Bitcoin Forum
May 03, 2024, 10:53:00 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: Be careful using Blockchain as your wallet...  (Read 16469 times)
opentoe (OP)
Legendary
*
Offline Offline

Activity: 1274
Merit: 1000

Personal text my ass....


View Profile WWW
October 10, 2012, 02:41:44 AM
 #1

I've been using Blockchain for a couple of months now. I've sent/received bitcoin on many occassions with no problems. All of sudden today I an unable to log in with my password. I am aware that Blockchain does not store your password locally so I wrote my password down on paper and put it in my safe. It is the same password I use on several of my banking sites, so I know the password well. For some reason I'm unable to log into my Blockchain account and there is no way they are able to help me!! I have this funny little feeling that they maybe have something to do with this. Since I'm unable to get to my money now and that account will just go stale I'm pretty sure that Blockchain will get that money eventually. Maybe they do this on purpose for random accounts? I'm %100 sure that I know my password. It is a little ironic that they don't store your password on their server and can't help me. Strange. So, if you have a lot of money tied up on Blockchain I would send it to your local wallet instead. I'm finding out that the best place to keep your bitcoin is your local wallet and NONE of these online places.

Need help with your Newznab usenet indexer? http://www.newznabforums.com
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714776780
Hero Member
*
Offline Offline

Posts: 1714776780

View Profile Personal Message (Offline)

Ignore
1714776780
Reply with quote  #2

1714776780
Report to moderator
1714776780
Hero Member
*
Offline Offline

Posts: 1714776780

View Profile Personal Message (Offline)

Ignore
1714776780
Reply with quote  #2

1714776780
Report to moderator
casascius
Mike Caldwell
VIP
Legendary
*
Offline Offline

Activity: 1386
Merit: 1136


The Casascius 1oz 10BTC Silver Round (w/ Gold B)


View Profile WWW
October 10, 2012, 02:42:50 AM
 #2

Just use a paper wallet.  And/or back up your keys to paper, Blockchain makes that pretty easy.

Companies claiming they got hacked and lost your coins sounds like fraud so perfect it could be called fashionable.  I never believe them.  If I ever experience the misfortune of a real intrusion, I declare I have been honest about the way I have managed the keys in Casascius Coins.  I maintain no ability to recover or reproduce the keys, not even under limitless duress or total intrusion.  Remember that trusting strangers with your coins without any recourse is, as a matter of principle, not a best practice.  Don't keep coins online. Use paper or hardware wallets instead.
julz
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001



View Profile
October 10, 2012, 02:46:09 AM
 #3

That they don't store the password on their server is a good feature.  I don't see how Blockchain can get that money eventually - unless you used a pretty simple password and they run a brute force against it.
Highly unlikely anyone external could brute force any but the simplest of passwords - as blockchain seems to do IP lockouts  (though perhaps via botnet?)

Also - check your keyboard isn't damaged.

..and - look for keyloggers. Perhaps someone got in via your system and changed the pass.


@electricwings   BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
casascius
Mike Caldwell
VIP
Legendary
*
Offline Offline

Activity: 1386
Merit: 1136


The Casascius 1oz 10BTC Silver Round (w/ Gold B)


View Profile WWW
October 10, 2012, 03:00:28 AM
 #4

Number of times I've typed a password again and again and again and SWORE I did it right but it clearly isn't working... only to discover that my keyboard is set in a foreign language, and I'm either typing "ραςςωoρδ", or it's AZERTY and I'm really typing the equivalent of "pqssword" or whatever.

Companies claiming they got hacked and lost your coins sounds like fraud so perfect it could be called fashionable.  I never believe them.  If I ever experience the misfortune of a real intrusion, I declare I have been honest about the way I have managed the keys in Casascius Coins.  I maintain no ability to recover or reproduce the keys, not even under limitless duress or total intrusion.  Remember that trusting strangers with your coins without any recourse is, as a matter of principle, not a best practice.  Don't keep coins online. Use paper or hardware wallets instead.
Atlas
Jr. Member
*
Offline Offline

Activity: 56
Merit: 1


View Profile
October 10, 2012, 03:03:17 AM
 #5

OP, all they store is your public keys/private keys in a encrypted JSON with a linked identifier. That's it. There's no way they can alter it unless they are storing your passwords which would ruin them.
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
October 10, 2012, 03:05:40 AM
Last edit: October 10, 2012, 03:27:40 AM by Stephen Gornick
 #6

It is the same password I use on several of my banking sites, so I know the password well.

Well, that could be one explanation as to what happened.   I'ld first be worried that my system has been compromised and then only after being able to rule that out would I continue to use it.  From a secure system, then I'ld change my bank passwords after this.  Again -- password reuse is not recommended.


Since I'm unable to get to my money now and that account will just go stale I'm pretty sure that Blockchain will get that money eventually.

No, they won't.  They don't have access to the unecrypted keys.

Now did you have a previous backup of your wallet from prior to having any trouble?

But if a thief got access to it, even with an older copy of the wallet the funds are likely spent.

