permanently enabled.

don't know. it sounds a bit sounds a bit how you're doing so all I see is Bitcoin I don't see like coin there at all. Um the Moldy Sig join Copay Wallet What's copay? Well well at the invitation code co-pays Secure shared Bitcoin Wallet There you go. It's open-source Is it? Get copay? Share was a true Bitcoin wallet, not an account service.

Manage your personal funds, multiple signatures or just one. Is this a hardware authenticated access to that? I guess Anyway, I'm not going to muck around with that. I just wonder why use it as a wallet itself? So there you go. I'm gonna send myself some coins and there's actually an option here.

verify address securely and there it is. but it needs a mobile episode to verify the QR code on there and things like that. so I'm not going to bother trying that. but I guess it's for those because it doesn't have a screen like the chisels and the Ledger's do.

That's just a way to verify it using a phone app, so probably you should use that if you're going to do this sort of stuff. But now I'm pretty confident. gone for broke. Okay I'm going to send myself some coins.

No. I know, let's have a look. I'm just putting my 2fa code and send hopefully bloody e-mail verification. Yeah, of course.

Sorry, this will take a bit. Okay I have sent my coins. they're just gone. So point double o4 I think I sent so history? Come on, you can do it.

Does it? Just refresh if I in order to make oh there we go, there's the Refresh Come on, come on. it'll of course take some time to authorize but the it should come through reasonably quickly. I transferred some Bitcoin the other night at it like it just took seconds to come through but it took of course much longer. To our author is based on the network and all that sort of stuff I was just about to ask.

does it support two-factor authentication which is like a phone based like you have an app on your phone which has and I highly recommend you do it for all your hardware wallets and also you're well if they support it and you're exchanged wallets and software wallets and things like that and so yes you can enable full 2fa Here there we go enable afterwards. a device running a digital bit box mobile app is required to send the coins so it says you have to be running the digital bit box mobile app. Well I kind of run like Google Authenticator um I don't like that I don't want to out like because I use Google Authenticator from my to FAS So I don't necessarily like that. Anyway, you can the desktop app to the digital bit box mobile app.
It creates an encrypted communications channel that's good so they've thought of that Well done. Still waiting. It just occurred to me that look this, it may not show up on your available balance until it's fully authorized. Then that could take many hours on the Bitcoin network.

So but yeah I don't like that. The others you know, the trees, ores and the ledges and whatnot will show up like very quickly. Like within seconds. a minute or two will show up the unconfirmed transaction.

So at least you know it's just my phone. At least you know that your yeah, you know it's like it's gone through. it's gone through on the network. It just needs to be authorized.

Gives you that confidence that you haven't sent it to the wrong address at the moment. I've got no visibility at all that anything's come through. I Don't like that you don't want to be go disabling to FA once you've enabled it because you must. The device must be erased to exit the to FA mode.

so you better have that backup and multiple copies and make sure it's damn working. So really, it's up to you whether or not you want the hassle of the two-factor authentication there. especially if you have to run a separate app and you've got to factor authentication. Google Authenticator For other things, you don't want to have to run the app and do that sort of jazz.

I Mean you're already reasonably secure by using the the hardware wallet anyway, so you can argue to FA is not hugely valuable here, But hey, for those who want to be, you know the best security possible, then you'd be using the two. FA We got one there it is. Yeah, sorry, yeah. I Send point double O 3 5 bitcoins Um I Don't like that it doesn't like pull the value from like like a Bitcoin like a price server you know Queen market cap or whatever it is and just give you an equivalent.

you know Yankee bucks value or something like that. It's just nice to see that sort of thing on Hardware wallet another our crypto wallet apps. this one doesn't have it. That would have been a nice addition and if you double-click on the transaction there it takes you over to I won't show you if it takes you over to block Explorer comm which you can then explore the actual block transaction that you just did.

Nice! So I guess that's pretty much it and that's all there is to the digital bit box. Thank you very much for sending that one in. Um, it's an interesting alternative to your screen based hardware. Wallets like this is not hugely cheaper.

I think it might even be very similar priced to the legend nos here and that's a screen based one. Supports more coins than of course this one so it says the supports like coin but I don't see the option to support like coin and then if you want to do our theory um, here it is. Let's go over to my Ether wallet which I like you can use this for your initial coin off runes and stuff like that. It's there it is.
digital bit box. Connect your digital bit box today and it works the same with the ledger and the traceur. As you can see, there's our support for those there. All right.

Connect your digital bit Box. Here we go. that's better. We're in like Flynn.

There it is and Digital Bit Box. So we're using the M-40 for 6000. that I won't explain. that's sort of passed.

Anyway, that's the one you want to use so we can unlock our wallet and we can go in there and view our token balances like this. So if we go in, there will be our two Ether Explorer and there's nothing there because we haven't done anything with it yet. Anyway, unlock your wallet. Tada.

We're in like Flynn and this is where we can. We've got Zero Ether. This is where we can show all our tokens. So this is where these are built in supporting my Ether Watt.

So all these tokens, all these different coins. They're tokens. They're both coins. They're actually tokens on the ERC 20 tokens on the Etherium of blockchain.

So there you go. So this is where you access. So if you buy into an initial coin offering, it either defaults here or you can add your own custom token here. They will give you that information to add it to my Ether wallet.

and then you can use your digital bit box to access your initial coin offering coins or tokens as they're called. So there you go. Umm, this seamless integration with my Ether-wall Exactly like the little Legend Nos and both of the Tresor models. It works.

Great worries whatsoever. So now we can send and receive Etherium and all the different tokens using my Ether wallet. Brilliant. But even though my Ether Wallet is a web-based wallet, you've got to have physical access to your hardware wallet in this case, the digital Bit Box to actually login and connect this thing because your keys are stored inside the physical hardware device itself.

So otherwise, like no one can hack my Ether wallet. For example, because you have to physically have the device and if you want to send here we go create transaction. Let's go. and this is where we do the touch button.

It's got a capacity of our touch button. we have to hold it for three seconds. Let's give it a go. My finger on it.

There we go. Yep, no worries there. If it, you know, I don't necessarily trust capacitive touch buttons, but it's good in that it's like sealed inside there. It's just more robust, was sent successfully.

Cool bananas. got much left. So there you have it. That's the digital bit box from Shift Crypto Security made in Switzerland I Kind of like I Like the physical nature of it and how it's better than just the like the female SD microSD and the USB C connectors on these.

They always feel fragile and you know if you're going to like insert the cable too many times you're going to break the poor little thing. you know. and like if you're inserting and removing these every single day playing around with this thing, then you know it's a problem. These this one from Digital Bit Box feels much more robust.
But the downside is it really only supports our Bitcoin natively. It said it supports like litecoin but I unless I'm missing something I Couldn't see how that worked, but of course it supports the theory I'm through my ether wallet which is fantastic. It's not a bad price, it's nice and physical security. I Like how it has the SD card backup and things like that.

but the problem with the SD card backup is like SD cards aren't the most hugely reliable things, especially if you get ones from the Shinzon market and you don't know have a clue where they've actually come from. But even if you get the genuine ones, like if you stick that micro SD card in the safe and leave it there for ten years and go back and use it and that's your only copy, you know. don't be surprised if it's if it doesn't work after a set amount of time. And of course, to copy it, you've got to copy it on a machine.

So I would copy it on a clean machine. If you're going to make multiple copies of it, copy it on a clean machine that's setup and isolated from the interwebs. and you know otherwise. If your machine is infected with malware, it could like potentially search for these sort of things.

Hackers can put malware on your machine by many different methods, and if they are actively targeting the digital bit box, it can know what files to look for and stuff like that. So you want to definitely want to make multiple backups. Do it on a clean machine. Don't store it on the cloud, and if you're doing that, then you're probably going to be safe and secure.

so I don't mind that at all. It's an interesting alternative. I Probably prefer the screen based ones I get more of a warm fuzzy with the screen based ones. but there's nothing wrong with this digital bit box.

It seems to work just fine. No issues with that set up. it's going to be more than secure enough order of magnitude more secur then you know, some sort of online wallet or exchanged wallet or something like that. Don't leave your coins on the exchanges, they'll just get hacked eventually.

If that's just the risk you take anyway, that's that's not a bad little thing. If you're just doing Bitcoin and you know in Aetherium, don'ts the business like it's it's I Trust this for longer-term physicality of the thing, especially if you you know you want to carry it around on you. then this one's going to be more reliable than either the legend nos So ultimately it feels a bit more physically robust than these devices. So you know if you're carrying around on your cheek keychain all the time, you know, especially if you're certain them in and out every day.
I Don't like these female female connector based ones and they're just ultimately going to wear out. so the digital bit box shouldn't do that with its male connector here. Male USB connector. it should last much longer.

I Guess the only other thing would be a ESD susceptibility electrostatic discharge. So if you count around your keychain in your you know wallet oh yeah, in your pocket or whatever, you're rubbing your feet on the carpet well, you touch the pins, you're in a high ESD Environment I Wouldn't know unless I actually depotted this thing and look to see if it has like an external dedicated ESD protection USB protection chip in or whether that's just relying on the building diode protection inside the microcontroller which is still okay. Things like that, it's probably no more susceptible than your regular USB memory stick or something like that. So I think that's an interesting alternative.

It's just a bit different to the others and it has its place in the market. I Think I Don't mind it at all. It worked pretty seamlessly to install with the Bitcoin and the My Ether wallet. So there you go.

It's not bad at all. I Don't mind it I'll link it in down below if you want to pick one up. As always, if you like the video, please give it a big thumbs up because that always helps a lot. And subscribe Bill icon notification all that sort of stuff catch you next time you.


Avatar photo

By YTB

17 thoughts on “Eevblog #1075 – digital bitbox hardware wallet review”
  1. Avataaar/Circle Created with python_avatars No pe says:

    How do you even know what your agreeing to when pressing the HW button.
    I really don't get the security model of that thing.
    Next time you do a review assume the Host PC you're using is 100% compromised all along the video.

  2. Avataaar/Circle Created with python_avatars GRBTutorials says:

    And hardware wallets are mainly for Windows users since Mac and Linux have close to no malware… Of course, it’s more secure, but unless you have thousands of euros/dollars in coins, it’s not worth it unless you use Windows.

  3. Avataaar/Circle Created with python_avatars Benedikt says:

    The SD card capability makes me suspicious. One could circumvent all the potting, etc. by exploiting the uC through the SD card interface by manipulating either the data transactions itself or through manipulating the file system. Since it has a full FAT32 and SD card driver stack, there must be the one bug that could be used to crack it. FAT32 support means it will be writing and reading to serve the file system's requirements.

  4. Avataaar/Circle Created with python_avatars Aatheus! says:

    A nice implementation of a hardware wallet. I would want to add a cap on the male USB end to protect it from stress fractures/other mishaps. Otherwise, nice bit of kit.

  5. Avataaar/Circle Created with python_avatars maverickbna says:

    I think your 0.004 BTC got truncated by the desktop app.

  6. Avataaar/Circle Created with python_avatars Phobos TK says:

    Well, "if you want to make money you have to spend money"… the only thing is that device is just an overpriced toy.

  7. Avataaar/Circle Created with python_avatars FuzzyLogicxxx says:

    Where is the part that Dave tears this thing open? "Don't turn it on, take it apart"

  8. Avataaar/Circle Created with python_avatars Morellio Benoir says:

    We might as well store our data on VHS.

  9. Avataaar/Circle Created with python_avatars J S says:

    I would think, as an educated man, you would see through the fallacy that is crypto currency. The shear amount of damage the entire movement does to the environment is sickening. Wasting so much electricity adding to the already serious problem we have with the climate issues.

    The hundreds of different currencies will never be the defacto used currency for the world. They are all just terrible hobbies that cause far more damage than they create entertainment.

  10. Avataaar/Circle Created with python_avatars rng8891 says:

    How did Dave know I hide mine in the bottom of my shoe?

  11. Avataaar/Circle Created with python_avatars Felenov says:

    I like the ledger for its form factor and the SE, but I like the new Trezor because it is open source and I can make my own units instead of buying them, it’s cheaper, and my version is waterproof and has USB B. I a lot of em in the safe. Nobody is getting those, especially in the safe.
    Well, the 2000£ safe from UK costs 10 times more than the stuff in it.

  12. Avataaar/Circle Created with python_avatars Cubeist Games says:

    What happens when, not if, the company that made this thing goes out of business and the software won’t run on your new machine/OS?

  13. Avataaar/Circle Created with python_avatars Landrew0 says:

    Too late; the Bitcoin train has left the station.

  14. Avataaar/Circle Created with python_avatars andyhello23 says:

    Even though i am penniless, and would never get into the crypto stuff.

    Its a good idea. The crypto currency world, is very dodgy and its a good idea to have such a thing with your coins.

    Like you said, nothing is impossible, but at least with such devices your making it harder, for dodgy people to steal your coins. The whole crypto coin stuff is a world of very dodgy people, and if your getting into it, at least do something like this, to give you some security.

    Bitcoins is heavily used by criminals on the net, and there will be so many ways they have to steal your details.

    So if you into this, its a very good idea to have an isolated device like this, away from your computer.

  15. Avataaar/Circle Created with python_avatars likfrikbik says:

    Msg to all hardware wallet manufactures: Crypto support sells your devices,Ledger is most popular because it supports most cryptos.
    I like this Bitbox,but i would never buy it because of support for only 2 or 3 cryptos.

  16. Avataaar/Circle Created with python_avatars Okurka says:

    "Bitcoin donations appreciated".
    Looks like that is the sole reason you made this video.

  17. Avataaar/Circle Created with python_avatars Killy MXI says:

    I don't think PCB trace connector much more reliable than proper mini/micro USB connector. Any research on this matter?

Leave a Reply

Your email address will not be published. Required fields are marked *