Bitcoin Forum
July 01, 2024, 05:24:37 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 [660] 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 ... 1160 »
13181  Bitcoin / Bitcoin Discussion / Re: WARNING - Coinomi Wallet CRITICAL Vulnerability Made Me Lose My Life Savings on: February 27, 2019, 04:38:36 AM
sorry about your losses, it really sucks.

i have never used any wallet on my phone so i don't really check these things but interestingly enough coinomi GitHub doesn't seem to be updated for more than 2 months[1] which makes me wonder whether their wallet is even open source because that is the first thing i checked after reading your topic, i wanted to see where the bug was and whether it was fixed or not (specially since this type of bug is so weird and obvious!). it seems like they have released a new version (yesterday) on google play but nothing is happening on their github.
comparing with other wallets (Electrum, Breadwallet, Mycelium, Samourai,...) they all are actively updating the source code and you can even compile it from source yourself.

[1] https://github.com/Coinomi/coinomi-android
13182  Bitcoin / Electrum / Re: Electrum Phishing on: February 27, 2019, 04:19:47 AM
I've run a Bitdefender scan of the whole computer which has turned up nothing, but I still feel a little worried I might have left something nasty on my machine.
as far as i can tell about the malicious versions that i have seen, they don't install any malware (like viruses or keylogger,...) on your computer. it is a simple modification of the code so that it spends your funds automatically as soon as you open the wallet and sends them to the hardcoded hacker's address.
so your Bitdefender or any other AV is never going to detect it.

Quote
I'm also a bit nervous about installing and setting up a new Electrum wallet (from the correct .org site!) just because like anyone I don't want to chuck my money away.

Any advise would be welcome.
familiarize yourself with digital signatures (PGP) and Web of trust concepts and learn how to use them to verify the authenticity of everything you download to install.
13183  Bitcoin / Bitcoin Discussion / Re: BITCOIN Genesis Keys on: February 27, 2019, 04:14:05 AM
the thing you are referring to here is probably about the lies that some people tell without proof and it is referring to the fact that the very least thing that anybody who claims to be Satoshi must do is to provide cryptographic proof that he owns the key to address(es) that is clearly associated with Satoshi Nakamoto. and without that anything they say should be disregarded and they should be considered fraudulent.

and by the way nobody can "spend" the coins created in Genesis Block because it is enforced by the protocol so even having the key to that address won't work.
13184  Bitcoin / Electrum / Re: White-hat message when sending transactions with older versions on: February 26, 2019, 06:50:33 AM
The only critical vulnerability i remember was JSONRPC bug where attacker can brute-force your wallet when you're online and open browser, if your wallet isn't protected, your coins would be stolen immediately.

More info : http://docs.electrum.org/en/latest/cve.html

it wasn't a "brute force" it was simply a call to the JSON-RPC interface which could access your secret information IF you didn't have any passwords but if you had the simplest password it would have protected you.

to OP:
see here what you are missing by using the old version https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES

It could be used to brute-force if the user open electrum and browser for hours even though it's last resort as attacker need wait few seconds for response.

theoretically yes, it is possible to do that but in practice it is impossible because the encryption that electrum uses for secret stuff (seeds and private keys) is AES-256 and that is a strong encryption that can not be brute forced that easily on its own. then you add the delays and restrictions of JOS-RPC and it becomes near impossible to perform it since it requires chained calls with each password iteration.
13185  Bitcoin / Bitcoin Discussion / Re: Who's filling up the mempool at the moment? on: February 26, 2019, 05:00:54 AM
it can not be a spam attack because the main characteristic of a spam attack is "constant" injection of transactions into the mempool and so far this does not look like a spam attack to me:



for comparison, the following is how a spam attack looks like (the picture is from Jan 2017)

pic ref: https://bitcointalk.org/index.php?topic=1776143.0
13186  Economy / Speculation / Re: Here we go. Bitcoin ripping through $4000 on: February 26, 2019, 04:43:24 AM
It was obvious that was a bull trap if you wanna call it but really just a normal part of the bottom phase bitcoin is in. Sometimes it will get a pump and sometimes a dump, doesn't mean the price is gonna launch up or crash down. We're 3+ months firmly in the bottoming out phase in the $3000s and we should expect plenty more months to come of this price range.

Call it a bull trap but it seems that there's someone who manipulated the price of bitcoin again. Anyways, at least there's a indication that investors are still willing to put their money on the market.

there wasn't any "traps" or even "manipulation" this time that price went back down. it is simply the normal market behavior at this point where an initial price rise after a big drop is not strong enough to break through a resistance like $4k that easily so it comes back down specially when you consider the number of short term traders who have been trading for 3-5% profits suddenly saw the >10% profit and started selling there. that easily brings the price back down.
and as i said above there is some leftover fear that prevents fresh money coming in for the time being until the uptrend repeats again.
13187  Bitcoin / Electrum / Re: White-hat message when sending transactions with older versions on: February 26, 2019, 04:30:30 AM
The only critical vulnerability i remember was JSONRPC bug where attacker can brute-force your wallet when you're online and open browser, if your wallet isn't protected, your coins would be stolen immediately.

More info : http://docs.electrum.org/en/latest/cve.html

it wasn't a "brute force" it was simply a call to the JSON-RPC interface which could access your secret information IF you didn't have any passwords but if you had the simplest password it would have protected you.

to OP:
see here what you are missing by using the old version https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES
13188  Bitcoin / Bitcoin Discussion / Re: Who's filling up the mempool at the moment? on: February 26, 2019, 04:04:42 AM
you just happened to catch this particular one, otherwise it has been happening for months. the spike size has also been the same size pushing the mempool to about 10-15 MB and drive fees up to 20 to 30 satoshi/bytes. this is one of the problems of adoption growing faster than scaling.

as for the fees of these transactions being low, the reason is because people know nowadays their low fee txs (like 1 s/b) will go through fast enough. for example during spike of today it would have taken a 1 s/b tx 12 hours to confirm in worst case scenario
13189  Bitcoin / Electrum / Re: Electru insufficien funds with positive balance (transaction sent but not reciev on: February 25, 2019, 05:04:51 AM
when you go to your History tab in your wallet do you see the transaction that you sent in there? if so then what does it say in its Date field? does it say something like "Local"?

a few minutes later i received another message stating insufficient funds. My account has a positive balance.

electrum does not give you unsolicited messages and that after "a few minutes". if you try spending more than you have you will see an error message right away and you won't even go into signing/sending process.

Quote
it is not available to inspect on block explorer (the webpage times out).
On block chain it has been confirmed 8 times now, and is labeled 'unspent' (i dont know what unspent means)
transaction ID is 311b5e24330c951cfa8725cccc71832102437dc7140dbea02abd7739e3e4c4d8

i am confused about these 3 statements. is this the transaction you can't find on block explorers and you say wasn't received or is it the one you are trying to spend?
this transaction is already confirmed https://blockchair.com/bitcoin/transaction/311b5e24330c951cfa8725cccc71832102437dc7140dbea02abd7739e3e4c4d8
and unspent means it is "not yet spent" and the the owner of 1PTzVVhYkxmzBa9yBZPrToPT82CaP3Zrie and    33EEEyMu6WHFdqBnmm8xGJyCLdag8XKzCn keys can spend their respective amount.
13190  Economy / Speculation / Re: Ways to Raise Prices bitcoin on: February 25, 2019, 04:59:12 AM
the only way for bitcoin price to truly rise is when its adoption grows, nothing else works. any other weird thing you try may work short term (like how altcoin pump and dumps are) but in the long run these things can not be sustained and will fail and all the gains would vanish.
this is actually why bitcoin price continues to rise even after 10 years of rising!

I think that the prices of bitcoin need a strategy from investors and traders & devlopers & companie

for example: - like mid 2017 When top exchanges imposed very strong restrictions to all deposit.
- creat special box loan fund (1 - 10 percent profit after 6 month & 0.01 percent profit after 1 month in top and trust exchange like binance , bitfinex , bittrex ) and that will encourage investor for holding their bitcoin with profit(  imagine if people invest about 1000000 btc for 6 moth and they can't desactive investement before 6 month.that can make price in stability and  bitcoin will gain time to 2020 and circulation of bitcoin will drop little)
- exchange print tusd and usdt (loan bank )
to be honest these two don't even make sense, specially the second one since it sounds like you want fake money be printed and injected in bitcoin to raise its price but you forget that it can crash just as easily and you also forget a more important thing that people aren't going to use these tokens to buy bitcoin, they will continue using their fiat to buy bitcoin.

- max sell in exchange is 1 bitcoin per day , without multiple acount (this is good way!) , there is no max buy
-dont allow mtgox and whale to sell their bitcoin in exchange.
you can't put this kind of silly restrictions on the market. it needs to remain a free market. besides the coins like mtgox coins need to enter circulating as fast and easy as possible so that we can have a better distribution of bitcoin.
ps. mtgox had nothing to do with the 2018 drop!
13191  Economy / Speculation / Re: Bitcoin factors drop in 2019 and now. on: February 25, 2019, 04:42:35 AM
You know for now, the price of Bitcoin is slowly falling.
"slowly falling" means price is losing a couple of percentages every couple of hours and at least goes down 10% per day. do you see that happening?

obviously not. all we had was a rise from $3600 to $4200 and then the panic kicked in from people thinking it is a "bull trap" and wanted to get out and price came back down to $3700+ that is not called "slowly falling".

