Author

Topic: I think I can build a more secure web wallet than any other so far. (Read 1317 times)

hero member
Activity: 714
Merit: 500
NEED CRYPTO CODER? COIN DEVELOPER? PM US FOR HELP!
I think using of web wallets can never be safe so i prefer just filling mine with the amount needed at a particular time and for that blockchain is doing well so far, so i guess another online wallet is not what's needed right now. Good luck with your project though and hope to see it soon in action.
legendary
Activity: 1204
Merit: 1002
Gresham's Lawyer
greenaddress.it is more secure than your suggested method.
newbie
Activity: 28
Merit: 0
If you really after a web wallet, then watch out myTREZOR.

It will be as easy to use as any web application with no sign-up. Your keys will be in your hand, literally, in a high security special purpose device, safe from any hacks.

http://www.bitcointrezor.com/news/2014-02-10-mytrezor-bop-bitcoin-server

Here you have its first public demo in Berlin:
http://vimeo.com/90026733


Agreed. TREZOR and other hardware wallets are strong security made simple, they're what's needed for bitcoin to go mainstream

I am really looking forward to the Trezor (I ordered 2 last year) but I think it will not be for everyone. The retail price for this thing is yet TBA and I doubt that it will be anything below $100! Not much for total security if you are a "whale" and have lots of bitcoins in your wallet, but too much for the bitcoin starter.

So there is still room for another "middle security" wallet solution, easy to use for the average joe but still secure enough so that it is not easily hacked.
You're right, now the main wallet is safe and simple to use.
Only safe and easy to use in order to be widely used, so you have to consider these two questions.
newbie
Activity: 28
Merit: 0
If you really after a web wallet, then watch out myTREZOR.

It will be as easy to use as any web application with no sign-up. Your keys will be in your hand, literally, in a high security special purpose device, safe from any hacks.

http://www.bitcointrezor.com/news/2014-02-10-mytrezor-bop-bitcoin-server

Here you have its first public demo in Berlin:
http://vimeo.com/90026733


Agreed. TREZOR and other hardware wallets are strong security made simple, they're what's needed for bitcoin to go mainstream

I am really looking forward to the Trezor (I ordered 2 last year) but I think it will not be for everyone. The retail price for this thing is yet TBA and I doubt that it will be anything below $100! Not much for total security if you are a "whale" and have lots of bitcoins in your wallet, but too much for the bitcoin starter.

So there is still room for another "middle security" wallet solution, easy to use for the average joe but still secure enough so that it is not easily hacked.
You're right, now the main wallet is safe and simple to use.
legendary
Activity: 2044
Merit: 1055
If you really after a web wallet, then watch out myTREZOR.

It will be as easy to use as any web application with no sign-up. Your keys will be in your hand, literally, in a high security special purpose device, safe from any hacks.

http://www.bitcointrezor.com/news/2014-02-10-mytrezor-bop-bitcoin-server

Here you have its first public demo in Berlin:
http://vimeo.com/90026733


Agreed. TREZOR and other hardware wallets are strong security made simple, they're what's needed for bitcoin to go mainstream

I am really looking forward to the Trezor (I ordered 2 last year) but I think it will not be for everyone. The retail price for this thing is yet TBA and I doubt that it will be anything below $100! Not much for total security if you are a "whale" and have lots of bitcoins in your wallet, but too much for the bitcoin starter.

So there is still room for another "middle security" wallet solution, easy to use for the average joe but still secure enough so that it is not easily hacked.
legendary
Activity: 1106
Merit: 1026
If you are looking to build a secure wallet, you may take a look at the 2-of-3 multi signature approaches by trustedcoin.com and bitgo.com.
b!z
legendary
Activity: 1582
Merit: 1010
If you really after a web wallet, then watch out myTREZOR.

