vayvanne
|
|
April 09, 2014, 12:42:32 AM |
|
It should depend does rpc accept connections from network by default config or not. If it does then wallets on such systems can be compromised and need a replacement. If it does not and user did not opened it to network then no reasons to worry.
|
|
|
|
BlockchainHelp?
Newbie
Offline
Activity: 28
Merit: 1
|
|
April 09, 2014, 12:43:03 AM |
|
I created 4 private keys offline in Bitcoin-QT 9.0 via TailsOS. My client never touched the internet, do I need to bring my cold storage online to create 4 new wallets in 9.1?
Man I'm worried now, I guess I will bring my wallets online tomorrow and create 4 new wallets *sigh*
|
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5390
Merit: 13426
|
|
April 09, 2014, 12:47:54 AM |
|
I hate being forced into new updates. Like MoonShadow once said (and I am paraphrasing): "I like to wait until they have ironed out the bugs with new releases before I update". I've been following that same rule, and only update if it's absolutely necessary. Which is why I never even upgraded to v0.9
That's a good policy. I also do that. You don't need to update from versions older than 0.9.0 unless you're using rpcssl. Most people aren't. EDIT: Also, are the cold addresses generated from bitaddress.org safe? Most of my cold Bitcoins are stored on addresses (with their keys) generated from bitaddress.org (i.e. the "Bulk Wallet" option)
bitaddress.org's HTTPS may have been compromised due to this OpenSSL bug, which could have allowed a man-in-the-middle to serve you malicious JavaScript. I recommend not using JavaScript Bitcoin software for anything important. I created 4 private keys offline in Bitcoin-QT 9.0 via TailsOS. My client never touched the internet, do I need to bring my cold storage online to create 4 new wallets in 9.1?
No, but don't ever run your 0.9.0 installation. When you want to access your cold storage, update to the latest version first.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
LogicalUnit
|
|
April 09, 2014, 12:53:18 AM |
|
I'm using Armory 0.90-beta with bitcoind 0.9.0. I don't believe I've ever used rcpssl -- but I'm not sure. I have an encrypted online wallet, and an offline wallet. Could my wallets be compromised?
|
|
|
|
STT
Legendary
Offline
Activity: 4102
Merit: 1453
|
|
April 09, 2014, 12:54:12 AM Last edit: April 09, 2014, 01:45:07 AM by STT |
|
If you ever used the payment protocol (you clicked a bitcoin: link and saw a green box in Bitcoin Core's send dialog), then you should consider your wallet to be compromised.
My exact thoughts. I think this is serious enough. alert is like defcon 1 I think, Im trying to imagine the crypto equal of an impending nuclear winter This vulnerability is caused by a critical bug in the OpenSSL library used by Bitcoin Core. Successfully attacking Bitcoin Core by means of this bug seems to be difficult in most cases, and it seems at this point that even successful attacks may be limited, but I recommend taking the above actions just in case.
I shivered for a monent. Next time try mentioning the good news first.
Thanks for the heads up!
I think action first is probably wise, prevention before cure? My noob question here is could gox claim this bug had any influence at all in their case That's a good policy. I also do that. You don't need to update from versions older than 0.9.0 unless you're using rpcssl. Most people aren't. Do they do alpha beta test before then allowing a recommended update to the masses
|
| CHIPS.GG | | | ▄▄███████▄▄ ▄████▀▀▀▀▀▀▀████▄ ▄███▀░▄░▀▀▀▀▀░▄░▀███▄ ▄███░▄▀░░░░░░░░░▀▄░███▄ ▄███░▄░░░▄█████▄░░░▄░███▄ ███░▄▀░░░███████░░░▀▄░███ ███░█░░░▀▀▀▀▀░░░▀░░░█░███ ███░▀▄░▄▀░▄██▄▄░▀▄░▄▀░███ ▀███░▀░▀▄██▀░▀██▄▀░▀░███▀ ▀███░▀▄░░░░░░░░░▄▀░███▀ ▀███▄░▀░▄▄▄▄▄░▀░▄███▀ ▀████▄▄▄▄▄▄▄████▀ █████████████████████████ | | ▄▄███████▄▄ ▄███████████████▄ ▄█▀▀▀▄█████████▄▀▀▀█▄ ▄██████▀▄█▄▄▄█▄▀██████▄ ▄████████▄█████▄████████▄ ████████▄███████▄████████ ███████▄█████████▄███████ ███▄▄▀▀█▀▀█████▀▀█▀▀▄▄███ ▀█████████▀▀██▀█████████▀ ▀█████████████████████▀ ▀███████████████████▀ ▀████▄▄███▄▄████▀ ████████████████████████ | | 3000+ UNIQUE GAMES | | | 12+ CURRENCIES ACCEPTED | | | VIP REWARD PROGRAM | | ◥ | Play Now |
|
|
|
almightyruler
Legendary
Offline
Activity: 2268
Merit: 1092
|
|
April 09, 2014, 12:58:12 AM |
|
I hate being forced into new updates. Like MoonShadow once said (and I am paraphrasing): "I like to wait until they have ironed out the bugs with new releases before I update". I've been following that same rule, and only update if it's absolutely necessary. Which is why I never even upgraded to v0.9
If you know how to use (or can figure it out) Gitian you could always recompile your favourite version of Bitcoin-qt with the newer version of OpenSSL. Third parties could do the same thing but obviously that would require a lot of trust.
|
|
|
|
southerngentuk
Sr. Member
Offline
Activity: 1316
Merit: 254
Sugars.zone | DatingFi - Earn for Posting
|
|
April 09, 2014, 01:00:14 AM |
|
Is there a quick guide to install this ? I have just switched from windows to Ubuntu, Help! I got 0.9.0 installed via PPA but the PPA is not updated yet ( + I would like to know how to do it without) I have :- Downloaded bitcoin-0.9.1-linux.tar.gzThen tar xvzf bitcoin-0.9.1-linux.tar.gz
This gives me a folder with bin + src but no ./configure. src has but that fails. Obviously I just don't get it
|
SUGAR | | | | ██ ██
██ ██
██ ██
██ ██
██ ██
██ ██ | | | | | | | | | ██ ██
██ ██
██ ██
██ ██
██ ██
██ ██ | | ███████████████████████████ ███████████████████████████ ██████ ██████ ██████ ▄████▀ ██████ ██████▄▄▄███▀ ▄█ ██████ ██████████▀ ▄███ ██████ ████████▀ ▄█████▄▄▄██████ ██████▀ ▄███████▀▀▀██████ ██████ ▀▀▀▀▀▀▀▀▀ ██████ ██████ ██████ ███████████████████████████ ███████████████████████████ | . Backed By ZetaChain | | ██ ██
██ ██
██ ██
██ ██
██ ██
██ ██ | | | | ██ ██
██ ██
██ ██
██ ██
██ ██
██ ██ | | | |
|
|
|
mufa23
Legendary
Offline
Activity: 1022
Merit: 1001
I'd fight Gandhi.
|
|
April 09, 2014, 01:02:48 AM |
|
I hate being forced into new updates. Like MoonShadow once said (and I am paraphrasing): "I like to wait until they have ironed out the bugs with new releases before I update". I've been following that same rule, and only update if it's absolutely necessary. Which is why I never even upgraded to v0.9
That's a good policy. I also do that. You don't need to update from versions older than 0.9.0 unless you're using rpcssl. Most people aren't. How can you tell when you are using rpcssl? What activates/turns it on? I've never manually ran any RPC commands that had to do with SSL. Just importing privkeys.
|
Positive rep with: pekv2, AzN1337c0d3r, Vince Torres, underworld07, Chimsley, omegaaf, Bogart, Gleason, SuperTramp, John K. and guitarplinker
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5390
Merit: 13426
|
|
April 09, 2014, 01:08:52 AM |
|
How can you tell when you are using rpcssl? What activates/turns it on? I've never manually ran any RPC commands that had to do with SSL. Just importing privkeys.
When you run bitcoind, you can run it with a number of command-line switches such as -config=..., -connect=..., etc. If you run bitcoind with -rpcssl=1, then you're potentially vulnerable to this bug.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5390
Merit: 13426
|
|
April 09, 2014, 01:11:20 AM |
|
Is there a quick guide to install this ? I have just switched from windows to Ubuntu, Help! I got 0.9.0 installed via PPA but the PPA is not updated yet ( + I would like to know how to do it without) I have :- Downloaded bitcoin-0.9.1-linux.tar.gzThen tar xvzf bitcoin-0.9.1-linux.tar.gz
This gives me a folder with bin + src but no ./configure. src has but that fails. Obviously I just don't get it The downloaded bin directory contains a few executable files. Find the locations of those files already on your system and replace them with the new versions. Maybe they're in /usr/bin?
