Bitcoin Forum
May 28, 2024, 12:33:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Wallet password protected and encrypted, is it safe ?  (Read 246 times)
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
April 11, 2019, 12:10:17 PM
 #21

HCP, has there been cases where someone downloaded electrum from the actual electrum website and gotten a fake electrum installed?  You say the other half protection is verifying the signature of the downloaded file.
No. But there are times where you think you are on the Electrum website, but you are actually at electrun.org or electrum.to or something like this. By verifying the signatures, you can always be 100% that the file is legit and that you downloaded it from the right place. Make this an obligatory step and you will never be phished for lacking attention.

Not 100% correct.

You can think you are on the official electrum site (electrum.org shown in the browser, secured through TLS), while in fact you are on an attackers copy of the site.
There are multiple ways to accomplish this as an attacker (e.g. DNS spoofing / cache poisining, MITM, etc..).



Quote
But is there a chance verifying the signature of the downloaded file could give you malware/keylogger/virus?
No.

Well.. yes.. in exactly 2 cases this would be possible:

1) TomasV publishes a malicious version of electrum (would be very dumb of him - legal consequences)
2) Someone gains access to ThomasV's signing key and uploads a malicious version signed with this key.


TryNinja
Legendary
*
Offline Offline

Activity: 2842
Merit: 7103


Crypto Swap Exchange


View Profile WWW
April 11, 2019, 12:13:13 PM
 #22

Well.. yes.. in exactly 2 cases this would be possible:

1) TomasV publishes a malicious version of electrum (would be very dumb of him - legal consequences)
2) Someone gains access to ThomasV's signing key and uploads a malicious version signed with this key.


In that case, there is no way for him to know if that’s what is happening and if ThomasV is uploading malware. I prefer to keep things simple to not complicate more in his mind (jerry sounds quite perfectionist ans that’s highly unlike to happen).

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
April 11, 2019, 12:29:20 PM
 #23

In that case, there is no way for him to know if that’s what is happening and if ThomasV is uploading malware. I prefer to keep things simple to not complicate more in his mind (jerry sounds quite perfectionist ans that’s highly unlike to happen).

The probability is extremely small (at least if ThomasV knows how to secure his PGP key; which i think he does), but he deserves to get as much information as he wants to   Wink

I am currently communicating with jerr0 via PM regarding hardware security of a laptop (encryption, bios, etc..). He seems to be very inquisitiv for knowledge.
Let him get as much knowledge as possible  Grin

Even if a lot is quite theoretical and probably won't happen in the field, it is good to know whats theoretically possible (IMO).

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!