Post
Topic
Board Wallet software
Re: Online Wallet: Sendbit
by
bit247
on 22/05/2020, 05:47:25 UTC
run run run
don't use this wallet
Warning

OP is promoting a new web wallet. They have full control over your private keys.
If you care about your BTC, do NOT use that wallet.



The Domain got registered less than a month ago.

Code:
Domain Name: SENDBIT.IO
Updated Date: 2020-04-16T18:15:20Z
Creation Date: 2020-04-11T08:53:43Z



Edit:

Additionally the provider of the web wallet, doesn't have a clue what they are talking about in the "security" section:

Application

We use SQL injection filters to prevent CSRF attacks and XSS attacks [...]
This doesn't make sense at all.


And additionally, instead of hashing the password client-side and transmitting the hash to the server, they are transmitting the password in plain text.
POST Request upon registering:
Code:
user_name=815ff46a-d01a-4582-ace7-9357a066c32d&email=test1%40test.com&password=test1234%21&password_repeat=test1234%21&register=REGISTER


Summary: Don't use that wallet! Even if it is build without malicious intend, already simple steps like not transmitting passwords in plain text aren't implemented.
This wallet is either a scam or unsecure.

Even if you ignore the fact that they have access to your private keys (which you shouldn't ignore), it is extremely unsafe to use that wallet.