Bitcoin Forum
November 07, 2024, 09:46:45 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: *warning* Two current security issues with mobile devices  (Read 2128 times)
DooMAD (OP)
Legendary
*
Offline Offline

Activity: 3948
Merit: 3191


Leave no FUD unchallenged


View Profile
August 10, 2016, 07:35:01 PM
Last edit: August 10, 2016, 08:00:14 PM by DooMAD
 #1

Just to make everyone aware, there are a few security risks presently affecting mobile devices that require people to be vigilant.

Firstly, there are still fake, malicious wallets circulating on the App Store, always make sure you use download links from a reputable source.

Secondly, some wallets are automatically backing up private keys to the cloud.  Keys stored online are potentially a serious security risk.  Make sure your apps aren't doing this, or if they have, move your funds to new addresses immediately.

It's generally good practice to only keep small amounts on portable devices in the event of physical loss or theft anyway.  Larger sums should be locked away in cold storage, offline, somewhere secure.

▄▄▄███████▄▄▄
▄█████████████████▄▄
▄██
█████████▀██▀████████
████████▀
░░░░▀░░██████████
███████████▌░░▄▄▄░░░▀████████
███████
█████░░░███▌░░░█████████
███
████████░░░░░░░░░░▄█████████
█████████▀░░░▄████░░░░█████████
███
████▄▄░░░░▀▀▀░░░░▄████████
█████
███▌▄█░░▄▄▄▄█████████
▀████
██████▄██
██████████▀
▀▀█████████████████▀▀
▀▀▀███████▀▀
.
.BitcoinCleanUp.com.


















































.
.     Debunking Bitcoin's Energy Use     .
███████████████████████████████
███████████████████████████████
███████████████████████████████
███████▀█████████▀▀▀▀█▀████████
███████▌░▀▀████▀░░░░░░░▄███████
███████▀░░░░░░░░░░░░░░▐████████
████████▄░░░░░░░░░░░░░█████████
████████▄░░░░░░░░░░░▄██████████
███████▀▀▀░░░░░░░▄▄████████████
█████████▄▄▄▄▄▄████████████████
███████████████████████████████
███████████████████████████████
███████████████████████████████
...#EndTheFUD...
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 761
Merit: 606



View Profile
August 10, 2016, 07:43:55 PM
 #2

Those are good warnings.  I am very nervous about mobile "anything" for absolute security.  I know it isn't necessary, but I prefer to setup a Trezor on a laptop first.  Then you use it with a mobile (e.g. MyCelium), however the mobile software never sees the private keys so it couldn't put them in the cloud if it wanted to.  Frankly, I personally don't do this, but I helped setup this configuration for a buddy.  His transactions are very small but its simple and safe this way.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
onlinedragon
Hero Member
*****
Offline Offline

Activity: 1036
Merit: 501


View Profile
August 10, 2016, 08:10:38 PM
 #3

Thanks for warning other people not that I hold any big amounts on mine phone. Anyway the malicious app is already removed from the AppStore can't find it anymore.
smoothie
Legendary
*
Offline Offline

Activity: 2492
Merit: 1474


LEALANA Bitcoin Grim Reaper


View Profile
August 10, 2016, 08:43:34 PM
 #4

Or just don't use mobile wallets entirely. Has worked for years so far with no problem and also utilizing cold storage.

███████████████████████████████████████

            ,╓p@@███████@╗╖,           
        ,p████████████████████N,       
      d█████████████████████████b     
    d██████████████████████████████æ   
  ,████²█████████████████████████████, 
 ,█████  ╙████████████████████╨  █████y
 ██████    `████████████████`    ██████
║██████       Ñ███████████`      ███████
███████         ╩██████Ñ         ███████
███████    ▐▄     ²██╩     a▌    ███████
╢██████    ▐▓█▄          ▄█▓▌    ███████
 ██████    ▐▓▓▓▓▌,     ▄█▓▓▓▌    ██████─
           ▐▓▓▓▓▓▓█,,▄▓▓▓▓▓▓▌          
           ▐▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▌          
    ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓─  
     ²▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓╩    
        ▀▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀       
           ²▀▀▓▓▓▓▓▓▓▓▓▓▓▓▀▀`          
                   ²²²                 
███████████████████████████████████████

. ★☆ WWW.LEALANA.COM        My PGP fingerprint is A764D833.                  History of Monero development Visualization ★☆ .
LEALANA BITCOIN GRIM REAPER SILVER COINS.
 
