{"id":15610,"date":"2017-09-30T00:00:00","date_gmt":"2017-09-29T16:00:00","guid":{"rendered":"https:\/\/www2019.dash.org\/2017\/09\/30\/coinomi-vulnerability-discovered-developers-react-harshly\/"},"modified":"2021-09-18T11:39:30","modified_gmt":"2021-09-18T11:39:30","slug":"coinomi","status":"publish","type":"post","link":"https:\/\/www.dash.org\/news\/coinomi\/","title":{"rendered":"Coinomi Vulnerability Discovered, Developers React Harshly"},"content":{"rendered":"

A privacy-related vulnerability was discovered in the Coinomi wallet, which provoked a hostile reaction from its developers.<\/p>\n

Coinomi is a multi-coin wallet long trusted as one of the most reliable, secure, and easy to use. Recently, however, a vulnerability was discovered that could potentially affect users\u2019 privacy. Initially discovered earlier this month by Luke Childs, the wallet apparently connects to Electrum servers unencrypted without SSL. Childs brought this issue up on GitHub:<\/p>\n

\u201cGreat work on Coinomi!<\/p>\n

Looking at the source it would appear your app is powered by Electrum servers. Connecting to these servers shows they are unencrypted without SSL:<\/p>\n

$ telnet vtc-cce-1.coinomi.net 5028
\nTrying 46.4.85.241\u2026
\nConnected to socrates.coinomi.net.
\nEscape character is \u2018^]\u2019.
\n{ \u201cid\u201d: 0, \u201cmethod\u201d: \u201cserver.version\u201d }
\n{\u201cjsonrpc\u201d: \u201c2.0\u201d, \u201cid\u201d: 0, \u201cresult\u201d: \u201cElectrumX 1.0.14\u2033}
\nDoes this mean your Android app is making all Electrum requests in plain text?\u201d
\nAfter over a week with no reply, Childs reiterated the gravity of the situation before taking to social media for a response:<\/p>\n

\u201cSo basically opening the Coinomi app is broadcasting all of my Bitcoin addresses in plain text over the network.<\/p>\n

Seriously guys, this is a massive privacy issue and needs addressing. ElectrumX supports SSL out of the box, all you need to do is generate a certificate. Do you have any plans to fix this?\u201d
\nDevelopers give a strong and defensive response<\/p>\n

Nearly two weeks after the issue was initially brought to light, one of the developers responded to the issue on GitHub:<\/p>\n

\u201cHey all,<\/p>\n

We have been working on extending the electrum protocol to support secure websockets so we could have a unified electrum indexer API for the mobile apps and websites.<\/p>\n

Keep an eye on the ElectrumX repo for a pull request.<\/p>\n

Sorry that it took so long to fix.\u201d
\nHowever, later the official Coinomi Twitter account responded to previously posted ongoing threads negatively to Childs for spreading awareness of the issue after having been unable to receive an initial response in a timely manner:<\/p>\n

Coinomi also called on Childs to apologize for bringing to light information that may cause users to seek an alternative, dubbed by Coinomi as \u201cinferior and insecure.\u201d<\/p>\n

Coinomi may have been referring to the Jaxx wallet, which had a certain degree of drama following the revelation that it stored its security pin unencrypted. Coinomi had used that instance as an opportunity for negative advertising:<\/p>\n

Users should do their due diligence as to which services to trust<\/p>\n

Dash users should always take precautions with the services they trust with their funds. Cryptocurrency is decentralized, peer-to-peer, and trustless, and while this provides many advantages over more traditional and centralized methods of transacting, it also imparts a greater responsibility on the consumer to do proper research into the services they use. While a major coin like Dash with a thoroughly-vetted code may be easily trusted, the myriad of smaller apps and services that comprise the Dash ecosystem may not have had the benefit of being exposed to the same level of scrutiny. As a starting point, users should only trust wallets listed on Dash.org (and keep abreast of any new vulnerabilities discovered in even these third-party wallets), and take caution when trusting other services.<\/p>\n","protected":false},"excerpt":{"rendered":"

