4 ms·
use blockchain.info They create an individual wallet file for each user AES encrypted with your password. They also support 2-factor auth and auto-backups to 3
by oneplusone 13y ago
use blockchain.info
They create an individual wallet file for each user AES encrypted with your password. They also support 2-factor auth and auto-backups to 3rd party services like Dropbox.
- sillysaurus3 13y agoHow can they support 2-factor auth without also having the ability to spend the bitcoin in the wallets? What's needed is a way to keep bitcoin on remote servers without them having the ability to spend it, but to grant access with 2FA. This prevents password phishing attacks and keylogger attacks, without the user having to worry about their harddrive crashing and losing their wallet. But I'm not sure whether that's possible short of making them keep an encrypted wallet, which negates all of the user convenience of using an exchange.
- ZoF 13y agoYeah this is an interesting problem to think about. A proper solution to this could have far more applications than bitcoin as well.
- nawitus 13y agoApparently blockchain.info only provides the encrypted wallet after the alternative authentication is succesful. They don't have the ability to spend your coins. "It is highly recommended you enable two factor authentication on your My wallet account. Your wallet data is still only encrypted with your password however a second authentication step will need to be passed before your encrypted wallet data is output." There's also GreenAdress.it which has interesting security system in place using "nLockTime": http://www.reddit.com/r/Bitcoin/comments/20puhg/while_blockchaininfo_is_down_what_about_testing/ http://www.reddit.com/r/Bitcoin/comments/20puhg/while_blockc...
- corresation 13y agoThey don't have the ability to spend your coins. If you trust every other aspect of their service (that they aren't capturing and storing your password, which of course they handle every time you use the service), then you can feel safe in knowing that you don't have to trust them not to spend your coins because they can't. But only if you trust that every other part is honored. That isn't a rational set of conditions. In the usage of Blockchain.info, they absolutely gain the capacity to capture your private keys. As does anyone who hacks the service.
- rys 13y agoThe way it's supposed to work, and I guess does work today otherwise we'd have heard about it, is that your passphrase doesn't actually get sent anywhere. Instead, it all happens client-side. So today they don't have your keys. Not to say they couldn't be malicious in the future, or get hacked, but that's not the case today. Again, as far as I know.
- hendzen 13y agoYes, blockchain.info's security is snake oil, and they are completely overmarketing themselves as "hack-proof". And of course the reason for this is because Javascript cryptography is an oxymoron [0]. [0] - http://www.matasano.com/articles/javascript-cryptography/ http://www.matasano.com/articles/javascript-cryptography/
- nawitus 13y agoApparently the password is never sent from the client-side, and I've read claims that the client-side JavaScript code is verified on this. You can install a plugin which notifies any changes to the JavaScript code.
- BrokenPipe 13y agoblockchain.info is great compared to some black box wallet but their model can't provide per transaction two factor, meaning once malware has your keys in memory you are good to go and you are going to have a real bad time. That's possible with multisig and GreenAddress offers 4 different kind of 2FA: Google Auth, SMS, email and Phone (robot call)
- ubercow13 13y agoIf I understand you right, that's already what blockchain.info does