BitShares Forum

Main => General Discussion => Topic started by: bitmarley on January 08, 2015, 12:00:39 am

Title: I want to buy more BTS but .....Fear of being hacked
Post by: bitmarley on January 08, 2015, 12:00:39 am
Its hard to buy more BTS cause I am scared of being hacked.  ???

Is there OTP authentication support?
Is there easy cold wallet setup that you can spend from via hot wallet?
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: speedy on January 08, 2015, 12:03:17 am
My procedure:
-Have a machine that you only use for 1 thing - crypto.
-Install Linux on it
-Compile the BTS wallet yourself from source. Happy to help if you have any problems with that.
-BACKUP on usb drives.

I dont think we have cold storage yet. But Im not too worried about being hacked with those steps. Hope Im not tempting fate.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitAndy on January 08, 2015, 03:02:04 am
I'm also worried about my wallet's safety on windows. I've got a decent antivirus, malwarebytes & spyshelter for keyloggers on a desktop that isn't used too much. I'm not sure if this is good enough security or if I should try learning about Linux?
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: arhag on January 08, 2015, 03:15:31 am
Is there easy cold wallet setup that you can spend from via hot wallet?

That doesn't really make sense. If you can spend the funds in the cold wallet from a hot wallet, then it isn't really cold, is it?

I think what you want is multisig, offline transaction signing, and also being able to change the votes of your cold storage funds via hot wallet but not be able to spend the money using only the hot client. All of those are in the pipeline, but who knows when it will actually be released and ready to use in the client.

Until then, you have two options. If you want to actively use your BTS (vote, trade in the market), speedy's solution is the best you can do at the moment. If all you want to do is buy BTS and hodl, then there is a cold storage solution currently if you are comfortable using the command line interface: http://wiki.bitshares.org/index.php/Best_Practices/Cold_Storage.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitmarley on January 08, 2015, 11:44:46 am
Thanks for your replies. Yes what I meant by that sentence was a cold wallet that supports offline signing and then manual loading into a hot wallet for transfer. The existing cold storage solution doesn't have a method to do that as far as I understand. Speedy's solution is good enough security though not too easy for the newbies that we hope will be rushing into bitshares soon. I understand 2 factor OTP authentication is a simple and strong option. I'm sure the devs are working on these features as we speak but until then the bts in-flows will be restricted. After all a secure setup is the first hurdle an investor needs to clear.


Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitmarley on January 10, 2015, 02:45:20 pm
The problem with Speedy's solution is that the wallet only remains cold until one need's to make a transfer. The only way to transfer is to make the cold wallet hot thereby breaking security. There needs to be cold/hot wallet splitting and offline signing features.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: islandking on January 10, 2015, 03:37:45 pm
The problem with Speedy's solution is that the wallet only remains cold until one need's to make a transfer. The only way to transfer is to make the cold wallet hot thereby breaking security. There needs to be cold/hot wallet splitting and offline signing features.

Maybe you could split your BTS over 10 or 20 accounts/addresses. That way when you do pull out the BTS from cold storage it is a smaller amount that you can spend, while the other 19 accounts are still in cold storage.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: cryptkeeper on January 11, 2015, 04:41:26 am
is it highly possible for your wallet to get hacked?
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: chryspano on January 11, 2015, 05:07:33 am
is it highly possible for your wallet to get hacked?

if you have your wallet in your "everyday use pc" then you are asking for trouble or if you have installed in your pc every altcoin you heard about then you are also asking for trouble.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitAndy on January 11, 2015, 05:57:21 am
is it highly possible for your wallet to get hacked?

if you have your wallet in your "everyday use pc" then you are asking for trouble or if you have installed in your pc every altcoin you heard about then you are also asking for trouble.

The only way someone could get into your BTS wallet is if they have a keylogger & catch you plugging in your password? Presuming it's a decent password & they can't brute force it.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: chryspano on January 11, 2015, 08:27:13 am
is it highly possible for your wallet to get hacked?

if you have your wallet in your "everyday use pc" then you are asking for trouble or if you have installed in your pc every altcoin you heard about then you are also asking for trouble.

The only way someone could get into your BTS wallet is if they have a keylogger & catch you plugging in your password? Presuming it's a decent password & they can't brute force it.

Yes, they will need your password and a copy of your wallet.

If you change your password at some point, your old backups are not affected by this change and will continue to use the old password.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitmarley on January 11, 2015, 08:50:45 pm

Yes, they will need your password and a copy of your wallet.

If you change your password at some point, your old backups are not affected by this change and will continue to use the old password.

Exactly. So a bitshares wallet is vulnerable since you can only run a hot wallet. It's no good for bitshares if we are trying to stand out as a decentralized market which is safe from the hacking that happens to centralized exchanges.  If we want Bitstamp, Kraken etc to accept BTS and bitUSD and act as gateway exchanges then with the existing client those companies are going to have no user friendly cold wallet features. Right now their bitshares balances would be over-exposed versus bitcoin balances which can be managed via cold wallet features.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: deprdoo on January 12, 2015, 11:24:01 pm
https://github.com/BitShares/bitshares/milestones

Looks like you only have to wait till the 21st for better cold storage support.
Title: Re: I want to buy more BTS but .....Fear of being hacked
Post by: bitmarley on January 13, 2015, 05:06:07 pm
https://github.com/BitShares/bitshares/milestones

Looks like you only have to wait till the 21st for better cold storage support.

 8) Yaahmaan! Thanks for the link. Doubled my BTS holdings cause of your post. Will double again after Jan 21 if cold wallet features are comprehensive.