Quote
Bitcoin prices have dropped nearly 25% this year. If analyzed since December 2018 the price of Bitcoin is very low, last year until now, the price of Bitcoin has dropped 75%.
your percentages are a bit off. this year we had mostly ups and downs not just drop. price started from a drop down to $3100 and went up to $4k and back to $3500 to stay there. and the overall drop is closer to 85%

Quote
I think that for this there are several main reasons why Bitcon prices and other digital currencies continue to plummet.
the reason for bitcoin price drop is not the same as the reason for altcoin price drops.


your reasons don't make much sense to me. you are focusing too much on the "government" while missing the fact that bitcoin is decentralized and things that involve centralization such as regulations are meaningless in the bigger picture.
13192  Bitcoin / Electrum / Re: I created a tutorial about how to check PGP signatures on Linux. on: February 25, 2019, 04:05:21 AM
this is very vague and incomplete in my opinion which is probably why it has not been merged yet.

i suggest turning it into clear steps and then also include alternative ways and also possible different replies that you get from each command.
for example:
1. Download files from electrum.org
-this should include what files (the .exe or tarball or .dmg file,... + signature file)
2. get the developer's public key
- then it should mention the alternative way here also you must mention what to do when you fail to connect to mit server since it is a common thing for it to go down!
3. do the verification
this should include the example of BOTH good and bad signatures highlighting the part of the response message saying whether it was good or bad and also explaining the other part (the error) that always confuses everyone.
13193  Bitcoin / Electrum / Re: Electrum wallet being attacked on: February 25, 2019, 03:55:41 AM
~
For example, ubuntu iso hasn't any signiture, only checksum...

it does have PGP signatures! but since ISO is big (Ubuntu 18.04 is nearly 2 GB) they use SHA hashes and then sign the hashes with their PGP private key and release the signature of that file instead.
so what you do is that you first check the signature of the hashes to see if you have the correct hash list file and then hash the file itself to see the file is correct.

in other words it is a combination of authenticity and integrity with 2 steps.
For this you need to know fingerprint of signature. For example, I exactly know fingerprint for electrum files, because I watched a video with this fingerprint and Thomas V standing beside.

have you even checked Ubuntu before making these comments? you already have all that. https://help.ubuntu.com/community/VerifyIsoHowto and their signatures have been in work since 2004 (15 years)

Moreover, you cannot verify google chrome file with signature, you cannot verify avast antivirus exe file with signiture, and most of known apps haven't got any signatures to verify them! And if they do have got such  signatures, you cannot trust them without checking reality of their fingerprints. But how can you  do it? You need to be sure that fingerprints are real!
they also have signatures but in a different more automatic way that is specific to Windows and is more like a certificate and it requires payment. and instead of using PGP it uses RSA which is another asymmetric  cryptography scheme.
any other "most known app" that doesn't have that signature may not need it. for example you don't need to verify the signature of Adobe Photoshop because it is not security sensitive!

of course if you want to be paranoid, there is no end to how much your paranoia is going to go, as it was mentioned your only remaining option would be to only use open source softwares and compiling all of them from source on your own.
13194  Economy / Speculation / Re: RIP Bull Market on: February 25, 2019, 03:38:51 AM
as i have been saying in the past week, there is not yet any bull market. what we have is the market trend between the bull and the bear markets! and as long as this transitioning phase is going on, you should expect this type of ups and downs where price plays jump rope with a level like this. just try to not get caught with your pants down thinking it is bull or thinking it is over they are both equally wrong.

also don't forget that there are currently thousands of altcoin bag holders who are dumping their bags as the altcoin market recovers a tiny bit thanks to bitcoin rise. the sheer amount of money that exits that way always puts extra pressure on bitcoin.
13195  Bitcoin / Bitcoin Discussion / Re: 1000 Bitcoin: The World's Most Expensive Prius on: February 25, 2019, 03:33:04 AM
that title is wrong on so many levels.
this is not an "expensive" purchase, this is just a purchase. he bought it at a good price at the time with appropriate amount of bitcoin. and that shows that he has understood what bitcoin is created for (to be a currency not something you hoard) and that is something that sadly many people still don't get.
13196  Economy / Speculation / Re: Here we go. Bitcoin ripping through $4000 on: February 24, 2019, 08:40:54 AM
there is still leftover fear in the market which is a natural thing after a long downtrend with lots of manipulation which is why this is not yet a breakout but instead a slow rise as the demand is increasing. what i expect is the same trend to last for a little while and possibly some corrections along the way but the only possible next step is a sharp rise after this as that leftover fear goes away and those who missed the chance to buy at the bottom (for any reason like waiting for a lower price) would rush to buy bitcoin because they fear missing out.
13197  Bitcoin / Electrum / Re: Electrum wallet being attacked on: February 24, 2019, 08:14:06 AM
~
For example, ubuntu iso hasn't any signiture, only checksum...

