Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: light888 on January 24, 2014, 07:08:20 AM



Title: NXT stolen
Post by: light888 on January 24, 2014, 07:08:20 AM
I only have 3 NXTs in my wallet and they are transferred to this address 10411181763421717624.
It is not much NXTs but I have absolutely no idea on how it got stolen.
Link to my address: http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=14639139826719190448 (http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=14639139826719190448)

I have never sent any NXT to anyone or any exchanges. Having troubles syncing my wallet, I looked up the blockchain, only to find that it
was transferred to this address somehow. My computer is with me all the time and I have a fairly secure password.

The point here is that NXT is not secure as it seems and can be easily compromised. I was trying to get started with NXT and was a believer of NXT until now, I have no idea how it happened but I will investigate more and will update on this matter. If anyone with similar experience or any solutions, I will appreciate your insights. I am trying to assume that I have downloaded malware that steals NXTs but so far my files are clean.

Any thoughts?


Title: Re: NXT stolen
Post by: ak84 on January 24, 2014, 07:16:59 AM
What was your password?


Title: Re: NXT stolen
Post by: light888 on January 24, 2014, 07:30:59 AM
What was your password?

10 chars, combination of alphabets, numbers and symbols.
Possible brute force attack but I would like to know how is it done. If the attacker has access to my network and PC then I need to do something about it. If it is just some sniffing and cracking passwords then I'd say that it is not that secure comparing to Bitcoin.


Title: Re: NXT stolen
Post by: ak84 on January 24, 2014, 07:34:35 AM
I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.


Title: Re: NXT stolen
Post by: digit on January 24, 2014, 07:38:55 AM
10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


Title: Re: NXT stolen
Post by: light888 on January 24, 2014, 07:52:04 AM
I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. :)

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?


Title: Re: NXT stolen
Post by: extee on January 24, 2014, 08:08:25 AM
it says clearly that the passpharse should be at least 30.
if you made a passphrase of only 10 charchters long it's your own fault . nothing to do with NXT.


Title: Re: NXT stolen
Post by: BCFrictionless on January 24, 2014, 08:12:10 AM
I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

why not check out 3RD GENERATION Frictionlesscoin https://bitcointalk.org/index.php?topic=429478.0
NXT IS JUST A STEPPING STONE TO FLC


Title: Re: NXT stolen
Post by: light888 on January 24, 2014, 08:19:27 AM
I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

Seems like trolling. A password for NXT should look like this

yx^Ffk]?Hn:dBDqNb/MuMV66sKR%C;dRxZ}WFu,gQrR,64XmuneYt>sj;ba#e{Kz*7XFN38@MHbX^NRgFt$kz)NZ&RRd4pNLXHHV

THE PASSWORD IS YOUR ACCOUNT/ WHO WOULD BE SO STUPID TO CHOOSE 10 CHARS?



However/why not check out 3RD GENERATION Frictionlesscoin https://bitcointalk.org/index.php?topic=429478.0

I am not trolling, but you sir are trolling.

it says clearly that the passpharse should be at least 30.
if you made a passphrase of only 10 charchters long it's your own fault . nothing to do with NXT.


Yes it is my fault for setting an insecure password. But I do not see what you said about passphrase length in the client.


Title: Re: NXT stolen
Post by: relgub on January 24, 2014, 08:22:22 AM
I have an extreme password. I received 3 nxt from a faucet and the transaction appeared in the unconfirmed transactions part of my wallet.
But the 3 nxt never made to my transactions.  Why is that?

This wallet doesn't seem to work. Needless to say my address is the same and I haven't changed the password.


Title: Re: NXT stolen
Post by: instacalm on January 24, 2014, 08:24:38 AM
I have an extreme password. I received 3 nxt from a faucet and the transaction appeared in the unconfirmed transactions part of my wallet.
But the 3 nxt never made to my transactions.  Why is that?

This wallet doesn't seem to work. Needless to say my address is the same and I haven't changed the password.

Check your balance: http://87.230.14.1/nxt/nxt.cgi?action=100 / http://www.mynxt.info/blockexplorer/

Perhaps your client's blocks are/were not synced with the network.


Title: Re: NXT stolen
Post by: digit on January 24, 2014, 08:27:12 AM
I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. :)

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?

NXT requires a complete change in thinking.  There is no wallet.dat to protect. The passphrase/password is the same as the privatekey in bitcoin type cryptos!  Entering that passphrase in NXT wallet is like importing a privatekey into a bitcoin wallet.  
The more complicated your passphrase the more secure your NXT will be, and like privatekeys in bitcoin each passphrase equals one unique NXT address.  

More information on security for NXT can be found here http://wiki.nxtcrypto.org/wiki/Account_Security


Title: Re: NXT stolen
Post by: Snail2 on January 24, 2014, 10:02:20 AM
A 10 char alphanumeric password is clearly too short. However OP has a good point about Average Joe who used to choose quite simple passwords.


Title: Re: NXT stolen
Post by: jason006 on January 24, 2014, 11:38:56 AM
the same to me
i have 2NXT got from the beginning i open an occunt
but one week later,it disappeared


Title: Re: NXT stolen
Post by: FrictionlessCoin on January 24, 2014, 11:41:13 AM
10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


Likely brute forced if 10 characters.


Title: Re: NXT stolen
Post by: FrictionlessCoin on January 24, 2014, 11:42:42 AM
I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. :)

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?

NXT requires a complete change in thinking.  There is no wallet.dat to protect. The passphrase/password is the same as the privatekey in bitcoin type cryptos!  Entering that passphrase in NXT wallet is like importing a privatekey into a bitcoin wallet.  
The more complicated your passphrase the more secure your NXT will be, and like privatekeys in bitcoin each passphrase equals one unique NXT address.  

More information on security for NXT can be found here http://wiki.nxtcrypto.org/wiki/Account_Security

Exactly.  Been screaming about this.  It is just insane.   You can collect all the addresses by reading the chain,  then you run a brute force to see if any matches the chain.

It is crazy!!


Title: Re: NXT stolen
Post by: QNX on January 26, 2014, 03:13:01 AM
Bastard 10411181763421717624 also stoled my 54 nxt, password was long ыbought, but only from digits 16 chars :(


Title: Re: NXT stolen
Post by: anderl on January 26, 2014, 03:14:22 AM
Avoid NXT.


Title: Re: NXT stolen
Post by: cryptohunter on January 26, 2014, 03:27:42 AM
yeah nxt is like someone already having your wallet infront of them with unlimited time and chances to crack your account.... sadly a good gpu farm will rape most passwords in a matter of days unless it is way longer than 10 digits. I bet on the way to your account he cracked a few others too.


Title: Re: NXT stolen
Post by: samysamy1 on January 26, 2014, 03:35:03 AM
Bastard 10411181763421717624 also stoled my 54 nxt, password was long ыbought, but only from digits 16 chars :(


Where and when did you download the last update of the client?


Title: Re: NXT stolen
Post by: Nullu on January 26, 2014, 03:37:01 AM
Why should security be the sole responsibility of the account holder? If my house got broken into I wouldn't expect people to blame me for not storing my wallet in a safe.

Nor would I expect my bank to let someone crack my credit card pin and not alert me something was up.

Madness.


Title: Re: NXT stolen
Post by: Armando on January 26, 2014, 03:50:12 AM
Why should security be the sole responsibility of the account holder? If my house got broken into I wouldn't expect people to blame me for not storing my wallet in a safe.

Nor would I expect my bank to let someone crack my credit card pin and not alert me something was up.

Madness.

So, if your house will be broken, you will blame doors manufacturers, because the cheapest doors are not secure enough? I feel sorry for people who had their NXTs stolen, but I don't think that it's developers fault.


Title: Re: NXT stolen
Post by: FrictionlessCoin on January 26, 2014, 11:17:00 AM
Why should security be the sole responsibility of the account holder? If my house got broken into I wouldn't expect people to blame me for not storing my wallet in a safe.

Nor would I expect my bank to let someone crack my credit card pin and not alert me something was up.

Madness.

So, if your house will be broken, you will blame doors manufacturers, because the cheapest doors are not secure enough? I feel sorry for people who had their NXTs stolen, but I don't think that it's developers fault.

I think in this case,  the developer is partly to blame.

Bitcoin public / private keys have been quite secure for 5 years now.

But the developer of Nxt decides to come up with his own novel strategy that encourages accounts from being hacked.  Nxt is likely the only crypto currency where you routinely hear people complain about their individual wallet being hacked.   The inside joke is that you can mine Nxt wallets using GPU farms.

Anyway,  NEX already has made the necessary code changes to use bitcoin technology rather than the flimsy one used by Nxt.  Consider NEX like 'industrial strength Nxt'.


Title: Re: NXT stolen
Post by: QNX on January 26, 2014, 02:12:40 PM
Bastard 10411181763421717624 also stoled my 54 nxt, password was long ыbought, but only from digits 16 chars :(


Where and when did you download the last update of the client?
from here https://nextcoin.org/index.php/topic,2041.0.html