Stop Using Blockfolio App - Its Calling Home with Too Much Info (+Small Safety Tutorial)

in bitcoin •  7 years ago 

What is Blockfolio

I have done a review of Blockfolio long ago here if you are not familiar its an app which allows you to track prices of chosen coins and has almost all altcoins you can imagine.

But it also has another neat option - you can add there amounts of coisn you have, price you bought at and it will constantly show you how much your whole coin portfolio is worth, you can check stats of all coins you have and more.

The app looks and works amazing. No doubt in this.

Blockfolio Tracks All Your Moves and Coins

While i knew this app is great i have only used it to track prices, i have never put there single info about my orders or amouns of what i own. Due to years online and 7th year in cryptocurrency (omg.. im so old) ive expected abuse to happen.

I hate tracking of any kind and imagine here you give full info on your net worth to randoms.

Due to todays findin it gets even better - they have over 100 000 downloads and can fully track move of everyone to not only track people but track and predict moves on markets.

The Finds

Website BitcoinErrorLog went by code and all homecalls in the app and found some sneaky things there.

But as i said - its nothing surprising. Possibly after this went public app owners will stop this or mangle it more..
Either way its never good to use such 3rd party apps that track you and trusting them with your money.

How to Stay Safe in Crypto World

  • Obviously - if you dont have key to your coins, they are not yours. Never trust exchanges or webwallets.
  • In Bitcoin a like coins - often change wallets, use new addresses for deposits.
  • Have backups of your keys for coins also outside home.
  • Use VPN and change IPs on it often, i currently use Traceless.
  • Never share your keys with anyone on internet.
  • Add 2FA on exchanges, if they dont have this option.. Dont even use them.

This are the basics to get you started.

Follow, Resteem and VOTE UP @kingscrown creator of http://fuk.io blog for 0day cryptocurrency news and tips!

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Nice post @kingscrown. I feel the same about keeping my private keys to myself. I use blockfolio too! I swear everyone has a motive lol. Thanks for the great post as always. Cheers.
Mark

If you want to continue using it while significantly minimising the risk of hackers taking notice of you, here is a solution for you:
https://steemit.com/bitcoin/@blockchainttmft/how-to-use-blockfolio-app-without-risking-losing-your-money

OMG blockfolio... I'm removing you right now... I feel so violated. I freaking loved this app. I was not concerned because i don't put actual tokens on there but this is just sad.

I'm in the same boat.. sepecially since I just re-balanced my holdings ¡Mierda DAMN!

Agree that everyone has a motive. You should always prefer open source project or a paid tool. You can checkout an alternative cryptocurrency portfolio manager like Cointracking which has both free and pad version.

i didn't use yet but info will bring me there.

Also, I've listed a few alternatives on this post. I used to be hooked up on Blockfolio as well. Regardless of how I feel about them, it's always good to have some alternatives !

Hi @oceancoinz, if you want to get rid of the commercial Blockfolio, I have written a simple and straightforward IPython Blockfolio.

Takes advice from 7 year old crypto king and unistalls the app.

Congratulations! This post has been upvoted from the communal account, @minnowsupport, by wayfaraway from the Minnow Support Project. It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, and someguy123. The goal is to help Steemit grow by supporting Minnows and creating a social network. Please find us in the Peace, Abundance, and Liberty Network (PALnet) Discord Channel. It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.

If you like what we're doing please upvote this comment so we can continue to build the community account that's supporting all members.

This comment has received a sweet gift of Dank Amps in the flavor of 21.84 % upvote from @lovejuice thanks to: @wayfaraway. Vote for Aggroed!

This comment has received a 3.16 % upvote from @booster thanks to: @wayfaraway.

I assumed this was how they were making money, using trade data. I still feel it's a useful app, just be cautious about putting buy and sell info into it.

Yeah, knowing this is only gonna stop me from updating my amounts. I still love the app.

The data provided to them is completely unreliable, anyone could enter $100m in some random coin and completely skew the data. The data is also after trades have been completed, this sort of data would be fairly hard to game.

I agree. I wouldn't necessarily let it worry me. But to be cautious, don't input all details on your blockfolio app. For example, I don't change what exchange I use to what's on my blockfolio that way there is less tracking, in a sense.

Whoaaaa! 😲😲😲
Nice 👍 pass @kingscrown
With the value of crypto and information... I've always suspected this a possibility.

Nothing surprising as you say but still kinda whooaaa wtf right?

Excellent tips and pointers on keeping things locked and tight.
And may I say, congrats on your 7th year in the space 🚀
😉😏😎

Stay well and Steem on kingscrown 🐳!

