diff options
author | Martin Habovštiak <martin.habovstiak@gmail.com> | 2015-02-02 18:54:55 +0100 |
---|---|---|
committer | bitcoindev <bitcoindev@gnusha.org> | 2015-02-02 17:55:03 +0000 |
commit | fdbd1340038a780f1e1ff1eb483f557805f539dc (patch) | |
tree | 9e2575f451503f1675c96b57b02b22a1309c9939 | |
parent | d6d2f901f2bb6a2b1be273a67709d3838395918d (diff) | |
download | pi-bitcoindev-fdbd1340038a780f1e1ff1eb483f557805f539dc.tar.gz pi-bitcoindev-fdbd1340038a780f1e1ff1eb483f557805f539dc.zip |
Re: [Bitcoin-development] Proposal to address Bitcoin malware
-rw-r--r-- | 70/e85ca1dc981541604f5d81fb84ca8b6a952055 | 115 |
1 files changed, 115 insertions, 0 deletions
diff --git a/70/e85ca1dc981541604f5d81fb84ca8b6a952055 b/70/e85ca1dc981541604f5d81fb84ca8b6a952055 new file mode 100644 index 000000000..6eda7bbe8 --- /dev/null +++ b/70/e85ca1dc981541604f5d81fb84ca8b6a952055 @@ -0,0 +1,115 @@ +Received: from sog-mx-3.v43.ch3.sourceforge.com ([172.29.43.193] + helo=mx.sourceforge.net) + by sfs-ml-1.v29.ch3.sourceforge.com with esmtp (Exim 4.76) + (envelope-from <martin.habovstiak@gmail.com>) id 1YILDD-0005XB-Gp + for bitcoin-development@lists.sourceforge.net; + Mon, 02 Feb 2015 17:55:03 +0000 +Received-SPF: pass (sog-mx-3.v43.ch3.sourceforge.com: domain of gmail.com + designates 209.85.216.43 as permitted sender) + client-ip=209.85.216.43; + envelope-from=martin.habovstiak@gmail.com; + helo=mail-qa0-f43.google.com; +Received: from mail-qa0-f43.google.com ([209.85.216.43]) + by sog-mx-3.v43.ch3.sourceforge.com with esmtps (TLSv1:RC4-SHA:128) + (Exim 4.76) id 1YILDB-0005GI-Ds + for bitcoin-development@lists.sourceforge.net; + Mon, 02 Feb 2015 17:55:03 +0000 +Received: by mail-qa0-f43.google.com with SMTP id v10so30216842qac.2 + for <bitcoin-development@lists.sourceforge.net>; + Mon, 02 Feb 2015 09:54:56 -0800 (PST) +MIME-Version: 1.0 +X-Received: by 10.140.39.179 with SMTP id v48mr24191052qgv.77.1422899695961; + Mon, 02 Feb 2015 09:54:55 -0800 (PST) +Received: by 10.140.19.18 with HTTP; Mon, 2 Feb 2015 09:54:55 -0800 (PST) +In-Reply-To: <68C03646-02E7-43C6-9B73-E4697F3AA5FD@gmail.com> +References: <27395C55-CF59-4E65-83CA-73F903272C5F@gmail.com> + <54CE3816.6020505@bitwatch.co> + <68C03646-02E7-43C6-9B73-E4697F3AA5FD@gmail.com> +Date: Mon, 2 Feb 2015 18:54:55 +0100 +Message-ID: <CALkkCJbk0czFj5mdMB6_0+Umw5V-fo-4tdBHgvg92zhyRZWiYQ@mail.gmail.com> +From: =?UTF-8?Q?Martin_Habov=C5=A1tiak?= <martin.habovstiak@gmail.com> +To: Brian Erdelyi <brian.erdelyi@gmail.com> +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: quoted-printable +X-Spam-Score: -1.6 (-) +X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. + See http://spamassassin.org/tag/ for more details. + -1.5 SPF_CHECK_PASS SPF reports sender host as permitted sender for + sender-domain + 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider + (martin.habovstiak[at]gmail.com) + -0.0 SPF_PASS SPF: sender matches SPF record + -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from + author's domain + 0.1 DKIM_SIGNED Message has a DKIM or DK signature, + not necessarily valid + -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature +X-Headers-End: 1YILDB-0005GI-Ds +Cc: Bitcoin Dev <bitcoin-development@lists.sourceforge.net> +Subject: Re: [Bitcoin-development] Proposal to address Bitcoin malware +X-BeenThere: bitcoin-development@lists.sourceforge.net +X-Mailman-Version: 2.1.9 +Precedence: list +List-Id: <bitcoin-development.lists.sourceforge.net> +List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/bitcoin-development>, + <mailto:bitcoin-development-request@lists.sourceforge.net?subject=unsubscribe> +List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=bitcoin-development> +List-Post: <mailto:bitcoin-development@lists.sourceforge.net> +List-Help: <mailto:bitcoin-development-request@lists.sourceforge.net?subject=help> +List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/bitcoin-development>, + <mailto:bitcoin-development-request@lists.sourceforge.net?subject=subscribe> +X-List-Received-Date: Mon, 02 Feb 2015 17:55:03 -0000 + +Good idea. I think this could be even better: + +instead of using third party, send partially signed TX from computer +to smartphone. In case, you are paranoid, make 3oo5 address made of +two cold storage keys, one on desktop/laptop, one on smartphone, one +using third party. +If it isn't enough, add requirement of another four keys, so you have +three desktops with different OS (Linux, Windows, Mac) and three +mobile OS (Android, iOS, Windows Phone), third party and some keys in +cold storage. Also, I forgot HW wallets, so at least Trezor and +Ledger. I believe this scheme is unpenetrable by anyone, including +NSA, FBI, CIA, NBU... + +Jokes aside, I think leaving out third party is important for privacy reaso= +ns. + +Stay safe! + +2015-02-02 18:40 GMT+01:00 Brian Erdelyi <brian.erdelyi@gmail.com>: +> Another concept... +> +> It should be possible to use multisig wallets to protect against malware.= + For example, a user could generate a wallet with 3 keys and require a tra= +nsaction that has been signed by 2 of those keys. One key is placed in col= +d storage and anther sent to a third-party. +> +> It is now possible to generate and sign transactions on the users compute= +r and send this signed transaction to the third-party for the second signat= +ure. This now permits the use of out of band transaction verification tech= +niques before the third party signs the transaction and sends to the blockc= +hain. +> +> If the third-party is malicious or becomes compromised they would not hav= +e the ability to complete transactions as they only have one private key. = +If the third-party disappeared, the user could use the key in cold storage = +to sign transactions and send funds to a new wallet. +> +> Thoughts? +> -------------------------------------------------------------------------= +----- +> Dive into the World of Parallel Programming. The Go Parallel Website, +> sponsored by Intel and developed in partnership with Slashdot Media, is y= +our +> hub for all things parallel software development, from weekly thought +> leadership blogs to news, videos, case studies, tutorials and more. Take = +a +> look and join the conversation now. http://goparallel.sourceforge.net/ +> _______________________________________________ +> Bitcoin-development mailing list +> Bitcoin-development@lists.sourceforge.net +> https://lists.sourceforge.net/lists/listinfo/bitcoin-development + + |