Bitcoin Forum
May 28, 2024, 10:45:26 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 »
41  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: April 15, 2014, 12:54:41 PM
I just installed mycelium on my android tablet and I have a question about the backup.  

The pdf says it contains "keys."  Does it contain keys or does it contain one key?  Basic users (who don't operate in expert mode) only have one key, from what I understand.
A previous post in this thread seems to indicate that the backup does include other imported keys.
The pdf wording is pretty skimpy.  If it's backing up the entire wallet, it should say so.  Could you please explain it better?

The "Keys" tab is really only needed if you want to do complicated things in expert mode, or if you want to restore a backup.

If you have a default install you have only one key. Yes, the PDF could be nicer and more precise in its wording. We have good reasons to rewrite the PDF rendering (UTF support) but we are still looking for the right library to do this. most libraries which do it properly use proprietary closed source binaries.
the very nice PdfDocument is unfortunately only for Android 4.4: https://developer.android.com/reference/android/graphics/pdf/PdfDocument.html

And to answer your question: YES, it backs up the entire wallet, and if you verified the backup you don't need anything else. unlike bitcoin-core you will not be required to repeat the backup process.
42  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: April 08, 2014, 08:27:53 AM
Our systems have been patched to be protected from CVE-2014-0160. Nevertheless, we must assume that - for 8 hours after publication of this bug - it was theoretically possible to extract the ssl private keys. therefore, we will exchange the hard-pinned SSL keys on the clients to continue to protect the privacy of our users.

see also:
http://filippo.io/Heartbleed/#mws1.mycelium.com
http://filippo.io/Heartbleed/#mws2.mycelium.com

of course, this has nothing to do with the user private keys. even if we kept that bug open, your funds would still be safe.
43  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 27, 2014, 10:55:42 PM
link to the offline desktop is online now, source is also on github. it is in fact a simple tool:

https://mycelium.com/wallet/tools.html

github source for this tool:
https://github.com/mycelium-com/wallet/blob/master/public/backuputil/src/main/java/com/mrd/bitlib/BackupUtil.java
44  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 27, 2014, 04:50:16 PM
If someone were to steal my phone, what would be the fastest way to use my backup to recover the coins without another android device?

You have to send the bitcoins to another wallet before the thief does.

Note that it may take the thief some time, because he first has to cut through your protection, like a 6-digit PIN.

For this you need a computer or smartphone. With a Mycelium backup the easier route is to use another smartphone, install Mycelium on it, restore the backup, and send all bitcoins to other wallets, for example to new wallets you create.

You could ask a trustworthy friend with a smartphone to do it for you, if you cannot obtain another new phone quickly enough.

There is a way to restore the wallet to a computer from the Mycelium backup, but I believe it is much more work.

i did create a backuputil.jar that allows you to restore the encrypted key to a desktop unencrypted. i will post a link to this tomorrow

the link will be: https://mycelium.com/wallet/tools.html but i did not upload it yet Wink
45  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 22, 2014, 08:36:24 PM
Just hitting back and getting to the main wallet screen is enough to wipe the Cold Storage key from memory.
the key is also deleted if you finish the wizard successfully.
46  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 17, 2014, 01:31:28 PM
Think I disovered a small backup related bug. (Does not affect integrity of backups)

My wallet currently has 1 active address, 8 watch only addresses and an archived address. In the backup, the active one is listed as 1 out of 9, and then the 8 watch only addresses are listed as 1-8 of 9. There is no 9 out of 9.
Any comment?

I know we had a bug in the labels of the PDF. i assume just the numbering is wrong and the actual backup is fine.

if so, i'll put it in the low-prio bug category. we will eventually fix it someday or sooner if we get a pull request for it.

