Bitcoin Forum
April 24, 2024, 06:15:00 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: How to verify Electrum that comes preinstalled on Tails?  (Read 231 times)
hatshepsut93 (OP)
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
July 26, 2019, 02:00:43 AM
 #1

I usually install and verify Electrum manually, but the last time I've used Electrum that comes with Tails (the OS itself was verified though), and I just realized that I didn't verify it, and simply trusted that it's the genuine version. How can I check that it was signed by Electrum devs? I'm not very experienced with Linux, so please, be detailed when you describe the steps.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
1713939300
Hero Member
*
Offline Offline

Posts: 1713939300

View Profile Personal Message (Offline)

Ignore
1713939300
Reply with quote  #2

1713939300
Report to moderator
1713939300
Hero Member
*
Offline Offline

Posts: 1713939300

View Profile Personal Message (Offline)

Ignore
1713939300
Reply with quote  #2

1713939300
Report to moderator
The forum strives to allow free discussion of any ideas. All policies are built around this principle. This doesn't mean you can post garbage, though: posts should actually contain ideas, and these ideas should be argued reasonably.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713939300
Hero Member
*
Offline Offline

Posts: 1713939300

View Profile Personal Message (Offline)

Ignore
1713939300
Reply with quote  #2

1713939300
Report to moderator
Abdussamad
Legendary
*
Offline Offline

Activity: 3598
Merit: 1560



View Profile
July 26, 2019, 03:10:39 AM
Merited by hatshepsut93 (1)
 #2

you can't since it was packaged by the tails developers. so if you trust the tails developers you can verify the gpg sig of the ISO file you downloaded against their signing key.

note that the version of electrum they include with tails is obsolete so you can no longer use it. you will have to update: http://docs.electrum.org/en/latest/tails.html
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
July 26, 2019, 11:26:11 AM
 #3

The version of electrum on tails is outdated.

Simply download the new version and verify this one.
If you don't have tails connected to the internet, use a mounted drive / USB.

And if you don't want to do this each time you boot up tails, create some persistence storage on your bootable drive (assuming you are using tails on a live-usb) and save the .AppImage there.

The persistence storage will not be deleted once you shut down tails.


P.s. Make sure to have a physical backup of your mnemonic code.
The wallet file is saved in a location which will be deleted upon shutdown.
If you don't want to enter your seed each time, move the wallet file to the persistence storage too.

NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6365


Looking for campaign manager? Contact icopress!


View Profile
July 26, 2019, 07:39:22 PM
 #4

I've played with Electrum on Tails not so long ago, so I can help with links.

Indeed, the Electrum from Tails is too old, you need to put a new one onto persistent storage. For that, the easiest tutorial is the official one.

While it didn't help me much on install side, this (too) detailed tutorial tells all you need about verifying (the new) Electrum.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
hatshepsut93 (OP)
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
July 26, 2019, 07:56:17 PM
 #5

The version of electrum on tails is outdated.

Simply download the new version and verify this one.
If you don't have tails connected to the internet, use a mounted drive / USB.


I know, but I use it offline, so I don't need to send transactions from it, I just sign transactions.

Normally you can't verify application which already installed, whether it's on Windows or Linux, unless it's portable application which only have file and you can compare/verify it's hash/signature.


I'm thinking, maybe there's some way to get a hash of the installed Electrum, than match it with a hash of another installed Electrum that I verified beforehand? Or is it all just not worth it, and I should just download and verify Electrum, save it on a USB stick and use it with my cold storage?

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Artemis3
Legendary
*
Offline Offline

Activity: 2016
Merit: 1563


CLEAN non GPL infringing code made in Rust lang


View Profile WWW
July 30, 2019, 03:19:07 AM
 #6

I've played with Electrum on Tails not so long ago, so I can help with links.

Indeed, the Electrum from Tails is too old, you need to put a new one onto persistent storage. For that, the easiest tutorial is the official one.

While it didn't help me much on install side, this (too) detailed tutorial tells all you need about verifying (the new) Electrum.

Persistence is not really needed, but you will of course need to reinstall it again on every boot. This is important for paranoid people that don't want any sort of writing.

██████
███████
███████
████████
BRAIINS OS+|AUTOTUNING
MINING FIRMWARE
|
Increase hashrate on your Bitcoin ASICs,
improve efficiency as much as 25%, and
get 0% pool fees on Braiins Pool
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
July 30, 2019, 03:54:58 AM
 #7

~
I know, but I use it offline, so I don't need to send transactions from it, I just sign transactions.
i can think of at least 5 different ways that a malicious wallet can steal your funds without even needing any internet connection. it goes from simplest way of changing your payto field to advanced cryptographic ways of revealing your private key to the hacker without you even noticing since the transaction wouldn't look any different.

Quote
I'm thinking, maybe there's some way to get a hash of the installed Electrum, than match it with a hash of another installed Electrum that I verified beforehand? Or is it all just not worth it, and I should just download and verify Electrum, save it on a USB stick and use it with my cold storage?
downloading, verifying and installing that is always the safest option. anything else is a workaround and is not as safe since you may miss many things.
as for hashes there are about 400-500 files in the tarball that you install on Linux and you'll have to calculate hash of each file and check it against the real files!

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
hatshepsut93 (OP)
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
July 30, 2019, 04:35:48 AM
 #8

~
I know, but I use it offline, so I don't need to send transactions from it, I just sign transactions.
i can think of at least 5 different ways that a malicious wallet can steal your funds without even needing any internet connection. it goes from simplest way of changing your payto field to advanced cryptographic ways of revealing your private key to the hacker without you even noticing since the transaction wouldn't look any different.

I was not talking about implications of running potentially malicious client offline, of course that would be stupid. bob123 was saying that Electrum that comes with tails is outdated, meaning that it probably can't send transactions, since servers would reject them to incentivize users to upgrade to newest versions that don't have the infamous phishing vulnerability. But it works for signing transactions or creating new wallets just fine.


.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
July 30, 2019, 08:30:12 AM
 #9

~
I know, but I use it offline, so I don't need to send transactions from it, I just sign transactions.
i can think of at least 5 different ways that a malicious wallet can steal your funds without even needing any internet connection. it goes from simplest way of changing your payto field to advanced cryptographic ways of revealing your private key to the hacker without you even noticing since the transaction wouldn't look any different.

I was not talking about implications of running potentially malicious client offline, of course that would be stupid. bob123 was saying that Electrum that comes with tails is outdated, meaning that it probably can't send transactions, since servers would reject them to incentivize users to upgrade to newest versions that don't have the infamous phishing vulnerability. But it works for signing transactions or creating new wallets just fine.

oh yeah of course, that is the only thing that matters as long as you are sure that the preinstalled version is legit. but i was just pointing out the main question here regarding "verification of the already installed Electrum on Tails." and how you couldn't be sure about it so there are still ways to lose money even if you were offline.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!