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
defaced
Legendary
Offline
Activity: 2198
Merit: 1014
Franko is Freedom
|
|
April 09, 2014, 01:15:05 AM |
|
I hate being forced into new updates. Like MoonShadow once said (and I am paraphrasing): "I like to wait until they have ironed out the bugs with new releases before I update". I've been following that same rule, and only update if it's absolutely necessary. Which is why I never even upgraded to v0.9
If you know how to use (or can figure it out) Gitian you could always recompile your favourite version of Bitcoin-qt with the newer version of OpenSSL. Third parties could do the same thing but obviously that would require a lot of trust. Yup, pretty easy stuff.
|
|
|
|
BlockchainHelp?
Newbie
Offline
Activity: 28
Merit: 1
|
|
April 09, 2014, 01:17:16 AM |
|
I created 4 private keys offline in Bitcoin-QT 9.0 via TailsOS. My client never touched the internet, do I need to bring my cold storage online to create 4 new wallets in 9.1?
Shameful quote, I need to know
|
|
|
|
H34P5PR4Y
Newbie
Offline
Activity: 11
Merit: 0
|
|
April 09, 2014, 01:19:42 AM |
|
just downloaded 0.9.1 win64 bit and i get this error: Assertion Failed! Program C:\Program Files\Bitcoin\bitcoin-qt.exe File ../../src/serialize.h, Line1013
Expression: nSize >=0
|
|
|
|
|
7Priest7
|
|
April 09, 2014, 01:35:00 AM |
|
Memorized private keys, the safest way to own bitcoin. Encrypted paper wallets, almost as safe.
Paper wallets without encryption could be physicly stolen then claimed. Bitcoin clients have the possibility of security vulnerabilities and are targeted by bitcoin related malware. Physical digital wallets are subject to theft just as unencrypted paper wallets are.
|
|
|
|
bitpop
Legendary
Offline
Activity: 2912
Merit: 1060
|
|
April 09, 2014, 01:51:02 AM |
|
I created 4 private keys offline in Bitcoin-QT 9.0 via TailsOS. My client never touched the internet, do I need to bring my cold storage online to create 4 new wallets in 9.1?
Shameful quote, I need to know Almost everyone should be pretty safe especially you. Unless they're not telling us something yet.
|
|
|
|
Siegfried
|
|
April 09, 2014, 01:54:26 AM |
|
How do I install this for Linux Mint? On the previous version there was just a bitcoin-qt file which I could click on and run. Now the extracted folder contains several files, none of which are executable. I am stupid and know almost nothing about using the terminal, compiling libraries, etc. Can someone give me a simple explanation please?
|
|
|
|
bitpop
Legendary
Offline
Activity: 2912
Merit: 1060
|
|
April 09, 2014, 01:58:19 AM |
|
How do I install this for Linux Mint? On the previous version there was just a bitcoin-qt file which I could click on and run. Now the extracted folder contains several files, none of which are executable. I am stupid and know almost nothing about using the terminal, compiling libraries, etc. Can someone give me a simple explanation please?
Go to bin 64
|
|
|
|
DeathAndTaxes
Donator
Legendary
Offline
Activity: 1218
Merit: 1079
Gerald Davis
|
|
April 09, 2014, 02:00:16 AM |
|
I hate being forced into new updates. Like MoonShadow once said (and I am paraphrasing): "I like to wait until they have ironed out the bugs with new releases before I update". I've been following that same rule, and only update if it's absolutely necessary. Which is why I never even upgraded to v0.9
That's a good policy. I also do that. You don't need to update from versions older than 0.9.0 unless you're using rpcssl. Most people aren't. How can you tell when you are using rpcssl? What activates/turns it on? I've never manually ran any RPC commands that had to do with SSL. Just importing privkeys. Even if you are using RPC you would have had to manually create a SSL private key and SSL cert using openssl and then manually install those by setting params in the bitcoin.conf in order to be be exectuing those RPC calls over SSL. If all of those sounds foreign the simple answer is unless you already knew you were using RPC over SSL you weren't using it.
|
|
|
|
Siegfried
|
|
April 09, 2014, 02:00:54 AM |
|
How do I install this for Linux Mint? On the previous version there was just a bitcoin-qt file which I could click on and run. Now the extracted folder contains several files, none of which are executable. I am stupid and know almost nothing about using the terminal, compiling libraries, etc. Can someone give me a simple explanation please?
Go to bin 64 I have done that and clicked bitcoin-qt. I get the following error: Could not display "/home/robert/Programs/bitcoin-0.9.1-linux/bin/64/bitcoin-qt". There is no application installed for shared library files. Do you want to search...
|
|
|
|
|