Bitcoin Forum
April 24, 2024, 02:39:06 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ideas for increased security  (Read 166 times)
csharpner (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
January 01, 2020, 09:37:46 PM
 #1

Here are some ideas for increased security with the Electrum wallet:

  • Publish the releases on IPFS.  (The link is also the hash & it's decentralized)
  • Digitally sign the releases (whether published on the legacy website or on IPFS)
  • Let me see the software version # when I launch the app, without having to enter my wallet password!  I need this to see if there's an update before entering my pw into a potentially vulnerable version.
  • Let me check for updates before entering my password to my wallet.
  • Establish a presence on the new, decentralized web platforms.  Operate under the assumption that your domain name will eventually be compromised either by thieves or the government (yet, I repeat myself! Smiley )
1713926346
Hero Member
*
Offline Offline

Posts: 1713926346

View Profile Personal Message (Offline)

Ignore
1713926346
Reply with quote  #2

1713926346
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713926346
Hero Member
*
Offline Offline

Posts: 1713926346

View Profile Personal Message (Offline)

Ignore
1713926346
Reply with quote  #2

1713926346
Report to moderator
1713926346
Hero Member
*
Offline Offline

Posts: 1713926346

View Profile Personal Message (Offline)

Ignore
1713926346
Reply with quote  #2

1713926346
Report to moderator
1713926346
Hero Member
*
Offline Offline

Posts: 1713926346

View Profile Personal Message (Offline)

Ignore
1713926346
Reply with quote  #2

1713926346
Report to moderator
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
January 01, 2020, 09:50:42 PM
 #2

This is probably the wrong place to make this also as you're better off posting it on their github... I don't think the electrum deva are as active here as elsewhere...

It is probably a good idea to enable users to check for an update before the password is entered but implementation might be difficult as it then changes how the software loads from the very start: which in theory should be easy to implement but turn out to be difficult to implement depending on how their engine renders screens...
GreatArkansas
Legendary
*
Offline Offline

Activity: 2296
Merit: 1345


Buy/Sell crypto at BestChange


View Profile WWW
January 02, 2020, 12:29:14 AM
 #3

It is probably a good idea to enable users to check for an update before the password is entered but implementation might be difficult as it then changes how the software loads from the very start(....)
This is something like, if ever there is an update you will be notify before to enter your password. Is it something like forcing the user to update their electrum client?
Might be difficult if that so, what if the user don't want to update their client? do they can still proceed?
Difficult implementation for sure .

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
January 02, 2020, 12:49:14 AM
 #4

I think op means the current implementation. As currently there's either a yes or no option or an OK one (I forget which).

It is probably a good idea to enable users to check for an update before the password is entered but implementation might be difficult as it then changes how the software loads from the very start(....)
This is something like, if ever there is an update you will be notify before to enter your password. Is it something like forcing the user to update their electrum client?
Might be difficult if that so, what if the user don't want to update their client? do they can still proceed?
Difficult implementation for sure .
pooya87
Legendary
*
Offline Offline

Activity: 3430
Merit: 10495



View Profile
January 02, 2020, 04:30:33 AM
Merited by ABCbits (1)
 #5

  • Publish the releases on IPFS.  (The link is also the hash & it's decentralized)
i don't think it can be a viable option because IPFS requires peers to continue seeding content. for example right now that we are on version 3.x peers have to continue seeding version 1.9 because someone might need it (eg. recovering a wallet file that doesn't work in new versions). and that is not something that people would do. best case scenario is decent seeds for new versions and older ones dying.

Quote
  • Digitally sign the releases (whether published on the legacy website or on IPFS)
the releases are already signed using PGP.

Quote
  • Let me see the software version # when I launch the app, without having to enter my wallet password!  I need this to see if there's an update before entering my pw into a potentially vulnerable version.
  • Let me check for updates before entering my password to my wallet.
this won't solve much. if you want security then you shouldn't be using the wallet online (on a computer that is connected to the internet). look into Electrum's cold storage options.
not to mention that the initial entering of your password only decrypts the public information such as your addresses and transaction history not your private keys.

Quote
  • Establish a presence on the new, decentralized web platforms.  Operate under the assumption that your domain name will eventually be compromised either by thieves or the government (yet, I repeat myself! Smiley )
it won't matter as long as users continue doing these two things:
1. verify the deterministic builds hashes
2. verify the PGP signature of each release.
or simply build from source code.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
DireWolfM14
Copper Member
Legendary
*
Offline Offline

Activity: 2170
Merit: 4237


Join the world-leading crypto sportsbook NOW!


View Profile WWW
January 02, 2020, 09:10:44 PM
 #6

Why do I get the feeling like the OP is just shilling for IPFS and their shit-file-coin?

Am I being overly cynical, is it just me?  I did have to go back to work today after two weeks off, so maybe it's just me.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!