Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
Already on GitHub? Sign in to your account
Add a lower severity disclaimer for wallets in-between software wallets and web wallets. #227
Conversation
|
It's not a good idea to equate closed-source with uses-centralized-services. Closed source is a much higher security risk, and I'm inclined to suggest we not list such clients at all. |
|
By definition, a centralized server is a closed-source model as we can't really see what's happening under the cover. This is what I really meant to say here. That said, I can just drop the part about "open-source" in the text as follow. FWIW, I would also be pretty uncomfortable with the idea of adding a closed source client on bitcoin.org . "This wallet relies on a centralized service by default |
saivann commentedAug 16, 2013
This disclaimer is meant to allow visitors to be better informed of the difference between fully open-source and decentralized wallets and those who partially depends on centralized and opaque services.
Applies to hybrid wallets (blockchain.info)
Applies to clients that are loading the block chain using a centralized server (Electrum, Mycelium)
Concerning blockchain.info, if anyone still feel it should have the big red warning, I'm OK with that too. However my personal opinion is that this disclaimer is better suited given that it explicitely recommends using strong passwords and backups, and since we are linking and recommending the Android app and browser extension.
Screenshot: