Author

Topic: How can we trust Electrum Windows EXE? (Read 176 times)

newbie
Activity: 6
Merit: 0
February 22, 2018, 04:22:02 AM
#9
TryNinja, jackg and Xynerise: Thank you for your replys!

I've learned something.

Great forum!
legendary
Activity: 2758
Merit: 6830
February 21, 2018, 02:17:49 PM
#8
Thanks for your reply. By "vendor lock-in" I mean that I cannot export my private keys out of any hardware wallet.

Yes, I am paranoid. I sign any transaction offline but I still have to trust the software producers. I don't want to trust.
You can[1], but it's not recommended. However, if you are going to use your wallet with the private-keys outside the hardware wallet device, why even have one in the first place? Your best choice would be to have an air-gapped computer with an offline wallet and a watch-only in your main online computer.

[1] Just get your hardware wallet seed, and in Electrum go to File -> New/Restore -> Standard Wallet -> I already have a seed -> Paste/write your seed -> Options -> Check 'BIP39 seed' -> Next.
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
February 21, 2018, 02:15:36 PM
#7
Thanks for you reply, but I don't believe it's that easy:

"Electrum was created by Thomas Voegtlin in November 2011.

Since then, various developers have contributed to its source code."

Source:
https://electrum.org/#about

I don't like the "vendor lock in" of a Hardware Wallet, I want to have my private keys.

ThomasV is the main developer of the client side of electrum, he has to sign the executable to say that he authorises it. If, in the unreasonable instance, a trojan is added by another developer and he misses it and signs the executable. He's still liable in a court of law for the error (in most countries). He would also be able to bring whomever coded the Trojan to court also if he can determine who it is.
sr. member
Activity: 322
Merit: 363
39twH4PSYgDSzU7sLnRoDfthR6gWYrrPoD
February 21, 2018, 02:01:08 PM
#6
Thanks for your reply. By "vendor lock-in" I mean that I cannot export my private keys out of any hardware wallet.

Yes, I am paranoid. I sign any transaction offline but I still have to trust the software producers. I don't want to trust.
You can export your private keys from Electrum and whenever you set up a hardware wallet for the first time you're shown a mnemonic seed that you can use to get access to your coins in any BIP39 wallet at any time.
newbie
Activity: 6
Merit: 0
February 21, 2018, 10:46:54 AM
#5
Thanks for your reply. By "vendor lock-in" I mean that I cannot export my private keys out of any hardware wallet.

Yes, I am paranoid. I sign any transaction offline but I still have to trust the software producers. I don't want to trust.
hero member
Activity: 616
Merit: 603
February 21, 2018, 09:13:41 AM
#4
The Binaries are usually created and uploaded on the site by ThomasV and he usually signs these Binaries with his PGP Key. I'm assuming there are tests performed to check for any issues in the source code during the code commits or when any pull requests are accepted.

Apart from that, you have the choice to run or install from source - Download the source code, install PyQT 5 and run 'python3 electrum' or to Build Wine / Windows binaries by yourself by referring to the documentation here: https://github.com/spesmilo/electrum/tree/master/contrib/build-wine

I don't like the "vendor lock in" of a Hardware Wallet, I want to have my private keys.

The Trezor hardware wallet is Open Hardware https://doc.satoshilabs.com/trezor-tech/hardware.html and also Trezor-core being Open source https://github.com/trezor. If by Vendor lock-in you mean having to rely on Trezor for support or services, well you may have to do that even with software wallets in case you face any difficulties. You can also have Trezor connected with Electrum for example if that's what you're looking into.
newbie
Activity: 6
Merit: 0
February 21, 2018, 06:20:01 AM
#3
Thanks for you reply, but I don't believe it's that easy:

"Electrum was created by Thomas Voegtlin in November 2011.

Since then, various developers have contributed to its source code."

Source:
https://electrum.org/#about

I don't like the "vendor lock in" of a Hardware Wallet, I want to have my private keys.
legendary
Activity: 1568
Merit: 1031
February 21, 2018, 06:11:41 AM
#2
The developer of the wallet (ThomasV) is known to the public and he is trustworthy. If at some point he decide to scam people, It would be easy to take him to court. If you are paranoid, you can always switch to a hardware wallet.
newbie
Activity: 6
Merit: 0
February 21, 2018, 05:43:23 AM
#1
First of all: I like Electrum a lot.

Electrum is Open Source and Electrum can be installed from sources. The sources can be verified by everyone and thus it is very unlikely that it contains scam.

BUT:

What if the Windows EXE is compiled from sources that are different? Who would ever notice?

So for example what if the EXE produces private keys that the authors of the software know beforehand because they programmed it that way? What if they decide to move the funds from these addresses one day?

Ever thought about that? I just did and do not feel well now...
Jump to: