Bitcoin Forum
July 19, 2024, 05:15:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Question] The security of disclosing MPK and Gap Limit Security  (Read 808 times)
lophie (OP)
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1001

Unlimited Free Crypto


View Profile
November 13, 2013, 04:02:49 AM
 #1

Hello, can anyone with knowledge around here help me understand if it is secure to share MPK publicly, And I am thinking of using 10 digit huge gap limit (9^10), Would that affect how secure the MPK is? and how come?

Will take me a while to climb up again, But where is a will, there is a way...
Tachikoma
Hero Member
*****
Offline Offline

Activity: 938
Merit: 1000



View Profile WWW
November 13, 2013, 09:21:17 AM
 #2

Your MPK exposes your addresses. So anybody with your MPK can view your balance and see where your money went. They won't be able to spend it however. Your MPK already exposes everything regardless of your gap limit. This is a client side setting that won't effect anything besides that. I wouldn't use a gap limit of 9^10th since Electrum will need to check balance for all these addresses to see if any funds came in. I doubt it would work.

Electrum: the convenience of a web wallet, without the risks | Bytesized Seedboxes BTC/LTC supported
tandit
Newbie
*
Offline Offline

Activity: 13
Merit: 0


View Profile
November 15, 2013, 06:10:34 AM
 #3

I think I found a bug in 1.9.4.  I entered my master public key on a separate internet connected computer to create a watching only wallet, but  if I right click on a public address, I can see the address's private key and it did not ask me for my password.  It may be nothing, but I would definitely NOT share your MPK until this is clarified.  I have transferred all my funds out of electrum for the time being. 

Does this happen to anyone else?
btcven
Hero Member
*****
Offline Offline

Activity: 715
Merit: 500


Bitcoin Venezuela


View Profile WWW
November 15, 2013, 07:55:14 AM
 #4

I think I found a bug in 1.9.4.  I entered my master public key on a separate internet connected computer to create a watching only wallet, but  if I right click on a public address, I can see the address's private key and it did not ask me for my password.  It may be nothing, but I would definitely NOT share your MPK until this is clarified.  I have transferred all my funds out of electrum for the time being. 

Does this happen to anyone else?

I entered my master public key on a separate internet connected computer to create a watching only wallet, but if I right click on a public address and click on "private key", I can see the address's private key without it asking me for my password.  Am I wrong or is this in effect no different than having an unencrypted wallet? If someone could hack into my computer, they could see the private keys for all my addresses.  Until this is clarified, I have transferred all my funds out of electrum wallets for the time being (though electrum is otherwise great).

Does this happen to anyone else?

I guess you are talking about the wallet that has your seed (not the watching-only wallet), and that you forgot to encrypt it.
just add a password..

or maybe you selected 'restore from seed' and typed your master public key there

Nope.  It is my watching-only wallet on a computer that has never had a hot wallet on it.  I even erased the watching only wallet, reentered my MPK and it still happens.  However, I compared the private keys shown on the watching-only wallet to the cold storage wallet the private keys are different.  Could a dev or someone explain what is going on?  Does this mean I am okay?

you definitely selected 'restore from seed' instead of 'restore from master public key', and typed your master public key there

No I definitely didn't either time, both times it said "watching only wallet" after it was created, and I can only create unsigned transactions.  Let's just take my word for it that I entered it in the correct place, what should be happening when I click on private key?  I'm on OSX Mavericks if that is of any help.

I'm on Mavericks and I can't reproduce what you are seeing. I've created a fresh wallet, then restore from its MPK and it doesn't appear to have the private key option as expected.

Then restore using the MPK entering it in the seed section and got a different set of a addresses, that obviously carries privkeys.

Admin: rdymac (PGP) | contacto@bitcoinvenezuela.com | @cafebitcoin | Electrum, lightweight bitcoin client
If I've been helpful tip me a coffee! Cheesy1rdymachKZpA9pTYHYHMYZjfjnoBW6B3k Bitrated user: rdymac.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!