Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a pretty unlikely scenario for a typical use case. The attacker would have to own the electrum server that the victim is connecting to, and orchestrate a fake transaction. Even then, if the person double checks the transaction via a third party like blockchain.info, they would see it's fake.

I think you are over-exaggerating the impact of this vulnerability given the safeguards available to mitigate the attack, such as running your own electrum server or cross checking transactions with a third party.



I guess it depends on the technical savvy of the user and whether “running your own electrum server or cross checking transactions with a third party” is really going to happen.

The project website doesn't advise taking these measures, nor disclose the possibility of this scenario. That's what bugs me the most here.

If their intended user is a knowledgeable Bitcoin hobbyist, who knows how the currency works inside and out, maybe it isn't a big deal, but just speaking personally as a Bitcoin newbie, the lack of disclosure/accountability suggested I stay away.


That's sounds like a very prudent decision to me. I fully agree that this issue should be clarified on the site. I will add it to my community service todo list to email the developer to try and help resolve the issue.

The project is still in its early stages of development, but is already very useful to bitcoin-tech savvy users. The ability to install it on my Android phone and other devices while running my own transaction server is a big plus for me currently.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: