Termcoin – A Bitcoin wallet for your terminal
github.com
github.com
For instance, you're getting the user's wallet passphrase at line 1361. Does the passphrase just sit around in memory somewhere, long after the wallet encryption has been kicked off?
https://github.com/chjj/termcoin/blob/master/bin/termcoin#L1...
In any case, if I had a pile of Bitcoin (unfortunately I do not) I wouldn't put it all in one wallet on one server. From what I've heard, paper wallets are the safest.
That said, maybe "zero out" your wallet before switching VPS providers, changing plans, etc.
This is from 2012 but probably still relevant as we saw with the recent Digital Ocean outrage. http://www.contextis.com/research/blog/dirty-disks-raise-new...
"It is worth noting that the data was not live, in that it was not due to sharing of disk contents between running instances of virtual servers. It is understood that the data is due to disk and swap data not being zeroed after use."
EDIT: Dumb question, running Mint 16 here, installed the nodejs package through apt, but termcoin looks for "node", not "nodejs". I copied the symlink as "node" and am just installing the npm modules now, but whats up with that?
However, I'll be damned if I install it on my machine for at least a year or two after it's been released and fully verified by everybody in the community who matters.
The only way that I can be sure that it's not going to steal from me is if it has been around for a few years, used extensively, and nobody has cried fowl.
That, or if they paid for a public auditing by respectable cryptographers.
Let me know if anyone is interested in taking a look.
From my README file:
bitc is a thin SPV bitcoin client.
- 100% C code,
- support for linux and mac platforms,
- console based: uses ncurses,
- home grown async network i/o stack,
- home grown poll loop,
- home grown bitcoin engine,
- multi-threaded,
- valgrind clean.
edit: indentation. electrum -g [text | stdio]
The terminal interfaces could use more testing to say the least, but Electrum has been around since 2011. It's written in Python and includes support for CLI based multisignature transactions [1], raw transactions, proxies, and server selection. It was recently added to the Debian official repos.It's actively used in ecommerce [2], and we've even heard on #electrum freenode of at least one Bitcoin exchange using it on the backend.
Electrum uses a deterministic mnemonic address generation system (soon to be BIP0032 compatible) and the Stratum protocol, which involves running a gateway daemon [3] and bitcoind on the backend, to tackle the large size of the blockchain and rather unwieldy individualized address generation scheme in use by Bitcoin-QT.
[1] https://gist.github.com/atweiden/7272732
[2] https://wordpress.org/plugins/bitcoin-payments-for-woocommer...
It's awesome because it's super lightweight and can be installed on virtually any device without even having to run an X ui server.
That also means that you don't have to install anything but this bitcoin client on the system, which dramatically lowers the possibility for attacks.
So it still makes a wallet.dat file but different wallet encryption? I'm a little confused.
For example, there is no way to retrieve the "send" addresses from the wallet via the api. The only way to do this is by using bdb to open the file and reading it as a berkeley database. Send address retrieval is the only thing termcoin does not use bitcoind for: termcoin has a "dumb" parser built-in which reads the wallet.dat and searches it for bitcoin addresses, when it finds them, it checks to see that they're valid and also checks them against "receive" addresses.
The bitcoind api is also incapable of re-labeling or deleting addresses (bitcoin-qt itself cannot delete "receive" addresses). A lot of people end up using a tool like pywallet (which links to bdb) to get around this. These are the only two limitations in termcoin's functionality that keep it from being a fully-fledged wallet.
[1] https://en.bitcoin.it/wiki/Original_Bitcoin_client/API_Calls...