Author

Topic: Electrum exposing addresses to public? (Read 785 times)

staff
Activity: 3458
Merit: 6793
Just writing some code
October 06, 2016, 11:35:26 AM
#15
Electrum wallet is the worse of the worse wallets in terms of privacy. It shows all your bitcoin addresses if you have only used 1 address then everyone can see the full addresses of this electrum wallet by using a simple website like walletexplorer.com .

Multibit Classic is the best out of the three Multibit,Multibit HD and Electrum for privacy as it keeps only one bitcoin address for each wallet and can create as many wallets as you like. Other people cannot link these addresses to be under the possesion of the same person differently from Electrum.

From this point of view, Electrum is far behind lacking big time in privacy compared to Multibit classic.
What the hell are you taking about? Both Electrum and Multibit use the same key derivation algorithm, bip32. Furthermore it is not possible to know the other addresses in a wallet by knowing Judy one address, they need to be forms linked, and any wallet software will likely end up spend linking all the addresses in the wallet.

Lastly, what does"each wallet" mean? For both software you have one wallet open at a time. A wallet is a collection of addresses, and no one knows the addresses in your wallet unless they are spend linked.
legendary
Activity: 910
Merit: 1000
October 06, 2016, 11:26:31 AM
#14
Electrum wallet is the worse of the worse wallets in terms of privacy. It shows all your bitcoin addresses if you have only used 1 address then everyone can see the full addresses of this electrum wallet by using a simple website like walletexplorer.com .

Multibit Classic is the best out of the three Multibit,Multibit HD and Electrum for privacy as it keeps only one bitcoin address for each wallet and can create as many wallets as you like. Other people cannot link these addresses to be under the possesion of the same person differently from Electrum.

From this point of view, Electrum is far behind lacking big time in privacy compared to Multibit classic.
legendary
Activity: 3710
Merit: 1586
October 06, 2016, 09:20:26 AM
#13
Thank you for the answer but are the new version of multibit secure?
Yes. I don't recommend Multibit because it makes it harder to do advanced tasks like import/export private keys, signing raw transactions, etc. However, if you don't need any of that, then Multibit is fine.

I am just trying out Multibit and it seems to be much better than electrum at first look,no idea why more people recommend electrum
But i created a test wallet and it gives timestamp and then on verification step it ask to put timestamp or leave blank if unknown but if i leave blank i cant press next and if i put a fake timestamp it also cant press next so have to give real timestamp,and cant use without the timestamp?

The timestamp helps it sync your wallet faster. Technically it can sync your wallet without the timestamp but why take a risk? Backup both the timestamp and the wallet words.

BTW you should ask these questions in the multibit forum:
https://bitcointalk.org/index.php?board=99.0
newbie
Activity: 16
Merit: 0
September 29, 2016, 12:19:02 PM
#12
Is my understading of bloom filters above correct?
If it's not can you please explain how they protect anything
sr. member
Activity: 322
Merit: 250
September 29, 2016, 12:09:43 PM
#11
yes i belive they are recording our ip addresses and our transaction history  and if they really are then also i do not actully care they can not have my wallet nor even my private key
newbie
Activity: 16
Merit: 0
September 29, 2016, 11:31:10 AM
#10
So I got 2 conflicting answers...so des the someone running electrum server can see my BTC address tied to my IP or not? If yes,is it the same with Multibit?
The person running the Electrum server can see all the addresses tied to your wallet.

It is not the same with Multibit because multibit does not use the same structure. Multibit is pure P2P so it relies on actual full nodes. It uses bloom filters to provide some privacy.

What about the IP addresses (I believe that's what OP asked)?  I've read quite a few about it and all of them seem to indicate that the servers can indeed see your IP address, are they all wrong?

From what I understand in this case it wont matter that the user IP is exposed since when multibit will try to get balance of your address it will in the sametime try to get balance of other addresses that dont belong to you
hero member
Activity: 798
Merit: 506
Thank satoshi
September 29, 2016, 11:27:30 AM
#9
So I got 2 conflicting answers...so des the someone running electrum server can see my BTC address tied to my IP or not? If yes,is it the same with Multibit?
The person running the Electrum server can see all the addresses tied to your wallet.

