Bitcoin Forum
July 05, 2024, 04:41:24 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 [7] 8 9 10 11 12 13 14 15 16 17 18 »
121  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NXT] Nxt - Official Thread on: June 13, 2014, 03:46:07 PM
1000 million coins invented out of thin air, thats a shit heap . How the fuck can you sleep noing this shit is a scam............

Define the scam property of Nxt. Where are people scammed?

Not sure if this is relevant, but scam spelled backwards is Macs, which is proof that Apple is a scam.. Did you ever notice that you have to replace computers regularly? SCAM! Don't eat apples to protest the backwards scam inherent in Macs (or at least boycott Macintosh apples, the rest may be okay but I'd still be suspicious- I heard they got worms - the kind that send emails to all your friends.. Oh, and I heard Tim Cook had mono once, so stay away from him too.)
122  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NXT] Nxt - Official Thread on: June 13, 2014, 02:05:35 PM
I just downloaded a new client last night -- the recommended client from http://www.nxtclient.org/.

Had to wait for blocks to update before I could transact.. Feel free to PM me if you need to get in touch - can provide all the TXIDs etc / any other details.. I hadn't touched that balance since 2013, so it was sent to an old numeric account, before the switch over.. I was assuming that it wasn't considered an effective balance because it had no activity prior to a fork and somehow got 'archived', so I figured bouncing it off another address would help wake it up.. Wasn't going to be generating many blocks with it, but again - my NXT balance was more an experiment for me than an investment. Again - PM me if you need to get in touch, too many threads to follow all of them closely Smiley
123  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NXT] Nxt - Official Thread on: June 13, 2014, 01:35:55 PM
Ugh... Are you kidding me? Are there bots prowling the network with a boatload of password-account combinations stored watching the for transactions to known addresses or something?

I got some NXT a long time ago and kept it tucked away, but with the updated client it seems I didn't have a public key, so I sent a message.. easy enough... my balance was there, but I couldn't forge because it was unconfirmed... so I figure this has something to do with old balances being 'unconfirmed' under the updated protocol until it's seen activity.. So I flip my NXT into another account that I used in the past (tx 3603756272827733121), wait for it to confirm, and as soon as it does the NXT has moved on to an account out of my control (tx 10738856805317237622)...!!!

WTF? I sat here waiting for a confirm to flip it right back, and it vanishes before my very eyes! We're talking within 2 seconds of the first confirmation!

If the network is this compromised, how do you ever expect mainstream adoption... I've had an eye on NXT since the beginning and was really into the new look and feel, the asset exchange, etc.. My interest was building in NXT again (initially less than impressed by the distribution, but it seemed a lot of great work had gone into the protocol..) Too bad.. Nxt looked cool, but as it stands I'm out.. Not sure that this can be called a 2nd generation crypto when it's this vulnerable to theft. I'd say the target audience is even more specialized than bitcoin; the average joe can hardly remember "Password1"!

Sorry for your loss.  Can you share the password of your second account?  I also find it weird that someone compromised your account that fast.

I would rather not share my 'passphrase' or unique key or whatever you want to call it because it has elements of a common password that I use for low security purposes (i.e. one-use account on random forums). It was admittedly a meager 21 chars including dictionary words and spaces.. Much better than a laymans password but not the level of security I usually use (thus why it was a depreciated account/wallet). I haven't been in that account for about 4-5 months and was just using it to bounce my nxt to see if that would get it properly recognized (effective balance was 0 despite having NXT).

The thing that concerns me is that the transaction occurred within 2 seconds of the first confirmation.. It's not like I left nxt sitting around in an unsecure account, this was just a brief bounce to try to 'reactivate' my nxt.

The amount is irrelevant in this case - about 250 nxt (all I had), but the fact that it was so rapidly snagged is concerning to say the least.. it made me realize a major flaw for NXT and the layman.. A bot can easily collect a massive list of  account keys and related 'security phrases' via brute force (offline so it's undetected), store these, and watch the blockchain for transactions to accounts that fall within it's dictionary, then instantly log in and with bot-like speed, snipe those NXT on the first transaction...


