SATWAT (OP)
Member
Offline
Activity: 1064
Merit: 51
|
|
December 04, 2020, 12:17:54 PM |
|
I am using electrum for sometime but today first time joined just because I need some information about Electrum wallet.
I have 2 computers and one is connected to Internet and other is not which is not connected I have Electrum Wallet and storing my coins for long term is this safe way to have coins in this wallet and connecting only when I have to transfer coins.
Second question can I transfer my coins without connecting internet if someone can guide me this could be great because I don't want take any risk with these my coins.
|
|
|
|
BlackHatCoiner
Legendary
Offline
Activity: 1708
Merit: 8343
Fiatheist
|
|
December 04, 2020, 12:36:39 PM |
|
You can't transfer funds without internet connection. What you can do is sign the transaction from the offline computer and broadcast it from the online one. I wouldn't do that, but Coding Enthusiast has implemented it on C#: BitcoinTransactionTool. If you have verified the signature of electrum and you have a clean operating system you can simply turn on the internet and just use it as a "safe electrum wallet". I say that it's secure, but it's not a cold storage anymore. If you want to make transactions very frequently you can just install electrum on the online pc, verify its signature and have for cold storage the offline pc. The conclusion is that if you want a cold storage in which you want to make transactions from it, then it's not a cold storage anymore.
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2954
Merit: 7561
Playgram - The Telegram Casino
|
|
December 04, 2020, 12:38:03 PM |
|
is this safe way to have coins in this wallet and connecting only when I have to transfer coins.
If both of your computers can connect to the Internet, you don't really have a cold storage option. One computer should never be able to go online. You use that offline machine to sign your transactions. You create the transaction on your online machine and save it on a USB drive. Connect that USB drive to your offline machine, load up the transaction in your cold storage computer, and sign it. Save the signed transaction on your USB drive, bring it over to the PC that can go online, and broadcast it. You need to make sure that your cold storage can't go online ever. Remove the network adapter, or if you don't want to do that, never connect it to the Internet or WIFI. Also make sure your cold storage is malware-free. It's a good idea to reinstall the OS on it to make sure it's clean.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
mpufatzis
|
|
December 04, 2020, 12:38:21 PM |
|
Q1. As long as you stay off internet is safe. Q2. read this for cold storage and how to sign transactions https://electrum.readthedocs.io/en/latest/coldstorage.html?highlight=usbI am using electrum for sometime but today first time joined just because I need some information about Electrum wallet.
I have 2 computers and one is connected to Internet and other is not which is not connected I have Electrum Wallet and storing my coins for long term is this safe way to have coins in this wallet and connecting only when I have to transfer coins.
Second question can I transfer my coins without connecting internet if someone can guide me this could be great because I don't want take any risk with these my coins.
|
|
|
|
SATWAT (OP)
Member
Offline
Activity: 1064
Merit: 51
|
|
December 04, 2020, 12:47:12 PM |
|
is this safe way to have coins in this wallet and connecting only when I have to transfer coins.
If both of your computers can connect to the Internet, you don't really have a cold storage option. One computer should never be able to go online. You use that offline machine to sign your transactions. You create the transaction on your online machine and save it on a USB drive. Connect that USB drive to your offline machine, load up the transaction in your cold storage computer, and sign it. Save the signed transaction on your USB drive, bring it over to the PC that can go online, and broadcast it. You need to make sure that your cold storage can't go online ever. Remove the network adapter, or if you don't want to do that, never connect it to the Internet or WIFI. Also make sure your cold storage is malware-free. It's a good idea to reinstall the OS on it to make sure it's clean. I really appreciate your this effort because you guide me in very easy language which is understandable for me now I can do this all if need help again then can post here because just checking few other sections this all stuff is really great and helpful just need some good time to learn and use this all hopefully in future I will able to give you merit for your this post as right now showing 0 for me thanks again.
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2954
Merit: 7561
Playgram - The Telegram Casino
|
|
December 04, 2020, 12:57:43 PM |
|
Don't worry about the merits. One more thing, have you verified the signatures of your downloaded Electrum software and has it been downloaded from the official site? No torrents, email links, etc.? Here is an easy to understand guide on how to verify Electrum signatures just in case you don't know how to do it: https://bitcoinelectrum.com/how-to-verify-your-electrum-download/
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
SATWAT (OP)
Member
Offline
Activity: 1064
Merit: 51
|
|
December 04, 2020, 01:03:36 PM |
|
Don't worry about the merits. One more thing, have you verified the signatures of your downloaded Electrum software and has it been downloaded from the official site? No torrents, email links, etc.? Here is an easy to understand guide on how to verify Electrum signatures just in case you don't know how to do it: https://bitcoinelectrum.com/how-to-verify-your-electrum-download/Today my first day and I have some good and enough information from here its really great start for me as I am feeling very secure with this all stuff thanks buddy for this link and all information's about this wallet hopefully in future as I need help I will ping you because for me first impression is from your way is very good and understandable for me stay safe take care.
|
|
|
|
ranochigo
Legendary
Offline
Activity: 3038
Merit: 4420
Crypto Swap Exchange
|
|
December 04, 2020, 01:05:35 PM |
|
I would install Linux in one of the computer and use it solely for the signing of the transaction. Linux is less targeted when it comes to malware due to the less widespread use and it's nature as an operating system. Under no circumstances should the computer go online and it should only be used for signing. Next, you can set up a watch-only wallet on an online computer using the xpub that you can get from the offline computer. Whenever you generate an un-signed transaction, you'll be able to copy the hex version out for your other computer.
While there isn't any huge concern for the use of a USB, you can explore using QR codes instead. The way that it works makes it better since you can be definitive about the information being transferred. Bad USB was an issue and I bet it could be an issue in the future, especially with flash drives.
|
|
|
|
SATWAT (OP)
Member
Offline
Activity: 1064
Merit: 51
|
|
December 04, 2020, 01:12:02 PM |
|
I would install Linux in one of the computer and use it solely for the signing of the transaction. Linux is less targeted when it comes to malware due to the less widespread use and it's nature as an operating system. Under no circumstances should the computer go online and it should only be used for signing. Next, you can set up a watch-only wallet on an online computer using the xpub that you can get from the offline computer. Whenever you generate an un-signed transaction, you'll be able to copy the hex version out for your other computer.
While there isn't any huge concern for the use of a USB, you can explore using QR codes instead. The way that it works makes it better since you can be definitive about the information being transferred. Bad USB was an issue and I bet it could be an issue in the future, especially with flash drives.
Here I agree with you USB is really problem and this could be big issue in future because sometime back I lost some good stuff just because of this USB but sadly I have one problem I never use this Linux and have no idea about this all from start I am using this Window stuff just because of this not taking any risk but now after this conversation I have some good new things which can help me in future for better security of my funds.
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2954
Merit: 7561
Playgram - The Telegram Casino
|
|
December 04, 2020, 01:47:22 PM |
|
Never hesitate to ask questions if there is something you don't know or understand. It's much better to do that than make serious mistakes that can lead to the loss of money. There are many more knowledgeable users here than me, and someone is usually around to help.
ranochigo's suggestion to use Linux is a good one. But if you have never used that OS, I understand the skepticism. As long as the PC you use for cold storage has a freshly installed OS and is 100% malware-free, using Linux isn't of the utmost importance. USBs can malfunction as ranochigo mentioned, but most of us have several of them around. In case one fails to perform, you can always use another one.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
ranochigo
Legendary
Offline
Activity: 3038
Merit: 4420
Crypto Swap Exchange
|
|
December 04, 2020, 01:50:46 PM |
|
USBs can malfunction as ranochigo mentioned, but most of us have several of them around. In case one fails to perform, you can always use another one.
No no. Bad USB as in the exploit. The firmware can be modified to execute malicious codes when the USB is connected to the computer. While the attack vector is significantly reduced when the computer is already isolated in the first place, I still regard that it would pose some degree of risks (albeit fairly minor). But yeah, don't think having a spoilt flash drive would affect anything.
|
|
|
|
Pmalek
Legendary
Offline
Activity: 2954
Merit: 7561
Playgram - The Telegram Casino
|
|
December 05, 2020, 07:36:02 AM |
|
No no. Bad USB as in the exploit. Oh, I see. That is why it is so important that the device used for the cold storage never goes online or has the capability to go online. Such an exploit would need Internet access to send the data/files, or whatever it steals, to the scammers. It would probably require Internet access to communicate and download the required files for the exploit. Unless an exploit is configured in such an advanced way that it can do that on the online machine, be brought over to the cold storage device, steal sensitive data, and send that data to the scammers upon a 2nd connection on the device that goes online. But I have never read about such a case here on Bitcointalk.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
hugeblack
Legendary
Offline
Activity: 2702
Merit: 3993
|
|
December 05, 2020, 10:28:39 AM |
|
Remember: the fact that the device is not connected to the Internet does not mean that it is safe, you need to remove all the files, install a new operating system, make sure that the new system is safe, remove the network connection parts and all the input and output units (physical removal except the screen and mouse) and then you can sign the message then use Barcode + device connected to the Internet to brodcast it.
Or you can choose the easiest solution and buy a hardware wallet after reading all the details about it.
|
|
|
|
NotATether
Legendary
Offline
Activity: 1792
Merit: 7388
Top Crypto Casino
|
|
December 06, 2020, 02:46:22 AM |
|
Remember: the fact that the device is not connected to the Internet does not mean that it is safe, you need to remove all the files, install a new operating system, make sure that the new system is safe, remove the network connection parts and all the input and output units (physical removal except the screen and mouse) and then you can sign the message then use Barcode + device connected to the Internet to brodcast it.
