Bitcoin Forum
June 27, 2024, 05:41:19 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 [168] 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 ... 422 »
3341  Other / Meta / Unclaimed forum donation on: October 11, 2013, 09:41:19 PM
Someone donated 10 BTC directly to the forum's main donation address 17RTTUAiiPqUTKtEggJPec8RxLMi2n9EZ9. (This is not what you're supposed to do if you want Donator status.) Someone is trying to claim this donation for Donator status, but they can't prove that they sent it. If you actually sent this 10 BTC, sign a message with 1ECTrZNum3ojyfDnZbkDBALtfwWL54wtZL. Otherwise, I'll give the status to the guy who already contacted me about claiming it.
3342  Bitcoin / Development & Technical Discussion / Re: Soft-fork Proposal: allow nLockTime specify an UPPER limit instead of lower lim. on: October 10, 2013, 11:25:59 PM
Hmm, I wasn't aware of anything special happening at the 100 block mark.
Can you repeat your answer with a few more details and references, for poor ignorant souls such as myself?

Sometimes (though very rarely), there is a large chain fork. In a fork, the miners mining on what ends up being the wrong side of the fork lose their mining rewards when the chain merges again. Anyone who received those newly-mined coins (perhaps over many "generations" of transactions) will have those transactions permanently invalidated. This is very bad. To prevent this from happening, the Bitcoin network prohibits coinbase transactions (mining rewards) from being spent for 100 blocks. As a result, a fork must be longer than 100 blocks for any non-coinbase transactions to be invalidated unless there's double-spending involved. Any change to Bitcoin which would allow a valid transaction to later become invalid would break Bitcoin's robustness in this area unless such transactions had similar 100-block spending restrictions.
3343  Bitcoin / Development & Technical Discussion / Re: Soft-fork Proposal: allow nLockTime specify an UPPER limit instead of lower lim. on: October 10, 2013, 06:20:22 AM
That would reduce Bitcoin's security/robustness model. Currently, it isn't possible for a transaction to become invalid after a chain fork of less than 100 blocks unless double-spending is involved. With threshold transactions, a long fork (due to a netsplit, bug, etc.) can cause widespread havoc by invalidating tons of transactions dependent on a threshold transaction. Maybe it'd be OK if threshold transactions had the same 100-block spending limit as coinbase transactions, but this extra complexity isn't worthwhile IMO unless there's some amazing application for these transactions.
3344  Other / Meta / Registration disabled temporarily on: October 10, 2013, 05:30:10 AM
Registration is disabled until I have time to fix some things.
3345  Economy / Auctions / Re: Advertise on this forum - Round 98 on: October 09, 2013, 11:17:20 PM
This auction will be done again: see https://bitcointalk.org/index.php?topic=308632.0 .
3346  Economy / Auctions / Advertise on this forum - Round 98 (speedy redo) on: October 09, 2013, 11:16:48 PM
Due to the hack, the last auction will be redone. This auction will end sometime in the next 48 hours.

In order to collect more money for the creation of good forum software and for other useful purposes, the forum is selling ad space in the area beneath the first post of every topic page.

Ads are allowed to contain any non-annoying HTML/CSS style. No images, JavaScript, or animation (no marquee or blinking). Ads must appear 3 or fewer lines tall in my browser. Ads will be prefixed with "Advertisement:". Ad text may not contain lies, misrepresentation, or inappropriate language. Ads may not link directly to any NSFW page. Ads may be rejected for other reasons.

There are 10 total ad slots which are randomly rotated. So one ad slot has a one in ten chance of appearing. Seven of the slots are for sale here. Ads appear only on topic pages with more than one post, and only for people using the default theme.

The ad lasts at least 7 days starting from when I put it up. (However, if you look at the ad history you'll see that ads frequently get 1-2 extra days, but this is random and definitely not guaranteed.)

Stats

Exact historical impression counts per slot:
https://bitcointalk.org/adrotate.php?adstats

Info about the current ad slots:
https://bitcointalk.org/adrotate.php?adinfo

Ad blocking

Hero members, Donators, VIPs, and moderators have the ability to disable ads. I don't expect many people to use this option. These people don't increase the impression counts for your ads.

