Bitcoin Forum
May 28, 2024, 12:28:19 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Closed BETA started! The only one secure iOS Bitcoin wallet that really works.  (Read 4997 times)
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 11:56:29 AM
 #21

test BTC confirmed.  Grin


tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 12:06:03 PM
 #22

Confirmation from my side.
https://www.dropbox.com/s/kgq0gbfwwl65dfe/Screen%20Shot%202014-03-14%20.png
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 12:19:26 PM
 #23

we may have some teething problems;

my brother in law has installed fruitwallet, and has sent me a request to send him some coins.
BUT - the address he sent me, via the fruitwallet app;

Please send bitcoins to

mrs61q1DPwScASkKzd2LCdHZyS17V9evRg


clearly, this is wrong... can you investigate the issue and let me know please?

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 12:20:53 PM
 #24

yep, pls wait few minutes.
Updated.
for some reason account was created at beta.fruitwallet.com Sad
Will resolve asap.
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 12:22:26 PM
 #25

yep, pls wait few minutes.
OK, let me know and I can relay the message to him.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 12:31:00 PM
 #26

2 e-mails were suddenly redirected to BETA.fruitwallet.com which is using not real bitcoins.

These are:
jos****@******
ro*******@******

If your brother is one of them, pls ask him to register at fruitwallet.com
We shut beta.fruitwallet.com down for now.

Issue resolved.
Thanks for help.
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 12:33:51 PM
 #27

yes, one of those is my bro in law

i've let him know, and also directed him to this thread.
can you remove the names above in the post now please^^

thanks.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 12:43:41 PM
 #28

done! sorry for inconvenience.  Wink
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 12:44:21 PM
 #29

done! sorry for inconvenience.  Wink

not a problem. just waiting on him re-installing so I can send him some coins.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
olsn
Newbie
*
Offline Offline

Activity: 55
Merit: 0


View Profile
March 14, 2014, 01:13:29 PM
 #30

Hi - I have not tested the app on my iOS device yet (only on my computer with a spoofed user agent)

I have three questions though:

1) Why is my password being sent in plain? - I know you do have an SSL-connection setup, but how do we know that your service won't fish for passwords? - Worst case scenario here is that passwords are saved in plain in the db or with a symetric key.
    -> It'd be more secure if noone knew my password but just a salted hash.

2) What is the specific reason for the OTA Profile Enrollment? Why do you need the UUID ect.?

3) What is proprietary about iOS devices/mobile safari that couldn't be done with other mobile browsers? (Or in short: Why is it iOS only and not Android as well?)

Besides that grats to the app so far.

raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 01:17:33 PM
 #31

OK, another issue I found.. the scan-qr function doesn't work, it simply asks my iphone to take a photo, you need to build a qr-scanner into it. This is essential.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 01:20:21 PM
 #32

and every time i try to send coins from it, it asks to install the profile. this needs fixed also.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
devthedev
Legendary
*
Offline Offline

Activity: 1050
Merit: 1004



View Profile
March 14, 2014, 01:22:49 PM
 #33

Will this ever be ported to Android? There's not too many decent wallets.

fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 01:51:37 PM
Last edit: March 14, 2014, 02:03:12 PM by fruitwallet
 #34

Answering all the questions.

1. Plain text. Have to clarify, Will update you asap.
Updated: WE use most secure approach for this module. If somebody will ever get your password (which we really doubt), he wont pass the next step of profile installation anyway. But we have even one more layer - it is your 4 digit protection code.

2. Profile is needed to tie your wallet to device. It ties when you do it first time. When sending bitcoins - it asks for profile to CHECK if it is REALLY your phone. This way we protect your send transactions.

3. This Profile feature is supported with Safari. Only safari as we discovered so far.
We didn't find 100% secure way for Android yet. We can do it theoretically, but we want to be 100% sure, your BTC are safe.

Scan QR works for us. Steps - 1. take photo, 2. click use. Result: it shows you the address, photo is not saved to gallery. Please explain.

Anymore questions guys?

Raskul,
"and every time i try to send coins from it, it asks to install the profile. this needs fixed also." Did I answer your question? It is just for your security.
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 01:59:40 PM
 #35

Scan QR works for us. Steps - 1. take photo, 2. click use. Result: it shows you the address, photo is not saved to gallery. Please explain.

Nope, I tried this but it is not importing the address for me.

Raskul,
"and every time i try to send coins from it, it asks to install the profile. this needs fixed also." Did I answer your question? It is just for your security.

yes thanks. just the qr scanning query which needs addressing now. take photo - yes, bitcoin address import - no.

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 02:05:40 PM
 #36

raskul, there should be button "use" just after you take a photo. I tested on 5c, 5, 4 iphones and iPad 2. Are you sure the photo quality is quite good? That is extremely important for us to understand the problem.
We won't like to add additional services to the app, it can influence security badly.
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 02:07:43 PM
 #37

raskul, there should be button "use" just after you take a photo. I tested on 5c, 5, 4 iphones and iPad 2. Are you sure the photo quality is quite good? That is extremely important for us to understand the problem.
We won't like to add additional services to the app, it can influence security badly.

yup, for sure... i've tried it many times, take photo - use photo - at different distances from the qr code I want to send to and it just doesn't import the bitcoin address...  Undecided

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
raskul
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
March 14, 2014, 02:12:47 PM
 #38

raskul, there should be button "use" just after you take a photo. I tested on 5c, 5, 4 iphones and iPad 2. Are you sure the photo quality is quite good? That is extremely important for us to understand the problem.
We won't like to add additional services to the app, it can influence security badly.

yup, for sure... i've tried it many times, take photo - use photo - at different distances from the qr code I want to send to and it just doesn't import the bitcoin address...  Undecided

OK now it has worked. not sure why it wasn't working before, but it's working now.
thanks

tips    1APp826DqjJBdsAeqpEstx6Q8hD4urac8a
fruitwallet (OP)
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
March 14, 2014, 02:24:39 PM
 #39

 Grin wow. best news Smiley
olsn
Newbie
*
Offline Offline

Activity: 55
Merit: 0


View Profile
March 14, 2014, 02:51:29 PM
 #40

Quote
1. Plain text. Have to clarify, Will update you asap.
Updated: WE use most secure approach for this module. If somebody will ever get your password (which we really doubt), he wont pass the next step of profile installation anyway. But we have even one more layer - it is your 4 digit protection code.

My concern was not someone logging into this app but saving innocent users. As you probably know MANY users have the same password for a lot of services. Now I don't want to say that this is good, but fact is that there are users out there who do it (many of them) - If you hash the password on the client with a salt before sending it anywhere you can make sure that just in case someone gets the hash they won't be able to do anything with it. Plus you cannot be accused of phishing passwords. Plus you are building more trust...

Device-Specific Profile:
What happens if I loose my device, it breaks or gets stolen? How will I be able to access the wallet?

And a question on the pricing: Will this service every cost anything? If so - what price-tag/subscription-model are you aiming for?
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!