Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

stop. storing. your. wallet. online. (I wanted to write this in caps, but I resisted)

I'll add this to my list of things that people know they should do but are too lazy to take a few minutes and setup: don't repeat passwords, use a password manager, make regular backups, don't use GoDaddy.

Stop thinking you're the exception dammit, these things don't take that much effort to do properly.



I have my coins split between a wallet that I control and an online wallet that I have some faith in.

Because honestly, I don't actually fully trust myself. The chance is not negligible that I get a trojan with a keylogger that watches for me to open my wallet. So I store some of my coins online as a hedge against my own stupidity and the inherent insecurity of desktop computing.

I may, in the future, move a large portion of my coins into a fully offline (generated on a machine that's never seen the internet), safety-deposit-box stored wallet. But that's a little bit excessive at this point.


Wouldn't a keylogger watch you open your online wallet too, and therefore provide the criminal access to your online wallet as well?


Yeah, it's really not too hard to use a live linux disc to boot into to do transactions, etc. Keep the wallet encrypted in the client, keep the USB drive you store the wallet on dm-crypted. Keep the wallet (and it's daily backups) backed up to your DropBox in case you lose your jump drive.

The weakest link is then DropBox + your BTC-client password. Or I guess if someone has modified the live environment on your jump drive or if they have a sophisticated attack on your UEFI/BIOS.


And this ladies and gentlemen is the reason that Bitcoin has a lot of work to go before it will be accessible to the non-technophile community.


To me, this signals a strong need for more secure bitcoin storage options, and since this is hacker news, perhaps some of us should get started on that :)


I may be spending a little karma in saying so, but this is exactly what DRM would be most useful for, when utilized by individuals in their own interest, as opposed to corporations using it to exercise power over individuals. This is exactly where being able to detect if an iPhone is non-jailbroken would be useful.

Or, we can dispense with having DRM on hardware we personally won. How about a protocol for providing a secure bitcoin wallet in the cloud? Basically, everyone runs their own open source mini-OS in their own obfuscated VM (1), which a smartphone app sets up for you and to which a smartphone app only acts as an interface. The wallet information is never on the smartphone, and the DRM is never on your own hardware.

Such an infrastructure would have many other uses, not just bitcoin.

(1) The security of each VM instance would be on an economic basis. Each one might be breakable within a week, say, but the system could be set up in a such a way that the week old information isn't work enough to motivate the effort.


I think I could do a pretty good job keeping wallets secure. But it would need to be a full-time job, not a side project, and it would need a big budget.

You don't bootstrap a bank.

(Plus I did some basics with Bitcoin a few years ago and got pissed off at the protocol and moved onto less annoying things.)


I don't like to spam with links, but http://www.bitalo.com aims to be the service you described, and will be launched soon. "Most secure" really means that no one, even the site admins/hosting platform can never touch your coins. This will be enforced by the technology used, not just some internal policies. And also, the site will be backed by a german AG company, which is basically a type of "Public limited company" backed by minimum of 50,000 EUR.


How do they plan to accomplish this without using javascript crypto?


I plan on using Javascript crypto. I've spent many hours reasoning over this idea, also studying security community reactions on mega.co.nz and I think it is possible to do now. I don't want to disclose all details now for obvious reasons, but all I can tell that I will not reinvent the wheel here - all parts needed are already available and mature, you just have to assemble them into a complete solution.


> you just have to assemble them into a complete solution.

Many (if not most) of the security vulnerabilites of the past years come from perfectly safe components assembled in an unsafe way.

Crypto-engineering is hard.


The point is that you are overstating the security benefit of your solution. A breach of the server will now only compromise wallets of anyone who logs in until the breach is detected instead of all wallets instantly.


No one can never touch my coins? Uh oh!

Blockchain.info can't touch my coins. But if there servers are compromised, a hacker could inject a tiny, tiny amount of JS and have my ID/password sent to... anywhere... and then the hacker could access my account. I'm curious to know how you'll get around that vulnerability.


The security on the client side will be on the level that blockchain.info provides, but this will be more than just a online wallet - it will also be an exchange. I'm aware about injecting JS vulnerability. Of course you can't get around it with anything on the main server. It's possible however to setup an external server that will be monitoring the files and firing alarms the minute something's wrong (asset checksums doesn't match). And that's exactly what we'll do. Another thing is that all SSH/SCP access is also logged and the whole team gets an email immediately when it happens.


Paper wallets are easy to make and relatively easy to use. Slightly harder to spend money with.

I suppose someone could customize a small Linux live CD to boot, not touch the hard drives, load an encrypted wallet off a secure jump drive and encourage backups. It's fairly straightforward if you use a dm-crypted jumpdrive and, say for example, Tails.


Hmmm, how about paypal linked to a bank account? Just as bad probably. They have a two factor authentication available with your phone, but perhaps even that is a bad idea.


Can you then please provide specific, step-by-step steps, for turning online BTC (in say, Coinbase or MtGox) into an offline, printed, "paper wallet"?

Thanks.


This isn't "perfect" in my mind, but it's close: https://blockchain.info/wallet/paper-tutorial

I like BlockChain. There's still an amount of trust and I can think of ways it could be compromised, but they do a pretty good job architecturally of preventing your loss in the case they're compromised (well, depends on how they're compromised)

Anyway, those instructions will give you a secure paper wallet and an account that will enable you to still check your balance through blockchain.info.

(Note, this method keeps your private keys on the paper wallet, and the public key with Blockchain which enables balance checking but prevents compromise via blockchain.info)


Agreed. As a long-time Bitcoin participant, I'm very impressed with blockchain.info They're by far the securest online wallet. The problem is, most people aren't able to distinguish between what blockchain has set up and something like instawallet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: