Bitcoin Forum
May 04, 2024, 03:11:59 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Possible security issue with blockchain.info (plaintext password)  (Read 627 times)
pminers (OP)
Newbie
*
Offline Offline

Activity: 21
Merit: 0



View Profile
October 20, 2012, 06:53:48 AM
 #1

Guys who plan to use blockchain.info online wallet please consider:

Hi blockchain.info support,

i wrote a mail complaining a possible security issue to you on 12. Oct and got no reply so far.
Therefore i will post the answer here and hope to get feedback soon:

"In the qr code for iphone device pairing the plaintext login password is contained. this is (in my opinion) a possible security issue and it makes me nervous because this means that my login password is stored in a way which is decryptable ( normally i would have expected that the password is stored as a salted hashvalue). so please can you explain."

Kind regards
-pminers


https://bitcointalk.org/index.php?topic=40264.msg1285194#msg1285194

1714835519
Hero Member
*
Offline Offline

Posts: 1714835519

View Profile Personal Message (Offline)

Ignore
1714835519
Reply with quote  #2

1714835519
Report to moderator
The forum strives to allow free discussion of any ideas. All policies are built around this principle. This doesn't mean you can post garbage, though: posts should actually contain ideas, and these ideas should be argued reasonably.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714835519
Hero Member
*
Offline Offline

Posts: 1714835519

View Profile Personal Message (Offline)

Ignore
1714835519
Reply with quote  #2

1714835519
Report to moderator
1714835519
Hero Member
*
Offline Offline

Posts: 1714835519

View Profile Personal Message (Offline)

Ignore
1714835519
Reply with quote  #2

1714835519
Report to moderator
1714835519
Hero Member
*
Offline Offline

Posts: 1714835519

View Profile Personal Message (Offline)

Ignore
1714835519
Reply with quote  #2

1714835519
Report to moderator
kgonepostl
Full Member
***
Offline Offline

Activity: 124
Merit: 100



View Profile
October 20, 2012, 04:55:21 PM
 #2

plaintext? REally?! Not even hashed? Let alone salted hashes!
FAIL!!!!!!!!!!!!!
Maged
Legendary
*
Offline Offline

Activity: 1204
Merit: 1015


View Profile
October 20, 2012, 09:25:26 PM
 #3

Of course it's plain text. Everything except for the storage of the wallet that is encrypted with that password is done client-side.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!