A privacy-related vulnerability was discovered in the Coinomi wallet, which provoked a hostile reaction from its developers.<\/p>\r\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[216],"tags":[],"acf":[],"yoast_head":"\nCoinomi Vulnerability Discovered, Developers React Harshly - Dash<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dash.org\/news\/coinomi\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coinomi Vulnerability Discovered, Developers React Harshly - Dash\" \/>\n<meta property=\"og:description\" content=\"A privacy-related vulnerability was discovered in the Coinomi wallet, which provoked a hostile reaction from its developers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dash.org\/news\/coinomi\/\" \/>\n<meta property=\"og:site_name\" content=\"Dash\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/DashPay\" \/>\n<meta property=\"article:published_time\" content=\"2017-09-29T16:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-18T11:39:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.dash.org\/wp-content\/uploads\/dash_facebook.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dash\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@dashpay\" \/>\n<meta name=\"twitter:site\" content=\"@dashpay\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dash\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/\"},\"author\":{\"name\":\"dash\",\"@id\":\"https:\/\/www.dash.org\/#\/schema\/person\/49e370ea57b37d1186318dab9e4e6513\"},\"headline\":\"Coinomi Vulnerability Discovered, Developers React Harshly\",\"datePublished\":\"2017-09-29T16:00:00+00:00\",\"dateModified\":\"2021-09-18T11:39:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/\"},\"wordCount\":531,\"publisher\":{\"@id\":\"https:\/\/www.dash.org\/#organization\"},\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/\",\"url\":\"https:\/\/www.dash.org\/news\/coinomi\/\",\"name\":\"Coinomi Vulnerability Discovered, Developers React Harshly - Dash\",\"isPartOf\":{\"@id\":\"https:\/\/www.dash.org\/#website\"},\"datePublished\":\"2017-09-29T16:00:00+00:00\",\"dateModified\":\"2021-09-18T11:39:30+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.dash.org\/news\/coinomi\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.dash.org\/news\/coinomi\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.dash.org\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Coinomi Vulnerability Discovered, Developers React Harshly\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.dash.org\/#website\",\"url\":\"https:\/\/www.dash.org\/\",\"name\":\"Dash\",\"description\":\"Dash is Digital Cash You Can Spend Anywhere\",\"publisher\":{\"@id\":\"https:\/\/www.dash.org\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.dash.org\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.dash.org\/#organization\",\"name\":\"Dash\",\"url\":\"https:\/\/www.dash.org\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dash.org\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/media.dash.org\/wp-content\/uploads\/dash-d.png\",\"contentUrl\":\"https:\/\/media.dash.org\/wp-content\/uploads\/dash-d.png\",\"width\":500,\"height\":500,\"caption\":\"Dash\"},\"image\":{\"@id\":\"https:\/\/www.dash.org\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/DashPay\",\"https:\/\/twitter.com\/dashpay\",\"https:\/\/www.instagram.com\/dashpay\",\"https:\/\/www.linkedin.com\/company\/10424093\",\"https:\/\/www.pinterest.com\/dashdigitalcash\",\"https:\/\/www.youtube.com\/c\/DashOrg\",\"https:\/\/en.wikipedia.org\/wiki\/Dash_cryptocurrency\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.dash.org\/#\/schema\/person\/49e370ea57b37d1186318dab9e4e6513\",\"name\":\"dash\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dash.org\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8aabe262ffeff934a0baa0b4a798992f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8aabe262ffeff934a0baa0b4a798992f?s=96&d=mm&r=g\",\"caption\":\"dash\"},\"url\":\"https:\/\/www.dash.org\/author\/dash\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Coinomi Vulnerability Discovered, Developers React Harshly - Dash","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dash.org\/news\/coinomi\/","og_locale":"en_US","og_type":"article","og_title":"Coinomi