pointbiz / bitaddress.org

JavaScript Client-Side Bitcoin Wallet Generator
https://www.bitaddress.org
2.44k stars 1.51k forks source link

There is a back door? #210

Open cocioale opened 4 years ago

cocioale commented 4 years ago

Hi, but there is a backdoor in the site web walletgenerator? https://www.youtube.com/watch?v=zGrV1FNLLH4 also in bitaddress? thanks

Xavier4492 commented 4 years ago

yes, both sites were bought by the same person. see https://bitcointalk.org/index.php?topic=5247201.msg54444963#msg54444963

17 mai 2020 à 17h55:00

C'est évidemment une arnaque, la personne qui a acheté walletgenerator, a aussi bitcoinpaperwallet.

Après quelques recherches, veuillez regarder ceci: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potential-malicious-3d8936485961 https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

et ensuite vous pouvez trouver que la liste des répertoires est activée: https://bitcoinpaperwallet.com/bitcoinpaperwallet/

et enfin ce site Web modifié: https://bitcoinpaperwallet.com/bitcoinpaperwallet/generate-walletfe23t9u2fhjnj3f32.html le https://bitcoinpaperwallet.com/bitcoinpaperwallet/generate-walletfe23t9u2fhjnj3f32.html

générateur aléatoire est cassé de la même manière que dans l'article:

Le ven. 22 mai 2020 à 10:05, Alessandro Valerio notifications@github.com a écrit :

Hi, but there is a backdoor in the site web walletgenerator? https://www.youtube.com/watch?v=zGrV1FNLLH4 also in bitaddress? thanks

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/pointbiz/bitaddress.org/issues/210, or unsubscribe https://github.com/notifications/unsubscribe-auth/APMRMXB4H4SBME3OBMW76NTRSYW5RANCNFSM4NHSOW3A .

cocioale commented 4 years ago

thanks, so we sould trust to bitaddress or not? and where I can find the place to create a paper wallet?

pointbiz commented 4 years ago

You can trust bitaddress.ORG it's hosted on github.com now. You can also download the HTML right from github.com https://github.com/pointbiz/bitaddress.org/blob/master/bitaddress.org.html

It's very sad the owners of those two domains sold. I have no plan to sell bitaddress.org it is and always has been a non-profit project.

Leon0008 commented 2 years ago

Hi,

i tried all possible ways with Fireofox and Notepad to save webpage www.bitaddress.org, and verify checksum. The results were different than one in CHANGELOG.

The only way i got correct value was through Github (for others: use the link directly above / choose RAW / save web page as text) Is something wrong with www.bitaddress.org?

Also please note that public key has expired.

Thank you in advance. Best regards, Leon

pointbiz commented 2 years ago

Hi,

i tried all possible ways with Fireofox and Notepad to save webpage www.bitaddress.org, and verify checksum. The results were different than one in CHANGELOG.

The only way i got correct value was through Github (for others: use the link directly above / choose RAW / save web page as text) Is something wrong with www.bitaddress.org?

Also please note that public key has expired.

Thank you in advance. Best regards, Leon

Please use a diff tool to compare what you downloaded from bitaddress.org versus what you downloaded from github.

Leon0008 commented 2 years ago

Hi, i tried all possible ways with Fireofox and Notepad to save webpage www.bitaddress.org, and verify checksum. The results were different than one in CHANGELOG. The only way i got correct value was through Github (for others: use the link directly above / choose RAW / save web page as text) Is something wrong with www.bitaddress.org? Also please note that public key has expired. Thank you in advance. Best regards, Leon

Please use a diff tool to compare what you downloaded from bitaddress.org versus what you downloaded from github.

It was kaspersky injecting code. After removing it checksum ver identical. Thank you!