I try to bypass Adblock Plus filters as much as possible, though this is not guaranteed. It is difficult or impossible for ABP filters to block the ad space itself without blocking posts. However, filters can match against the URLs in your links, your CSS classes and style attributes, and the HTML structure of your ads.

To prevent matches against URLs: I have some JavaScript which fixes links blocked by ABP. You must tell me if you want this for your ads. When someone with ABP and JavaScript enabled views your ads, your links are changed to a special randomized bitcointalk.org URL which redirects to your site when visited. People without ABP are unaffected, even if they don't have JavaScript enabled. The downsides are:
- ABP users will see the redirection link when they hover over the link, even if they disable ABP for the forum.
- Getting referral stats might become even more difficult.
- Some users might get a warning when redirecting from https to http.

To prevent matching on CSS classes/styles: Don't use inline CSS. I can give your ad a CSS class that is randomized on each pageload, but you must request this.

To prevent matching against your HTML structure: Use only one <a> and no other tags if possible. If your ads get blocked because of matching done on something inside of your ad, you are responsible for noticing this and giving me new ad HTML.

Auction rules

Post your bids in this thread. Prices must be stated in BTC per slot. You must state the max number of slots you want. When the auction ends, the highest bidders will have their slots filled until all seven slots are filled.

So if someone bids for 7 slots @ 5 BTC and this is the highest bid, then he'll get all 7 slots. If the two highest bids are 7 slots @ 4 BTC and 1 slot @ 5 BTC, then the first person will get 6 slots and the second person will get 1 slot.

The notation "2 @ 5" means 2 slots for 5 BTC each. Not 2 slots for 5 BTC total.

- When you post a bid, the bids in your previous posts are considered to be automatically canceled. You can put multiple bids in one post, however.
- All bid prices must be evenly divisible by 0.25.
- The bidding starts at 0.50.
- I will end the auction at an arbitrary time no more than 12 days from now. (I will probably end the auction 1-3 days before the ads are scheduled to go up.)
- If two people bid at the same price, the person who bid first will have his slots filled first.
- Bids are considered invalid and will be ignored if they do not specify both a price and a max quantity, or if they could not possibly win any slots

If these rules are confusing, look at some of the past forum ad auctions to see how it's done. I also post periodic status updates which should help make things clear.

You must pay for your slots within 24 hours of receiving the payment address. Otherwise your slots may be sold to someone else.
3347  Other / Meta / Re: Custom avatars don't working now? on: October 09, 2013, 08:26:23 PM
If you uploaded your avatar recently, it may have been lost in the move.
3348  Other / Meta / Re: Site activity is not updating ! on: October 08, 2013, 11:51:44 PM
I think I fixed that.
3349  Other / Meta / Re: About the recent attack on: October 07, 2013, 10:18:14 PM
SMF v2.0.2 has many vulnerabilities.

Yeah. SMF 2.x is basically 1.x with more features (ie. more attack area) and a slightly more secure database escaping scheme. Upgrading probably isn't worthwhile unless we want the better license.
3350  Other / Meta / Re: About the recent attack on: October 07, 2013, 07:47:24 PM
I think it unlikely that if there was a two-year backdoor, it was placed by the recent defacer.

No, I verified its existence using my old forum backups.
3351  Other / Meta / Re: About the recent attack on: October 07, 2013, 01:08:29 PM
It is somewhat scary that admins can modify forum code from within the forum itself if I understand correctly.

That's how Satoshi set it up (maybe the SMF default), but I fixed it a while ago.
3352  Other / Meta / About the recent attack on: October 07, 2013, 05:18:33 AM
On October 3, it was discovered that an attacker inserted some JavaScript into forum pages. The forum was shut down soon afterward so that the issue could be investigated carefully. After investigation, I determined that the attacker most likely had the ability to execute arbitrary PHP code. Therefore, the attacker probably could have accessed personal messages, email addresses, and password hashes, though it is unknown whether he actually did so.

