Bitcoin Forum

Bitcoin => Electrum => Topic started by: didaw on June 05, 2017, 08:28:24 PM



Title: electrums safty
Post by: didaw on June 05, 2017, 08:28:24 PM
Hey guys, ive been looking in to storing my BTC on Electrum and ive got a concern. My concern is that some one could set up a bot to crack in to accounts since their is no password and the next button appears when you put in the right seed in. also my custom words what i put in didnt seem to work as i was able to logon with out them and just with my normal seed. i dont know if any one els has this issue? i did put in my custom words and it accept them when i set up my account but it just dosnt seem to ask for them.


Title: Re: electrums safty
Post by: HCP on June 05, 2017, 08:38:48 PM
Given there are 2048 words in the list of valid seed words... and 12 words in a seed... the number of combinations is "very large" :P

You will find the next button "appears" whenever you put any valid seed in... but there are literally millions of millions of millions of valid seeds, good luck "cracking" that...

As addresses are based from the seed, it is highly likely that it let you put in the seed without custom words but the generated bitcoin addresses and private keys would have been different.

I don't quite understand what you mean by "logon" using your seed? ??? You are supposed to use your seed once when setting up the wallet, then you add a password (and optionally encrypt the file with your password)... when you want to open the wallet and/or send transactions, the app should ask for your password... but you certainly don't need your seed.


Title: Re: electrums safty
Post by: didaw on June 05, 2017, 09:12:15 PM
yeah i know its unlikely, i dont know it just seems less secure than a username and a password in a way because you dont need either of them, you just need to get 12 valid words and if millions of people use Electrum then it seem like not necessary your account would be hacked in to but a random account could be hacked in to. yeah you are right i come to a different address when i put my custom words in this gives me more confident in it and suddenly makes it seem alot more secure that it did seem thanks, im happy with it now i thought that the words i put in had no affect :) i was referring to logon as putting in your seed fresh because im testing how it works ive been putting in that seed alot and its became second nature to call it a logon since iver been using it for that purpose :P thanks for the reply


Title: Re: electrums safty
Post by: naukop on June 06, 2017, 01:50:45 PM
If the number of seed words is 2048 then there are 2048^12=(2^11)^12=2^(11*12)=2^132 ~= 5.4*10^39valid combinations

that is not attackable by a brute force :)