InvoKing
Legendary
*
Offline Offline

Activity: 2142
Merit: 1065


✋(▀Ĺ̯ ▀-͠ )


View Profile WWW
August 10, 2016, 08:47:10 PM
 #5

Or just don't use mobile wallets entirely. Has worked for years so far with no problem and also utilizing cold storage.

just don't put too much moneh there and everything should be fine, mobile wallets are ez 2 use and available everywhere

PSPD:law and order enforcement!
Press Section Police Department!
rizzlarolla
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1001


View Profile
August 10, 2016, 08:53:31 PM
 #6

Or just don't use mobile wallets entirely. Has worked for years so far with no problem and also utilizing cold storage.

just don't put too much moneh there and everything should be fine, mobile wallets are ez 2 use and available everywhere

Op said "Larger sums should be locked away in cold storage, offline, somewhere secure."

I don't use a mobile wallet. I barely use a mobile. But if I did, this post is clear info I would like to see.
Thanks OP.
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3015


Welt Am Draht


View Profile
August 10, 2016, 09:09:33 PM
 #7

I'm guilty of sometimes leaving respectable amounts on mobile devices. For some reason I don't think of them as anywhere near as howlingly insecure as a PC is, yet I'm sure there are plenty of issues that I'm blithely unaware of. Must use more paper.
yayayo
Legendary
*
Offline Offline

Activity: 1806
Merit: 1024



View Profile
August 10, 2016, 09:57:26 PM
 #8

Nobody should keep bigger amounts of Bitcoin on devices connected to the Internet. This holds true for PC's but even more for mobile phones, since the wallet software available for these devices is less secure (i.e. not fully validating, new apps).

It should be best practice to store all funds that are not used for daily purchases entirely offline - for example by using paper wallets. Mobile Bitcoin wallets should be used like ordinary hard cash wallets: The amount stored in them should be so small that it can be afforded to be lost.

It's sad that many users are not paying enough attention to security when using Bitcoin. In contrast to money stored at banks, Bitcoins have no insurance against theft. So it's entirely up to the owner to ensure they are not stolen.

ya.ya.yo!

.
..1xBit.com   Super Six..
▄█████████████▄
████████████▀▀▀
█████████████▄
█████████▌▀████
██████████  ▀██
██████████▌   ▀
████████████▄▄
███████████████
███████████████
███████████████
███████████████
███████████████
▀██████████████
███████████████
█████████████▀
█████▀▀       
███▀ ▄███     ▄
██▄▄████▌    ▄█
████████       
████████▌     
█████████    ▐█
██████████   ▐█
███████▀▀   ▄██
███▀   ▄▄▄█████
███ ▄██████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████▀▀▀█
██████████     
███████████▄▄▄█
███████████████
███████████████
███████████████
███████████████
███████████████
         ▄█████
        ▄██████
       ▄███████
      ▄████████
     ▄█████████
    ▄███████
   ▄███████████
  ▄████████████
 ▄█████████████
▄██████████████
  ▀▀███████████
      ▀▀███
████
          ▀▀
          ▄▄██▌
      ▄▄███████
     █████████▀

 ▄██▄▄▀▀██▀▀
▄██████     ▄▄▄
███████   ▄█▄ ▄
▀██████   █  ▀█
 ▀▀▀
    ▀▄▄█▀
▄▄█████▄    ▀▀▀
 ▀████████
   ▀█████▀ ████
      ▀▀▀ █████
          █████
       ▄  █▄▄ █ ▄
     ▀▄██▀▀▀▀▀▀▀▀
      ▀ ▄▄█████▄█▄▄
    ▄ ▄███▀    ▀▀ ▀▀▄
  ▄██▄███▄ ▀▀▀▀▄  ▄▄
  ▄████████▄▄▄▄▄█▄▄▄██
 ████████████▀▀    █ ▐█
██████████████▄ ▄▄▀██▄██
 ▐██████████████    ▄███
  ████▀████████████▄███▀
  ▀█▀  ▐█████████████▀
       ▐████████████▀
       ▀█████▀▀▀ █▀
.
Premier League
LaLiga
Serie A
.
Bundesliga
Ligue 1
Primeira Liga
.
..TAKE PART..
The Sceptical Chymist
Legendary
*
Offline Offline

Activity: 3514
Merit: 6985


Top Crypto Casino


View Profile
August 10, 2016, 11:17:26 PM
 #9

I use mobile wallets exclusively.  I assume Mycelium is safe, right?  From all I've read about it here, it seems to be at least one of the preferred wallets. 

And how about the one by "Bitcoin Wallet developers" for Android.  That's one I saw on the app store, and it's one that comes up second when you search for "bitcoin wallet".

███████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████

███████████████████████
.
BC.GAME
▄▄▀▀▀▀▀▀▀▄▄
▄▀▀░▄██▀░▀██▄░▀▀▄
▄▀░▐▀▄░▀░░▀░░▀░▄▀▌░▀▄
▄▀▄█▐░▀▄▀▀▀▀▀▄▀░▌█▄▀▄
▄▀░▀░░█░▄███████▄░█░░▀░▀▄
█░█░▀░█████████████░▀░█░█
█░██░▀█▀▀█▄▄█▀▀█▀░██░█
█░█▀██░█▀▀██▀▀█░██▀█░█
▀▄▀██░░░▀▀▄▌▐▄▀▀░░░██▀▄▀
▀▄▀██░░▄░▀▄█▄▀░▄░░██▀▄▀
▀▄░▀█░▄▄▄░▀░▄▄▄░█▀░▄▀
▀▄▄▀▀███▄███▀▀▄▄▀
██████▄▄▄▄▄▄▄██████
.
..CASINO....SPORTS....RACING..


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3015


Welt Am Draht


View Profile
August 10, 2016, 11:26:00 PM
 #10

I use mobile wallets exclusively.  I assume Mycelium is safe, right?  From all I've read about it here, it seems to be at least one of the preferred wallets.  

And how about the one by "Bitcoin Wallet developers" for Android.  That's one I saw on the app store, and it's one that comes up second when you search for "bitcoin wallet".

I think the issue is with Android itself. No one ever seems to give its overall security any thought. They just assume it's fine and press on.

Considering how much lucrative info is on the average phone these days there are going to be ever more attempts to gain nefarious entry into it.

And in this particular case the second problem is a 'feature' of the OS and it's exposing your data to google. I can't imagine their security is anything other than exemplary but you never know.
extrabyte
Legendary
*
Offline Offline

Activity: 840
Merit: 1000



View Profile
August 10, 2016, 11:39:28 PM
 #11

...
Secondly, some wallets are automatically backing up private keys to the cloud.  Keys stored online are potentially a serious security risk.  Make sure your apps aren't doing this, or if they have, move your funds to new addresses immediately.

It's generally good practice to only keep small amounts on portable devices in the event of physical loss or theft anyway.  Larger sums should be locked away in cold storage, offline, somewhere secure.

I didn't know that the private keys are hosted on the cloud for the greenaddress app, I think it is dangerous if their cloud gets hacked so the hacker can spends our bitcoin without getting noticed. I prefer more to store small amounts on mobile if we travel or we need to, but the cold wallet should be offline.
plpbtc1526
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile
August 11, 2016, 12:04:59 AM
 #12

This is alarming because i only mobile wallet application. But have not encounter some issues so far. Dont download wallet from not trusted sites or any refferal site. I suggest, you must go to website of the wallet you want to have and dowload it from their website so you are surely safe from fake applications
Wind_FURY
Legendary
*
Offline Offline

Activity: 3094
Merit: 1929



View Profile
August 11, 2016, 12:26:21 AM
 #13

How do these malicious apps get included in the Apple app store? I thought they had higher quality control and that they are more strict in choosing which apps are accepted and which ones are rejected.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
shinratensei_
Legendary
*
Offline Offline

Activity: 3276
Merit: 1031


Leading Crypto Sports Betting & Casino Platform


View Profile
August 11, 2016, 12:44:42 AM
 #14

Just to make everyone aware, there are a few security risks presently affecting mobile devices that require people to be vigilant.

