Pages:
Author

Topic: Wallet Security - page 3. (Read 3520 times)

hero member
Activity: 714
Merit: 500
RISE Project Manager
October 28, 2013, 03:16:32 PM
#13
How secure is this method that I used?

Use a factory reset android telephone to access bitddress.org

Then use an offline browser on the telephone and open bitaddress.org (offline) and run brain wallet.

Type in an impossibly large and random alpha numerique code.

Generate address

Take a screenshot of the private key and public key using screenshot function on android phone.

Disconnect PC from the internet

Transfer screenshot from android phone to a brand new and encrypted sha-256 usb drive

Print out paper wallet and store in envelope

Take photo with a digital camera of paper wallet and store on SD card.

Delete screenshot on android phone.

Remove encrypted usb drive from PC before reconnecting to internet.

Store SD card, encrypted USB drive and paper wallet in safe places.




 



Android's RNG is not random

I'm not an expert on computers but doesn't the brain wallet provide a unique output when somebody inputs random typing like......

3903450EFZDFZOJF3405340F9ZDFF034T038TGERPJEPRFP034FZEFZEF03450324534508ZEFZOFJZ ELFJ345


In other words it would be unlikely anybody else would type that exact code in and get the same brain wallet results?
hero member
Activity: 952
Merit: 1009
October 28, 2013, 03:08:38 PM
#12
How secure is this method that I used?

Use a factory reset android telephone to access bitddress.org

Then use an offline browser on the telephone and open bitaddress.org (offline) and run brain wallet.

Type in an impossibly large and random alpha numerique code.

Generate address

Take a screenshot of the private key and public key using screenshot function on android phone.

Disconnect PC from the internet

Transfer screenshot from android phone to a brand new and encrypted sha-256 usb drive

Print out paper wallet and store in envelope

Take photo with a digital camera of paper wallet and store on SD card.

Delete screenshot on android phone.

Remove encrypted usb drive from PC before reconnecting to internet.

Store SD card, encrypted USB drive and paper wallet in safe places.




 



Android's RNG is not random
hero member
Activity: 714
Merit: 500
RISE Project Manager
October 28, 2013, 03:06:02 PM
#11
How secure is this method that I used?

Use a factory reset android telephone to access bitddress.org

Then use an offline browser on the telephone and open bitaddress.org (offline) and run brain wallet.

Type in an impossibly large and random alpha numerique code.

Generate address

Take a screenshot of the private key and public key using screenshot function on android phone.

Disconnect PC from the internet

Transfer screenshot from android phone to a brand new and encrypted sha-256 usb drive

Print out paper wallet and store in envelope

Take photo with a digital camera of paper wallet and store on SD card.

Delete screenshot on android phone.

Remove encrypted usb drive from PC before reconnecting to internet.

Store SD card, encrypted USB drive and paper wallet in safe places.




 

legendary
Activity: 1050
Merit: 1002
October 28, 2013, 03:01:54 PM
#10
^ Yes, I expressed similar sentiments in a past post.

If you want to protect yourself from hackers see my above post. If you want to protect yourself from the NSA you need to start migrating to open source software.
legendary
Activity: 4760
Merit: 1283
October 28, 2013, 02:51:37 PM
#9

In terms of unique access, the most important factor to me seems to be what operating system is being run.  Given the material released by Snowden, I would find it more likely than not that by Win-8 vintage it is possible for the NSA and whatever parties they choose to work with to access almost anything on a stock computer (including smart phones.)  That is not to say that they would probably make a habit of it though, and certainly not to snake a few BTC.  If/when they choose to do so, however, I would not anticipate encryption slowing them down excessively.

Even if one is simply worried about garden variety cyber-criminal ankle biters, the question of operating system is still an big part of the equation.  A brand new computer which has been treated carefully is probably fairly safe from this class of attackers until and unless they exploit holes arranged for higher category attackers.  I'm not aware of this being an issue at this time (though my Android seems to get hacked at will and from a fresh wipe.)

legendary
Activity: 1456
Merit: 1018
HoneybadgerOfMoney.com Weed4bitcoin.com
October 28, 2013, 02:44:30 PM
#8
Be sure you encrypt your wallet with a strong password and you should be fine.

However, for very large amounts I'd look into a trezor, cold storage etc.

The problem is a computer is a multi-purpose device. It's meant to run programs; and there are very many ways for external programs to eventually execute on your computer, not all of them benign. This is why very many computer users do experience malware at some point. Could you be sure nobody did any Internet browsing or inserted arbitrary flash drives on your computer over an extended time? For substantial amounts you might be stressed ever leaving your computer unattended.

If you're intent on this route, however, you can button down your computer as well as you can. Don't install anything and turn off absolutely everything, javascript, flash, browser plug-ins, everything. Also, as LiteCoinGuy points out be sure you have backups to the wallet which exist, ideally on printout as well as USB. Also remember it's not a good idea to keep every single coin you have at one single point of failure.



+10,000

Paper wallet is safer than electronic...especially if its somewhere safe like a deposit box and covered such that you need to tamper with a seal to gain access to a private key.  I wouldn't trust any computer at all. I would only use a thumbdrive for certain if I knew that it was being kept in similar conditions to a paper wallet.
legendary
Activity: 1050
Merit: 1002
October 28, 2013, 02:40:51 PM
#7
Be sure you encrypt your wallet with a strong password and you should be fine.

However, for very large amounts I'd look into a trezor, cold storage etc.

The problem is a computer is a multi-purpose device. It's meant to run programs; and there are very many ways for external programs to eventually execute on your computer, not all of them benign. This is why very many computer users do experience malware at some point. Could you be sure nobody did any Internet browsing or inserted arbitrary flash drives on your computer over an extended time? For substantial amounts you might be stressed ever leaving your computer unattended.

If you're intent on this route, however, you can button down your computer as well as you can. Don't install anything and turn off absolutely everything, javascript, flash, browser plug-ins, everything. Also, as LiteCoinGuy points out be sure you have backups to the wallet which exist, ideally on printout as well as USB. Also remember it's not a good idea to keep every single coin you have at one single point of failure.

legendary
Activity: 1148
Merit: 1014
In Satoshi I Trust
October 28, 2013, 02:21:52 PM
#6
question: are you the only one you has access to the pc? password protected?

if yes: its a possibility but i would recommend not to leave your wallet on that computer.
Yes, I would be the only one with access.

Why would you recommend otherwise?

i just thought: whats happens when someone steals that computer? wouldnt it be more clever to store it on several USB sticks in several locations?

when you are only talking about 500 USD in bitcoins okay, do it on the computer. but with an activity of over 700 you might have more than 500 USD in bitcoin...  Wink
legendary
Activity: 1792
Merit: 1000
October 28, 2013, 02:13:26 PM
#5
It would be a lot cheaper to store your coins in a paper wallet!
To do this I also need to purchase an uncompromised computer - if I have to do that anyway, then why not have a dedicated computer for Bitcoin?
legendary
Activity: 1792
Merit: 1000
October 28, 2013, 02:10:54 PM
#4
question: are you the only one you has access to the pc? password protected?

if yes: its a possibility but i would recommend not to leave your wallet on that computer.
Yes, I would be the only one with access.

Why would you recommend otherwise?
hero member
Activity: 552
Merit: 501
October 28, 2013, 01:44:02 PM
#3
It would be a lot cheaper to store your coins in a paper wallet!
legendary
Activity: 1148
Merit: 1014
In Satoshi I Trust
October 28, 2013, 01:32:01 PM
#2
question: are you the only one you has access to the pc? password protected?

if yes: its a possibility but i would recommend not to leave your wallet on that computer.
legendary
Activity: 1792
Merit: 1000
October 28, 2013, 01:28:31 PM
#1
I'd like to know peoples opinions on the risks of having my coins stolen in the following situation..

I purchase a new PC and only connect it to the internet to download/update Bitcoin-qt and to update the blockchain/send transactions.

The PC is not used for anything else.

I find it highly unlikely that the private keys could get compromised, but I may be missing something.




Pages:
Jump to: