Bitcoin Forum
June 21, 2024, 10:58:20 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: How vulnerable is electrum to the seed issue that android has  (Read 1272 times)
jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
August 12, 2013, 07:07:41 AM
 #1

https://bitcointalk.org/index.php?topic=271831.0

How vulnerable is electrum to the seed issue that android has
particularly on the various os

eg

OSX 10.8 +
WIN7 / WIN 8
UBUNTU

etc
etc

does any one even know???

how can we check we are not doing

http://www.nilsschneider.net/2013/01/28/recovering-bitcoin-private-keys.html

this?

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
ThomasV
Moderator
Legendary
*
Offline Offline

Activity: 1896
Merit: 1353



View Profile WWW
August 12, 2013, 07:14:27 PM
Last edit: August 12, 2013, 07:52:50 PM by ThomasV
 #2

At this point I do not know if the android version of Electrum is concerned, but that's quite possible. I am investigating this problem right now.

update:
From what we can gather, this issue seems to be a Java PRNG implementation issue.
Electrum should be safe from this, because it does not use Java; it uses /dev/urandom directly.
However, there might be other bugs in the Android platform, which is under overall scrutiny following this issue.

Electrum: the convenience of a web wallet, without the risks
-Mk23-
Member
**
Offline Offline

Activity: 84
Merit: 10



View Profile
August 13, 2013, 04:33:31 AM
 #3

I restored a wallet using a bit address single wallet private key qr code. All this was done over a android running a cm10 based mod.
Does the issue just apply to the seed or are the actual address's that are created off of it in question?

Am I at risk Wink specifically what are the implications of my bitaddress seed??
ThomasV
Moderator
Legendary
*
Offline Offline

Activity: 1896
Merit: 1353



View Profile WWW
August 13, 2013, 08:44:42 AM
 #4

I restored a wallet using a bit address single wallet private key qr code. All this was done over a android running a cm10 based mod.
Does the issue just apply to the seed or are the actual address's that are created off of it in question?

Am I at risk Wink specifically what are the implications of my bitaddress seed??

That issue had nothing to do with the seed, or the way private keys are generated. it had to do with the way transaction are signed.
Note that if you generated keys with Electrum, and then imported those keys in one of the Android wallets concerned with this issue, then you are at risk.

Electrum: the convenience of a web wallet, without the risks
jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
August 13, 2013, 11:01:19 PM
 #5

At this point I do not know if the android version of Electrum is concerned, but that's quite possible. I am investigating this problem right now.

update:
From what we can gather, this issue seems to be a Java PRNG implementation issue.
Electrum should be safe from this, because it does not use Java; it uses /dev/urandom directly.
However, there might be other bugs in the Android platform, which is under overall scrutiny following this issue.



how about the OSX
and windows version.?

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
btcven
Hero Member
*****
Offline Offline

Activity: 715
Merit: 500


Bitcoin Venezuela


View Profile WWW
August 14, 2013, 01:48:05 AM
 #6

how about the OSX
and windows version.?

https://bitcointalk.org/index.php?topic=167276.0

Admin: rdymac (PGP) | contacto@bitcoinvenezuela.com | @cafebitcoin | Electrum, lightweight bitcoin client
If I've been helpful tip me a coffee! Cheesy1rdymachKZpA9pTYHYHMYZjfjnoBW6B3k Bitrated user: rdymac.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!