Vulnerability Discovered, Developers React Harshly - Dash","og_description":"A privacy-related vulnerability was discovered in the Coinomi wallet, which provoked a hostile reaction from its developers.","og_url":"https:\/\/www.dash.org\/news\/coinomi\/","og_site_name":"Dash","article_publisher":"https:\/\/www.facebook.com\/DashPay","article_published_time":"2017-09-29T16:00:00+00:00","article_modified_time":"2021-09-18T11:39:30+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/media.dash.org\/wp-content\/uploads\/dash_facebook.png","type":"image\/png"}],"author":"dash","twitter_card":"summary_large_image","twitter_creator":"@dashpay","twitter_site":"@dashpay","twitter_misc":{"Written by":"dash","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dash.org\/news\/coinomi\/#article","isPartOf":{"@id":"https:\/\/www.dash.org\/news\/coinomi\/"},"author":{"name":"dash","@id":"https:\/\/www.dash.org\/#\/schema\/person\/49e370ea57b37d1186318dab9e4e6513"},"headline":"Coinomi Vulnerability Discovered, Developers React Harshly","datePublished":"2017-09-29T16:00:00+00:00","dateModified":"2021-09-18T11:39:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dash.org\/news\/coinomi\/"},"wordCount":531,"publisher":{"@id":"https:\/\/www.dash.org\/#organization"},"articleSection":["News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.dash.org\/news\/coinomi\/","url":"https:\/\/www.dash.org\/news\/coinomi\/","name":"Coinomi Vulnerability Discovered, Developers React Harshly - Dash","isPartOf":{"@id":"https:\/\/www.dash.org\/#website"},"datePublished":"2017-09-29T16:00:00+00:00","dateModified":"2021-09-18T11:39:30+00:00","breadcrumb":{"@id":"https:\/\/www.dash.org\/news\/coinomi\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dash.org\/news\/coinomi\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.dash.org\/news\/coinomi\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.dash.org\/"},{"@type":"ListItem","position":2,"name":"Coinomi Vulnerability Discovered, Developers React Harshly"}]},{"@type":"WebSite","@id":"https:\/\/www.dash.org\/#website","url":"https:\/\/www.dash.org\/","name":"Dash","description":"Dash is Digital Cash You Can Spend Anywhere","publisher":{"@id":"https:\/\/www.dash.org\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dash.org\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.dash.org\/#organization","name":"Dash","url":"https:\/\/www.dash.org\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dash.org\/#\/schema\/logo\/image\/","url":"https:\/\/media.dash.org\/wp-content\/uploads\/dash-d.png","contentUrl":"https:\/\/media.dash.org\/wp-content\/uploads\/dash-d.png","width":500,"height":500,"caption":"Dash"},"image":{"@id":"https:\/\/www.dash.org\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/DashPay","https:\/\/twitter.com\/dashpay","https:\/\/www.instagram.com\/dashpay","https:\/\/www.linkedin.com\/company\/10424093","https:\/\/www.pinterest.com\/dashdigitalcash","https:\/\/www.youtube.com\/c\/DashOrg","https:\/\/en.wikipedia.org\/wiki\/Dash_cryptocurrency"]},{"@type":"Person","@id":"https:\/\/www.dash.org\/#\/schema\/person\/49e370ea57b37d1186318dab9e4e6513","name":"dash","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dash.org\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8aabe262ffeff934a0baa0b4a798992f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8aabe262ffeff934a0baa0b4a798992f?s=96&d=mm&r=g","caption":"dash"},"url":"https:\/\/www.dash.org\/author\/dash\/"}]}},"_links":{"self":[{"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/posts\/15610"}],"collection":[{"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/comments?post=15610"}],"version-history":[{"count":1,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/posts\/15610\/revisions"}],"predecessor-version":[{"id":19308,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/posts\/15610\/revisions\/19308"}],"wp:attachment":[{"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/media?parent=15610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/categories?post=15610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dash.org\/wp-json\/wp\/v2\/tags?post=15610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}