Creating paper wallets:
Problematic action: Create a paper wallet on a paper wallet service website without disconnecting from the internet. Reason: It's extremely insecure for many reasons, some being 1) the website is hacked with generated private keys sent to the hacker; 2) there may be malware in the browser or in the operating system that sends the private keys to the hacker. Solution: The bottom line is to disconnect the internet before creating the paper wallet. It's not secure enough because 1) the malware can save the private keys and wait for internet connection to send them out; 2) the malware can interfere with the generation process itself and give you a private key that is already known to the hacker, which is called backdooring the random number generator; 3) the private keys may exist on the hard disk therefore may be extracted by malware or after the computer is disposed. Better solution: Use a live operating system, such as a Ubuntu live CD, to run the paper wallet software. This is not ultimately bullet-proof, especially for high-value targets, because there exist malware that can hide in the BIOS and firmware of your computer and can infect your live operating system. It should be secure enough for average Joes.
Problematic action: Create a paper wallet without serious verifying. Reason: There may be incompatible issues with operating systems and browsers. Solution: Run tests on various operating systems and various browsers before putting BTC in. Make sure the generated private keys are identical. This applies to regular paper wallets and BIP38 paper wallets. Make sure the decrypted BIP38 keys are correct.
Problematic action: Use a wireless printer. Reason: It's insecure because wireless networks are insecure. Solution: Use a wired printer.
Problematic action: Use an advanced printer, which has internal storage, such as a hard drive. Reason: It is insecure because the private key of the paper wallet printed may be stored on the internal storage, therefore may be recovered if the printer is sold or scrapped. Solution: Use a dumb printer. Or smash the printer, including and especially the internal storage, or keep it locked up and never sell or scrap it.
Problematic action: Leave the printer open for other people to access after printing without turning it off. Reason: It's insecure because the private key printed may still be in the memory of the printer. Solution: Turn the printer off after printing.
Problematic action: Leave the computer untreated after printing. Reason: It's insecure because the printer driver and/or operating system may be keeping copies of the documents you print in some sort of "spool" or print queue. Solution:
Quote from https://bitcoinpaperwallet.com/#popupDelete (the popup doesn't work).
Macintosh:
Enable 'FileVault' to encrypt your filesystem so that cache files cannot be 'undeleted'. Set up a symbolic link from /private/var/spool/cups/cache/ to a removable media volume (e.g. a SD card) and disconnect it when not in use.
Windows:
Use an encrypted filesystem so that your cache files cannot be 'undeleted'. Read this FAQ on how to change the destination of your cache (spool) files to removable media.
Linux:
Use a live-boot CD instead of a regular hard drive OS install. This way when you reboot your computer, all cache files are deleted from memory and no jobs are ever written to disk.
Problematic action: Use a shared printer (at work or school, for example). Reason: It's insecure because 1) the printer may have a glitch and someone else may get your printouts; 2) the printing jobs may be centrally logged. Solution: Don't. Use your own printer.
Problematic action: Use a printer to print the private key or the QR code of the private key. Reason: See above. Solution 1: Don't use a printer for private key stuff. Hand-write the private key. Ignore the QR code since hand-drawing the QR code of the private key may be too time-consuming. Double check. Then check it again, preferably on a different day. Get someone you trust to check it. Then get him/her to check it again, preferably on a different day. (Testing the private key in a wallet app can make it sure. But it comes with risks.) Solution 2: Don't use a printer for private key stuff. Use brain wallet. Write down the passphrase and the relevant information, e.g., the name of the tool used (bitaddress.org/WarpWallet/etc.) and the instructions. Store it the same way as a paper wallet. Save and store some copies of the tool, in case the future versions become incompatible. (There are pitfalls for creating man-made passphrases. It is beyond the scope of this post. In a nutshell, don't create passphrases with your brain.)
Problematic action: Import a paper wallet private key into a wallet app, then spend directly from the paper wallet address.
