Bitcoin Forum
May 07, 2024, 11:50:58 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Wallet password protected and encrypted, is it safe ?  (Read 246 times)
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
April 11, 2019, 12:10:17 PM
 #21

HCP, has there been cases where someone downloaded electrum from the actual electrum website and gotten a fake electrum installed?  You say the other half protection is verifying the signature of the downloaded file.
No. But there are times where you think you are on the Electrum website, but you are actually at electrun.org or electrum.to or something like this. By verifying the signatures, you can always be 100% that the file is legit and that you downloaded it from the right place. Make this an obligatory step and you will never be phished for lacking attention.

Not 100% correct.

You can think you are on the official electrum site (electrum.org shown in the browser, secured through TLS), while in fact you are on an attackers copy of the site.
There are multiple ways to accomplish this as an attacker (e.g. DNS spoofing / cache poisining, MITM, etc..).



Quote
But is there a chance verifying the signature of the downloaded file could give you malware/keylogger/virus?
No.

Well.. yes.. in exactly 2 cases this would be possible:

1) TomasV publishes a malicious version of electrum (would be very dumb of him - legal consequences)
2) Someone gains access to ThomasV's signing key and uploads a malicious version signed with this key.


1715125858
Hero Member
*
Offline Offline

Posts: 1715125858

View Profile Personal Message (Offline)

Ignore
1715125858
Reply with quote  #2

1715125858
Report to moderator
1715125858
Hero Member
*
Offline Offline

Posts: 1715125858

View Profile Personal Message (Offline)

Ignore
1715125858
Reply with quote  #2

1715125858
Report to moderator
"With e-currency based on cryptographic proof, without the need to trust a third party middleman, money can be secure and transactions effortless." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715125858
Hero Member
*
Offline Offline

Posts: 1715125858

View Profile Personal Message (Offline)

Ignore
1715125858
Reply with quote  #2

1715125858
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6978



View Profile WWW
April 11, 2019, 12:13:13 PM
 #22

Well.. yes.. in exactly 2 cases this would be possible:

1) TomasV publishes a malicious version of electrum (would be very dumb of him - legal consequences)
2) Someone gains access to ThomasV's signing key and uploads a malicious version signed with this key.


In that case, there is no way for him to know if that’s what is happening and if ThomasV is uploading malware. I prefer to keep things simple to not complicate more in his mind (jerry sounds quite perfectionist ans that’s highly unlike to happen).

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
April 11, 2019, 12:29:20 PM
 #23

In that case, there is no way for him to know if that’s what is happening and if ThomasV is uploading malware. I prefer to keep things simple to not complicate more in his mind (jerry sounds quite perfectionist ans that’s highly unlike to happen).

The probability is extremely small (at least if ThomasV knows how to secure his PGP key; which i think he does), but he deserves to get as much information as he wants to   Wink

I am currently communicating with jerr0 via PM regarding hardware security of a laptop (encryption, bios, etc..). He seems to be very inquisitiv for knowledge.
Let him get as much knowledge as possible  Grin

Even if a lot is quite theoretical and probably won't happen in the field, it is good to know whats theoretically possible (IMO).

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!