Bitcoin Forum
June 16, 2024, 07:47:15 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Heartbleed bug  (Read 902 times)
pinksheep (OP)
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
April 11, 2014, 10:02:34 PM
 #1

Just was reading about the Heartbleed bug. Can anyone tell me if sites like bitcoinpaperwallet & bitaddress were affected by this bug? I made my paper wallets on bitcoinpaperwallet using a tablet which was only ever connected to the internet long enough to save the page for offline usage & which will never be online again. Could the security of my paper wallets have been affected in any way?


▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
PRIMEDICE
The Premier Bitcoin Gambling Experience @PrimeDice
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
byt411
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


View Profile
April 12, 2014, 01:07:57 AM
 #2

No, no and no.
To check if a site is vulnerable, use this: http://filippo.io/Heartbleed/
jdun
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
April 12, 2014, 04:47:07 AM
 #3

You're taking a risk storing coins online. Websites come and go frequently. Exchanges come and go. I've lost coins when exchanges have been hacked or taken offline. I wouldn't trust any paperwallet site to keep my coins for any length of time. You're always better off keeping your coins on your computer. Even with a strong exchange like bitstamp or coinbase, I trust my computer more. If Mt.Gox could fold, then any of the exchanges could fold and you could lose it all.

YinCoin YangCoin ☯☯First Ever POS/POW Alternator! Multipool! ☯ ☯ http://yinyangpool.com/ Free Distribution! https://bitcointalk.org/index.php?topic=62
jparsley
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
April 12, 2014, 05:59:05 AM
 #4

I think those sites are safe as yous browser dosent send info back to the site.

please unban me.
Equate
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
April 12, 2014, 06:12:51 AM
 #5

The data you send over the browser is not in encrypted form even though you browse SSL site.Your information is comprised.
Dare
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500


Techwolf on #bitcoin and Reddit


View Profile WWW
April 12, 2014, 07:27:14 AM
 #6

Just was reading about the Heartbleed bug. Can anyone tell me if sites like bitcoinpaperwallet & bitaddress were affected by this bug? I made my paper wallets on bitcoinpaperwallet using a tablet which was only ever connected to the internet long enough to save the page for offline usage & which will never be online again. Could the security of my paper wallets have been affected in any way?
While the websites themselves may have been affected, your paper wallets are safe. Heartbleed allows attackers to peek into protected system memory by sending a malformed TLS heartbeat packet, which will only work if the target device is connected to the internet. As you generated your wallets offline, the only way this could have affected you is if bitaddress was hacked and set to use a faulty random number generator before you downloaded the page, and this highly unlikely and would almost definitely have been noticed and publicized by others shortly after the hack. Even a faulty RNG would still probably provide some security, albeit far less than a working one.

TL;DR: Your paper wallets are safe.

BTC: 1M8oUcBnkRDEhWWgV8ZXLTB6p1mgnejVbX
How Forum Activity Works
Bitcointalk Forum Rules
|
|
|
Firstbits (lucky vanitygen): 1WoLfRUGDx1
How Forum Trust Works
Bitcoin Source Code
pinksheep (OP)
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
April 12, 2014, 10:26:53 AM
 #7

Well, I'm not much the wiser Smiley byt411 & Dare say my paper wallets are safe & Equate says my details are compromised, not sure who to believe.

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
PRIMEDICE
The Premier Bitcoin Gambling Experience @PrimeDice
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
Equate
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
April 12, 2014, 02:53:08 PM
 #8

Well, I'm not much the wiser Smiley byt411 & Dare say my paper wallets are safe & Equate says my details are compromised, not sure who to believe.

its not compromised  , but it could have been possible if that bug was exploited . Better change your passwords on sites using ssl.
byt411
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


View Profile
April 12, 2014, 03:03:31 PM
 #9

Well, I'm not much the wiser Smiley byt411 & Dare say my paper wallets are safe & Equate says my details are compromised, not sure who to believe.

Read below.

The data you send over the browser is not in encrypted form even though you browse SSL site.Your information is comprised.

You clearly have no idea what you are talking about, since you don't understand what "saved the page for offline usage" means. As dare said, the wallets were generated offline, and Heartbleed can only be exploited if something is online.

You're taking a risk storing coins online. Websites come and go frequently. Exchanges come and go. I've lost coins when exchanges have been hacked or taken offline. I wouldn't trust any paperwallet site to keep my coins for any length of time. You're always better off keeping your coins on your computer. Even with a strong exchange like bitstamp or coinbase, I trust my computer more. If Mt.Gox could fold, then any of the exchanges could fold and you could lose it all.

Please read what OP wrote before writing useless comments. His wallets and coins are not online in any shape or form.
cookmac
Full Member
***
Offline Offline

Activity: 152
Merit: 100


View Profile
April 12, 2014, 06:57:31 PM
 #10

So basically get a paper wallet.
byt411
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


View Profile
April 12, 2014, 07:48:43 PM
 #11

So basically get a paper wallet.

Have you finished your sentence? So basically get a paper wallet for sercurity? For safekeeping? Huh?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!