-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added Coinomi wallet #780
Added Coinomi wallet #780
Conversation
…e no deterministic build system is involved in the build process whatsoever
Downgraded Coinomi's transparency level to checkpasstransparencyopensource since no deterministic build system is involved in the build process whatsoever
I have reviewed Coinomi based on the current wallet requirements criteria and my evaluation is below. The summary is that the wallet passes on security and overall design. However, because the website that links to executable code is not yet secure (no TLS) and the website does not reference the project principals as I noted in the review, I cannot at this time recommend it for listing. Coinomi is working on these issues and I will be glad to recommend Coinomi for listing once the website is updated. I concur with the current scoring in the pull request. CoinomiVersion v1.5.13Review version 2015042501The wallet list is based on the personal evaluation of the maintainer(s) and regular contributors of this site, according to the criterias detailed below. These requirements are meant to be updated and strengthened over time. Innovative wallets are exciting and encouraged, so if your wallet has a good reason for not following some of the rules below, please submit it anyway and we'll consider updating the rules. NOTE Coinomi is a multi-coin wallet. Only the Bitcoin wallet functionality was tested/reviewed. Basic requirements:
PASS No concerning issues NOTE Fairly small amount of feedback https://github.com/Coinomi/coinomi-android/issues
PASS No indication (see above sources)
PASS No indication. Few issues above were addressed quickly.
PASS Uses bitcoinj
PASS No indication. Some unit testing. Well functioning code.
PASS Released 4-Nov-2014 https://bitcointalk.org/index.php?topic=713649.msg9431499#msg9431499
PASS No concerning bugs were found
FAIL No TLS support for site referencing download coinomi.com
FAIL No TLS
FAIL No TLS
FAIL Not listed on coinomi.com. Developers only listed on github.
PASS When setting up a new wallet, passwords must be 8 characters long and must not be in a common 10,000 password list NOTE Setting a password is optional NOTE When restoring an existing wallet, password complexity is not checked
N/A
PASS BIP39 phrase and QR code in Settings
PASS Restoring wallet from BIP39 phrase works
PASS https://github.com/Coinomi/coinomi-android
N/A
N/A
Optional criterias (some could become requirements):
NOTE No formal audit, but some peer review http://www.reddit.com/r/blackcoin/comments/2r5k2k/blackcoin_added_to_coinomi_multicoin_android/
PASS Uses new change addresses
PASS Uses a new receiving address for each transaction (can be disabled in settings)
PASS Does not show “received from” addresses
PASS Uses RFC 6979. Wallet signatures were duplicated with custom code.
PASS Provides a contact form on coinomi.com
N/A
PASS Supports BIP32 with multi-coin BIP44 path. Used custom code to verify generated addresses.
PASS During setup provides a step to write down recovery phrase and allows user to test it
PASS Uses Scrypt
N/A
N/A
|
@crwatkins Thanks for the review and feedback. We are working on a new website that uses HTTPS and will update this once we are ready. |
@crwatkins thanks for your review, I am happy to confirm that the failing issues:
|
I have re-reviewed Coinomi based on the current wallet requirements criteria and the updates to my evaluation are below. I gladly recommend Coinomi for listing. CoinomiVersion v1.5.13Review version 2015051401
PASS HTTP redirects to HTTPS on coinomi.com and www.coinomi.com
PASS Grade A+ (CloudFlare)
PASS 180 days
PASS Front and center on coinomi.com |
64d1cdc looks good to me (preview below). Thanks everyone! In the absence of critical feedback, this pull will be merged around 12:00 UTC Monday. |
The preview looks great! @harding @crwatkins thanks so much both for your help! |
No description provided.