(what is more annoying is the lack on UTF-8 support in the pdf... ) this needs a major rewrite with a different PDF generation engine.
47  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 13, 2014, 11:18:07 PM
as this story develops, it looks like it might be exaggerated reporting. apparently, you would need a modified kernel that this needs to be exploited:

http://www.xda-developers.com/android/samsung-backdoor-may-not-be-as-wide-open-as-initially-thought/

http://arstechnica.com/security/2014/03/virtually-no-evidence-for-claim-of-remote-backdoor-in-samsung-galaxy-phones/

accoring to these articles, only the Galaxy S would be really affected.

Anyways, this serves as a reminder that one should store significant amounts on Paper only, and verify that the backup works.
48  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 13, 2014, 11:00:57 PM
Let me add that you need to install an app that exploits the back door to be vulnerable (or update an existing app which adds an exploit)
This is not true. The exploit gives access to anybody broadcasting a pirate signal from capable equipment also. Correct?

As far as i understand, you need to have actual malware installed, which in turn can bypass the process isolation. Of course, this malware can request access rights to Internet, Bluetooth or whatever, which could be used to abuse this remotely. But this is still quite fresh now, maybe i'm wrong.
49  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 13, 2014, 01:13:49 PM

One more thing: I had the chance to use message signing for the first time the other day, and it got me thinking - it's currently only possible to do this for keys that are stored on the device - would it be possible to integrate this feature with the cold storage spending functionality, so that we can sign messages on an ad-hoc basis, without needing to fully import the private key?

yes. this makes a lot of sense. it is just a question of how to integrate it in the UI.
50  Bitcoin / Development & Technical Discussion / Re: Berkeley Database version 4.8 requirement unsustainable on: March 07, 2014, 03:28:39 PM
if there is any remote plan to move to a new format, it is a good idea to include that change early, and already migrate.

so if you some day drop BDB completely from the standard distribution, you can say, wallets v0.XX or later do not need a migration.
51  Economy / Speculation / Re: REAL SATOSHI SPEAKS OUT ON P2P FOUNDATION WEBSITE on: March 07, 2014, 02:04:49 AM
but no double-space sentence ending.  how do we know the posting from feb.11 was not someone else?  
52  Bitcoin / Hardware wallets / Re: [ANN] btchip : a Smartcard wallet - now with HD wallets support on: March 07, 2014, 01:54:49 AM
A sample desktop video of an integration in KryptoKit : http://www.hardwarewallet.com/video.html (webm, so Chrome only ... just like KryptoKit  Grin)

This shows a bit better how the second factor works
how exactly did you obtain the pin that you had to enter later?
53  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 04, 2014, 10:29:03 AM
Would it be considered "unsafe" to test a cold wallet address (properly generated, live USB, BIP 38, dumb printer etc.) with the Mycelium cold storage spending function. All this on a dumb smartphone (factory reset, not connected to GSM network, just connected to wpa2 secure wifi to D/L mycelium to make the test spend)

Or should I be more paranoid and this address should be considered not "cold" anymore by having touched breifly the network? And using Armory is the only solution ?


that depends on your paranoia level. i'd say it is cold enough.
since i don't know anything about root exploits of that dumb smartphone, be sure to ONLY install mycelium.
54  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 03, 2014, 04:17:18 PM
Security question here: I store my backup online, but the 15 character password locally. If someone were to get ahold of my encrypted backup, how quickly could they bruteforce it? With 26 characters to choose from, there is 26^15 possibilities, but how long does it take to test each one?

I just measured it using this program:
Code:
@Test
   @Ignore
   public void testSpeed() throws InterruptedException {
      long start = System.currentTimeMillis();
      int tries = 1000;
      for (int i = 0; i < tries; i++) {
         KdfParameters params = new KdfParameters("123" + i, TEST_SALT_1, MrdExport.V1.DEFAULT_SCRYPT_N, MrdExport.V1.DEFAULT_SCRYPT_R, MrdExport.V1.DEFAULT_SCRYPT_P);
         EncryptionParameters.generate(params);
      }

      double duration = (System.currentTimeMillis() - start)/1000.0;
      System.out.println("duration:" + duration+" s");
      double speed = (double) tries / duration;
      double secondperTry = 1/speed;