Blockfolio released a statement regarding this issue an hour ago:
https://www.blockfolio.com/june_30_privacy_statement.html

Good. Maybe they just got caught redhanded. Lol

It seems like a reasonable response. At least they reacted and fixed the major issues.

Are you saying that the data wouldn't be stored in a database on a centralized server anyway? B/c, if so, API calls don't mean anything. You'd be far better to data mine with SQL queries than send some kind of API call from the app itself.

right answer lol

Thanks for the heads-up. I have the Blockfolio app but haven't put any of my transaction info on it yet. Glad I found your post!
Do you know if cryptocompare.com might be doing this too?

I'm actuallying using coincap's app. its helpful!

I think it's safe to say, these kinds of things are rarely ever free. Your data is much more valuable then the cost of an app. READ THE FINE PRINT!

If its free.. you are the product!

Nice find. People in general are way too trusting with their private information. Especially financials is not something one should put in a random app.

Good advice on security too.

  ·  7 years ago (edited)

it look like fake Blockchain.info

Great post @kingscrown.🐱‍💻
Hope this inspires people to further secure their crypto😎

I would defiantly stay clear from Blockfolio. Burpsuite is a tool used for commonly used for web application penetration testing/hacking activities. A massive red flag

What alternative would you recommended for portfolio management? https://www.cryptocompare.com has a nice one but its not encrypted :(

I would also recommend using a unique password for everything markets, wallets, est. This can all be managed securely with password managers. Also think about running AV scans and auditing the machine you use. Cant be using a insecure machine :P

follow me @shifty0g

Seems like were a little off and they are clearing up the confusion

In order to provide better services and develop business products, we plan to analyze the data on our platform. To date, we have not made use of any of the data in any way. When we do, we will ensure the privacy of our users is a top priority.

Data is associated with device IDs, or hashed values, and is non-personally identifiable.

https://www.blockfolio.com/june_30_privacy_statement.html

Great write-up on this app. You got some good tips that will keep others safe. Been following you for a few days...

Thats not the way we wanna go. Wont use it pal ☢

Thanks a lot..safety first buddy...

A much better alternative to tracking your portfolio and investements is Cointracking.info (referral link). It's also much more advanced than Blockfolio and allows you to do all sorts of analytics on your investments.

Also, I've listed a few alternatives on this post.

spies everywhere you look..

Congratulations @kingscrown!
Your post was mentioned in my hit parade in the following category:

  • Upvotes - Ranked 7 with 552 upvotes

I was always a little fearful of using Blockfolio, I instead prefer to use a Google Sheets doc that uses APIs to get the most up to date prices. Here's an instruction article I wrote:

https://steemit.com/cryptocurrency/@jhcooper7/cryptfolio-the-utterly-amazing-portfolio-management-tool-you-ve-always-needed-coinmarketcap-com-api

Also, I've listed a few alternatives on this post. I used to be hooked up on Blockfolio as well. Regardless of how I feel about them, it's always good to have some alternatives ! I should include your Google Sheet alternative whenever I get the chance (currently uneditable)

Surely by using Google Sheets, you are making your financial data available to Google and possibly others? As the sheet is linked to your Google account, then you are personally identifiable, whereas with Blockfolio you are not. Seems a strange choice if you are worried about privacy.

Perhaps, but I trust Google with that more than some shady app developers. If i log into an exchange using Chrome I'm trusting them with that too, having a few numbers on a sheet isn't the greatest of my concern.

This post received a 1.5% upvote from @randowhale thanks to @kingscrown! For more information, click here!

feel free to check our simple app that works as crypto portfolio, it is very simple and we are not sharing your data, not even with our server, everything you create it will remain on your app.

check the link below:
https://steemit.com/technology/@sarkawt909/all-my-coins-android-app

Thank you for sharing this information. I just started using Blockfolio. Will be cautious what information I put in there

I've just downloaded Blockfolio today and just now came across this post. While reading the post I was thinking, there goes my app that can give me a good overview of bitcoins/altcoins value! Than I saw that Blockfolio came with a fast reaction which took my worries away. Thank God, because I had a long search before finally finding a good app on my phone to give me the right insights. Still have to give it a try, but this post won't keep me from using it.

Also, I've listed a few alternatives on this post. I went through the same you're going on right now, and it wasn't easy finding softwares for this purpose. Good research is always the way to go !

The best Folio app is
an Excell sheet you keep locally at your computer. :)

I have deleted that app two weeks before , I had some other issue, so I removed and not using it more.