The login page shows three backup methods ... Dropbox, Google Drive, and Email.

You can configure it so that a copy of the encrypted wallet is sent to your e-mail after each change.

Also, setting it up with a second password (required for spending) is a good recommendation.

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
October 10, 2012, 03:09:36 AM
Last edit: October 10, 2012, 03:26:47 AM by Stephen Gornick
 #7

This is good reading:

Caution: Do You Bank Online?
 - http://market-ticker.org/post=212456

by Karl Denninger, Ticker Guy


[Update:
And also:

Quote
[Project Blitzkrieg is] a collaborative effort designed to exploit the U.S. banking industry’s lack of anti-fraud mechanisms relative to European financial institutions, which generally require two-factor authentication for all wire transfers.

Project Blitzkrieg’ Promises More Aggressive Cyberheists Against U.S. Banks
 - http://krebsonsecurity.com/2012/10/project-blitzkrieg-promises-more-aggressive-cyberheists-against-u-s-banks ]

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


allthingsluxury
Legendary
*
Offline Offline

Activity: 1540
Merit: 1029



View Profile WWW
October 10, 2012, 03:24:44 AM
 #8

Wow hopefully it is just something simple like a keyboard error. Hopefully you get access to your cash soon.

dancupid
Hero Member
*****
Offline Offline

Activity: 955
Merit: 1002



View Profile
October 10, 2012, 03:59:22 AM
 #9

If you have a backup of the wallet just open another account and import it to it - or import it into multibit.
I would also just use a watch address for the bulk of your bitcoins with the private key stored offline.


edit - just realised you'd still have the same password problem though. But blockchain do not store any bitcoins they just store an encrypted wallet that is decrypted in the browser. They can't steal these bitcoins.
I suggest you keep trying the same password - perhaps try it on a different computer
ralree
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


Manateeeeeeees


View Profile
October 10, 2012, 04:58:47 AM
 #10

I'm cool with blockchain, but their app doesn't have any sort of authentication (or at least I haven't seen it).  I think my hard limit on what I keep in there is going to be 10BTC for the moment - no reason to risk losing it if I lose my phone.

1MANaTeEZoH4YkgMYz61E5y4s9BYhAuUjG
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
October 10, 2012, 05:27:50 AM
 #11

I'm cool with blockchain, but their app doesn't have any sort of authentication (or at least I haven't seen it).

Account details -> Secuirty

You can enabled two-factor authentication.  This can be an e-mail, SMS text message, Yubikey, or Google Authenticator.


no reason to risk losing it if I lose my phone.

As long as you have it save backups (or send them to you), you are protected from lost.  You can also set up a second password that is required only for spending.  So even if the phone is stolen and someone tries to send funds, they can't without the second password.

Account details -> Passwords


 - http://www.Blockchain.info/wallet

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


julz
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001



View Profile
October 10, 2012, 05:28:42 AM
Last edit: October 11, 2012, 10:44:28 PM by julz
 #12

I'm cool with blockchain, but their app doesn't have any sort of authentication (or at least I haven't seen it).  I think my hard limit on what I keep in there is going to be 10BTC for the moment - no reason to risk losing it if I lose my phone.

For the android app - you can put on a second password which is required when spending. (edit:  ^^ what he (Stephen Gornick) said!)

I believe when you 'pair' a device - the QR code contains the main decryption password, which I suppose may be somewhat vulnerable when stored in your phone.

I find it annoying that the QR code even contains this password - as otherwise I'd carry around a printout of various pairing QRs in my wallet and scan them as necessary.
The second password still wouldn't make this safe as with the decryption password they can still go to the website and change all the account settings... I guess 'two factor' is the way to stop that.

@electricwings   BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
piuk
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1005



View Profile WWW
October 10, 2012, 07:41:50 AM
 #13

I am aware that Blockchain does not store your password locally so I wrote my password down on paper and put it in my safe.

Try opening notepad or another simple text editor and writing the password in plaintext exactly how you think it should appear. Then copy and paste it into the password field.

Keeping you own paper backup or .aes.json backup is the always recommended. Then you can restore the wallet using a desktop client if need be.

kokojie
Legendary
*
Offline Offline

Activity: 1806
Merit: 1003



View Profile
October 10, 2012, 12:44:23 PM
 #14

I've been using Blockchain for a couple of months now. I've sent/received bitcoin on many occassions with no problems. All of sudden today I an unable to log in with my password. I am aware that Blockchain does not store your password locally so I wrote my password down on paper and put it in my safe. It is the same password I use on several of my banking sites, so I know the password well. For some reason I'm unable to log into my Blockchain account and there is no way they are able to help me!! I have this funny little feeling that they maybe have something to do with this. Since I'm unable to get to my money now and that account will just go stale I'm pretty sure that Blockchain will get that money eventually. Maybe they do this on purpose for random accounts? I'm %100 sure that I know my password. It is a little ironic that they don't store your password on their server and can't help me. Strange. So, if you have a lot of money tied up on Blockchain I would send it to your local wallet instead. I'm finding out that the best place to keep your bitcoin is your local wallet and NONE of these online places.

