Post
Topic
Board Service Discussion
Re: https://bitcoinvanitygen.com - not samr7 vanitygen
by
NotATether
on 23/12/2020, 08:25:43 UTC
I’m glad that shitty site is down now, but watch out for any new ones just like it that pop up, I found this one about a week ago: http://vanitygenbitcoin.net/

Their method of delivery reeks of insecurity.

Quote
Safety is our top priority. Upon completion of your address generation, our system will automatically send it to your email.
We have no access to your keys because the entire process is encrypted, fully automatic and excludes all traces of generation.

Nobody should be sending private keys over plain-text email. At the very least, they should encrypt it with the customer's PGP key. (And if you're not giving vanity generators like this a way to encrypt your keys, then why the heck are you using one in the first place?)

The whole process is definitely not encrypted, because eventually the key is output from samr7 vanitygen in plaintext at some point.

Seriously, people who are trusting others give them private keys better read the fine print like this and use their brain to check if anything is done unsafely.