Author

Topic: Android wallet and TOR (Read 2395 times)

newbie
Activity: 19
Merit: 0
November 24, 2013, 04:23:30 PM
#11
Ok, thanks for the info
legendary
Activity: 1526
Merit: 1134
November 24, 2013, 02:02:30 PM
#10
It could feed you transactions that are fake and will never confirm. If you're not waiting for confirmations, then you could be fooled by this. The Satoshi client has all the data needed to validate even unconfirmed transactions, so the tx can't actually be fake (although with a MITM you cannot know if the tx was really propagated and thus, whether it could be double spent).

Basically, Tor is bad news unless you're OK with waiting for confirmations (preferably, several), and that's true regardless of which client you use. Even if you THINK you're OK with waiting, the MITM could filter out block announcements so you just think the network is being really unlucky and not finding a block, so you give up waiting and decide to risk it.
newbie
Activity: 19
Merit: 0
November 24, 2013, 01:16:18 PM
#9
Exactly what kind of an attack could a rogue exit node orchestrate?

And why is the android wallet more vulnerable than the satoshi client?
legendary
Activity: 1526
Merit: 1134
November 24, 2013, 08:42:58 AM
#8
Yes, the risk is higher.

The new network stack is ready for testing. Andreas could produce a test/beta version that routes traffic over Tor now. But if Orbot is already doing it for all applications, then it doesn't seem useful.
newbie
Activity: 19
Merit: 0
November 23, 2013, 11:03:43 AM
#7
Just to follow up on this. I tested this network log application
https://f-droid.org/repository/browse/?fdid=com.googlecode.networklog

And with the information it provides it looks very much like Orbot manages to route the Android Wallet over Tor.

Btw. is the Android wallet more at risk from an rogue exit node than the satoshi client?
hero member
Activity: 483
Merit: 551
November 18, 2013, 05:15:45 AM
#6
@lukey I pm'ed you.
full member
Activity: 135
Merit: 100
November 17, 2013, 03:36:21 PM
#5
I don't know if this can answer this question, but i recently sent a small amount of bitcoins to a market place. I'm still waiting on the transaction. It still hasn't transmitted and completely froze my wallet on my phone you can say. Every time I try to send a payment, it says that my current balance on my wallet is still waiting for confirmation. I don't understand lol.

~ I did use Tor
newbie
Activity: 19
Merit: 0
November 03, 2013, 01:05:09 AM
#4
Is there a way to know for sure whether the android wallet bypasses Orbot or not?

I did a test transaction and looked it up at http://blockchain.info and the IP address listed under 'Relayed by IP' was not my own. But then again it doesn't have to be even if the android wallet connects directly.
legendary
Activity: 1526
Merit: 1134
November 02, 2013, 11:23:32 AM
#3
Matt has been working on a rewrite of the network layer that would let us route traffic over Tor. It's not obvious that it's a good idea though. Using Tor essentially puts a MITM on every connection you make, unless you're connecting to hidden services. Supporting discovery of hidden services would take a bit more work.
hero member
Activity: 483
Merit: 551
November 02, 2013, 10:53:09 AM
#2
I think it doesn't work because bitcoinj/netty doesn't support setting a proxy.
newbie
Activity: 19
Merit: 0
November 02, 2013, 02:27:23 AM
#1
I'm wondering whether the Android bitcoin wallet works with TOR?

Because this page https://code.google.com/p/bitcoinj/wiki/Limitations gives the impression that it wouldn't work. But then again Orbot https://www.torproject.org/docs/android.html.en gives the impression that it can take the network traffic from the bitcoin wallet and route it over TOR.

I'm confused.
Jump to: