Welcome, Guest. Please login or register.

Author Topic: Does an running client weaken security?  (Read 49 times)

0 Members and 1 Guest are viewing this topic.

Offline achim

  • Fresh Nxter
  • *
  • Posts: 3
    • View Profile
Does an running client weaken security?
« on: December 09, 2013, 09:21:32 PM »
I have a really long and strong password for the NXT client. What possibilities does a hacker have to still steal my coins?

If he managed to have a keylogger running on my machine, he could probably read my password, ut that would also be possible with the bitcoin client.

What happens if I leave the client open for mining? If he gained control over my machine, he wouldn't even have to enter a password to do a transaction, right?

I'm sure the devs thought this through, so what didn't I get? Or is the second scenario improbable anyway?

Offline Come-from-Beyond

  • Established Nxter
  • ***
  • Posts: 171
    • View Profile
Re: Does an running client weaken security?
« Reply #1 on: December 09, 2013, 09:25:59 PM »
If u webpage is closed then only scanning java process memory can retrieve ur passphrase. For rootkits this is not a problem at all.

Offline opticalc

  • Global Moderator
  • Nxter
  • *****
  • Posts: 107
    • View Profile
Re: Does an running client weaken security?
« Reply #2 on: December 09, 2013, 11:17:39 PM »
If u webpage is closed then only scanning java process memory can retrieve ur passphrase. For rootkits this is not a problem at all.

unless the rootkit has a keylogger
Not a stakeholder, so NXT accepted here: 12692935506199079028 if you think I've given value here

Offline Come-from-Beyond

  • Established Nxter
  • ***
  • Posts: 171
    • View Profile
Re: Does an running client weaken security?
« Reply #3 on: December 09, 2013, 11:20:34 PM »
Rootkits live in ring 0, they have access to the whole memory, no need to log keypresses.

Offline opticalc

  • Global Moderator
  • Nxter
  • *****
  • Posts: 107
    • View Profile
Re: Does an running client weaken security?
« Reply #4 on: December 09, 2013, 11:52:03 PM »
Rootkits live in ring 0, they have access to the whole memory, no need to log keypresses.

sorry, i misread the intent of your previous message
Not a stakeholder, so NXT accepted here: 12692935506199079028 if you think I've given value here