One simple question: If you google your password (with the quotes "" , i.e " blah blah my pass") , how many hits do you get?

If it's in thousands you just as well post it here and change your other password

Quote
The thing that concerns me is that the transaction occurred within 2 seconds of the first confirmation.. It's not like I left nxt sitting around in an unsecure account, this was just a brief bounce to try to 'reactivate' my nxt.


That's because the hacker had pre calculated the hash for it as it well known password already in his database. When his computer saw the transaction to that account, it did immediate transaction in 2 seconds.


Clearly the pass phrase was in his database. Googling it provides just over 10,000 results, though most include other punctuation. Admittedly more than I expected, but at 21 chars it's still a hell of a lot better than an average joe's "password1". Again - I figured a couple minutes would be safe - more concerned about barriers to usability for the layman than the paltry sum of NXT lost. Wasn't going to take over the world with 250 NXT, it was really just to play with and get a feel for the system / participate in some way.



... (effective balance was 0 despite having NXT)...

Relating to this, your effective balance can be thought of as your forging balance. To forge, you need to wait for 1440 confirmations (roughly 1.5 days).

Until you get 1440 confirmations, effective balance remains at 0 no matter how many Nxt you have in the account. Had you just moved it when you saw this?

(I could probably check most of this on the blockchain but can't right now)


That NXT had been sitting in my wallet since 2013.



Yes, there are Bots monitoring the blockchain for transactions related to accounts with weak passwords.

****
Bots

A Bot in general is an automated computer program. In the case of Nxt, the bots have been programmed to find the account numbers to all accounts associated with Weak Passphrases (such as ‘Dog’, ‘12345’ and ‘opensesame’). They continuously scan the Blockchain looking for Transactions happening in these accounts. Once a Transaction is detected, the Bots then automatically log into the account and move the NXT to an account they control. This often only takes a matter of minutes from the transaction into the account and nothing can be done to retrieve the stolen NXT. It is therefore VERY IMPORTANT to use a Strong Passphrase to ensure that your NXT is not stolen. Also see Brainwallet.

****
Source: Nxt Glossary >>> https://wiki.nxtcrypto.org/wiki/Glossary

Allowing people to use weak passwords was a flaw, client's now create strong diceware passwords for users (you can still enter any password you want but there are extra steps). Sorry for you loss, I'll send you 250 NXT when I get home if no one else has done it before me, just post the address you want it to go to.


We're talking about a 21 char password - not 'dog' or 'opensesame', more like 'dog opensessame 12345'. I moved away from it BECAUSE it was unsecure, but figured it was secure enough for a quick bounce of NXT. Clearly a bad call on my part, didn't expect that bot exploitation was nearly that bad.

I appreciate your offer Daedelus, and will take you up on it.. Moving over to NXT-ZNL5-2A7Q-G5GJ-7K4SX.. I've always had an interest in NXT, would love to see it thrive despite my personal lack of NXT, but I see some serious barriers to broader adoption.. LOVE the asset exchange, and would love to see live web portals, though that brings a slew of new security concerns along with it.. The benefit of the passphrase is portability, but the down-side is security.. Always hard to find a balance between usability and security, and I certainly hope NXT can find that balance Smiley

Cheers
Z
124  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: June 13, 2014, 01:31:43 PM
I see difficulty as 3.35, but no block found in 30+ hours... something ain't right.

Last block was 290450 -- a rounded enough number that it looks like a bug in the codebase.. Something tells me we won't see any more Meow without a hard fork (well, technically not hard considering that the blockchain appears to be frozen).. How many lives does Kitteh have left at this point? :p
125  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NXT] Nxt - Official Thread on: June 13, 2014, 12:38:45 PM
Ugh... Are you kidding me? Are there bots prowling the network with a boatload of password-account combinations stored watching the for transactions to known addresses or something?

I got some NXT a long time ago and kept it tucked away, but with the updated client it seems I didn't have a public key, so I sent a message.. easy enough... my balance was there, but I couldn't forge because it was unconfirmed... so I figure this has something to do with old balances being 'unconfirmed' under the updated protocol until it's seen activity.. So I flip my NXT into another account that I used in the past (tx 3603756272827733121), wait for it to confirm, and as soon as it does the NXT has moved on to an account out of my control (tx 10738856805317237622)...!!!

