Celebrating three years of the Trezor Model T!

04.03.2021 / Payment system news

The first Trezor Model T hardware wallets were sold three years ago today. Since then, thousands of devices have been bought by happy customers across the world, as more and more people realize the importance of Bitcoin self-custody. But how does a Trezor Model T make it easier and safer to secure your keys?

In this blog, we’ll cover some of the important improvements that the Model T brought over the first-generation Trezor Model One, and how they work.

From a more user-friendly design to a revolutionary new way to create backups, the Model T has become popular as a reliable everyday cryptocurrency wallet that suits beginners, veterans and businesses alike.

The most striking difference between the two devices is of course the large, full-color touchscreen that replaces the buttons of the Model One, so let’s take a look at why it is key to the isolated design, making everything from smart backup to security token authentication more secure.

Hardware wallets are built to secure keys offline

Cryptocurrencies are, by their nature, natively online and digital. That makes it tricky to secure them offline, where they are not exposed to the many vulnerabilities that affect networked systems.

Thanks to a system of public and private keys, and some clever improvements over the years, it is possible to create your keys completely offline and only use them to sign transactions when needed, without exposing the seed they derive from. This is what hardware wallets were designed for, and has been the most convenient way to securely store your keys ever since the Trezor Model One was invented.

A touchscreen makes it safer to restore your wallet

When restoring your wallet from a recovery seed backup, it was previously only possible to do so using a combination of your computer and Model One device. Thanks to having a touchscreen, though, the Trezor Model T lets you enter your recovery seed words directly on the device, meaning no information is passed through the host computer.

User manual:Recovery

To restore your wallet on a Trezor Model T, a simple 9-button virtual keypad is used, which allows you to spell out any seed word in the same way old mobile phone keypads worked. It can take a little longer than a full keyboard would, but since the words are all unique from the fourth letter onward, your Trezor will autocomplete any word it recognizes, keeping the whole process quick and easy.

Remember that your seed is created securely on your Trezor. If you import a seed from somewhere else, it may have been exposed to a network or otherwise compromised. Your coins are only as secure as your seed, so make sure you generate it properly on your device.

A whole new standard for backups

As great as it is to be able to restore your seed directly on your device, the standard itself is a little fragile. When it was first developed, the BIP-39 (Bitcoin Improvement Proposal 39) standard for seed words offered a huge improvement, in terms of both practicality and security, over the long, unreadable wallet data files that were commonly used as backups.

The BIP-39 standard allows anyone to generate a wallet based on a human-readable list of words, making it incredibly easy to generate a seed entirely offline and keep a paper or engraved backup of it somewhere physical that no hacker can access. Developed by a team including SatoshiLabs founders Stick and Slush, it paved the way for hardware wallets to become the most dependable way to protect your coins for the long term.

Like most first-generation solutions, the BIP-39 passphrase has since been refined. The new open standard Shamir backup, or SLIP-39 (SatoshiLabs Improvement Proposal 39), was developed in-house by SatoshiLabs engineers, to make it safer to keep a backup without the risk of loss.

Instead of one single backup seed, Shamir lets you safely create a split seed, a special set of multiple lists of words that can withstand things like theft, loss or damage. For more information about making a Shamir backup on your Model T, look no further than last week’s blog:

Multisig and split backups: two ways to make your bitcoin more secure

Better authentication for a smarter internet

The Trezor Model T was been designed to be forward-thinking. Even as it crosses this milestone three year point, it holds its pole position as the only FIDO2-compatible authenticator with a touchscreen. As businesses and platforms transition to support this two-factor standard, your Model T will be ready.

Instead of relying on shared secrets, which Google Authenticator does, FIDO standards have long been a safer option for many reasons. What you may know as U2F is a widely-accepted FIDO standard. FIDO2 improves upon it by allowing you to easily verify the portal or app you are connecting to through your Trezor screen, and uses unique keys for each site you visit which prevents websites from being able to track you across sites.

Increase your security with FIDO2 | Trezor

Using Trezor as an authenticator is easy and lets you benefit from the same standard of security that protects the keys to your cryptocurrencies. All you need to do to enable FIDO2 is to choose your Model T as a FIDO security key on whichever service you wish to use, as long as they support it. At the time of writing, it is supported on popular services such as Github, Dropbox, Microsoft Live, and Binance.

Hardware wallets make for the perfect security token. More services will move to FIDO2 in the near and mid future, but until then, the best way to secure your accounts is FIDO U2F. To set up a FIDO U2F key, most websites and services have an option to ‘Add Security Key’, or similar phrasing. Simply connect your Trezor, hit that button and then confirm it on your device.

There’s no limit to how many keys you can create, so you can depend on your Trezor for all your logins. And since it’s all backed up on a recovery seed — or better yet, Shamir backup — you’ll never have to worry about losing access over time.

What’s next for the Trezor Model T?

With Trezor Suite moving out of beta in the coming months, Trezor hardware wallets will continue to improve as more and more features are enabled by Suite’s ecosystem. For more information about the development timeline, take a look at the highlights from our community AMA in November:

All You Wanted to Know About Trezor Suite: AMA Highlights

The Model T’s unique, forward-thinking security features are kept transparent, verifiable and open, for anyone to implement. The Model T is one of the most widely-supported hardware wallets on the market, and lets the innovations it brings to the community be used by other manufacturers, providing a safer environment for everyone.

Stay ahead of the curve with a Trezor Model T.

Celebrating three years of the Trezor Model T! was originally published in Trezor Blog on Medium, where people are continuing the conversation by highlighting and responding to this story.