Passwords were hashed very strongly. Each password is hashed with 7500 rounds of sha256crypt and a 12-byte random salt (per password). Each password would need to be individually attacked in order to retrieve the password. However, even fairly strong passwords may be crackable after a long period of time, and weak passwords (especially ones composed of only a few dictionary words) may still be cracked quickly, so it is recommended that you change your password here and anywhere else you used the password.

The attacker may have modified posts, PMs, signatures, and registered Bitcoin addresses. It isn't practical for me to check all of these things for everyone, so you should double-check your own stuff and report any irregularities to me.

How the attack was done

I believe that this is how the attack was done: After the 2011 hack of the forum, the attacker inserted some backdoors. These were removed by Mark Karpelles in his post-hack code audit, but a short time later, the attacker used the password hashes he obtained from the database in order to take control of an admin account and insert the backdoors back in. (There is a flaw in stock SMF allowing you to login as someone using only their password hash. No bruteforcing is required. This was fixed on this forum when the password system was overhauled over a year ago.) The backdoors were in obscure locations, so they weren't noticed until I did a complete code audit yesterday.

After I found the backdoors, I saw that someone (presumably the attacker) independently posted about his attack method with matching details. So it seems very likely that this was the attack method.

Because the backdoors were first planted in late 2011, the database could have been secretly accessed any time since then.

It was initially suspected by many that the attack was done by exploiting a flaw in SMF which allows you to upload any file to the user avatars directory, and then using a misconfiguration in nginx to execute this file as a PHP script. However, this attack method seems impossible if PHP's security.limit_extensions is set.

The future

The forum is now on a new server inside of a virtual machine with many extra security precautions which will hopefully provide some security in depth in case there are more exploits or backdoors. Also, I have disabled much SMF functionality to provide less attack surface. In particular, non-default themes are disabled for now.

I'd like to publish the forum's current code so that it can be carefully reviewed and the disabled features can be re-enabled. SMF 1.x's license prohibits publishing the code, though, so I will have to either upgrade to 2.x, get a special copyright exception from SMF, or do the auditing myself. During this investigation, a few security disadvantages to 2.x were brought to my attention, so I don't know whether I want to upgrade if I can help it. (1.x is still supported by SMF.)

Special thanks to these people for their assistance in dealing with this issue:
- warren
- Private Internet Access
- nerta
- Joshua Rogers
- chaoztc
- phantomcircuit
- jpcaissy
- bluepostit
- All others who helped

Code:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

As of October 7 2013, the Bitcoin Forum has been restored to bitcointalk.org.
-----BEGIN PGP SIGNATURE-----

iF4EAREIAAYFAlJSRF8ACgkQxlVWk9q1keemWgD/WcvrsikPq6AHpEo20KGmQInp
FlyAWNbX74z65KJrsUEBAIcCzYnHZ7gAs49mlhSq1fR9o2LZCETV3BJveCTu7lAi
=b9Xb
-----END PGP SIGNATURE-----
3353  Bitcoin / Bitcoin Discussion / Re: SilkRoad domain Seized? on: October 03, 2013, 12:10:20 AM
It's tragic that an innocent person will be inprisoned by the government and that the free market has been interfered with, but I'm confident that an even better Silk Road will appear in the near future.

Didn't DPR say that he bought Silk Road from someone else? What happened to that? Was he just lying?

Would you believe that I, as an ancap, also find Rothbard unconvincing?  Not only that, but I don't think the "non-aggression principle" is an adequate guide for political philosophy.  I'm not a libertarian due to moral axioms, but rather, because I think it produces the best outcomes. 

I'm also a "Friedmanite ancap", though I also generally believe that the NAP is a good moral rule to follow in almost all cases. Rothbard may have contributed a lot to libertarianism and economics, but his ethical theory is contradictory in some places in disturbing in others.

Even if you're an ancap purely for moral reasons, it's good to know the non-moral arguments for it: A lot of people simply disagree with the NAP, and your moral arguments will be useless against such people.
3354  Bitcoin / Bitcoin Technical Support / Re: building bitcoin on unix is now a pain thanks to bitcoin devs on: October 01, 2013, 10:03:14 PM
the software i use without no compensation was written by satoshi, not the people who manage it now.

