Add a sentence explaining a risk with unsecure money receivers. #581

pull alokmenghrajani wants to merge 2 commits into bitcoin:master from alokmenghrajani:alok/bip32 changing 1 files +3 −1
  1. alokmenghrajani commented at 7:57 PM on August 24, 2017: none

    No description provided.

  2. Add a sentence explaining a risk with unsecure money receivers. 995b8154f9
  3. nit: consistent use of written numbers. 4cbf507520
  4. luke-jr commented at 8:02 PM on August 24, 2017: member
  5. schildbach commented at 8:33 PM on August 24, 2017: contributor

    Actually three Java impls exist: bitcoinj is missing.

  6. alokmenghrajani commented at 11:52 PM on August 25, 2017: none

    re: bitcoinj, I (or anyone else) can add that in another PR.

  7. luke-jr added the label Proposed BIP modification on Sep 16, 2017
  8. alokmenghrajani commented at 7:36 PM on December 15, 2017: none

    friendly ping

  9. nym-zone commented at 8:10 AM on January 8, 2018: contributor

    NACK:

    +Obviously, if someone illegally obtains access to the webserver, they can steal money by diverting future transactions to their own address.

    Too obviously! Obviously also, in this scenario, the intruder could steal credit card info, reduce the prices of all products to zero, insert Javascript malware into every page, replace the homepage with an offensive “shock” image, or rm -rf / the whole server.

    Sadly, the BIP 32 standard omits specification of magical means to stop the hax0r who pwned your server from replacing your Bitcoin addresses with his Bitcoin addresses. NOTABUG.

    So, yes, an intruder who takes control of a server can control the server and its outputs. This is not a BIP 32-specific or Bitcoin-specific issue. To explain such an elementary general fact in the standard would make the standard look dumb, and insult the intelligence of the reader.

  10. alokmenghrajani closed this on Apr 1, 2020

  11. alokmenghrajani deleted the branch on Apr 1, 2020

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-04-14 11:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me