Sounds like your fault for not properly backing up your wallet, both on paper and in encrypted form (it's impossible for blockchain.info or anyone else to change your password on your backups). Plus since you re-use your password, how do you know if your password has not been compromised somewhere else, and the hacker simply went into your blockchain.info account. It can be pretty useless to hack into online banking, so you might not notice your online banking has been hacked. If your coin hasn't been moved, then if you have properly backed up, you would not have lost anything.

btc: 15sFnThw58hiGHYXyUAasgfauifTEB1ZF6
ralree
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


Manateeeeeeees


View Profile
October 11, 2012, 09:52:45 PM
 #15

I'm cool with blockchain, but their app doesn't have any sort of authentication (or at least I haven't seen it).  I think my hard limit on what I keep in there is going to be 10BTC for the moment - no reason to risk losing it if I lose my phone.

For the android app - you can put on a second password which is required when spending. (edit:  ^^ what he said!)

I believe when you 'pair' a device - the QR code contains the main decryption password, which I suppose may be somewhat vulnerable when stored in your phone.

I find it annoying that the QR code even contains this password - as otherwise I'd carry around a printout of various pairing QRs in my wallet and scan them as necessary.
The second password still wouldn't make this safe as with the decryption password they can still go to the website and change all the account settings... I guess 'two factor' is the way to stop that.


Thanks (and thanks to Stephen Gornick as well).  I'll go do that tonight.

1MANaTeEZoH4YkgMYz61E5y4s9BYhAuUjG
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
October 12, 2012, 08:47:32 PM
 #16

I've been using Blockchain for a couple of months now. I've sent/received bitcoin on many occassions with no problems. All of sudden today I an unable to log in with my password. I am aware that Blockchain does not store your password locally so I wrote my password down on paper and put it in my safe. It is the same password I use on several of my banking sites, so I know the password well.
Password re-use is never a good idea.

For some reason I'm unable to log into my Blockchain account and there is no way they are able to help me!! I have this funny little feeling that they maybe have something to do with this.
What 'funny feeling'?  That is a pretty strong accusation coming from a low post forum account against piuk.  Something tells me that there would be many more 'interesting' account for them to 'steal' if he were so inclined.

Since I'm unable to get to my money now and that account will just go stale I'm pretty sure that Blockchain will get that money eventually.
I am pretty sure that you don't understand how the service works given that this is near impossible (as others have pointed out).

Maybe they do this on purpose for random accounts? I'm %100 sure that I know my password.
Knowing and communicating the password to the server are two entirely different things (also as others have pointed out).  Why would they risk their reputation to steel random piddly accounts?

It is a little ironic that they don't store your password on their server and can't help me. Strange.
I think you need to re-educate yourself with the meaning of irony: http://theoatmeal.com/comics/irony

So, if you have a lot of money tied up on Blockchain I would send it to your local wallet instead. I'm finding out that the best place to keep your bitcoin is your local wallet and NONE of these online places.
This is of course a personal decision and there is no right way for 100% of the people.  Personally I have like BCI because an un-encrypted version of my wallet never hits my disk.

Sorry to be so negative, but attacks on long standing services / members irritate the hell out of me, especially when done from sock/low count accounts. 

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
October 17, 2012, 06:50:20 PM
 #17

I'd like to add other issue.
I sent some bitcoins from my Blockchain wallet to an exchange, but the transaction is unconfirmed for 24 hours. I found that it contains a double-spent coins. I would send less coins (minus double-spent ones) but I can't cancel the transaction. It seems I lost my bitcoins.
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
October 18, 2012, 12:44:38 AM
 #18

I'd like to add other issue.
I sent some bitcoins from my Blockchain wallet to an exchange, but the transaction is unconfirmed for 24 hours. I found that it contains a double-spent coins. I would send less coins (minus double-spent ones) but I can't cancel the transaction. It seems I lost my bitcoins.
You didn't lose your coins. Wait until the transaction fall off and you will have them back.

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
October 18, 2012, 06:50:59 AM
 #19

I'd like to add other issue.
I sent some bitcoins from my Blockchain wallet to an exchange, but the transaction is unconfirmed for 24 hours. I found that it contains a double-spent coins. I would send less coins (minus double-spent ones) but I can't cancel the transaction. It seems I lost my bitcoins.
You didn't lose your coins. Wait until the transaction fall off and you will have them back.

It's good news. But those double-spends r so annoying.
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
October 18, 2012, 12:42:09 PM
 #20

I'd like to add other issue.
I sent some bitcoins from my Blockchain wallet to an exchange, but the transaction is unconfirmed for 24 hours. I found that it contains a double-spent coins. I would send less coins (minus double-spent ones) but I can't cancel the transaction. It seems I lost my bitcoins.
You didn't lose your coins. Wait until the transaction fall off and you will have them back.

It's good news. But those double-spends r so annoying.
Agreeded.  Are you using another wallet? Or perhaps a service like one of the dice?  You normally shouldn't get double spends unless something out of the ordinary is going on.

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!