Why don't you use 0.3.19 if the current developers aren't adding anything?
3355  Other / Meta / Re: bitcointalk.org has now 150 000 registered members on: October 01, 2013, 09:58:38 PM
Currently: With 150,399 members, I estimate that 47,903 accounts have been used by humans and 10,622 accounts are active. "Used by humans" = (received a PM and sent a PM) or at least 2 posts. "Active" = activity > 14 and logged in within the last month.

What's the period of time for the "most online" measurement, is it 24 hours?  Seems kind of slim!

That's not being tracked anymore, so that statistic may be wrong.
3356  Other / Meta / Re: Get Donator status by donating 10 BTC on: September 30, 2013, 09:20:24 PM
MagicalTux got "free" VIP status for hosting the forum for a long time, too. I think that him plus Hal are the only free donator statuses I gave out. You'd have to do something pretty extraordinary to convince me to give out another free one.

I don't see any point in donating 5 BTC now and then 5 BTC later. You won't get Donator status until you've donated a total of at least 10 BTC. It'd be better for you to earn interest on the 5 BTC somewhere until you're ready to pay 10 BTC. The forum isn't in need of money.
3357  Bitcoin / Bitcoin Discussion / Re: [VIDEO] Future of Money: Bitcoin and autonomous agents on: September 29, 2013, 05:20:11 AM
For some reason, I've never seen a talk by Mike before, but he's a really fantastic speaker! This kind of stuff is what makes Bitcoin really cool.
3358  Other / Meta / Re: [Feature added] Color besides usernames for Ignored by % of established members. on: September 29, 2013, 02:32:42 AM
smoothie was finally unseated as ignore champion! Jaroslaw was permabanned, though, so who knows how long his reign will last.

Code:
member established_ignores raw_percentage posts adjusted_percentage

Jaroslaw 174 .04720 727 .04708
smoothie 138 .03743 9022 .03281
MPOE-PR 137 .03716 4328 .03509
wopwop 132 .03581 687 .03570
ElectricMucus 132 .03581 6289 .03267
ChartBuddy 129 .03499 3119 .03357
zyk 114 .03092 411 .03097
Come-from-Beyond 109 .02957 2024 .02874
iCEBREAKER 106 .02875 1719 .02809
crumbs 96 .02604 1821 .02532
Walsoraj 85 .02306 541 .02303
eve 83 .02251 346 .02260
sublime5447 82 .02224 1676 .02160
bulanula 79 .02143 2961 .02009
TECHICENINE 78 .02116 302 .02126
Matthew N. Wright 77 .02088 6516 .01762
bonker 77 .02088 616 .02082
Ira H. Fuchs 77 .02088 40 .02113
subSTRATA 75 .02034 42 .02059
MysteryMiner 73 .01980 1474 .01927
Atlas 72 .01953 934 .01929
Coinseeker 72 .01953 975 .01927
nkspace 70 .01899 188 .01916
WaverleyStreet 70 .01899 78 .01921
becoin 67 .01817 952 .01793
puffpuffpass 62 .01682 190 .01698
gweedo 62 .01682 5255 .01424
lucif 60 .01627 1970 .01548
Maria 59 .01600 427 .01604
Viceroy 57 .01546 1843 .01473
bitrebel 56 .01519 928 .01496
cunicula 56 .01519 1998 .01437
3359  Bitcoin / Bitcoin Technical Support / Re: Is it possible to send multiple transactions at once with bitcoin-qt? on: September 28, 2013, 08:45:45 PM
It's in the lower left.
3360  Bitcoin / Bitcoin Discussion / Re: So what happened to Satoshi? on: September 28, 2013, 03:53:25 PM
He's really shy, so he doesn't want to be involved in Bitcoin now that so many people are involved (and very interested in him). He's probably working (alone) on some other interesting project now.
Pages: « 1 ... 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 [168] 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 ... 422 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!