Bitcoin Forum
June 08, 2024, 01:56:02 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Wallet choice/safety guide!  (Read 188 times)
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 24, 2018, 10:35:39 PM
Last edit: May 06, 2018, 03:59:30 AM by BQ
 #1

There are a lot of questions, and while I am not an expert, I thought I'd try and put the information I know in a place to help people.
if you find any flaws/wrongs please write and I will edit!

MyEtherWallet is a popular wallet.
However, it's an interface, they don't save your keys, they can't help you if you lose your keys/funds.
MyEtherWallet is only a bridge to communicate with the blockchain.
Many people use this, and due to this DNS 'hack' and other hacks like it that has happened, I thought I would make a simple guide.

I suggest that if you want to keep using MyEtherWallet, do it offline!
Here's a guide on how to use MEW offline: https://myetherwallet.github.io/knowledge-base/offline/running-myetherwallet-locally.html
Always make sure the lock icon next to the url bar is Green!

MyEtherWallet also allows you to 'generate' a wallet (basically get a public+private key). The safest choice would be to download an encrypted keyfile and use that to login.
This means that even if someone were to access your keyfile, they'd require your password.
However, if you submit this data to a phishing site, you'd still lose your funds!
Entering your private key in plain text is unwise as a keylogger/middleman could read this data.

Another popular choice is MetaMask.
https://metamask.io/
MetaMask is a browser plugin which basically lets you do all your transactions in a little browser window, instead of going to for example MyEtherWallet.
MetaMask is great because it also allows you to easily interact with any type of dApps with ease(basically your MetaMask would work as an account in a way).
MetaMask also protects you versus phishing sites.
As I understand it, MetaMask stores a file locally encrypted with a password.
The public key is seen in MetaMask, however you can also export the private key.


Hardware wallets
I personally advocate for Trezor as it is open source(therefore all code can be verified to be safe).
The most popular wallet however, I believe is Ledger Nano.

Basically how a hardware wallet works is, keys are generated inside it.
Whenever you want to do a transaction, all that happens is that the transaction is signed inside your hardware wallet,
and this signed transaction data is broadcasted. The private key never leaves your wallet.
The recipient address could still be changed by a virus!
Hardware wallets generally have a screen and buttons to confirm transactions and you can confirm the address.


In my personal opinion, hardware wallets are the best choice for most people - they are foolproof and safe.
You get a recovery phrase you write down in case you lose your wallet.
To access it, you need to enter a PIN that you choose on first time setup.
Trezor/Ledger supports many different cryptos, not only bitcoin/eth.

However, of course a physical device comes with a cost - ~$50-100 depending on which one you go for.
If you believe your crypto will one day be worth a lot, or already is - it's definately a sound investment!

sites:
www.ledgerwallet.com
www.trezor.io


Keeping funds on an exchange
This is quite popular, and I guess there is nothing wrong with it.
But, people need to be aware of the risks involved.
Any funds kept on an exchange, is not truly your funds!
All it is, is their database saying that your account holds [these cryptos].
It doesn't mean they actually have coverage to cover everyone incase a mass cashout(probably a small risk tho).

What is more important, is to consider what this means - they're in control of your funds,
and theoretically, they can very easily prevent you from ever receiving your funds.
Of course, this is not something that one has to worry about in general - however, just keep in mind that it's not actually yours.
It's like a bank.

This also means that if your account is hacked, or if the exchange itself is hacked, you might end up lose part of/all your funds.
Hot wallet: this is the wallet(s) the exchange uses to payout/receive to, and usually holds a small percentage(<10%) of all funds.
So if an exchange were hacked, they shouldn't be able to lose more than what is in their hot wallets.

Cold wallet: These are wallets that are not exposed to the internet (in terms of private key access by software etc).
An exchange should keep the majority of their funds here.

Summary
This is my personal opinion
Ordering by safety
1. Hardware Wallet
2. MetaMask
3. MyEtherWallet
4. Exchange

I would like to expand on one topic regarding safety:
a more 'technical savvy' person, could be perfectly fine with his private key in plaintext.
however, in general, one should be cautious of exposing your private key(in any form - plaintext, encoded), to any sort of software.
If you have a virus, an encrypted file isn't enough, because the moment you decrypt it you'd expose your password to the virus.
If you are using many different plugins in your browser, they might be reading your data(check permissions).

There are too many risks, and way too many people are being scammed.
Don't do it too late, ensure that you're safe today, because in the end - noone can help you.
Part of what's great about crypto is this aspect; isn't it? You and only you are in control of your funds, in all aspects - including safekeeping.'

Here are a few tips I think could be useful:
  • Scan your computer for viruses on a regular basis(Malwarebytes AntiMalware is a good choice)
  • If possible, use a second computer with a factory state OS
  • use a different browser without any plugins(apart from MetaMask if that's your choice)
  • always ensure that any site you access and intend to put your crypto information in, has a valid certificate.
  • (valid certificate: click the green lock next to the URL bar, check the info, confirm it's always the same).
  • no company handling money would let their certificate expire.
  • if you only want to check your funds, use etherscan.io and search your public address

if you are using Windows, you can also install a second OS - for example Linux Mint.
It's free, and only requires a CD/USB. You can have dualboot setup, so when you want to access your crypto,
just restart your computer, enter Linux Mint, do your business, and restart back into Windows!

A useful browser plugin is NoScript which prevents any site from running javascript without your manual approval.
Other useful plugins in my opinion(somewhat unrelated): uBlock Origin, Privacy Badger, Cookie AutoDelete, Disconnect  Roll Eyes

Finally, if you are not at all a technical person, it might be better to leave your crypto at an exchange.
Surely the exchange is not the safest place, but a virus riddled computer or general risk behaviour is definately not safer!

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
Matthewmorris4
Member
**
Offline Offline

Activity: 350
Merit: 10

BitbondSTO.com | Germany’s First STO | Earn Stable


View Profile
April 24, 2018, 10:43:47 PM
 #2


Summary
This is my personal opinion
Ordering by safety
1. Hardware Wallet
2. MetaMask
3. MyEtherWallet
4. Exchange


Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.

Still prefer on metamask anyway, easy to use and very flexible

griezmann
Newbie
*
Offline Offline

Activity: 181
Merit: 0


View Profile
April 24, 2018, 10:52:22 PM
 #3

For me, i'm still using MyEtherWallet since i got into crypto, since the first time i'm using it, i haven't found any problem yet, that's why i don't think i need another wallet for my altcoins, i read there are already so many wallet these days, but MEW is still the best for me, because it's so simple and easy to use.
Milansilver7
Newbie
*
Offline Offline

Activity: 168
Merit: 0


View Profile
April 24, 2018, 10:59:59 PM
 #4

very interesting information. You provide tips to avoid hackers and how to prevent them, thanks to all this exciting information. MEW and metamask users will be greatly helped by the information you provide.
richaerich
Newbie
*
Offline Offline

Activity: 182
Merit: 0


View Profile
April 24, 2018, 11:00:40 PM
 #5

Before you choose your wallet, make sure the wallet that you're going to use is not a phising site, as for me, i used MyEtherWallet (MEW) since the beginning,

https://www.myetherwallet.com/

right after i join into crypto, my friend told me to use this wallet, since that, i enjoyed using MEW as my wallet, it is so simple and easy to use for me.
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 24, 2018, 11:02:43 PM
 #6

Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.

Still prefer on metamask anyway, easy to use and very flexible

I've also seen there were some exploits, however one weren't at risk unless there were physical access to it?(might be wrong).
again it's only my personal opinions, hardware wallets are quite easy to use atleast,
and for many who often fall for phishers, viruses etc, a hardware wallet atleast doesn't expose the private key!  Cheesy

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
batang_bitcoin
Hero Member
*****
Offline Offline

Activity: 2996
Merit: 600


Eloncoin.org - Mars, here we come!


View Profile
April 24, 2018, 11:09:06 PM
 #7

Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.
Are you referring to this incident?
Man’s Life Savings Stolen from Hardware Wallet Supplied by a Reseller

Hardware wallets are still trustworthy and very safe to use. If you'll notice on what happened to the guy that lost his life savings through his hardware Ledger Nano S. He bought the wallet and the recovery words were already established by the re-seller so it only means that the re-seller can open his wallet which is very intentional and the guy isn't knowledgeable through as its his first time of buying it.



 

 

 

 

 

 


▄▄████████▄▄
▄▄████████████████▄▄
▄██
████████████████████▄
▄███
██████████████████████▄
▄████
███████████████████████▄
███████████████████████▄
█████████████████▄███████
████████████████▄███████▀
██████████▄▄███▄██████▀
████████▄████▄█████▀▀
██████▄██████████▀
███▄▄█████
███████▄
██▄██████████████
░▄██████████████▀
▄█████████████▀
████████████
███████████▀
███████▀▀
.
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██████████
███████████
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
▀█
██████████████████████▀
▀██
███████████████████▀
▀███████████████████▀
▀█████████
██████▀
▀▀███████▀▀
.
 ElonCoin.org 
.
████████▄▄███████▄▄
███████▄████████████▌
██████▐██▀███████▀▀██
███████████████████▐█▌
████▄▄▄▄▄▄▄▄▄▄██▄▄▄▄▄
███▐███▀▄█▄█▀▀█▄█▄▀
███████████████████
█████████████▄████
█████████▀░▄▄▄▄▄
███████▄█▄░▀█▄▄░▀
███▄██▄▀███▄█████▄▀
▄██████▄▀███████▀
████████▄▀████▀
█████▄▄
.
"I could either watch it
happen or be a part of it"
▬▬▬▬▬
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 24, 2018, 11:25:43 PM
 #8

Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.
Are you referring to this incident?
Man’s Life Savings Stolen from Hardware Wallet Supplied by a Reseller

Hardware wallets are still trustworthy and very safe to use. If you'll notice on what happened to the guy that lost his life savings through his hardware Ledger Nano S. He bought the wallet and the recovery words were already established by the re-seller so it only means that the re-seller can open his wallet which is very intentional and the guy isn't knowledgeable through as its his first time of buying it.

That's an important note, although it is mentioned on the wallet sites: only buy from approved resellers, or from the company itself!

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 25, 2018, 12:06:31 AM
 #9

Also an interesting link with useful content:
https://medium.com/@myetherwallet/stop-getting-phished-heres-how-310694d8fc5f

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
awazieik
Full Member
***
Offline Offline

Activity: 448
Merit: 100



View Profile WWW
April 25, 2018, 12:51:49 AM
 #10

Loads of information here which will be helpful to the community. Unfortunately it is sad that despite this information is available for all, people would still fall for such a scam. Today, lots of people lost their money to Phishing. Thanks for this great info. Take care

► HackenAI ◄ ♦ HackenAI - Personal Cybersecurity Application ♦ ► HackenAI ◄
───●●───●●───●●───●●───●●─[   Bounty Detective   ]─●●───●●───●●───●●───●●───
Facebook|Twitter|Medium|Reddit|Telegram|Whitepaper
Crypto Chips
Full Member
***
Offline Offline

Activity: 363
Merit: 101

Cryptocurrency is Dilema


View Profile WWW
April 25, 2018, 12:57:51 AM
 #11


Summary
This is my personal opinion
Ordering by safety
1. Hardware Wallet
2. MetaMask
3. MyEtherWallet
4. Exchange


Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.

Still prefer on metamask anyway, easy to use and very flexible
really that hardware wallet is potentialy infected with malware?
what about ledger nano s that i use now for store my bitcoin ?
batang_bitcoin
Hero Member
*****
Offline Offline

Activity: 2996
Merit: 600


Eloncoin.org - Mars, here we come!


View Profile
April 25, 2018, 05:53:58 AM
 #12

Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.
Are you referring to this incident?
Man’s Life Savings Stolen from Hardware Wallet Supplied by a Reseller

Hardware wallets are still trustworthy and very safe to use. If you'll notice on what happened to the guy that lost his life savings through his hardware Ledger Nano S. He bought the wallet and the recovery words were already established by the re-seller so it only means that the re-seller can open his wallet which is very intentional and the guy isn't knowledgeable through as its his first time of buying it.

That's an important note, although it is mentioned on the wallet sites: only buy from approved resellers, or from the company itself!
That's right, you should only buy from official website
https://www.ledgerwallet.com/

You can also buy from their legit partners and retailers
https://www.ledgerwallet.com/retailers



 

 

 

 

 

 


▄▄████████▄▄
▄▄████████████████▄▄
▄██
████████████████████▄
▄███
██████████████████████▄
▄████
███████████████████████▄
███████████████████████▄
█████████████████▄███████
████████████████▄███████▀
██████████▄▄███▄██████▀
████████▄████▄█████▀▀
██████▄██████████▀
███▄▄█████
███████▄
██▄██████████████
░▄██████████████▀
▄█████████████▀
████████████
███████████▀
███████▀▀
.
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██████████
███████████
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
▀█
██████████████████████▀
▀██
███████████████████▀
▀███████████████████▀
▀█████████
██████▀
▀▀███████▀▀
.
 ElonCoin.org 
.
████████▄▄███████▄▄
███████▄████████████▌
██████▐██▀███████▀▀██
███████████████████▐█▌
████▄▄▄▄▄▄▄▄▄▄██▄▄▄▄▄
███▐███▀▄█▄█▀▀█▄█▄▀
███████████████████
█████████████▄████
█████████▀░▄▄▄▄▄
███████▄█▄░▀█▄▄░▀
███▄██▄▀███▄█████▄▀
▄██████▄▀███████▀
████████▄▀████▀
█████▄▄
.
"I could either watch it
happen or be a part of it"
▬▬▬▬▬
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 25, 2018, 10:28:31 AM
 #13


Summary
This is my personal opinion
Ordering by safety
1. Hardware Wallet
2. MetaMask
3. MyEtherWallet
4. Exchange


Hardware in this day i think its not worth anymore. There also some problem in there. Since i heard news some hardware wallets have been compromised with a malware.
So its like even you have the key of your hardware wallets, there is someone that even know it too.

Still prefer on metamask anyway, easy to use and very flexible
really that hardware wallet is potentialy infected with malware?
what about ledger nano s that i use now for store my bitcoin ?


as far as I am aware(I might be wrong), you can't lose your funds without:
1. downloading a bad update
2. someone uses a physical exploit

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
AK47-
Sr. Member
****
Offline Offline

Activity: 644
Merit: 250



View Profile
April 25, 2018, 10:31:52 AM
 #14

Until today, I would have blindly told everyone to go ahead with MEW, but after the recent phishing attack, I cannot recommend it to anyone. I am myself in dilemma as to which wallet to choose. I have been considering using a hardware wallet now since the probability of a thief breaking into my house is way lower than a person scamming me on the internet.
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
April 25, 2018, 10:42:47 AM
 #15

Until today, I would have blindly told everyone to go ahead with MEW, but after the recent phishing attack, I cannot recommend it to anyone. I am myself in dilemma as to which wallet to choose. I have been considering using a hardware wallet now since the probability of a thief breaking into my house is way lower than a person scamming me on the internet.

there is also a PIN code, so even if someone stole it, they couldn't access it! (without threatening you for the pin I guess!)
and if you lose it, you have a 24 word recovery phrase which you can enter in the right order again to restore the same keys(on a new device).
so it's surely quite good.

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
richan
Member
**
Offline Offline

Activity: 392
Merit: 11


View Profile
April 25, 2018, 10:47:23 AM
 #16

MyEtherwallet is the best wallet I have used over the years to hold most of my altcoins. It allows you to control the private keys to receive and send tokens.  Metamask is another wallet which is most secured and even Mytherwallet even recommend anyone to use to log in instead of private keys.
mpufatzis
Full Member
***
Offline Offline

Activity: 840
Merit: 128



View Profile WWW
April 29, 2018, 10:58:29 AM
 #17

What if you make an off-line transaction, following these instructions:

https://kb.myetherwallet.com/offline/making-offline-transaction-on-myetherwallet.html

And use two PCs, one off-line (cold storage) and one one-line (hot wallet).
Do you think there is still a danger?
BQ (OP)
Member
**
Offline Offline

Activity: 616
Merit: 53

CoinMetro - the future of exchanges


View Profile
May 01, 2018, 01:33:23 AM
 #18

What if you make an off-line transaction, following these instructions:

https://kb.myetherwallet.com/offline/making-offline-transaction-on-myetherwallet.html

And use two PCs, one off-line (cold storage) and one one-line (hot wallet).
Do you think there is still a danger?

That is the usual way for any type of exchanges and such to handle business I think, so as long as you keep everything safe in general on the offline computer, that should be quite safe I think!

5 EUR free crypto on signup! XCM exchange token ⚜⚜⚜  CoinMetro - Copy Trading - Margin - 0% maker fee  ⚜⚜⚜ - generate €500 volume in July for a chance to win €100!
bubblebubble
Member
**
Offline Offline

Activity: 616
Merit: 23


View Profile
May 01, 2018, 05:11:13 AM
 #19

Great post for a Newbie!
This is very useful for who starts with crypto assets!

Thanks for your effort!
grifinmch
Sr. Member
****
Offline Offline

Activity: 756
Merit: 250


View Profile
May 01, 2018, 05:45:58 AM
 #20

There are a lot of questions, and while I am not an expert, I thought I'd try and put the information I know in a place to help people.
if you find any flaws/wrongs please write and I will edit!

MyEtherWallet is a popular wallet.
However, it's an interface, they don't save your keys, they can't help you if you lose your keys/funds.
They are just a bridge to communicate with the blockchain.
Many people use this, and due to this DNS issue today(and in the past) it seems like it's rerouting to some phishing site.
Therefore, I suggest that if you want to keep using MyEtherWallet, do it offline!
Here's a guide on how to use MEW offline: https://myetherwallet.github.io/knowledge-base/offline/running-myetherwallet-locally.html
Always make sure the lock icon next to the url bar is Green!

MyEtherWallet also allows you to generate a wallet. The safest choice would be to download an encrypted keyfile and use that to login.
This means that even if someone were to access your keyfile, they'd require your password.
However, if you submit this data to a phishing site, you'd still lose your funds!
Entering your private key in plain text is unwise as a keylogger/middleman could read this data.


MyEtherWallet according to me is the best wallet. talking about security this time some MEW, this happened not because of a weak system. but because many phishing sites affected that they open themselves. outline and MEW security system still remain secure.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!