WTF? I sat here waiting for a confirm to flip it right back, and it vanishes before my very eyes! We're talking within 2 seconds of the first confirmation!

If the network is this compromised, how do you ever expect mainstream adoption... I've had an eye on NXT since the beginning and was really into the new look and feel, the asset exchange, etc.. My interest was building in NXT again (initially less than impressed by the distribution, but it seemed a lot of great work had gone into the protocol..) Too bad.. Nxt looked cool, but as it stands I'm out.. Not sure that this can be called a 2nd generation crypto when it's this vulnerable to theft. I'd say the target audience is even more specialized than bitcoin; the average joe can hardly remember "Password1"!

Sorry for your loss.  Can you share the password of your second account?  I also find it weird that someone compromised your account that fast.

I would rather not share my 'passphrase' or unique key or whatever you want to call it because it has elements of a common password that I use for low security purposes (i.e. one-use account on random forums). It was admittedly a meager 21 chars including dictionary words and spaces.. Much better than a laymans password but not the level of security I usually use (thus why it was a depreciated account/wallet). I haven't been in that account for about 4-5 months and was just using it to bounce my nxt to see if that would get it properly recognized (effective balance was 0 despite having NXT).

The thing that concerns me is that the transaction occurred within 2 seconds of the first confirmation.. It's not like I left nxt sitting around in an unsecure account, this was just a brief bounce to try to 'reactivate' my nxt.

The amount is irrelevant in this case - about 250 nxt (all I had), but the fact that it was so rapidly snagged is concerning to say the least.. it made me realize a major flaw for NXT and the layman.. A bot can easily collect a massive list of  account keys and related 'security phrases' via brute force (offline so it's undetected), store these, and watch the blockchain for transactions to accounts that fall within it's dictionary, then instantly log in and with bot-like speed, snipe those NXT on the first transaction...

I really don't see any other way this could have happened.. I was working on something else and came back probably 3 minutes after the block to see the nxt was gone - sent to a so-far unused account. The vulnerability is human error, and seeing as you're looking for humans to use this system, I'd call that a pretty big barrier when it comes to user adoption.. I'm an IT business analyst by trade and that just doesn't fly for me - NXT has a lot of great things that Bitcoin does not, but at the end of the day, it's harder to steal someone's bitcoins because you basically have to steal their wallet.dat whereas with NXT you just need to figure out their passphrase..

In this case the theif used NXT-X6AP-V3S7-RBHA-GQW8Z, which I'm sure will see no activity for some time before it goes through a wash.. I remember from the get-go there were countless issues with theft, looks like this has gotten worse. Enough to scare me off NXT. GL.
126  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NXT] Nxt - Official Thread on: June 13, 2014, 03:25:15 AM
Ugh... Are you kidding me? Are there bots prowling the network with a boatload of password-account combinations stored watching the for transactions to known addresses or something?

I got some NXT a long time ago and kept it tucked away, but with the updated client it seems I didn't have a public key, so I sent a message.. easy enough... my balance was there, but I couldn't forge because it was unconfirmed... so I figure this has something to do with old balances being 'unconfirmed' under the updated protocol until it's seen activity.. So I flip my NXT into another account that I used in the past (tx 3603756272827733121), wait for it to confirm, and as soon as it does the NXT has moved on to an account out of my control (tx 10738856805317237622)...!!!

WTF? I sat here waiting for a confirm to flip it right back, and it vanishes before my very eyes! We're talking within 2 seconds of the first confirmation!

If the network is this compromised, how do you ever expect mainstream adoption... I've had an eye on NXT since the beginning and was really into the new look and feel, the asset exchange, etc.. My interest was building in NXT again (initially less than impressed by the distribution, but it seemed a lot of great work had gone into the protocol..) Too bad.. Nxt looked cool, but as it stands I'm out.. Not sure that this can be called a 2nd generation crypto when it's this vulnerable to theft. I'd say the target audience is even more specialized than bitcoin; the average joe can hardly remember "Password1"!
127  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NEM] NEM -New Economy Movement - No Envy Movement - Updates+Discussion thread on: June 12, 2014, 09:08:09 PM
my 2 cents:
1. Nothing has changed with nem, this is simply the credibility of the front man. Could be catastrophic if he has access to NEM assets and exploits that or if he turns this into a campaign against NEM, but so far neither of those have happened. For now I think people are over reacting.
2. I've watched NEM for a long time. I have always been impressed by the community engagement. Nothing has changed there.
3. it is without question that UP has made significant contributions. Man has grappled with greed for eons, and it appears that it may have gotten the best of him. This tarnishes his record, but does not undo the wealth of positive contributions he has made. As it stands, in the name of fairness, I still believe that he should be rewarded for his efforts. That said, his actions may merit some penalty to that reward.

finally, gorilla, dude, you make some valid arguments and I appreciate the variety that those views add to the discussion, but please try to be civil and respectful. Some of your posts serve to undercut your legitimate concerns and opinions.

Cheers,
Zachamo
128  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [PRE-ANN] Syscoin - Business on the Blockchain on: May 26, 2014, 01:50:07 PM
a re-read through the description makes me think of etherium.  Neat if you can pull off some of the key selling points of that project before it comes to fruition. for the market, it would be neat if a name coin style DNS alternative had an embedded marketplace with escrow.. you could built something like eBay right in the blockchain.. Keeping it simple would more easily breed mainstream adoption.. Not just a framework on which a market can be built on, but a built in market..

good luck!
129  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: May 08, 2014, 10:15:08 AM
I'm wary of the input-based leadership model... Heck, why not have a voting system based on how much MEOW someone has? I see the intention, but it stands to give some jobless kitteh full control over the direction of the coin, no?

Now for your moment of Meow: http://www.buzzfeed.com/expresident/best-cat-pictures?bffb
130  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [NEM] NEM -New Economy Movement - No Envy Movement - Updates+Discussion thread on: May 07, 2014, 06:52:37 PM
Seems there haven't been any github commits in 2+ months..? No github expert, but that seems odd doesn't it?
131  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: May 05, 2014, 05:18:14 PM
My thoughts as a sideliner / longstanding member of the Kitteh community:
- Don't discourage people who are trying to help.
- Discourse is worthwhile and speaking out when you don't agree with something is good, but try to avoid being offensive or overly direct (Who the hell are you and what makes you think you're so high and mighty!!!???)
- Collaboration is key!
- A central leader is great, though not really necessary. Leadership can be broken out into areas and governed by general consensus.. Open Source doesn't require the kind of democracy that's implemented in politics (which is kind of a false democracy as it is), nor does it require authoritarianism.. Open Source evolves as it grows, both in terms of the software and the infrastructure, social structure, and people behind it.

My own take in terms of leadership:
- responsibility should be broken out into areas -- Marketing, Development, Community Engagement, Charity, Collaboration (across leadership silos) etc.. There should be an even number of these roles and an individual responsible for each area. All of these people should be considered equals and each of them would be leaders in their respective area. Some will need to collaborate more closely than others.

Benefits to this approach:
- Lower risk of burn-out
- Lower correlation between KittehCoin and an individual (if they run a scam, back-out, or nude pictures surface, Kitteh's reputation isn't as directly tied to them)
- Higher degree of collaboration
- More focus and attention in the most important areas
- More people to approach with ideas / concerns / questions etc
- More consensus for important decisions
- More transparency on the leadership team on who is doing what, who is responsible for what, and who to talk to for what.

Dano & the leadership team already worked on the framework for this, the next step is to discuss and finalize it (perhaps capture the roles, expectations, etc in a little write-up), get people into those roles, and work out the tools for collaboration across this leadership team and the broader community.

I like the enthusiasm that I'm seeing here. I was worried for awhile there when the post count dropped to minimal, there was little but FUD and blind faith, and no one was talking about useful / important things in any relevant manner.

Wish I had the time to step up, but alas - all I am is a proverbial old man of questionably sage advice Smiley
132  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 18, 2014, 01:38:07 PM
no time to post much other than this:
the Dev team has been fantastic. you can't code community support, and they asked for marketing help on several occasions but nothing solid ever materialized. playing the blame game, pointing fingers, and claiming you could have dome better is not only unproductive, it's counter productive.