Or you can choose the easiest solution and buy a hardware wallet after reading all the details about it.
Not to mention a hardware wallet is less expensive than setting up cold storage yourself of comparable security, if you don't already have screwdrivers and computer parts handy. Plus it is easy to accidentally destroy your cold storage as you setup a computer for it if you're not careful.
|
|
|
|
Bronsted
Newbie
Offline
Activity: 11
Merit: 7
|
|
December 06, 2020, 09:31:41 AM |
|
Remember: the fact that the device is not connected to the Internet does not mean that it is safe, you need to remove all the files, install a new operating system, make sure that the new system is safe, remove the network connection parts and all the input and output units (physical removal except the screen and mouse) and then you can sign the message then use Barcode + device connected to the Internet to brodcast it.
Or you can choose the easiest solution and buy a hardware wallet after reading all the details about it.
Not to mention a hardware wallet is less expensive than setting up cold storage yourself of comparable security, if you don't already have screwdrivers and computer parts handy. Plus it is easy to accidentally destroy your cold storage as you setup a computer for it if you're not careful. Building your own instance on a raspberrypi may be cheaper, coming in at about $50 for the 2gb version here and add in SD card should be $60. A ledger costs about $150 around here before shipping fees. from the other thread, it seems that it could offer decent security for its price and its quite idiotproof to do. You cannot lose the private key unless you lose the seeds. I think destroying a raspberrypi computer when using it as a cold storage device is not a big deal.
|
|
|
|
o_e_l_e_o
In memoriam
Legendary
Offline
Activity: 2268
Merit: 18747
|
I think some of the answers here run the risk of overloading the OP with information. He wants to set up an airgapped machine, which already means his coins will be more secure than >95% of bitcoin users who are using web wallets or hot wallets. I think we should be striving to help him do that, even on Windows, rather than adding more and more complicated steps regarding Linux and Raspberry Pis which run the risk of making him give up on the whole thing and just run a hot wallet instead. Will his set up be perfect? No. But don't let perfect by the enemy of good. It will still be far better than most. OP, here are some basic instructions on what you want to do. - Have one computer which will connect to the internet. You can use this computer as your usual daily computer if you wish, but you should strive to make sure it is free of viruses, malware, and such like. If you can format it and install a clean OS from scratch, then all the better.
- Have one computer which will be permanently airgapped. What this means is that it will never connect to the internet or any other wireless communication again. The best way to achieve this is to at a minimum disable the hardware such as the WiFi card, Bluetooth, etc. but preferably physically remove these pieces of hardware instead.
- On this airgapped computer, you must format it and install a clean version of your operating system. Linux is preferable, but Windows will be fine.
- On your online computer, download Electrum from this site only (electrum.org) and verify it using the instructions here: https://bitcoinelectrum.com/how-to-verify-your-electrum-download/
- Copy it to your airgapped computer via a removable USB drive, and install Electrum on both computers.
- Next, on your airgapped computer, create a new Electrum wallet, select Standard wallet, select Create a new seed, choose Segwit or Legacy (I would recommend Segwit for lower fees), write down the seed phrase on paper, confirm the seed phrase, and set up a password.
- Then, click on Wallet -> Information, copy your Master Public Key (a long string of characters beginning with zpub or xpub), save on your USB drive, and move your USB drive back to your online computer.
- On your online computer, open Electrum, create a new wallet, select Standard wallet, select Use a master key, paste in your Master Public Key, and set a password. This creates what is known as a "watch only" wallet.
If you have skipped any of these steps - not verifying Electrum, not ensuring your airgapped computer is airgapped, not ensuring your airgapped computer is clean and a fresh OS, etc. - then you should start the process again as your wallets are not secure. Make sure you can recover your current wallets before you format your airgapped computer!
To make a transaction: - Start with your watch only wallet on your online computer.
- Go to Tools -> Preferences -> Transactions, and check "Advanced preview".
- In the Send tab, create the transaction you want to make, hit Pay, choose the fee you want at the bottom, hit "Finalize".
- Now click on "Export", and either Export to file and save on your USB disk, or display as a QR code if your two computers each have a camera.
- If using a USB disk, move this to your airgapped device.
- Open your airgapped wallet, go to Tools -> Load transaction, and choose either From file to load from your USB drive, or From QR code to scan the QR code.
- Once your transaction has loaded, click on "Sign", enter your password, and then reverse the above process to export your signed transaction, either via file or QR code, and transfer it back to your online computer.
- On your online computer, again load the transaction, and click on "Broadcast".
|
|
|
|
|