Bitcoin Forum
May 25, 2024, 12:47:12 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 [124] 125 »
2461  Bitcoin / Press / Re: Bitcoin press hits, notable sources on: June 28, 2011, 10:39:55 AM
http://www.thinq.co.uk/2011/6/28/mt-gox-flaw-opens-door-free-bitcoins/

I know mtgox allows you to put in orders without having the funds yet (which is very useful when putting in a sell-buy combo)
.. not sure how that would allow someone to game it for free bitcoins though.
2462  Bitcoin / Bitcoin Discussion / Re: Is Mt. Gox aware that Open Orders isn't working? on: June 26, 2011, 06:16:44 PM
That happened to me at first. But I've since put in 2 separate orders for 1 coin each - and they were fulfilled.
2463  Bitcoin / Bitcoin Discussion / mtgox trading up on: June 26, 2011, 06:12:24 PM
It's working - just bought 2 coins. Not displaying on bitcoinmonitor yet though..

2464  Bitcoin / Bitcoin Discussion / Re: Mt. Gox to open trading in competition with churches around the world... on: June 26, 2011, 01:42:02 PM
Mt. Gox -- you should delay a few hours until most people get back from church.

Come on, we're not a nation of atheists, even if some people here are! 

15:00 GMT is:

11:00 EDT
10:00 CDT
9:00 MDT
8:00 PDT

That is basically PRIME TIME for churches across America on Sunday morning.

Come on, Mt. Gox -- show a little respect for America's religious sensibilities!

Matthew

US centric much???  Withdraw from these big ol global internets and run your own bitcoin on a lan if you want to go all parochial. Tongue
2465  Bitcoin / Bitcoin Discussion / Re: Why are you going back to MtGox? on: June 26, 2011, 01:19:30 PM

what? MtGox lets you fake the entire orderbook by letting you enter orders that never get executed because you dont have the funds?

The orders are inactive as long as the funds for them are not there.

Yeah - I always assumed they were just put in as some sort of pending order.

I also emailed tradehill about allowing a similar thing.  For example - it takes a while for your BTC deposit to be confirmed at tradehill - but it'd be nice to setup a sell order at the same time as arranging the deposit.

The tradehill folks sounded positive on the idea and responded: "That way, you can leave a few open orders, monitor the different exchanges and make a transfer to the exchange you choose, all while keeping your BTC in your wallet."
..which is a usecase I hadn't thought of - but I guess that could be good.

2466  Bitcoin / Bitcoin Discussion / Re: Why are you going back to MtGox? on: June 26, 2011, 11:31:56 AM
as above
+ it's easy to get AUD in
+ tradehill doesn't seem to let me place orders if I don't have the funds to cover them at the time of placing the order whereas on mtgox it seems I could place a sell high and buy low even if there weren't any USD to cover the buy.
(perhaps for those sort of orders I should be using an external tool - but for now mtgox is more convenient)
2467  Bitcoin / Bitcoin Discussion / Re: ! Mt. Gox PASSWORDS List Released - Your Password Could Be Here - Check ! on: June 26, 2011, 10:41:13 AM
Fine - be happy. But take a little time to understand what you are being happy about.
then again..  maybe too much understanding is not a recipe for happiness...  
As you were!

I won't use Mt Gox again, they'll have to earn my trust back.
Yeah.. fair enough. I was just being snarky because you seemed to jump to the conclusion they were hacked again.
I've been jumping to my own wrong conclusions so I can't really talk.
2468  Bitcoin / Bitcoin Discussion / Re: ! Mt. Gox PASSWORDS List Released - Your Password Could Be Here - Check ! on: June 26, 2011, 10:36:33 AM
ouch. That's potentially damning for the 'no sql injection attack occurred' line.
There are also some script tags in there that I didn't notice before.
Not really. The records with those names were inserted succesfully, which means that no succesful sql injection happened.

At least there...
Oh yeah.. Makes sense!
2469  Bitcoin / Bitcoin Discussion / Re: ! Mt. Gox PASSWORDS List Released - Your Password Could Be Here - Check ! on: June 26, 2011, 08:49:45 AM
My favorite username and passwords were
Quote
UserID   Username   Email   Password            
12558   hehehe\'   0   0   0)waitfor delay\'0:      $1$ldybUNj/$jZ5XJRWM8DsOTM3FU9TyN0   
14250   &   39 union select 1   2   3   4   5   6

ouch. That's potentially damning for the 'no sql injection attack occurred' line.
There are also some script tags in there that I didn't notice before.

2470  Bitcoin / Bitcoin Discussion / Re: ! Mt. Gox PASSWORDS List Released - Your Password Could Be Here - Check ! on: June 26, 2011, 07:11:55 AM
Quote
1q2w3e!Q@W#E
qwe123QWE!@#

interesting that these got cracked, was it salted?  looks like it would be more difficult to crack than a lot of the ones on that list

It is interesting.. but note that on a standard qwerty keyboard - it's a pattern of 6 keys at the top left.. first unshifted then shifted.

Perhaps some wannabe security guru recommended it to a bunch of suckers as an easy way to remember your complicated password?!
2471  Bitcoin / Bitcoin Discussion / Re: ! Mt. Gox PASSWORDS List Released - Your Password Could Be Here - Check ! on: June 26, 2011, 07:05:58 AM
They got hacked again?
No. *some* of the passwords have been extracted from the *previously* released list of (lightly) encrypted passwords.
Everyone should have changed their mtgox passwords by now, and also on other services if they were silly enough to use the same password elsewhere.
This is just an interesting exercise in seeing what insecure passwords people tend to use.
The shorter, dictionary based passwords are easily cracked. The more complex ones will take time - if anyone can even be bothered.

I'm happy now that I withdrew all my remaining bitcoins from Mt Gox.

Fine - be happy. But take a little time to understand what you are being happy about.
then again..  maybe too much understanding is not a recipe for happiness...  
As you were!


2472  Bitcoin / Bitcoin Discussion / Re: Mt. Gox to open trading in competition with churches around the world... on: June 26, 2011, 06:55:12 AM
I know I'm not the only Bitcoin user who goes to church. I sincerely hope not!

Now trading is always going on while I'm gone to church, shopping, etc. and that's nothing new.
But a re-start of trading on Mt. Gox, which has been down for A WEEK, might provide unique opportunities that I might miss.

Why did they have to pick such a time?



Because your particular choice of spending sunday time is not more important than anyone elses - be it golf, work, family bbq, favourite wanking time, whatever.

Religions are renowned for their sense of self-importance. 
Don't make the mistake of assuming anyone else should think you're spending your time there well - let alone take it into consideration for a globally operating concern.
2473  Bitcoin / Bitcoin Discussion / Re: Request for input into name of Bitcoin backed digital cash on: June 26, 2011, 04:51:33 AM
Quote
PROBLEM
This may hinder business takeup. It also means micro transactions are not currently feasable.

I don't fully understand the bitcoin transaction process - but the apparent difficulty in using bitcoins for micropayments is a huge disappointment for me.

I keep hearing how bitcoins are highly divisible - yet with such an arcane transaction system (where the fee changes based on the makeup of coins in your wallet?!) - the average user just isn't going to trust that (or know whether) they can send X uBTC or nBTC without losing a huge slice.

I think it's not only a hindrance for business uptake - but for the individual who just hears of bitcoin now and wants to try it out.

People trying it out now - might get 1mBTC from the faucet..   and probably nothing from mining pool.
It takes what.. a month with a modern but not top-of-the-line graphics card to even get a payout? Even if people have the ability to figure out the mining part - many will give up I think. (The very fact that pools don't seem to payout til some relatively huge size just reinforces the idea that small transactions aren't really catered for in bitcoin)

People need - right now - the ability to confidently send and receive micro BTC amounts.  Because I don't understand the transaction details - I worry that even sending a few uBTC back and forth with a friend - will somehow fragment my wallet and cause higher transaction fees in future!
I may be completely wrong in this - but until transactions are understandable - this is a problem.

In short - I think your proposal is premature, because it just adds to the complexity.
What we need first is stability and UNDERSTANDABILITY in the transaction behaviour of bitcoin client software.

Better documentation at bitcoin.org is probably the answer..  and it needs devs to think from the perspective of people who own merely 1mBTC.
I suspect all the devs have many whole BTC - and are oblivious to the needs of the 'poor'.  Same old story with any economy I guess Sad







2474  Bitcoin / Bitcoin Discussion / Re: Something I don't get about GOX. on: June 25, 2011, 03:25:40 PM
...If their site was already secure, why do they need to 'vastly improve' the security?
It sounds like a tacit admition to the sql injection rumors floating around. 

The database leak showed that the passwords were not stored particularly securely - so that at least needed to be fixed.
Because a fair amount of the account info is now public - that also forced them to implement extra security features e.g the IP address checking they did for account reclamation.
Also - they said they intended to keep the existing server 'as is' for investigation purposes.

It does seem a possibility that the auditor story is a cover story for an underlying sql injection vulnerability - but I don't see this as a tacit admission
 -  it's still just speculation as far as I can tell.


2475  Bitcoin / Bitcoin Discussion / Re: mtgox fee calculations not accurate. on: June 25, 2011, 01:52:08 PM
When MtGox comes back up, it will have an entirely new backend.  The old backend was built by the previous owner and MagicalTux has beeem working on a rewrite since right after he purchased the site.  Discussing an issue with the previous backend us pointless at this point.  Wait until it is back up and then check.  If it's still an issue, open a ticket and let us know.

That's good to hear.  It was just a point of concern..  and I understand if it's not a priority just now.

2476  Bitcoin / Bitcoin Discussion / Re: mtgox fee calculations not accurate. on: June 25, 2011, 01:50:52 PM
What's that, bash scripting? Which language uses $ in front of a variable?
perl, tcl, php.. 
The language is irrelevant.

Anyway you are wrong and it seems you cant see it. I give up.

You should give up. Making comments about programming when you clearly don't have a clue is bound to be embarrassing for you.
2477  Bitcoin / Bitcoin Discussion / Re: Testing My Account [Security] on: June 25, 2011, 01:17:54 PM
"If you can hack into my account, you can keep the money."

The only way I'd attempt something like this would be if tradehill also gave permission.
Seems unlikely they would, unless the 'hacker' were to give some undertaking they'd do so in ways that are highly unlikely to disrupt the system, and also that tradehill would be given time to fix any hole before the exploit were made public.

2478  Bitcoin / Bitcoin Discussion / Re: mtgox fee calculations not accurate. on: June 25, 2011, 09:36:49 AM
Who told you the exchange rate was exactly $17.29 and has not been rounded?

The logs show it as $17.29000 - and I'm fairly sure I asked for the trade to occur at 17.29!
It is simply not legitimate to show it with this many decimal places if it was rounded off at 2DP.



Quote
It's very hard to mess up an easy task like multiplying 2 numbers when you program.

No. This is the problem with amateur programmers who try to code with currency.
It is *very easy* to get apparently simple things wrong.

e.g 0.1 * 21.55
depending on the precision used could come out as say 2.1550000000000002

now store that in a variable $x 
check if you have the expected value  $x == 2.155   and the program returns FALSE.
In this example, I've used floats - just to demonstrate one pitfall.

Rounding during intermediate calculations is another way to introduce inaccuracies and it looks to me as though this is what mt gox is doing.









2479  Bitcoin / Bitcoin Discussion / mtgox is processing deposited funds - looks good. on: June 25, 2011, 08:48:55 AM
When I first logged in to the mtgox claim site to see my account - I saw the balance from around the crash time.

Now I see funds that I deposited on the 20th have shown up in the account in USD Smiley
2480  Bitcoin / Bitcoin Discussion / Re: mtgox fee calculations not accurate. on: June 25, 2011, 06:42:56 AM

This is surely a big no-no.  This is as bad as using floats for currency.
Doesn't anyone else have concerns about this?Huh

I do. But I think the best course would be to let them handle the current, more pressing issues... once the site is back up and things are returning to normal, and MagicalTux actually gets to have a full night's sleep, then see if you can open a ticket with them about it.

I agree... it's not something I want to hassle them about right now.. but I do think it warrants discussion and should be public knowledge.
Pages: « 1 ... 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 [124] 125 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!