It is not the same with Multibit because multibit does not use the same structure. Multibit is pure P2P so it relies on actual full nodes. It uses bloom filters to provide some privacy.

What about the IP addresses (I believe that's what OP asked)?  I've read quite a few about it and all of them seem to indicate that the servers can indeed see your IP address, are they all wrong?

Edit:
Wait, by addresses you mean IP addresses or Bitcoin addresses?  Tongue
newbie
Activity: 16
Merit: 0
September 29, 2016, 11:24:31 AM
#8
Thank you for the answer but are the new version of multibit secure?
Yes. I don't recommend Multibit because it makes it harder to do advanced tasks like import/export private keys, signing raw transactions, etc. However, if you don't need any of that, then Multibit is fine.

I am just trying out Multibit and it seems to be much better than electrum at first look,no idea why more people recommend electrum
But i created a test wallet and it gives timestamp and then on verification step it ask to put timestamp or leave blank if unknown but if i leave blank i cant press next and if i put a fake timestamp it also cant press next so have to give real timestamp,and cant use without the timestamp?
staff
Activity: 3458
Merit: 6793
Just writing some code
September 29, 2016, 11:20:57 AM
#7
Thank you for the answer but are the new version of multibit secure?
Yes. I don't recommend Multibit because it makes it harder to do advanced tasks like import/export private keys, signing raw transactions, etc. However, if you don't need any of that, then Multibit is fine.
newbie
Activity: 16
Merit: 0
September 29, 2016, 11:12:20 AM
#6
So I got 2 conflicting answers...so des the someone running electrum server can see my BTC address tied to my IP or not? If yes,is it the same with Multibit?
The person running the Electrum server can see all the addresses tied to your wallet.

It is not the same with Multibit because multibit does not use the same structure. Multibit is pure P2P so it relies on actual full nodes. It uses bloom filters to provide some privacy.
Thank you for the answer but are the new version of multibit secure?
staff
Activity: 3458
Merit: 6793
Just writing some code
September 29, 2016, 11:06:41 AM
#5
So I got 2 conflicting answers...so des the someone running electrum server can see my BTC address tied to my IP or not? If yes,is it the same with Multibit?
The person running the Electrum server can see all the addresses tied to your wallet.

It is not the same with Multibit because multibit does not use the same structure. Multibit is pure P2P so it relies on actual full nodes. It uses bloom filters to provide some privacy.
newbie
Activity: 16
Merit: 0
September 29, 2016, 10:58:42 AM
#4
So I got 2 conflicting answers...so des the someone running electrum server can see my BTC address tied to my IP or not? If yes,is it the same with Multibit?
hero member
Activity: 798
Merit: 506
Thank satoshi
September 29, 2016, 10:56:40 AM
#3
Yes, it's true, and you can't avoid it other than using other wallet that doesn't rely on servers such as bitcoin core.  You can use tor or VPN to mask your real IP, though.
legendary
Activity: 1120
Merit: 1008
CryptoTalk.Org - Get Paid for every Post!
September 29, 2016, 10:55:32 AM
#2
Electrum software is client side that mean all information about your wallet, balance are stored in your side and nothing is stored in their server.
Check this in their docs http://docs.electrum.org/en/latest/faq.html#does-electrum-trust-servers
Also they use simple payment verification system to boardcast transaction, know more about this here http://docs.electrum.org/en/latest/spv.html
However i couldn't find anything regarding recording users IP and associated bitcoin address in their server and i think if they do than it is possible for them to record.
newbie
Activity: 16
Merit: 0
September 29, 2016, 10:48:45 AM
#1
When using Electrum I think for it to update balances it must make some request to a server with information about balance on specific address so it means that the person operating that server can see that a specific BTC address belong to a specific IP is this true? and if it is how to avoid it
Jump to: