Bitcoin Forum
May 02, 2024, 08:40:43 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 »  All
  Print  
Author Topic: WARNING when using mobile device wallets (Android, iOS)  (Read 693 times)
tech30338
Full Member
***
Offline Offline

Activity: 532
Merit: 125


Defend Bitcoin and its PoW: bitcoincleanup.com


View Profile WWW
August 02, 2023, 12:10:36 AM
 #21

Thanks op for the information, there is a reason why i dont use mobile phone and install wallet, since one of my friend got hack and lost his coins.
Just want to add to OP post, sometimes our phone are already infected or compromise without knowing, when we install app, we allow or authorize them to access information in our phone, maybe a malware has already there in the first place, this malware are sometimes attach to an application, without us knowing, and is just waiting for the right time to strike, and steal our funds.
This is why others prefer desktop, and Hardware wallet for additional security, but others who are more careful in installing applications, and wallet on mobile phones, especially those who experience and witness it before.
That is why if you are using you phone with wallets you should be very careful opening links, installing applications, and also scan your phones to be sure.

1714639243
Hero Member
*
Offline Offline

Posts: 1714639243

View Profile Personal Message (Offline)

Ignore
1714639243
Reply with quote  #2

1714639243
Report to moderator
1714639243
Hero Member
*
Offline Offline

Posts: 1714639243

View Profile Personal Message (Offline)

Ignore
1714639243
Reply with quote  #2

1714639243
Report to moderator
The grue lurks in the darkest places of the earth. Its favorite diet is adventurers, but its insatiable appetite is tempered by its fear of light. No grue has ever been seen by the light of day, and few have survived its fearsome jaws to tell the tale.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Dr.Bitcoin_Strange
Hero Member
*****
Offline Offline

Activity: 574
Merit: 514


Go after the goal... Go!!! It is worth getting!


View Profile WWW
August 02, 2023, 12:54:28 AM
 #22

My hot wallet is on my mobile, and I don't usually keep a huge amount of asset in it for this kind of reason. I have read a similar warning like this before about downloading and using a third-party keyboard, and many of those apps are built by hackers with inbuilt malware that can be used to hack and steal someone's assets. After reading that information about a year ago, I had to uninstall about two of the ones I had on my phone. The reason I even had them was because of the fancy designs they had and also because they could allow one to pin numerous messages on the keyboard, but I never knew it was even going to cause more harm to me.
_act_
Hero Member
*****
Online Online

Activity: 882
Merit: 1155



View Profile
August 02, 2023, 08:05:37 AM
 #23


Electrum keyboard on mobile phones is a virtual keyboard which is safe than the mobile phone keyboard. That is true but I noticed that you are using the old Electrum wallet. Electrum virtual keyboard looks different now and it does not allow screenshot.

For update, it is https://electrum.org/#download

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Upgrade00
Legendary
*
Offline Offline

Activity: 2030
Merit: 2173


Professional Community manager


View Profile WWW
August 02, 2023, 11:12:00 AM
 #24

This is why others prefer desktop, and Hardware wallet for additional security,
Just like your mobile wallet, your desktop wallet can also be compromised with malware's or virus if you install a corrupted file on the device. As far as the device is not airgapped than it's at risk of any danger which is available on the internet, limiting the applications you install and only doing that through the official websites reduce the risk but does ko eliminate it.

As a hot wallet you can use your regular device, as long as the amount you store there is small in comparison to how much it costs to buy a hardware wallet.

That is why if you are using you phone with wallets you should be very careful opening links, installing applications, and also scan your phones to be sure.
And if you can don't actively use your phones that have your Bitcoin wallet.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
satscraper
Hero Member
*****
Offline Offline

Activity: 728
Merit: 1338


Cashback 15%


View Profile
August 02, 2023, 12:33:58 PM
 #25

Wallet on Android device  is  like a cheesecake for those who create malicious programs because it indicates that user of  given mobile is  interested in crypto thereby his interest can be exploited to make a convenience of attacker, for instance, for cryptocurrency mining. One of the latest case is discovering of CherryBlos and FakeTrade, "involved in cryptocurrency-mining and financially-motivated scam campaigns targeting Android users".

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
DaveF
Legendary
*
Offline Offline

Activity: 3458
Merit: 6258


Crypto Swap Exchange


View Profile WWW
August 02, 2023, 01:35:32 PM
 #26

What about Samsung keyboard?
The same as I described above - closed sourced and operated by a huge corporation which makes large amounts of money from your data. I wouldn't trust it.

Gboard: https://reports.exodus-privacy.eu.org/en/reports/com.google.android.inputmethod.latin/latest/
SwiftKey: https://reports.exodus-privacy.eu.org/en/reports/com.touchtype.swiftkey/latest/

All of these keyboards require internet access. I wonder why? Roll Eyes

Minor nitpick but all of them USE the internet none of them REQUIRE it.

I have a 100% offline phone that I use as a 2fa device and a couple of other things. All apps have been side loaded on it and even though all wireless is broken, Gboard and Swiftkey and the stock Samsuck keyboard (when it was installed) worked fine.

You loose some features, but it's not 100% needed.

But, as I have been saying ALL PHONES NO MATTER WHAT THE BRAND ARE NOT SECURE. PERIOD. FULL STOP.

-Dave


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
SmartGold01
Hero Member
*****
Offline Offline

Activity: 686
Merit: 726


Don't joke with my Daughter


View Profile WWW
August 02, 2023, 06:48:14 PM
 #27

Mobile wallets are not exactly the most secure wallets in the world, but in case you really have to use them, please keep in mind one very important piece of information.

DO NOT use third-party keyboards while you are using the wallet app!

Somebody has already been robbed because of this. You must only use the stock Android or Apple keyboard, and no others. Better if you uninstall all 3rd party keyboards completely. They collect all data you type on the keyboard at all times, which is a requirement for them to function properly, and there is no telling who is at the other end of the server!

What! Is this also applicable?
This is why one needs to be generally visiting most of the various section of this forum because, if I am not mistaken never posted over here or even have to come read things over here that much, opening this section and I found this topic make me feels I am missing a lot of things. But nevertheless, I won't enable any other keyboard from my phone apart from in-build keyboard, although I do love using customized theme just as a Go-Launcher with various style of theme color displayed including keyboard but with this post I won't dear to allow that happened again. Truly they said "Knowledge is power"!

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
.
.SIGN UP.
Volgastallion
Sr. Member
****
Offline Offline

Activity: 476
Merit: 263


CONTEST ORGANIZER


View Profile
August 02, 2023, 06:58:32 PM
 #28

I think its more easy to think and use the corrects tools.

1- Never use a mobile wallet like your saves wallet.

2- Use mobile wallet only to and when you need to do some transfer or if you are gonna travel, and send from other wallets the X ammount you think you are gonna spend, nothing more and nothing less.

So, in the worst case scenario of a hacking you are not gonna lose so much or also nothing.

Anyways asides of my explanation, really good info you are spreading about the problem of third parties keyboard, people tends to trust so much in all.

███████████████████████████████▀▀▀▀
███████████████████████████████
█████████▀▀▀▀▀█▀█▀▀▀▀▀█████████
███▄▀▀▀   ▄▄▄▄   ▄▄▄▄   ▀▀▀▄███
███████▀▀▀████▌ ▐████▀▀▀███████
█████▀███▀█▀██▌ ▐██▀█▀███▀█████
███████▀▄▀▄███▌ ▐███▄▀▄▀███████
█████▄██▄██▄██   ██▄██▄██▄█████
███████▄▄▄████   ████▄▄▄███████
██████████▀▀▀▀   ▀▀▀▀██████████
██████████▄▄▄▄▄▄▄▄▄▄▄██████████
███████████████████████████████
███████████████████████████████▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
TRUST DICE
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
█▀▀▀