Firstly, there are still fake, malicious wallets circulating on the App Store, always make sure you use download links from a reputable source.

Secondly, some wallets are automatically backing up private keys to the cloud.  Keys stored online are potentially a serious security risk.  Make sure your apps aren't doing this, or if they have, move your funds to new addresses immediately.

It's generally good practice to only keep small amounts on portable devices in the event of physical loss or theft anyway.  Larger sums should be locked away in cold storage, offline, somewhere secure.
Tha's good information and I very believe with that, because to this day I'm always found the fake apps are copying the original apps just to trap the users, maybe some people is not careful is they installing the apps and using that. especially for btc wallet apps and maybe that's looks like original apps.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Chris!
Legendary
*
Offline Offline

Activity: 1382
Merit: 1123



View Profile
August 11, 2016, 12:55:32 AM
 #15

Lol well I have a blackberry so I'm not on the world's least secure device (apple) therefore this isn't a concern. Of course most people in the world use an android device and I'm using android ported apps so I guess the same applies. Don't store more than you are be willing to risk. I never keep more than 0.05BTC in mycelium. I thought that was a good solution for blockchain.info when I was a newbie, but somehow my 2FA was 'hacked' (rofl, clearly not. Thanks blockchain.info for the important lesson. Never trust those fools with my money).
ethereumhunter
Hero Member
*****
Offline Offline

Activity: 3066
Merit: 542


Leading Crypto Sports Betting & Casino Platform


View Profile
August 11, 2016, 01:26:50 AM
 #16

in my android i only use mycelium, and don't know about the other wallet. i am really afraid about the other apps that i don't know and don't want to install it on my android. i hope that in android can be secure from malicious apps.

i remember when i was first time add 2FA on my PC, and suddenly in one day, i can not login into market exchanger account, and search how to solve this. from what i've read, better we install 2FA on our android, don't install it on the browser, especially chrome because in chrome, there are many add-on that we don't know is it safe to install or not. and after that, i change 2FA from browser into my androids, and i hope i don't have this experience again in future.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Decoded
Legendary
*
Offline Offline

Activity: 1232
Merit: 1030


give me your cryptos


View Profile
August 11, 2016, 01:48:25 AM
 #17

That's why you use reputable wallets, like mycelium, breadwallet or greenbits. Those are the only three I trust. Anything else should be used with extreme caution.

looking for a signature campaign, dm me for that
noictib
Hero Member
*****
Offline Offline

Activity: 966
Merit: 515


One of the world's leading Bitcoin-powered casinos


View Profile
August 11, 2016, 02:05:25 AM
 #18

i had never care about this these type of security but now after seeing your post now i realising that these security advice should noted . but one another thing in my mind that can any app is at playstore that can steal or disclose our privacy and can hack our system .
Yakamoto
Legendary
*
Offline Offline

Activity: 1218
Merit: 1007


View Profile
August 11, 2016, 03:25:00 AM
 #19

I personally don't both using mobile wallets mostly for this reason; there simply isn't enough of a reliability or security that there is with most other wallets, desktop wallets especially, and most online wallets allow for you to log in through a mobile platform, and those maintain far better security standards than mobile wallets, so I'd rather use those instead to be honest.
~Bitcoin~
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
August 11, 2016, 03:42:51 AM
 #20

Thanks for very useful security tips. There are lots of security issue coming up regarding android apps as what apps do inside is quite unknown to normal users. I have blockchain.info wallet and electrum mobile wallet downloaded from official account in google playstore, hope those are fine and also i don't install other useless apps and games.

Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!