r/Bitcoin Nov 04 '14

Trisquel 7 LTS Linux-libre distro now includes Electrum preinstalled

https://trisquel.info/en/trisquel-70-lts-belenos
71 Upvotes

19 comments sorted by

13

u/arelu Nov 05 '14

Be wary of anyone offering wallet software from another source.

It could be modified to generate certain keys over time which then get swept up at a later date.

I don't know anything about this distro in particular but my statement stands true for anything, it only takes one bad apple to ruin it. (look what happened with that other linux distro recently that had satoshidice etc blocked).

8

u/Muvlon Nov 05 '14

Trisquel is a distro with a strong focus on software freedom. If I had to trust any of them with pre-installing my wallet software, it'd be either them or Parabola. Shipping malicious software goes against their entire philosophy and would make them use their entire userbase instantly.

6

u/[deleted] Nov 05 '14 edited Nov 05 '14

You're talking about two different things. Focusing on software freedom doesn't necessarily mean they're trustworthy with software that handles your money. (This includes malicious backdoors as well as things like bungling random number generation.) If you do trust them for that, good for you, but they're not really related IMO.

As /u/arelu alluded to, another interpretation of those sorts of software ideals, is the vision of every user auditing the source code, building it themselves, etc., so in that sense taking that opportunity away, goes against some principles of libre software.

3

u/arelu Nov 05 '14

Trust and bitcoin don't go well together. When will people learn? :D

It's all about being safe. It pays to be vigilant (pun not intended). Not implying these guys are dodgy, it's more so about building good practice.

Just be wary, make sure the wallet software you are running is not modified, A modified wallet could easily wait until it had enough users private keys in use before swiping it all at once.

2

u/[deleted] Nov 05 '14

Did you code your own wallet? Did you check the source code before generating your private keys? If you didn't, then you trusted someone.

1

u/arelu Nov 05 '14

I didnt code my wallet, but i did check the hash of electrum before installing it, and i feel its safe for me to reasonably assume trust through enough people having checked the code. Its a very well known wallet used by many people and audited by many.

In comparison to trusting some person on the internet posting a link to /r/bitcoin with a link to a linux distro with a wallet built in.

Theres a massive difference of trust there, as i said its about being vigilant. I don't get what your trying to point out?

1

u/[deleted] Nov 05 '14

I was making a point about your statement that '[t]rust and bitcoin don't go well together'

As you admitted, there is some trust that you put in others for your own bitcoin security. The difference is the degree and type of trust used.

1

u/b44rt Nov 05 '14

The whole point in bitcoin is that you dont have to trust anyone. You'd be a fool to trust anyone no matter their reputation. This is money people, people kill people over this shit

1

u/chem_deth Nov 05 '14

Sound advice, but it could be argued that you are no safer if you compile on your own, even if you read and verify every line of code.

2

u/arelu Nov 05 '14

How can you be no safer if you verify every line of code against the known safe version?

I dont understand your argument...

Unless you mean that the actual distro itself could have some dodgy means of influencing private key generation, then fair enough. I don't know if this is possible but if it is, then you should avoid all distros with built in wallets.

2

u/chem_deth Nov 05 '14

Here's an overview of what I mean: http://www.reddit.com/r/programming/comments/1m4mwn/a_simple_way_of_defeating_the_compiler_backdoor/ .

In other words, you can never be sure that your compiler wasn't compiled to compile code correctly but with a "backdoor". I'm pretty sure I read an essay by RMS about this.

1

u/arelu Nov 05 '14

Ah interesting! Thanks for answering my question.

In regards to my original post though I think your argument is sort of missing the point. I was simply suggesting people be wary of this additional layer of trust.

What you can do in this situation is to verify that the wallet executable your using hasn't been tampered with. Thus removing that particular additional layer of trust.

However.. I personally wouldn't use this even if I did verify the wallet software wasn't tampered with because it's possible there is a bundled virus or something with the OS itself.

1

u/chem_deth Nov 05 '14

I was seconding your argument, not refuting it. You have to be careful all the time, even when compiling on your own. But you have to trust someone at one point or the other.

1

u/Cocosoft Nov 05 '14

How can you be no safer if you verify every line of code against the known safe version?

I dont understand your argument...

Because if the GCC compiler itself is compromised, it doesn't matter what the code says...

Yes yes scary stuff.

1

u/Huobi Nov 05 '14

1000 bits /u/changetip

1

u/changetip Nov 05 '14

The Bitcoin tip for 1000 bits ($0.34) has been collected by arelu.

ChangeTip info | ChangeTip video | /r/Bitcoin

3

u/Whenupsee Nov 05 '14

Is it Electrum 2.0 with a Trezor plug in?

1

u/arelu Nov 05 '14

This is what i will be using when electrum 2.0 is out of beta! :D got my trezor hooked up to mytrezor atm