█▄▄▄
#1 RATED CRYPTO
CASINO IN THE WORLD
██ ██ ██ ██ █Trustpilot
▀▀▀█











▄▄▄█
▄█████████████████████████████
██████████████████▀▀█████▀▀████
█████████████████▀█████████▀███
██████████████████████████████
███████████████████████████▄███
█████████████████████████▄▄████
███████████████████████████████
█████████████░░░███████████████
███████████░░░█████████████████
█████████░░████████████████████
█████░░░██████████████████████
███░░█████████████████████████
▀░░░█████████████████████████▀
█▀▀▀











█▄▄▄
▀▀▀█











▄▄▄█
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
August 03, 2023, 08:18:47 AM
 #29

Minor nitpick but all of them USE the internet none of them REQUIRE it.
Right right. But unless you have rooted your phone (which brings a whole host of other security risks) and can individually block specific permissions or specific apps, is there anyway to prevent these keyboard apps from accessing the internet any time you are connected? I suspect not.

Smart phones in general are awful for your privacy and security. Everyone should go in to their phone's permissions at some point and take a look at just how many apps can access your camera, your microphone, your files, your messages, your location, and so on. And for lots of these apps, if you try to disable these unnecessary permissions they will just refuse to work.
Agbe
Hero Member
*****
Offline Offline

Activity: 882
Merit: 1252


View Profile
August 03, 2023, 02:34:57 PM
 #30

Mobile wallets are not exactly the most secure wallets in the world, but in case you really have to use them, please keep in mind one very important piece of information.

DO NOT use third-party keyboards while you are using the wallet app!

Somebody has already been robbed because of this. You must only use the stock Android or Apple keyboard, and no others. Better if you uninstall all 3rd party keyboards completely. They collect all data you type on the keyboard at all times, which is a requirement for them to function properly, and there is no telling who is at the other end of the server!
Add it to what the op has said, don't use third party desktop, laptop and mobile phone to login your wallet accounts because most of those guys, your friends, and family members set their devices autofill, that is automatically saved the username and the password so even though you logout from the device at the moment, once the person went to the browser/app and a click in the login box, all your details appear and once he clicks the username, the password would automatically refill in the box and the person will login to your wallet. I have heard this one before but for the keyboard this is the first time I am hearing it. Thank you op for the information. Caution must be taken and will be extent to friends and families.
sokani
Sr. Member
****
Offline Offline

Activity: 532
Merit: 434


Top Crypto Casino


View Profile WWW
August 03, 2023, 06:19:22 PM
 #31

I won't enable any other keyboard from my phone apart from in-build keyboard, although I do love using customized theme just as a Go-Launcher with various style of theme color displayed including keyboard but with this post I won't dear to allow that happened again. Truly they said "Knowledge is power"!
I'm glad you now know the harm they can cause you because they are not worth it. One of the ways hackers get access to your phone and wallet is through malware-infested apps and google playstore is good place where most of these apps are dumped by hackers. Stay clear off fancy keyboards and launchers, only use stock android keyboard, limit the way you give permissions to third party apps and when importing your seed phrase make sure your phone is not connected to the internet

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
CASINO
.
SPORTS
.
RACING
OFFICIAL PARTNER OF
Argentina NT
CLOUD9
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Z-tight
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1031


Only BTC


View Profile
August 03, 2023, 07:06:05 PM
 #32

Add it to what the op has said, don't use third party desktop, laptop and mobile phone to login your wallet accounts because most of those guys, your friends, and family members set their devices autofill, that is automatically saved the username and the password so even though you logout from the device at the moment, once the person went to the browser/app and a click in the login box, all your details appear and once he clicks the username, the password would automatically refill in the box and the person will login to your wallet.
You are describing an online web wallet here, which is unsafe to begin with and one should not even think of using a web wallet to store their BTC. In a web wallet you do not control your keys and your funds can be easily be hacked because it is online, there are enough open source software and hardware wallets like Electrum, Sparrow and Passport that you can use to hold your coins. And if you are using a good self custody wallet, it is obvious that you should not use your seed phrase or private key to import you wallet into any unsafe device or one that is not yours.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Minecache
Legendary
*
Offline Offline

Activity: 2184
Merit: 1024


Vave.com - Crypto Casino


View Profile
August 05, 2023, 04:02:13 PM
 #33

Ideally, you should only use open source wallet apps which use their own virtual keyboard for entering seed phrases, where you can verify exactly what the keyboard is doing. Electrum is one such example. Even using the stock Android or Apple keyboard isn't completely safe. These stock apps are usually not open source and are so deeply embedded in the phone's firmware that it is near impossible to verify if anything suspicious is happening in the background. And neither Google nor Apple exactly have a great reputation when it comes to privacy, data harvesting, and spying on users/collecting data they promised they wouldn't.

I have a question, if we can't trust the stock Android or Apple keyboard, can we trust their operating system or hardware product? Because we are also using their phone or computer to install Electrum. I am using Iphone, and everytime I install 3rd party app, they ask me if I allow the app to track me or not. Maybe Apple is trying to protect their customers' privacy from 3rd parties, but when I download their apps I don't see any warning. I suspect that it is entirely possible that they secretly collect user data.

internetional
Legendary
*
Offline Offline

Activity: 1456
Merit: 1693



View Profile WWW
August 05, 2023, 06:46:43 PM
 #34

If I am not wrong Gboard is the stock keyboard comes with most of the android devices
I use Gboard with all my mobile devices, both iOS and Android driven. I suppose Apple doesn’t even know what I type. Probably it’s even a little bit safer than using different stock keyboards with different mobile devices.
Z-tight
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1031


Only BTC


View Profile
August 05, 2023, 07:24:46 PM
 #35

I have a question, if we can't trust the stock Android or Apple keyboard, can we trust their operating system or hardware product? Because we are also using their phone or computer to install Electrum. I am using Iphone, and everytime I install 3rd party app, they ask me if I allow the app to track me or not.
Hot wallets are very prone to hacking, even if you use an open source OS only a small amount of funds should be held in a hot wallet. You should use either a hardware wallet to store your main funds or a properly set up air-gapped wallet that will never be connected to the internet, with a Linux based OS installed. If you use a cold storage set-up to store your funds, you can then install apps you want on your online device because it does not hold any of your funds, except maybe a small amount of it for daily transactions.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
un_rank
Hero Member
*****
Offline Offline

Activity: 714
Merit: 684


- Jay -


View Profile WWW
August 05, 2023, 07:47:15 PM
 #36

I have a question, if we can't trust the stock Android or Apple keyboard, can we trust their operating system or hardware product? Because we are also using their phone or computer to install Electrum.
You are not trusting that either, rather you are trusting verifying that electrum does not remotely store your private keys which will leave it exposed to be stolen. Even if the OS says they are not monitoring your data, they most likely are, what you have to do is limit to a minimum the amount of data they can access.

But as suggested above using an airgapped device or an open source hardware wallet like Passport is your safest option, cause the OS plays a huge role in the security of the applications that are run on them.

- Jay -

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
m2017
Legendary
*
Offline Offline

Activity: 1806
Merit: 1303


keep walking, Johnnie


View Profile
August 06, 2023, 04:37:28 PM
 #37

Mobile wallets are not exactly the most secure wallets in the world, but in case you really have to use them, please keep in mind one very important piece of information.
You are right when you say that mobile phones are, to put it mildly, not the safest. If possible, you should minimize the interaction with cryptocurrencies using mobile devices. If you store crypto on it, then only for pocket expenses, which you are ready to part with at any moment.

If desktop devices can be customized at your own discretion (choose an OS, programs and check their code), then in mobile devices the OS is preinstalled and all that remains is to believe the manufacturer's security assurances.

Somebody has already been robbed because of this. You must only use the stock Android or Apple keyboard, and no others. Better if you uninstall all 3rd party keyboards completely. They collect all data you type on the keyboard at all times, which is a requirement for them to function properly, and there is no telling who is at the other end of the server!

There are no guarantees that stock Android devices (especially from Chinese manufacturers) don't collect data either.


What about Samsung keyboard? Samsung smartphones come with it. Windows Phones came with Microsoft's Word Flow keyboard app and Swiftkey belongs to MS too. While I absolutely agree with the advice that you give here, I still don't think that that would be an issue for that person.

The person I quoted in the OP was robbed while using Swiftkey, so I really do mean it when I say only use those keyboards that ship in stock Android and iOS. And as o_e_l_e_o said, built-in open-source keyboards in wallet apps are even better - although you should NOT be storing crypto on a Windows Phone, because those devices don't get security updates anymore.
Updates on Windows Phone are no longer released, but this may play into the hands. There are relatively few such devices, and therefore, will attackers want to spend time and effort creating malicious programs for outdated, unpopular, moreover, dead operating systems? It seems to me that it is easier for them to concentrate on Android and iOS, where, due to the mass character, they will be able to find their victims. And Windows Phone, at best, is used by one and a half Johns around the world, and even those who don't have cryptocurrencies on these phones.

What are your thoughts on feature phones, like the blackberry with an external keyboard and the like? Astro Slide 5G Transformer, for example (although who knows what apps will be preinstalled here).

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
August 07, 2023, 07:29:18 AM
Merited by Minecache (1)
 #38

when importing your seed phrase make sure your phone is not connected to the internet
This is a completely false sense of security. Any decent malware can just wait until internet access is reestablished in order to transmit data. Devices are either airgapped or they are not. There is no such thing as this temporary airgap that people talk about.

I have a question, if we can't trust the stock Android or Apple keyboard, can we trust their operating system or hardware product?
The stock OSs which come pre-installed on phones are almost all closed source, so the answer is generally no, unless you are one of the few people using phones such as PinePhone or Librem.
Minecache
Legendary
*
Offline Offline

Activity: 2184
Merit: 1024


Vave.com - Crypto Casino


View Profile
August 07, 2023, 10:22:28 AM
 #39



I have a question, if we can't trust the stock Android or Apple keyboard, can we trust their operating system or hardware product?
The stock OSs which come pre-installed on phones are almost all closed source, so the answer is generally no, unless you are one of the few people using phones such as PinePhone or Librem.

That means our bitcoins are never safe even when we store them in the most secure ways. Even hardware wallets because they are produced and distributed by centralized companies, and they can come under pressure from the government at any time.

I've never used Linux before, but I've heard people say it's an open source operating system. So is it safe for me to use Electrum in conjunction with the Linux operating system?

If Linux is really secure, then setting up an air-gapped wallet is the safest for us.

o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
August 07, 2023, 12:16:58 PM
Merited by Minecache (1), Synchronice (1)
 #40

That means our bitcoins are never safe even when we store them in the most secure ways.
Not at all. There are plenty of secure ways to store your keys, but a hot wallet is never one of them.

Even hardware wallets because they are produced and distributed by centralized companies, and they can come under pressure from the government at any time.
So use a hardware wallet where all the hardware and software is open source, such as Passport. Should they come under pressure to implement backdoors or similar, that will be viewable in the code.

I've never used Linux before, but I've heard people say it's an open source operating system. So is it safe for me to use Electrum in conjunction with the Linux operating system?
A good Linux distro will be safer than Windows or MacOS, but simply using Linux does not make your wallets magically impenetrable. It is a single part of a good security set up.
Pages: « 1 [2] 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!