Bitcoin Forum
May 01, 2024, 07:27:28 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Client feature request, no private keys in server logs.  (Read 184 times)
Slumberwatcher (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 20, 2017, 11:40:52 AM
 #1

Sorry for the cryptic subject.

I was curious and wanted to try to run an electrumx-server.

Got things up and running and everything seems to work ok, but I noticed some strange error-messages:

Nov 19 02:38:27 tv electrumx_server.py[23874]: INFO:ElectrumX:[2269] too many errors, last: 5HpH(removed)h9bY is not a valid address

(The (removed) is put there by me since it is a complete private key.)

Most of the errors are empty or contain some kind of base64-encoded string. But what is scary is that some (8 so far) has been valid private keys from random users. I don't know if these are keys that are in use or if it is just random data that happen to look like keys.

So, this is my feature request for the electrum client (not the server). If it would be possible to check and refuse/give a warning if you try to send something that looks like a private key to the server.
TalkImg was created especially for hosting images on bitcointalk.org: try it next time you want to post an image
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714591648
Hero Member
*
Offline Offline

Posts: 1714591648

View Profile Personal Message (Offline)

Ignore
1714591648
Reply with quote  #2

1714591648
Report to moderator
1714591648
Hero Member
*
Offline Offline

Posts: 1714591648

View Profile Personal Message (Offline)

Ignore
1714591648
Reply with quote  #2

1714591648
Report to moderator
1714591648
Hero Member
*
Offline Offline

Posts: 1714591648

View Profile Personal Message (Offline)

Ignore
1714591648
Reply with quote  #2

1714591648
Report to moderator
Abdussamad
Legendary
*
Offline Offline

Activity: 3598
Merit: 1560



View Profile
November 20, 2017, 12:47:16 PM
 #2

Are you saying users are querying your server manually using the electrum console? If that is the case then they are advanced users and should be left to their own devices. Otherwise electrum doesn't send private keys to servers during normal operation. It wouldn't be a secure client if it did that.

One other thing. Private keys starting with 5 are for uncompressed addresses. Electrum stopped creating those with version 2.0. Make of that what you will.
Slumberwatcher (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 20, 2017, 01:11:42 PM
 #3

I assumed (naively) that they were using the gui-client and maybe had managed to cut n'paste a private key into the wrong field.

Just got a bit spooked when I saw these things in my server log since I know the client never ever should send those.

But as you say, if people sends private keys it is their problem. It still bothers me that they are testing my morals. Smiley
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!