Bitcoin Forum
November 05, 2024, 11:56:08 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Is it safe to have a vanity address?  (Read 1344 times)
KingZee (OP)
Sr. Member
****
Offline Offline

Activity: 952
Merit: 452


Check your coin privilege


View Profile
November 29, 2014, 07:02:57 AM
 #1

For websites like http://bitcoinvanitygen.com/ , Is it safe to generate an address from there and use it as your own?
When they generate it, it appears to be an automated e-mail I received, so is it sure that no one has access to my private key?
I see websites having multiple addresses like 1Dicexxxxxxxxxxxx, and 1Casinoxxxxxxxxxxx. So did they use the website too?
Thanks

Beep boop beep boop
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3990
Merit: 2713


Join the world-leading crypto sportsbook NOW!


View Profile
November 29, 2014, 07:10:29 AM
 #2

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Vod
Legendary
*
Offline Offline

Activity: 3878
Merit: 3166


Licking my boob since 1970


View Profile WWW
November 29, 2014, 07:18:24 AM
 #3

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Are you sure they are safe?  They know your private key after generating your address - how can you be sure they will never use it?

I post for interest - not signature spam.
https://elon.report - new B.P.I.P. Reports!
https://vod.fan - fast/free image sharing - coming Nov
KingZee (OP)
Sr. Member
****
Offline Offline

Activity: 952
Merit: 452


Check your coin privilege


View Profile
November 29, 2014, 07:38:51 AM
 #4

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Why exactly would this one be less safe than others? Like Vod said I'm mainly worried about my private key disclosure. Do you know other websites that give out vanity addresses that are "safer" than this one?

Beep boop beep boop
JoelKatz
Legendary
*
Offline Offline

Activity: 1596
Merit: 1012


Democracy is vulnerable to a 51% attack.


View Profile WWW
November 29, 2014, 07:43:52 AM
 #5

Are you sure they are safe?  They know your private key after generating your address - how can you be sure they will never use it?
They don't know your private key. You give them the public key, they give you an offset that you use to generate the private key. But they do not know the private key for the vanity address. (At least, that's how the vast majority of such sites work.)

Here's how it works:

1) You give them only a public key.

2) They give you an offset.

3) You combine the offset with your private key to get the private key for the vanity address.

4) If they had the private key to the vanity address, they could subtract the offset from it and have the private key corresponding to the public key you gave them in step 1. So if this scheme is insecure, then someone could get your private key from just your public key, which would mean ECDSA itself is insecure.

Why exactly would this one be less safe than others? Like Vod said I'm mainly worried about my private key disclosure. Do you know other websites that give out vanity addresses that are "safer" than this one?
Ones that use the method I described above are safer than those that just give you the private key to the vanity address.

I am an employee of Ripple. Follow me on Twitter @JoelKatz
1Joe1Katzci1rFcsr9HH7SLuHVnDy2aihZ BM-NBM3FRExVJSJJamV9ccgyWvQfratUHgN
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3990
Merit: 2713


Join the world-leading crypto sportsbook NOW!


View Profile
November 29, 2014, 07:49:57 AM
 #6

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Are you sure they are safe?  They know your private key after generating your address - how can you be sure they will never use it?

I was referring to vanity addresses being safe, but obviously that depends on where and how you create them, much like paper wallets.

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Why exactly would this one be less safe than others? Like Vod said I'm mainly worried about my private key disclosure. Do you know other websites that give out vanity addresses that are "safer" than this one?

Well like everything there are legit sites methods and sites/methods that will try to steal your money somehow. If in doubt with any service I just wouldn't use it because it's not worth the worry. I personally cannot vouch for any and wouldn't want to, but just make sure you do your research and know what you're doing first.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
anshar
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250


View Profile
November 29, 2014, 09:02:26 AM
 #7

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Are you sure they are safe?  They know your private key after generating your address - how can you be sure they will never use it?

Not sure about this site, but others force users to use split key generation.

A pool generates part and the site generates the actual public key. You need to trust the private key pool though I think.
KingZee (OP)
Sr. Member
****
Offline Offline

Activity: 952
Merit: 452


Check your coin privilege


View Profile
November 29, 2014, 09:46:43 AM
 #8

Yes, they are safe, but like paper wallets they're only as safe as you are and the site you used to create them. If in doubt don't use them, but there are legit sites and services that create them. I cannot vouch for that particular one though.

Are you sure they are safe?  They know your private key after generating your address - how can you be sure they will never use it?

Not sure about this site, but others force users to use split key generation.

A pool generates part and the site generates the actual public key. You need to trust the private key pool though I think.

Yeah, that method is the most secure one I found yet like JoelKatz said too, it costs a little and takes a bit of time but it's worth it unlike the first website I linked.

Beep boop beep boop
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
November 29, 2014, 10:12:48 AM
 #9

I would never trust a site like this. I would recommend to generate your vanity address in person.

The best tool is vanitygen: https://bitcointalk.org/index.php?topic=25804.0
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1086


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 29, 2014, 10:26:14 AM
 #10

As pointed out by @JoelKatz the only risk is that you have given out your public key but as soon as you send BTC *from* the vanity address you would have done that anyway.

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Brad Pitt
Member
**
Offline Offline

Activity: 64
Merit: 10


View Profile
November 29, 2014, 10:43:14 AM
 #11

I would never trust a site like this. I would recommend to generate your vanity address in person.

The best tool is vanitygen: https://bitcointalk.org/index.php?topic=25804.0

I wouldn't trust a website to generate these, but vanitygen seems ok from what I've read. Is it absolutely necessary you need a vanity address?
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1086


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 29, 2014, 10:53:04 AM
 #12

@Brad Pitt and @LOBSTERHACKED both obviously have no idea about how these type of new vanity address websites work so OP should just ignore their posts.

I would advise the OP to simply verify that the website works as @JoelKatz explained and assuming it does weigh up the risk as stated by him (which I echoed).

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
KingZee (OP)
Sr. Member
****
Offline Offline

Activity: 952
Merit: 452


Check your coin privilege


View Profile
November 29, 2014, 12:01:22 PM
 #13

@Brad Pitt and @LOBSTERHACKED both obviously have no idea about how these type of new vanity address websites work so OP should just ignore their posts.

I would advise the OP to simply verify that the website works as @JoelKatz explained and assuming it does weigh up the risk as stated by him (which I echoed).


That is what I did, I looked around and found a vanity pool, where you put the public key and then they generate the part private key for you.

But unfortunately the website I have linked in the first post does not use this method. It straight up gives you your private address. This website is unfortunately also the most famous one, so there might be a pretty big problem someday.

I would never trust a site like this. I would recommend to generate your vanity address in person.

The best tool is vanitygen: https://bitcointalk.org/index.php?topic=25804.0

I wouldn't trust a website to generate these, but vanitygen seems ok from what I've read. Is it absolutely necessary you need a vanity address?

Generating my own address takes too much time/power that I don't have.

Beep boop beep boop
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1086


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 29, 2014, 12:03:54 PM
 #14

But unfortunately the website I have linked in the first post does not use this method. It straight up gives you your private address. This website is unfortunately also the most famous one, so there might be a pretty big problem someday.

In that case you certainly would not want to use it so instead find a website that does use the safe approach or use vanitygen as suggested by others.

My guess is that website has been set up by scammers (unfortunately about 90% of what goes on in the whole crypto-currency area at the moment is scamming).

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!