Don't be counter productive. I applaud the outstanding efforts of the team that was voted best coin Dev team, and while whole a lot more could have and can be done, there is no blame but for the blame on every kitteh out there who did not step up (including myself). it's easy to criticize, much harder to contribute. Blame the criticizers for not contributing, not the contributors.

Dano didn't start this coin and did an amazing job of picking it up and running with it. I'm actually impressed that he stuck with it as long as he did, which is notably much longer than the original Dev did. Sad to see him step back, but only sad because of the talent and commitment from both him and the rest of the Dev team, not because I feel they took this coin the wrong direction or underdelivered. Dano took on too much in becoming the central figurehead behind the coin, primary medium of communication, and the lead developer. with the lack of gratitude the Dev team has seem, who can blame him and all of them for burning out? Hell, there would be a risk of burnout if they were being paid handsomely, and they did it all in their free time for a handful of nickels at best..
133  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 14, 2014, 06:55:04 PM
Not sure what you expect -- daily updates from the devs? If this was some sort of major corporate project, weekly projects would be a reasonable expectation, but we're lucky we get the updates we do for a side project done in dev's free time!!

Look to Twitter, Reddit, and IRC if you want to keep up to date, that's where the more productive conversations are happening -- seems this thread has just been hijacked by FUD and market speculation..  Undecided
134  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 04, 2014, 07:18:31 PM
135  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 04, 2014, 03:23:49 PM
Looks like Dano's return has restored some confidence to the markets -- moving up.
136  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 02, 2014, 04:19:31 PM
The dev team is probably sitting back and hoping the community will pick up the slack.. Instead, everything went quiet.

As for the buy wall, I think that's there to a) get cheap coins and b) support SOMEONE ELSE'S push on the price.. I don't think the whale will bring up prices themselves; they're just providing the conditions to bring prices up, hoping someone else will actually do the buying. they probably already have a ton of Meow and are looking to sell it at a higher price, but looking for someone else to pick up the buying trend.
137  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: April 01, 2014, 04:26:31 PM
138  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: March 31, 2014, 07:31:58 PM
Why can't I, for once in my life, make some money off investing?  Cry

because you don't have a crystal ball ...

btw can buy MEOW in prelude.io with fiat.. ! don't have to go through bitcoin
in coinedup its too bad they removed MEOW/LTC..  LTC is also traded vs fiat without need for BTC

I have a crystal ball, but sadly it doesn't seem to do much for me.. Maybe I just don't know how to turn it on?
139  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][MEOW] KittehCoin Relaunch IS HERE!!!! on: March 29, 2014, 12:52:33 PM
I am with kitteh from the begining. I don't like posting in forums but i can no longer remain silent because I like this coin. But I think that this coin is going to die. Why? Because every day this coin is getting less and less support from everywhere. I always thought that the strongest part of this coin is development. But now I think this coin has no support even from development. Since the beginning of February i can see only Dano some annuoncments about big features like merged minning, zero coin and so on without any result or real timelines. But the last think that make me disappointed with develompent was announcment about Donation to get Meow on Mintpal. It say "... is about 780 votes! That is much more than we'd ever generate trying to vote every day with the limits and such." It is strange announcement from developer. I am not web developer but it took me about 2-3 hours to make small program to vote every hour on MintPal for meow.  It is about 120 votes daily from one account. Just spread it though all team of meow and you will have much more votes without any donations. Without real management and development support this coin will die soon... Because it is the same as other shitcoins on the market...

0 activity 1 post

haz credibility!  Cheesy

+
lol.

Looking at his words and not his post count, I'd say he may have credibility folks.. he also makes a good point.
140  Economy / Scam Accusations / Re: [Suspect Scam] nmc-wallet.com on: March 27, 2014, 09:22:52 PM
Same host and platform as instant-e.com -- it's a scam.
Pages: « 1 2 3 4 5 6 [7] 8 9 10 11 12 13 14 15 16 17 18 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!