Looks at blockfolio app running in the background...

memetry.png

what app would you recommend to use in its replacement?

yea this is what I want to know because blockfolio is extremely useful for me

OK I just thought about it and came up with two solutions:
If you want to continue using it while significantly minimising the risk of hackers taking notice of you, here is a solution for you:
https://steemit.com/bitcoin/@blockchainttmft/how-to-use-blockfolio-app-without-risking-losing-your-money

I put up a list of softwares and recommendations on this post. If you'd care to take a look !

yeah they shouldn't be want so much information, cryptocurrency is about completing transactions without any personal info!

Awesome tips. This is really important stuff!

just wants upvotes and didn't read post

You are right bro without keys cryptocurrencies are just like Delicious food in front of you and you cannot eat
🍇🍈🍉🍊🍋🍎🍏🍑🍒🍒🍏🍖🍗🍔🍟🍕🌭🧀🍞🌰🍄🍥🎂🍰🍡🍫🍬🍧🍨🍝🍜🌯🍳🍲🍿🍱🍘🍙🍣🍛🍮🍯🍭🍹🍺🍻

7 years? you must be a billionaire!

Love your post man.

How's your crypto portfolio looking? And what are your plans in the near future?

I will give you a follow :)

Awesome Post!

I'd be interested to hear how they would "snoop" on my positions since I never game them an API key. So anything they could "snoop" into would be stuff that I'd entered into the app itself, which is more complicated than necessary. I don't get the point, really.

Thanks man for the info!!!

What about Gravychain app?

Never tried, will check it

Also never heard of Gravychan, but I've listed a few alternatives on this post.

  ·  7 years ago (edited)

Thank you for posting this info. I will take a deeper look at it. Thanks for sharing.

I've never used Blockfolio, but i'll be sure to be safe if i do. Thanks for the info @kingscrown

I just heard about blockfolio, I might download it just to track prices myself, I wouldn't feel comfortable letting the world know my net worth in crypto (even though its not much). I like holding crypto offline in cold storage, used to have some paper wallets for ETH but I go really paranoid about it once I started buying a lot. Thanks for info.

Also, I've listed a few alternatives on this post. If you'd care to take a look !

I'm right there with you. Personally I love the app and use it regularly but have never inputted my account keys.

great post ! thank you so much

Great article, thank you for posting this. I am pretty much a noob in crypto world, and use my blockfolio way too often and look at it way too often haha, but I definitely to keep my coins as safe as possible.
Followed and upvoted!
Best,
@milanademort

If you can't find how you are paying for an app, you are usually paying with your privacy.

thnx nice post

  ·  7 years ago (edited)

Very informative article, re-esteemed! Blockfolio is really an awesome app and not using it makes problem for many traders. The thing is I truly believe in privacy and not being tracked but in many things specially trading convenience has an effect on the quality of your work. Any alternative?

@p0o, I've listed a few alternatives on this post. If you'd care to take a look.

Its not just blockfolio, most of apps on our phones is using our private data without our knowledge!

This is to be expected, but you are only telling half the story here. Aggregate data is pushed but no data to identify individuals. That being said, should their data be hacked one could surmise it could only lead to problems. Either way I think has become a mountain out of a molehill.

This is a great blog. It is really true to have your pricate keys safe. And just to add something. If you transfer coins to another account always double check or even triple check it if you are sending it to the right address. I go hacked before when I was transferring mine from blockchain to electrum because my computer had a virus. Damn

Thanks for looking out! I was just looking into this, great info to know.

best way

Here Is The Code For Calling Home

I deleted the app not too long ago ha! reason being was tht I couldn't get the app to work properly. I can't remember exactly the reason but yeah it's gone!

I enjoyed reading this, resteemed!
And thx f0r the link - https://traceless.me/en I've bn lkN f0r a gd VPN service ;)

nice ))

i will follow you and i hope you will follow me : )

Follow for follow doesn't provide value for anyone. Why not provide some value in your comment and then suggest that someone follows you, give them a good reason to follow you.

Thanks for the info. Appreciated!

is it safe to use blockfolio app ????

Good to know, thank for sharing! Great tips, keep your crypto coins safe everyone. Bye bye blockfolio...

@digicoins, I've listed a few alternatives on this post. If you'd care to take a look !

Wow I had no idea about this! I usually swear by Blockfolio and even use it to keep track of the amounts of STEEM and SBD I receive each day from Steemit. But of course, in this day and age, remote surveillance can happen anywhere and on any app. Thanks for raising awareness @kingscrown - I'll be a lot more careful from here on out!

I have been addicted to blockfolio the last 2 months. But will stop inserting my worth and actions at this time, cause of the info you just presented. Only use it to monitor the markets, and for "dip-alarms"

If you want to continue using it while significantly minimising the risk of hackers taking notice of you, here is a solution for you:
https://steemit.com/bitcoin/@blockchainttmft/how-to-use-blockfolio-app-without-risking-losing-your-money

That was an excellent idea, dividing it by a choosen Order. Nice one

After Wikileaks published the Vault 7 documents it should be clear to all of us, that there are many hackers and even more companies using this backdoor spying on us.

Data sets are the new gold; to know your customer's habits and what he's doing next - means lots of cash for the players who are all in.

Cheers... - Brave New World Order!

wow this is scary stuff but couldn't you input any random number of coins into your folio so how can they verify the integrity of the data

Interesting information!

Oh the dreaded push notification, I've got some $500 phone bills over those before

useful info, all the time, thanks for this sharing, nice article followed.

Thanks for your warning and the tips at the end of post.

I've been using Coincap for a while now. I'm pretty sure it's from the folks that made shapeshift. Does anyone know if this is doing the same?

I'm not, but I've listed a few alternatives on this post. If you'd care to take a look !

Blank.

Thanks for the needed information!

I just had it to see the price moves in a manner I was accustomed to .. Now: DELETED. Thanks for the post exposing yet another shady player.

Thanks for the heads up and advice on keeping our info safe.

I just downloaded it and what do you mean by what you just said

Once again thanks for the info. The amount of crypto's are exploding so the scope for abuse increases as well. Chur

Interesting, never thought about this possibility.

I am not using Blockfolio, but i assume its the same with all similar apps

Re to all this so any great information is really appreciated, thank you!⭐️

  ·  7 years ago (edited)

That's the problem i have with most exchanges. There is no wallet for all these coins. Most popular wallets like Exodus or hardware one's like Trezor only allow you to store 5-6 of the most popular coins. So when you want to buy coins that are not included in these wallets you are forced to hold them on exchanges. That's when problems can happen. Myself had a few issues with some exchange, Poloniex not to name it. When it's time to withdraw those alt-coins you ran into problems. I don't know if you ever had to deal with customer service on a site like poloniex but let me tell you, you don't want to have to deal with them. Just go on Reddit and looks for Poloniex and you'll see the true picture. Anyway the point is, keep your coins safe. It's like silver, if you don't hold it, you don't have it.

Excellent work! Thanks for posting!

Need to be careful! Yikes. I have blockfolio! It's where I track all my small coins! Check out my small coin strategy. Hot trending article on steemit!

https://steemit.com/cryptocurrency/@jrose1010/the-small-coin-strategy-potential-to-make-hundreds-of-thousands-maybe-millions

  ·  7 years ago (edited)

Conniving little bastards. This way one can manipulate market easily... This sort of "services" should be exposed, just like you did, thank you!

Yes! Every tech company is trying to track your every move from the empires of Google and Apple to these small cyptocurrency apps,

@kingscrown if you want to see how much you earn compared to other jobs, I mentioned you in my latest post :)

Yeah man..couldn't agree more. I read something else last week about this so never got into it. Much better alternatives. Thanks for reinforcing what I already thought!

Also, I've listed a few alternatives on this post. If you'd care to take a look !

I just got a Exodus wallet today. So far so good. Thanks for this.

I really like your post @kingcrown. What is the alternative do you suggest personally? I wrote this post on my blog last week: https://chesatochi.com/software-monitoring-crypto-investments/

Nice post @kingscrown

I just use it to watch prices and set alerts, but I will uninstall. I keep my trades on a spreadsheet like a boring person haha

I have it installed on my phone tracking my crypto portfolio. Everyone is doing it from Google to Facebook they sell or use your data in their own ways. Primarily Facebook use the data to sell on to advertisers.

That's one of the main benefits of the decentralized economy ! ;)

Own your data !

This is why I don't give third-party apps (which can include Coinigy, etc) WRITE access to exchanges. You don't know what they could be doing.

whats wrong with them knowing your coins location? that they will know anyway. you need to send that info to get portfolio value info back...

I suspected the CoinCap app of doing the same thing! Don't let ANYONE know how much you have!

So today morning blockchain sent the request to update their app. Wondering what?? Updates they've made

Thanks for the info! Usually dont trust stuff like this, but had good reviews. What are your thoughts on coin tracker? Similar situation?

Also, I've listed a few alternatives on this post. I give all of them a review. As far as I know coin tracker is fine !

Great post

Nice post! I followed you

Great info for a newbie like me.Have to keep one’s guard up.

Thank you @kingscrown for planting a seed in my mind as a newbie that I need to re-evaluate some things. Knowing you're 7 years into this journey gives me pause with my own security choices. This new shift in my thinking is going to keep me up at night while I try to sort it all out. Do you ever get on Steem Chat? I am dying to ask you a question I feel silly asking on a public forum.

Honestly I think they kinda deserve this data for providing such a cool app.

As the saying goes 'if its free you are the product'