It will be as easy to use as any web application with no sign-up. Your keys will be in your hand, literally, in a high security special purpose device, safe from any hacks.

http://www.bitcointrezor.com/news/2014-02-10-mytrezor-bop-bitcoin-server

Here you have its first public demo in Berlin:
http://vimeo.com/90026733


Agreed. TREZOR and other hardware wallets are strong security made simple, they're what's needed for bitcoin to go mainstream
member
Activity: 70
Merit: 10
Well you've got my attention and many others will come I'm sure.  Wallet security is always a good thing and if you can outdo the current top wallets in you opinion I'd like to know more about it.  Subscribed.
+1
Agree with what you said, I also very the attention of the wallet safe.
legendary
Activity: 1232
Merit: 1002
If your service can withstand someone stealing your wallet.dat file without losing funds, you are headed in the right direction.

qt can withstands this as far as I know if you use a nice pass-phrase!
member
Activity: 70
Merit: 10
Wallet security is always a problem if more secure than it is now purse, I think is definitely good.
legendary
Activity: 1008
Merit: 1007
If your service can withstand someone stealing your wallet.dat file without losing funds, you are headed in the right direction.
newbie
Activity: 42
Merit: 0
Use a local wallet is the safest!
hero member
Activity: 798
Merit: 500
Time is on our side, yes it is!
Well you've got my attention and many others will come I'm sure.  Wallet security is always a good thing and if you can outdo the current top wallets in you opinion I'd like to know more about it.  Subscribed.
hero member
Activity: 836
Merit: 1030
bits of proof
If you really after a web wallet, then watch out myTREZOR.

It will be as easy to use as any web application with no sign-up. Your keys will be in your hand, literally, in a high security special purpose device, safe from any hacks.

http://www.bitcointrezor.com/news/2014-02-10-mytrezor-bop-bitcoin-server

Here you have its first public demo in Berlin:
http://vimeo.com/90026733
legendary
Activity: 1232
Merit: 1011
Monero Evangelist
So difference vs. blockchain.info is:

- no sending without 2FA
- GPG encryption of password

?
member
Activity: 172
Merit: 10
To become mainstream a simpler solution must be made, to encrypt, save it on external harddisk and use a os securer than windows. This might apply us that are into the technology, but others its to much hasle.


I don't really understand why anybody uses web wallets. 

Use a local wallet.  Keep it encrypted.  Unencrypted keys are never stored, and keys encrypted or not never leave the local machine.  Keep it on removable media and remove it when you're not using it.  Then just run an OS more secure than Windows to keep keyloggers etc off of it.


legendary
Activity: 924
Merit: 1132

I don't really understand why anybody uses web wallets. 

Use a local wallet.  Keep it encrypted.  Unencrypted keys are never stored, and keys encrypted or not never leave the local machine.  Keep it on removable media and remove it when you're not using it.  Then just run an OS more secure than Windows to keep keyloggers etc off of it.

newbie
Activity: 38
Merit: 0
If I build the following web wallet, it will be the most secure web wallet currently on the market. Agree or disagree ?

1. The client will be a 1 page backbone.js app deployed directly from the repository on github. The page would be signed with my PGP public key.

Why?

a. Because it would then be possible to write a chrome or firefox plugin to verify the wallet downloaded to your machine corresponds to the code on the repository. Blockchain.info has a form of this already but without the PGP signing.

b. If any third party such as github/cloudflare tampered with the wallet the user would be able to see and flags would be raised.

2. All javascript in plain text and easy to read. (unobfuscated).

Why ? Because the wallet is then open for peer review. Like all solutions that use cryptography peer review is the way to go.

3. No naked private keys stored on the server. No naked keys ever passed to the server.
Why ?


a. Search for “Bitcoin wallet hacked” on google then come back here.
b. Because there is no technical reason why we should ever do this again. And that includes exchanges too.

4. Users shouldn't pick their own passwords.

Why ?

a. Because a lot of users, pick either very week password or re-use passwords on other sites.
b. Because we can then pick passwords with sufficient entropy to properly encrypt private keys.

5. Users should not be able to send coins to the wallet until 2FA is enabled. All operations requiring spends should also be protected with 2FA.

Why ? To defend against malware such as key loggers.

6. A way for users to recover their wallet if the operator goes away.

Recovery procedure should be quick and simple. i.e. electrum passphrase.
Jump to: