Bitcoin Forum

Economy => Service Discussion => Topic started by: cakir on April 06, 2015, 11:13:44 PM



Title: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: cakir on April 06, 2015, 11:13:44 PM
If a user wants to change payout address on a campaign you should ask for a signed message with old address.
That prevents users funds from hacking. Let's say X hacked some hero member's account on a signature campaing who earned 0.15 BTC in a week, and X comes to thread and says "hey please change my address to that one". If the campaign manager don't ask for signed message that Hero member will loose that money.

I'm asking to the campaing managers to consider that condition.

Ps: I've posted this suggestion on the Dadice campaign (https://bitcointalk.org/index.php?topic=973949.msg11004253#msg11004253), posting here for more publicity.


Title: Re: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: Quickseller on April 07, 2015, 01:50:13 AM
This is how evil panda handled address changes. It also keeps the campaign manager accountable as they have documentation as to why they sent payment to specific addresses. People should be able to freely change their payment addresses at the start of a payment period though


Title: Re: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: dznuts85 on April 07, 2015, 10:10:07 AM
If a user wants to change payout address on a campaign you should ask for a signed message with old address.
That prevents users funds from hacking. Let's say X hacked some hero member's account on a signature campaing who earned 0.15 BTC in a week, and X comes to thread and says "hey please change my address to that one". If the campaign manager don't ask for signed message that Hero member will loose that money.

I'm asking to the campaing managers to consider that condition.

Ps: I've posted this suggestion on the Dadice campaign (https://bitcointalk.org/index.php?topic=973949.msg11004253#msg11004253), posting here for more publicity.

I think this is already in cycle and most of the campaigns doesnt accept changes of payment address until the payment is made for the current week or month


Title: Re: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: TheGame on April 07, 2015, 12:36:53 PM
I guess you can't really force people to do this but it's definitely a good idea. I've seen several campaigns require some proof from an old address but also a few that don't care but I guess it's just up to each campaign manager individually whether they do or not.


Title: Re: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: redsn0w on April 07, 2015, 12:40:38 PM
If a user wants to change payout address on a campaign you should ask for a signed message with old address.
That prevents users funds from hacking. Let's say X hacked some hero member's account on a signature campaing who earned 0.15 BTC in a week, and X comes to thread and says "hey please change my address to that one". If the campaign manager don't ask for signed message that Hero member will loose that money.

I'm asking to the campaing managers to consider that condition.

Ps: I've posted this suggestion on the Dadice campaign (https://bitcointalk.org/index.php?topic=973949.msg11004253#msg11004253), posting here for more publicity.


If I can say my opinion: I support your idea and this is a normal use of bitcoin (signed message) so why shouldn't we use it? However to control if someone has change password (through email or directly) check here https://bitcointalk.org/seclog.php and it will be more souspicious if he change the payout address after that the password was changed.


Title: Re: [SUGGESTION] To The Signature Campaign Managers - Payout Address Changes
Post by: robbo389 on April 07, 2015, 06:07:35 PM
Some campaigns ask you to put your address in your profile page and don't pay if you change or remove it. A hacker controlling someone's account could not divert those funds to himself.