Pages:
Author

Topic: Security concerns of Bitcoin-QT with encrypted wallet? (Read 4609 times)

member
Activity: 112
Merit: 10
OK quick question:

1) you have a dummy (empty) wallet.dat in .bitcoin so as your bitcoin-qt can stay up to date
2) you keep your real wallet.dat encrypted (say truecrypt) in a usb or maybe also on your mail or dropbox.
3) if you want to make a transaction:
    a) get your encrypted wallet
    b) decrypt it and copy it into .bitcoin
    c) make transaction
    d) replace real wallet.dat with dummy one

question: Is this secure enough or are you still in danger during the transaction (for as long as you have your real wallet.dat linked to bitcoin-qt)?

SK       
You would be better off doing this with a cheap dedicated device: http://youtu.be/1pDSzOiFgIk

Point taken Wink,
Thanks Jan.
Jan
legendary
Activity: 1043
Merit: 1002
OK quick question:

1) you have a dummy (empty) wallet.dat in .bitcoin so as your bitcoin-qt can stay up to date
2) you keep your real wallet.dat encrypted (say truecrypt) in a usb or maybe also on your mail or dropbox.
3) if you want to make a transaction:
    a) get your encrypted wallet
    b) decrypt it and copy it into .bitcoin
    c) make transaction
    d) replace real wallet.dat with dummy one

question: Is this secure enough or are you still in danger during the transaction (for as long as you have your real wallet.dat linked to bitcoin-qt)?

SK       
You would be better off doing this with a cheap dedicated device: http://youtu.be/1pDSzOiFgIk
member
Activity: 112
Merit: 10
OK quick question:

1) you have a dummy (empty) wallet.dat in .bitcoin so as your bitcoin-qt can stay up to date
2) you keep your real wallet.dat encrypted (say truecrypt) in a usb or maybe also on your mail or dropbox.
3) if you want to make a transaction:
    a) get your encrypted wallet
    b) decrypt it and copy it into .bitcoin
    c) make transaction
    d) replace real wallet.dat with dummy one

question: Is this secure enough or are you still in danger during the transaction (for as long as you have your real wallet.dat linked to bitcoin-qt)?

SK       
legendary
Activity: 2128
Merit: 1065

P.S. Care to double check my math again 2112?  No guarantees that I haven't made another dumb mistake.

I'm just going to post here what I posted for jim618 in his Multibit thread.
Do people think this is an easier way to remember 128 bits?
Jim, are you, by chance, a monolingual person? Are you capable of reading any other script than Latin?

Just lay off this problem. It tends to become a paranoidal obsession, similar to the one exhibited in other thread where very intelligent people assume that Internet is operational but all sources of time are compromised.

As far as your software: just make sure that Unicode and various Input Method Editors are operational.

Really just lay it off for a while: it isn't a technical issue and really a behavioral health issue.
legendary
Activity: 3388
Merit: 4615
If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".
A reasonable compromise would be a passphrase with just one non-word, e.g. "This is my gP#m6ij_% password." . . .
Correct Horse Battery Staple
That's 28 characters.  So what you are saying is, "use a longer password"?
But to answer the question, don't rely on something a simple key logger can defeat. I consider a password like a lock on a door. If you want security, get rid of the door!

EDITED and re-posted to address a really dumb math mistake...

I'm familiar with the xkcd comic, OP was specifically asking about an 11 digit password.  My suggestion was to use a completely random set of capital letters, lowercase letters, numbers, symbols/punctuation which would provide 9411 possible combinations.  That is approximately 72 bits of entropy, as such, it is about as secure as you are going to get with 11 characters, though still less secure than a bitcoin address (having 160 bits).  If you want your password to be as secure as a bitcoin address, you'll need at least 25 characters as long as it was a completely random arrangement of capital letters, lowercase letters, numbers, and symbols/punctuation since 9425 > 2160


P.S. Care to double check my math again 2112?  No guarantees that I haven't made another dumb mistake.
legendary
Activity: 3388
Merit: 4615
My suggestion was to use a completely random set of capital letters, lowercase letters, numbers, symbols/punctuation which would provide 1194 possible combinations.
Ugh. Please check your math.

In[1]:= 11^94

Out[1]= 7778796406007058285951393811497112871791787694\
6029329123560958680818697236800243835465535478292041

In[2]:= 94^11

Out[2]= 5062982072492057196544
Bah! What a dumb mistake to make.  I know better too.  Sorry about that.  Can't believe I did that.  I've deleted the post, as the whole thing was based on that really bad math.
legendary
Activity: 2128
Merit: 1065
My suggestion was to use a completely random set of capital letters, lowercase letters, numbers, symbols/punctuation which would provide 1194 possible combinations.
Ugh. Please check your math.

In[1]:= 11^94

Out[1]= 7778796406007058285951393811497112871791787694\
6029329123560958680818697236800243835465535478292041

In[2]:= 94^11

Out[2]= 5062982072492057196544
legendary
Activity: 1106
Merit: 1001
Just today I started playing around with Armory (offline and online wallets) and at first glance it seems pretty impressive.
It's great software, I just hate the launch times.  First launching the QT client and waiting for that to load, then waiting for Armory to load on top of it...

You must not be very concerned about security if a couple of minutes of load time inconveniences you.

I used to be worried about keeping my Bitcoins safe, and being able to safely use them at the same time. Since I started using Armory it's no longer a concern. I keep multiple wallets with multiple levels of security and it works wonderfully. Put what you might spend on a more convenient wallet, put the rest in deep savings, offline only. Fund the spending wallet as needed with offline transfers.

I keep digital wallet backups in multiple physical locations to protect against disaster.





Thanks. I'm doing just about the same right now, and as I said, quite impressed with it. The whole process for signing an offline transaction does take well under a minute and having digital and paper backups for the wallets is very reassuring.
legendary
Activity: 3388
Merit: 4615
. . .  Are we talking 100's of universes of time to crack an 11-digit PW, or should I go with something even longer?

. . . If you use an eleven character password . . . If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".  Under those conditions, I'd expect an eleven character password to be beyond any current technology of cracking in your lifetime.  Want to be more sure?  Make it even longer . . .

If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".
A reasonable compromise would be a passphrase with just one non-word, e.g. "This is my gP#m6ij_% password." . . .

That's 30 characters.  So what you are saying is, "use a longer password"?

If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".
A reasonable compromise would be a passphrase with just one non-word, e.g. "This is my gP#m6ij_% password." . . .
Correct Horse Battery Staple

That's 28 characters.  So what you are saying is, "use a longer password"?
legendary
Activity: 1500
Merit: 1021
I advocate the Zeitgeist Movement & Venus Project.
3 Rules of Computer Security:

Do not own a computer; Do not power it on; and do not use one.
legendary
Activity: 1400
Merit: 1005
Just today I started playing around with Armory (offline and online wallets) and at first glance it seems pretty impressive.
It's great software, I just hate the launch times.  First launching the QT client and waiting for that to load, then waiting for Armory to load on top of it...

You must not be very concerned about security if a couple of minutes of load time inconveniences you.

I used to be worried about keeping my Bitcoins safe, and being able to safely use them at the same time. Since I started using Armory it's no longer a concern. I keep multiple wallets with multiple levels of security and it works wonderfully. Put what you might spend on a more convenient wallet, put the rest in deep savings, offline only. Fund the spending wallet as needed with offline transfers.

I keep digital wallet backups in multiple physical locations to protect against disaster.
I do value convenience highly.  I do not currently have a large BTC balance, but if that changes in the future, I will obviously put more weight into the most secure solutions.

I don't really have any spare computers that don't touch the web... that's what you're talking about, right?  A spare machine that is always offline, and that you use with armory and a USB key to sign transactions?  Maybe I should build one out of spare parts... how much ram is required for an offline only machine?
legendary
Activity: 1988
Merit: 1012
Beyond Imagination
I had a feeling that keyloggers will be the next biggest threat for BTC security

And on the other hand, the password management could really become a pain, sooner or later someone lost many of his coin permanantly because he just forgot one of his brainwallet password  Grin Grin
legendary
Activity: 1400
Merit: 1005
How is the encryption?  Are we talking 100's of universes of time to crack an 11-digit PW, or should I go with something even longer?
I wouldn't be worried about the encryption being cracked.  I'd be far more concerned with creating a password that won't be cracked.  If your eleven digit password is 11111111111, I'd expect it to get cracked.  If you use an eleven character password , but only use lowercase characters (such as "mysecurepwd"), I'd still expect it to be cracked.  Add in some numbers and symbols, and now you are improving your chances of having a secure password.  If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".  Under those conditions, I'd expect an eleven character password to be beyond any current technology of cracking in your lifetime.  Want to be more sure?  Make it even longer.  Of course, the problem with such a password is it can be difficult to remember it if you haven't used it in a while.  This tends to people writing the password down.  If you are going to put the password on paper, you might as well consider paper wallets, since either way you are subject to the same risks and benefits.
Thanks.  The password certainly isn't something that will be cracked by anything but a non-pattern brute-forcer, but it's still short enough to be easily remembered.  I feel good about my chances then.

Just today I started playing around with Armory (offline and online wallets) and at first glance it seems pretty impressive.

Disclaimer: I am not exactly a technophobe, but compared to most others on this forum I'm quite close. So if anyone knows of any potential pitfalls with Armory, I'd like to hear about them.
It's great software, I just hate the launch times.  First launching the QT client and waiting for that to load, then waiting for Armory to load on top of it...

I have a fresh install of Linux Mint on a Laptop that rarely touches the Net.
I use Armory and have a watch only Armory wallet on my Windows 8 machine.
I have multiple backups of my wallet in Truecrytpt containers... some in the cloud, some on a USB stick.
I feel pretty safe.

I wouldn't want bits of paper knocking around unless I had a fireproof safe.
Paper isn't even THAT safe inside a fire safe either.  Safer, but an intense house fire without intervention could have it brown to the point of unreadability.
newbie
Activity: 35
Merit: 0
I have a fresh install of Linux Mint on a Laptop that rarely touches the Net.
I use Armory and have a watch only Armory wallet on my Windows 8 machine.
I have multiple backups of my wallet in Truecrytpt containers... some in the cloud, some on a USB stick.
I feel pretty safe.

I wouldn't want bits of paper knocking around unless I had a fireproof safe.
vip
Activity: 1386
Merit: 1136
The Casascius 1oz 10BTC Silver Round (w/ Gold B)
If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".

A reasonable compromise would be a passphrase with just one non-word, e.g. "This is my gP#m6ij_% password.".

On the topic of passwords, the usage of Unicode characters hasn't been frequently discussed. It certainly broadens the dictionary that the attackers would have to use, at the cost of potentially finding encoding problems that prevent its legitimate usage. But think of it, a single "ñ", "β" or "©" can completely change the game.

I specified that my paper wallet encryption scheme must use UTF-8, and included a test vector consisting of all Greek characters.  So at least there is an established definition for encoding Unicode passwords.  There's still the possibility for confusion with respect to composed versus non-composed characters, but don't think it will present a major issue (non-composed characters, as I understand it, are far more commonly used, and this is a function of the input method that has nothing to do with the wallet encryption in the first place)
legendary
Activity: 1974
Merit: 1029
If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".

A reasonable compromise would be a passphrase with just one non-word, e.g. "This is my gP#m6ij_% password.".

On the topic of passwords, the usage of Unicode characters hasn't been frequently discussed. It certainly broadens the dictionary that the attackers would have to use, at the cost of potentially finding encoding problems that prevent its legitimate usage. But think of it, a single "ñ", "β" or "©" can completely change the game.
legendary
Activity: 1106
Merit: 1001
Just today I started playing around with Armory (offline and online wallets) and at first glance it seems pretty impressive.

Disclaimer: I am not exactly a technophobe, but compared to most others on this forum I'm quite close. So if anyone knows of any potential pitfalls with Armory, I'd like to hear about them.
legendary
Activity: 3388
Merit: 4615
How is the encryption?  Are we talking 100's of universes of time to crack an 11-digit PW, or should I go with something even longer?
I wouldn't be worried about the encryption being cracked.  I'd be far more concerned with creating a password that won't be cracked.  If your eleven digit password is 11111111111, I'd expect it to get cracked.  If you use an eleven character password , but only use lowercase characters (such as "mysecurepwd"), I'd still expect it to be cracked.  Add in some numbers and symbols, and now you are improving your chances of having a secure password.  If you really want it secure, use a completely random set of capital letter, lowercase letters, numbers, symbols/punctuation, and make sure that there aren't any "words".  Under those conditions, I'd expect an eleven character password to be beyond any current technology of cracking in your lifetime.  Want to be more sure?  Make it even longer.  Of course, the problem with such a password is it can be difficult to remember it if you haven't used it in a while.  This tends to people writing the password down.  If you are going to put the password on paper, you might as well consider paper wallets, since either way you are subject to the same risks and benefits.
legendary
Activity: 1232
Merit: 1001
Type in the last five or so chars of you pass phrase with the on-screen keyboard, complicated put key logger proof  Grin (at least as far as I know)
legendary
Activity: 1400
Merit: 1005
I'd like to bring this thread back to the QT client specifically, rather than focusing on paper wallets.  I understand paper wallets have their merits, I would just like to better understand the risks of the QT client and how those risks can be mitigated.
Assuming that you don't have any old unencrypted copies of the wallet.dat sitting around anywhere, it sounds like you already understand it pretty well.  To steal/spend your bitcoins a potential thief would need both the encrypted private keys from your wallet.dat file and your password.  Electronically this can be done with a key logger.  I suppose it would also be possible to install a hidden camera that would record your keyboard to get the password.  Someone with that sort of access to your computer would probably be able to physically access your wallet.dat as well.  Same thing with looking over your shoulder while you type your password.

If we are talking really high tech, I suppose it might be possible to remotely record the sound of you tapping on the keyboard (laser picking up sound vibrations from your window?).  Using the rhythm, volume, and timing of your keystrokes, perhaps it would be possible to reduce the number of possible combinations to something that could be brute-forced?  If we want to think of this like a spy movie, I suppose someone could sneak in and clean all fingerprints off your keyboard just before you enter the room to send some bitcoins somewhere.  Then as soon as you leave they can identify which keys you hit by looking at the fingerprints?  A gun to your head might do the trick as well.
Thanks for the confirmation.

I'm not too worried about someone physically surveying me, but you never know.  If that's the case, I probably have much larger problems than my meager BTC holdings.  Wink

How is the encryption?  Are we talking 100's of universes of time to crack an 11-digit PW, or should I go with something even longer?
Pages:
Jump to: