Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I agree with the other comment that says that the only good wallet generator is one that runs off line but even if you wanted to use an online one this site isn't even secured with HTTPS no way I would trust this for anything.


see the above comment where no data is sent to their server.


But since the content isn't delivered over HTTPS, it could be MITM'd to include malicious code that does send your keys somewhere.


If you watch your browser you can see if it does or doesn't. You only need trust your browser at that point.

If you don't trust your browser, you can monitor network activity as the OS level. Should provide a pretty good assurance.

That said, I still wouldn't use it without (a) a private browser window, (b) taking the machine offline, and (c) killing the browser before going back online. Unfortunately, I don't think most people who will use this will do such a thing.

(And I'm still not sure I'd trust it for any really serious work.)


Well that's not the only way it could be broken. The generator could give you a chosen (or less-random) address.


I assumed it didn't, if it did that would be even worse. The problem assuming you trust the creators of that site is that since the connection is unsecured the javascript could be modified for a compromised version w/o you knowing. Even if you watch your connection like a hawk and make sure it doesn't send any data out it could generate a key that might look random but is really based on some shared secret only the attacker knows.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: