Bernard Lerring (OP)
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 10:42:04 PM |
|
Suppose I create an online wallet with https://blockchain.info/ in Tor browser and keep a small stash of BTC in there. It's an anonymous stash, right? So long as I only access via Tor browser, use change addresses and send BTC wisely. But I've recently read about people running Tor exit nodes and maliciously sniffing the data through them, so I was wondering if this is a safe way of having an online wallet without anyone gaining access to my password/BTC. Any thoughts?
|
|
|
|
karlb187
Full Member
![*](https://bitcointalk.org/Themes/custom1/images/star.gif) ![*](https://bitcointalk.org/Themes/custom1/images/star.gif)
Offline
Activity: 210
Merit: 100
Need To Contact Me? Go To My Site!
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 10:56:30 PM |
|
not sure... ![Huh](https://bitcointalk.org/Smileys/default/huh.gif)
|
|
|
|
BitCoinDream
Legendary
Offline
Activity: 2352
Merit: 1204
The revolution will be digital
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 10:57:43 PM |
|
Suppose I create an online wallet with https://blockchain.info/ in Tor browser and keep a small stash of BTC in there. It's an anonymous stash, right? So long as I only access via Tor browser, use change addresses and send BTC wisely. But I've recently read about people running Tor exit nodes and maliciously sniffing the data through them, so I was wondering if this is a safe way of having an online wallet without anyone gaining access to my password/BTC. Any thoughts? Tor data is encrypted. So I'm not sure how sniffing can expose you to vulnerability. On the other hand, blockchain.info wallet scripting is client side. So, I think, even if u use Static IP, still you are secure...
|
|
|
|
notlist3d
Legendary
Offline
Activity: 1456
Merit: 1000
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 10:57:54 PM |
|
Every once in a while there will be a exploit at exit nodes.
I would not trust it myself for anything important.
|
|
|
|
notlist3d
Legendary
Offline
Activity: 1456
Merit: 1000
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 10:59:31 PM |
|
Suppose I create an online wallet with https://blockchain.info/ in Tor browser and keep a small stash of BTC in there. It's an anonymous stash, right? So long as I only access via Tor browser, use change addresses and send BTC wisely. But I've recently read about people running Tor exit nodes and maliciously sniffing the data through them, so I was wondering if this is a safe way of having an online wallet without anyone gaining access to my password/BTC. Any thoughts? Tor data is encrypted. So I'm not sure how sniffing can expose you to vulnerability. On the other hand, blockchain.info wallet scripting is client side. So, I think, even if u use Static IP, still you are secure... There have been multiple exploits at exit node. On exit node it actually pulls up site so it is visible when there is a operational exploit. The nodes in the middle you are correct they dont see end traffic.
|
|
|
|
Bernard Lerring (OP)
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:02:55 PM |
|
Thanks for the replies. I keep most in paper wallets, which use BIP38 encryption. I was just wondering about small, shopping transactions in https://blockchain.info/ for convenience sake, since it's very easy to fire up Tor browser and access your account. I will bear in mind that there is a slight risk of exploiting Tor exit nodes and give it a try.
|
|
|
|
BitCoinDream
Legendary
Offline
Activity: 2352
Merit: 1204
The revolution will be digital
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:03:24 PM |
|
Suppose I create an online wallet with https://blockchain.info/ in Tor browser and keep a small stash of BTC in there. It's an anonymous stash, right? So long as I only access via Tor browser, use change addresses and send BTC wisely. But I've recently read about people running Tor exit nodes and maliciously sniffing the data through them, so I was wondering if this is a safe way of having an online wallet without anyone gaining access to my password/BTC. Any thoughts? Tor data is encrypted. So I'm not sure how sniffing can expose you to vulnerability. On the other hand, blockchain.info wallet scripting is client side. So, I think, even if u use Static IP, still you are secure... There have been multiple exploits at exit node. On exit node it actually pulls up site so it is visible when there is a operational exploit.The nodes in the middle you are correct they dont see end traffic. Is this how Julian Assange got secured information ? I heard he and his accomplishes used to run Tor. Thanks for the replies. I keep most in paper wallets, which use BIP38 encryption. I was just wondering about small, shopping transactions in https://blockchain.info/ for convenience sake, since it's very easy to fire up Tor browser and access your account. I will bear in mind that there is a slight risk of exploiting Tor exit nodes and give it a try. Why dont u use your normal connection to access blockchain.info ?
|
|
|
|
Bernard Lerring (OP)
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:08:26 PM |
|
Why dont u use your normal connection to access blockchain.info ?
I just figured that Tor was secure and recently learned about exit nodes being hacked. It's not really as good a system as I thought it was.
|
|
|
|
b!z
Legendary
Offline
Activity: 1582
Merit: 1010
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:20:59 PM |
|
A cold wallet is the most secure.
|
|
|
|
btctalkme
Newbie
Offline
Activity: 13
Merit: 0
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:39:01 PM |
|
![Grin](https://bitcointalk.org/Smileys/default/grin.gif) i read 4x topic where people say this danger ![Cool](https://bitcointalk.org/Smileys/default/cool.gif) 1 guy in china lost big bitcoins and a lot in this scene i am read and etc... ![Shocked](https://bitcointalk.org/Smileys/default/shocked.gif)
|
|
|
|
btctalkme
Newbie
Offline
Activity: 13
Merit: 0
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 14, 2014, 11:47:24 PM |
|
not sure... ![Huh](https://bitcointalk.org/Smileys/default/huh.gif) same i think bad idea ![Roll Eyes](https://bitcointalk.org/Smileys/default/rolleyes.gif)
|
|
|
|
dothebeats
Legendary
Offline
Activity: 3710
Merit: 1354
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 03:52:01 AM |
|
I think using the blockchain.info wallet in the Tor browser is compromised and one person here in the community have posted an issue about stealing his coins. I think the reason is about the exit nodes? I'm not sure but yeah, the security is vulnerable and is prone to hacks.
|
|
|
|
Bernard Lerring (OP)
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 05:08:10 AM |
|
I guess I will have to keep using electrum through SOCKS5 proxy then. I thought that blockchain.info over Tor would be a simpler solution.
|
|
|
|
hilariousandco
Global Moderator
Legendary
Offline
Activity: 3892
Merit: 2654
Join the world-leading crypto sportsbook NOW!
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 07:04:58 AM |
|
A cold wallet is the most secure.
Only as safe as you are. If you use a dodgy site or the documents are saved in your printer that's two ways you could lose coins. I think using the blockchain.info wallet in the Tor browser is compromised and one person here in the community have posted an issue about stealing his coins. I think the reason is about the exit nodes? I'm not sure but yeah, the security is vulnerable and is prone to hacks.
Several people have lost coins due to compromised nodes. I wouldn't bother logging in via it to be safe. Why must you use tor to have an account?
|
|
|
|
Bernard Lerring (OP)
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 08:21:09 AM |
|
Several people have lost coins due to compromised nodes. I wouldn't bother logging in via it to be safe. Why must you use tor to have an account?
I thought it might be handy in case I ever want to open up one of my BIP38 paper wallets, since blockchain.info accepts a BIP38 private key import automatically. Then send some of the remaining balance back to a new cold (paper) wallet. I like to use electrum with SOCKS5 to send tumbled coins to an offline paper wallet to ensure that they're not traceable in future.
|
|
|
|
Skinnyman
Member
![*](https://bitcointalk.org/Themes/custom1/images/star.gif)
Offline
Activity: 61
Merit: 10
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 10:59:15 AM |
|
Several people have lost coins due to compromised nodes. I wouldn't bother logging in via it to be safe. Why must you use tor to have an account?
I thought it might be handy in case I ever want to open up one of my BIP38 paper wallets, since blockchain.info accepts a BIP38 private key import automatically. Then send some of the remaining balance back to a new cold (paper) wallet. I like to use electrum with SOCKS5 to send tumbled coins to an offline paper wallet to ensure that they're not traceable in future. Why would you need to use tor though for that? You could also use a proxxy if you wish but make sure that isn't compromised or saves your data.
|
|
|
|
notlist3d
Legendary
Offline
Activity: 1456
Merit: 1000
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 15, 2014, 03:00:54 PM |
|
As long as tor uses exit nodes there is a chance off bad things. (It HAS to use exit nodes so you are always at risk).
You can use it and it will be rolling the dice on if you get compromised.
|
|
|
|
HeroCat
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 18, 2014, 10:05:36 PM |
|
BTC wallet security is very important and not easy. There are a lot cases with trojans and so on. In fact I you want serious wallet security, PM me - even here in forum are different people - I have really good knowledge how to prevent your computer and wallet at best possible way.
|
|
|
|
notlist3d
Legendary
Offline
Activity: 1456
Merit: 1000
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 18, 2014, 11:28:24 PM |
|
In a perfect world you use cold storage.
Can I ask is it ok to show IP for security? Or do you have to be anonymous completely.
|
|
|
|
Omikifuse
Legendary
Offline
Activity: 1792
Merit: 1009
|
![](https://bitcointalk.org/Themes/custom1/images/post/xx.gif) |
November 19, 2014, 12:46:54 AM |
|
Suppose I create an online wallet with https://blockchain.info/ in Tor browser and keep a small stash of BTC in there. It's an anonymous stash, right? So long as I only access via Tor browser, use change addresses and send BTC wisely. But I've recently read about people running Tor exit nodes and maliciously sniffing the data through them, so I was wondering if this is a safe way of having an online wallet without anyone gaining access to my password/BTC. Any thoughts? Tor data is encrypted. So I'm not sure how sniffing can expose you to vulnerability. On the other hand, blockchain.info wallet scripting is client side. So, I think, even if u use Static IP, still you are secure... sometimes bugs are discovered in the encryptation protocol, like the last time the forum advised everyone to change password
|
|
|
|
|