amoveo icon indicating copy to clipboard operation
amoveo copied to clipboard

Password handling

Open tallakt opened this issue 7 years ago • 1 comments

The first thing I try when approaching a new coin is to make a private key printable on paper.

When looking at the way passwords are handled, there should be an interactive version of any command that requires password of private key input. The command history is stored on disk and may present an attack vector for people trying to fins keys.

https://github.com/zack-bitcoin/amoveo/blob/master/docs/api/keys.md

tallakt avatar Oct 20 '17 14:10 tallakt

You are right, the password is being sent to the log file. This is a problem. Thank you for pointing this out.

zack-bitcoin avatar Oct 20 '17 14:10 zack-bitcoin