it does have PGP signatures! but since ISO is big (Ubuntu 18.04 is nearly 2 GB) they use SHA hashes and then sign the hashes with their PGP private key and release the signature of that file instead.
so what you do is that you first check the signature of the hashes to see if you have the correct hash list file and then hash the file itself to see the file is correct.

in other words it is a combination of authenticity and integrity with 2 steps.
13198  Other / Beginners & Help / Re: Schnorr signatures are creeping into the news again on: February 24, 2019, 08:05:16 AM
~
Since beginning, MuSig:Schnorr (which made for Bitcoin) was developed by developer who work at blockstream (or used to work there) and when people talking about Schnorr for Bitcoin, actually they're talking about MuSig Schnorr.

For people who interested with it's technical detail, you can check this thread MuSig: Schnorr Multisig and signature aggregation

MuSig is only one part of Schnorr signatures that focuses on an alternative and safer way of "multi signature" features of Schnorr signatures which is used for aggregating signatures and for example offer the possibility of having a 50 of 50 multi sign transaction but only with the size of a single key tx since there will only be 1 signature and 1 public key and that will increase scaling of bitcoin drastically considering currently a lot of the transactions in blocks are multisignature with at least 3 signatures so using Schnorr can drop at least 2 sig + 2 public keys from each of them (considering they are 2 of 3) and that is 2*(32+32+7)+2*(33+1) = 210 bytes per tx! also considering this will probably be released with new SegWit version and SegWit has some overhead we can effectively be saving about 205 bytes per transaction per block and that is great.

but Schnorr is a lot more than just MuSig! https://github.com/sipa/bips/blob/bip-schnorr/bip-schnorr.mediawiki
the main thing i am excited about is batch verification. not to mention that creating signature is so much faster with ECSDSA compared to ECDSA because it doesn't have the modular multiplicative inverse.
13199  Economy / Games and rounds / Re: Ok, here's a 1BTC puzzle. on: February 24, 2019, 07:49:40 AM
Hello, I just registered here.
I`m trying to solve this puzzle from a week now and I tried
everything that came to my mind.
Tried to search for answen for:
Why Satoshi Nakamoto made bitcoin amount to be 21 million - no eight english words answer
Why combs have 21 teeth - no eight english words answer
What is the meaning of the number 21 - it is the sum of all first 6 natural numbers - matematics, Fibonacci,
spritual, what so ever involves the number 21, 21 century stuff, I tried and tried.... and no luck...

I don`t think that even Satoshi Nakamoto(or Natasha Otomoski) can answer that question.

I wish you people luck to crack that puzzle! Smiley



This puzzle I suppose requires some technical workaround in cryptography.
I've tried hashing the question into a sha256 and minus the transaction hash no eight english words there.

This riddle or puzzle is extremely difficult to solve, but I think it is only a matter of months anyone would solve this.

knowledge of cryptography is only a secondary requirement and it will only be needed in the last step, if at all. the first step is to understand the puzzle question and have a starting point instead of making guesses and/or brute forcing random words to get something out of it.

at this point i am convinced that this either was a trolling attempt considering overall activity of OP or if it is an actual puzzle, it was very poorly designed which makes it impossible to solve.
13200  Bitcoin / Electrum / Re: Electrum wallet being attacked on: February 24, 2019, 07:39:49 AM
No need to check the signature since I already downloaded from the original website. Electrum.org and I double verified before I downloaded. Also, I changed the name of the setup. thing is really weird because I am not connecting to this server at all. I get this msg even when I am into a different server.

What kind of verification that you did? Checking the site name twice?
Remember that it is also possible that your DNS was hijacked, so you've download a malicious app. I'd rather verify it just to be safe.
Excuse me... So even you cannot be sure in security! For example, before installing electrum you need to install a correct OS. How can you be sure your OS is real! Maybe  you downloaded your OS ( for example, ubuntu) not from real ubuntu.com, but someone hijacked your DNS...

that is why the concept of checking the authenticity of a downloaded file was invented. which means you download anything from the internet and then check its authenticity with a key that you trust. under the hood the (asymmetric) cryptography that is used gives an easy way of verifying that with virtually zero chance of fault.

the most common case is usage of PGP signatures. which means when you download Ububtu for example you verify the ISO file signature against the public key using the cryptographic scheme that was used and if you  get a "thumbs up" you can be sure it was the real OS.

so now it doesn't matter where you download the file from, you don't even have to go to ubuntu.com, you can go to anywhereelseevenafakesite.com and download the ISO and as long as you verify its signature with the real public key and get the valid signature you will be good to go.
Pages: « 1 ... 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 [660] 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 ... 1160 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!