      System.out.println("secondperTry "+ secondperTry+" / s ");
   }

output:
Code:
duration:104.771 s
secondperTry 0.10477099999999999 / s

i ran it with -server VM in sun JDK

so it does about 10 tries/second under near-optimal conditions on a fast CPU. (i7 4770K) in single-thread mode, with JIT compiler.

this means a single core takes 390 times the age of the universe to crack a single backup. when you speed that up to graphics cards, asics if becomes shorter but still outside human lifespans.
55  Bitcoin / Development & Technical Discussion / Re: Request for Comments on Audit Protocol on: March 03, 2014, 03:49:56 PM
this is an important topic.

without having read the full spec, i have to comment the following:

1) make liabilty proofs decoupled from asset proofs
liabilty (user balances) can and should be updated in real-time, while cold storage signatures can be updated manually each time the cold storage is accessed, or even less frequently. this does not protect against "losing the keys" but i cannot see how you can have a millisecond accurate proof when we are talking about cold storage.

2) it would be enough to sign+publish an HD wallet pubkey for the cold storage. a smart application could be checking the proofs by expanding the keys with a known lookahead window.

3) the asset proofs must include unique identification for an exchange, otherwise the exchanges

4) the liability proofs must include user email/id in a meaningful schema (part of the spec?)

5) the spec could also provide a target of cold storage funds (90% 98% etc) - the signed cold storage should typically be slightly lower than the stated liabilities, except if you commingle fees there.

Mycelium would love to see this implemented on exchanges, and we would implement an independent audit client, since our software already provides some of the needed infrastructure to query addresses.
56  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: March 01, 2014, 06:18:10 PM
I would like to make a simple feature request, if it's not already available (I was not able to find it): give the possibility to copy to the clipboard a public key in the address book or in the wallet.

Use case is when I'm chatting with someone or browsing a site requesting an address to make a payment I would be able to choose one of my addresses and give it to them.

Keep up the excellent work!
When you press receive you can copy your address to clipboard
57  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: February 27, 2014, 03:05:07 PM

v1.1.10  published.

(changes from 1.1.6)
*) message signing (go to Keys tab)
*) Hebrew, French, Korean, Polish translation
*) canonical S-values in signatures.
*) improved handing of exchange rates
*) remove Mtgox
*) added Kraken, Bitpay, Coinbase
*) new high-res launcher icons

58  Bitcoin / Bitcoin Wallet for Android / Re: KnC Wallet on: February 26, 2014, 11:01:06 AM
they did release their source
but i think they need to reconsider the licensing
the eula states the software is shipped in two blocks, but in fact it is one single source tree
apparently they added
Code:
/*
 * This is KnC Software
 * Please see EULA for more information
 */
to all new classes.

the eula contains a few clauses that are incompatible with the GPL, such as
Quote
If you are under the age of 18 you must get your parent or guardian’s permission to download and use the KnC Software which forms a part of the App.
59  Bitcoin / Bitcoin Discussion / Re: List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses on: February 26, 2014, 09:30:28 AM
We know nothing certain about mtgox. for now, the coins are in limbo.There are enough threads to speculate about the situation, lets keep it to the facts here.
60  Bitcoin / Mycelium / Re: Mycelium Bitcoin Wallet on: February 26, 2014, 02:03:11 AM
A feature that should be implemented if it's not already, every month or other interval, mycelium should remind users to verify their backup again, and if they can't to create a new backup. This will ensure that users always have a working backup and won't forget to keep it up to date, even though mycelium reminds them when they have un-backed-up keys.

EDIT: Also, something after using the wallet for a while that I would find useful, a button to turn on the QR scanner right on the main balance screen instead of having to go into the send menu first. Not sure how others feel about this.

having the qr code scanner more accessible makes sense, has been suggested already. https://github.com/mycelium-com/wallet/issues/20

i am not so fond of that other suggestion, for many reasons.
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!