Mistake: Expect the paper wallet automatically receives/holds changes, similar to a real-life wallet, which may not be the case. Reason: Early wallet apps didn't handle the changes correctly. The changes became the transaction fees of the miners. Explanation: It's a misunderstanding of how Bitcoin works. There is no account balance of any kind in Bitcoin. There is only Unspent Transaction Output (UTXO). The receiving addresses of changes, which will become the new UTXOs, must be specified when BTC is spent. Otherwise, the changes will become the transaction fees. This depends on the implementation of the wallet app, which should not be trusted.
Mistake: Think nothing is wrong if changes are handled correctly. Reason: It's called address reuse, which is not recommended in Bitcoin because 1) it reduces anonymity of both the sender and all the consecutive receivers; 2) it reduces the security by exposing the public key, which is vulnerable to quantum computing. Addresses are hashes of public keys, which are safe from quantum computing.
Mistake: Destroy the paper wallet after it's imported into an HD wallet, thinking that it has become a part of the HD wallet and it's safe to destroy because the master seed of the HD has been backed up. Reason: It is not a part of the HD wallet. If the paper wallet (the paper) is destroyed and the app is uninstalled, the BTC is gone even if the HD wallet is recovered from its master seed.
The right way: Spend (transact) all BTC in a paper wallet to an address of your wallet app. Spend BTC from there. After all the spending is finished, create a new paper wallet and transact all the remaining BTC to it. Store the new paper wallet. Keep the old one for future reference, or destroy it if you don't want the trace.
Problematic action: Destroy a paper wallet after it is used. Reason: You may need to prove you had control of that address some day, e.g., for taxation purpose. In the case of a chain split, you may have a balance on the other chain. Solution: Don't ever destroy a paper wallet. Keep it on file. Mark it with the relevant information, e.g., "Used in April 2017". Unless you don't want to be tied to the address.
Problematic action: Google a famous wallet app, click the first link or the sponsored link, download/install it, and use it, without serious research. Reason: It's insecure because the wallet app may be a scam. Solution: Do thorough research prior to deciding which wallet app to use. Find the official site prior to downloading/installing it.
Additions and corrections are welcome.
Edit: multiple editing for additions, corrections, and clarifications.
Visit link:
Summary: pitfalls of paper wallets : Bitcoin
- Chinas Bitcoin Exchanges Say Banks Will Close Their Accounts [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- How I created my own bitcoin [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- How I created my own bitcoin-like currency [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Bitcoin players knock on Washington doors [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- How does Bitcoin work? - Bitcoin [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Should We Do a Bitcoin Sketch? - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Bitcoin Talk Show #4 with Chris Ellis and Thomas Hunt - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Bitcoin - an Introduction - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Bitcoin ATM Unveiled on Capitol Hill - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Fla. Bitcoin Case Tests Money Laundering Limits - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Capitol Hill Bitcoin ATM...No Anonymity! April 10 2014 - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- BREAKING: US Congressman Steve Stockman To Introduce First Bitcoin Bill - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- 10 Things You Didn't Know About BitCoin - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- All about Bitcoin - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Internet vs Bitcoin - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Bitcoin: The Future of Currency? - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Watching Bitcoin dropping to new lows - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bitcoin ATM unveiled in Washington DC: revolutionary digital currency arrives on Capitol Hill - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Qu'est-ce que le bitcoin ? - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Decentralize Everything -- Congresswoman Velazquez supports Bitcoin -- Stallman in Vienna - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Drake Bitcoin's Here Music Video - Bitcoin T Shirt Store - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- China tightens leash on bitcoin - Biz Wire - April 4,2014 - BONTV China - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- What is BITCOIN? Andreas Antonopoulos & Amir Taaki explain BTC value - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Texas Bitcoin Conference - Robocoin & Coinvault ATM - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Texas Bitcoin Conference - BitShares - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Is Bitcoin the Future of Money? (with Timothy B. Lee) - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Robert Murphy at Texas Bitcoin Conference 2014 about Austrian Economics, money theory and Bitcoin - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- CryptexCard - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Father of Virtual Reality on Bitcoin April 8 2014 - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- California's first bitcoin ATM launches in Silicon Valley - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bitcoin Fight Night: Kickboxing for bitcoin and Max Keiser 'defeats banksters' - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bitcoin blunder: Satoshi Nakamoto denies all involvement with cryptocurrency [Last Updated On: April 13th, 2014] [Originally Added On: April 13th, 2014]
- Bitcoin gets easier for consumers to buy, spend [Last Updated On: April 13th, 2014] [Originally Added On: April 13th, 2014]
- 11.04.14 Forex, Bitcoin Romanov Capital - Video [Last Updated On: April 13th, 2014] [Originally Added On: April 13th, 2014]
- USA: Capitol Hill gets its own Bitcoin ATM - Video [Last Updated On: April 13th, 2014] [Originally Added On: April 13th, 2014]
- Bitcoin, a moeda virtual. - Video [Last Updated On: April 13th, 2014] [Originally Added On: April 13th, 2014]
- Bitcoin creator Satoshi Nakamoto tracked down, but says story has no currency [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Bitcoin's backers know they need to win you over [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- [Structure] Heartbleed and Bitcoin - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- BitCoin mining frame - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Where Do You Think US Bitcoin Regulations Are Headed? - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Dwyer 4-11-14 Bitcoin Update - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- 4/10/14 - China & BTC, Bitcoin Tax Solutions, Libra, BitInvest Coincards - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Ben Lawsky & NY Regulators on Bitcoin - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Bill to Change IRS Ruling on Bitcoin - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Bitcoin is not over! Bitcoin Indian Food Night Saturday! (adult language, parody and yelling) - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Demonstrating a Bitcoin ATM at Dig South - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- 10 Things You Didn t Know About BitCoin - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- How Bitcoin Works in 5 Minutes - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Bitcoin Below $400, Massive Security Breach, 4,000 Merchants, and Congress - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Reddit Co-founder Alexis Ohanian talks Bitcoin security, Mt. Gox on Joe Rogan Experience - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Cointools: Drupal & Bitcoin == $awesome - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Bitcoin ATM, Black Star Pastry, Rosebery, Sydney, Australia (Vending machine, BTM) - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- My Bitcoin Call to Alex Jones Infowars Digital Paper Wallets Storage - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- The Bitcoin Group #25 (Live) -- Bitcoin Sports -- Gox Buyout? -- Sidechains -- Dogecoin Merged? - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- 4/11/14 - China, Mt. Gox buyout, Gyft Cloud, BIT, new bitcoin symbol - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- 9 Year Old Explains Bitcoin - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- CITP Bitcoin Panel 2 Altcoins - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Why US Regulators Should Go Easy on Bitcoin - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- In Crypto We Trust Hackathon Pitches - Bitcoin Expo 2014 - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- CITP Bitcoin - Panel 1: Economics and Public Policy - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- David Chen of Lightspeed Ventures visits Plug and Play Bitcoin - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Video: Roundup of This Week's Bitcoin News 11th April 2014 - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Peace and Bitcoin Remastered - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- [Bitcoin] Cannot be divorced from pre-existing political theory - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Bitcoin Trade 114 - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Wall Street's Fair Value of Bitcoin - Inside Bitcoins NYC 2014 - Video [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Elliotte Wave Technical Analysis Applied to Bitcoin - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Bitcoin Wisdom Depth Chart - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Live - Paris Bitcoin Startup #2 @TheFamily - Mercredi 16/04/2014 ds 19h - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Not Tax Day, Bitcoin Day! - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Preview: The Bitcoin Uprising - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- WCN Live: iNacho -- an interview with Jerica Truax -- win a bitcoin by rating Nachos! 🙂 - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Can You Use Bitcoin for a Tax Haven? - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- What Is Proof Of Stake In Nextcoin (NXT) vs. Proof Of Work In Bitcoin (BTC) - By Tai Zen - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Bitcoin, little failures and huge successes - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Dutch Ethereum & Bitcoin Meetup: Coin Unlimited over Bitcoin en altcoins - Edwin van den Ouden - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Dutch Ethereum & Bitcoin Meetup: Tor (The Onion Router) Joachim de Koning - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Dutch Ethereum & Bitcoin Meetup: First Steps in Ethereum - Joachim de Koning (part one) - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Dutch Ethereum & Bitcoin Meetup: First Steps in Ethereum Joachim de Koning (part two) - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]