4 ms·
They don't have the ability to spend your coins. If you trust every other aspect of their service (that they aren't capturing and storing your password, which
by corresation 13y ago
They don't have the ability to spend your coins.
If you trust every other aspect of their service (that they aren't capturing and storing your password, which of course they handle every time you use the service), then you can feel safe in knowing that you don't have to trust them not to spend your coins because they can't.
But only if you trust that every other part is honored.
That isn't a rational set of conditions. In the usage of Blockchain.info, they absolutely gain the capacity to capture your private keys. As does anyone who hacks the service.
- rys 13y agoThe way it's supposed to work, and I guess does work today otherwise we'd have heard about it, is that your passphrase doesn't actually get sent anywhere. Instead, it all happens client-side. So today they don't have your keys. Not to say they couldn't be malicious in the future, or get hacked, but that's not the case today. Again, as far as I know.
- hendzen 13y agoYes, blockchain.info's security is snake oil, and they are completely overmarketing themselves as "hack-proof". And of course the reason for this is because Javascript cryptography is an oxymoron [0]. [0] - http://www.matasano.com/articles/javascript-cryptography/ http://www.matasano.com/articles/javascript-cryptography/
- nawitus 13y agoApparently the password is never sent from the client-side, and I've read claims that the client-side JavaScript code is verified on this. You can install a plugin which notifies any changes to the JavaScript code.