Bitcoin Forum
June 24, 2024, 01:11:35 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 ... 63 »
81  Bitcoin / Development & Technical Discussion / Re: An unexpected backup system suggestion on: April 06, 2024, 10:37:48 AM
I believe it is lack of creativity from their part. You can do a host variety of things to secure your bitcoin. Write the seed phrase down on paper, hide it on multiple places, use washers for long-term storage etc.

If he doesn't like BIP39, then maybe he should look for Electrum's seed standard? In any case, keeping your private keys encrypted is a bad idea. SD cards, disk drives, DVDs etc., are all prone to corruption. And you need to store both the GPG private key and the encrypted data somewhere. Losing access to one of them means loss of funds.

He is symmetrically encrypting the keys. So he must have a strong password to decrypt them. I don't know how he stores the password though. I didn't ask for obvious reasons.

I am not in favour of digital storage either. I am afraid of disk failures.

As far as BIP39 is concerned, he actually said "I don't use seed phrases, especially BIP39". So I am assuming he must dislike Electrum as well.
Personally I mostly use electrum instead of BIP39, but I understand that BIP39 is the most widespread, software agnostic, backup protocol.
82  Bitcoin / Development & Technical Discussion / An unexpected backup system suggestion on: April 06, 2024, 10:04:16 AM
Yesterday, I had a conversation (in real life) with a person who I really think is very knowledgeable in Bitcoin.

I will not provide more details about his setup, because I value his privacy. I asked him to join the forum and open a thread to discuss about it. The forum would have a lot to learn from him. He will not...

He provided me with some important arguments against BIP39, but most importantly, he described a backup system that he finds superior.

But this system was (and still is) a red flag for me.

He said that he prefers to GPG encrypt private keys in WIF format and store them digitally.

So... What are your thoughts?  I am aware that this system caused Luke Dashjr losing a lot of funds, so I can't believe he literally suggested it.

I won't be very active this weekend, but I will be back to read and discuss with you next week.
83  Bitcoin / Hardware wallets / Re: Jade DIY hardware wallet on: April 05, 2024, 08:56:17 PM
I should think about it twice before questioning Blockstream for their lack of research.  Tongue

Especially since the founder has invented the core mining mechanism of bitcoin  Tongue

Seriously though, nice catch and nice study. You have provided us with some knowledge.
84  Bitcoin / Hardware wallets / Re: Jade DIY hardware wallet on: April 05, 2024, 06:53:33 AM
This is how I would approach the question.
Also, I am irrationally risk-averse when it comes to losing Bitcoin (I said irrationally!) so I would further lower that threshold.

Some bad feeling likely remains with a device that showed signs of unreliability. A one-time bad day I would brush off, kind of.

You are both correct. And since I have been asked the question a lot, about why I keep trusting the device and why I still use it, I want to make something clear.

1. I can read and understand C, so I feel confident reading the code. Which is important for me.
2. My usage is pretty limited. Once a month, I scan a private key QR code, I sign a transaction (usually a pretty small one), I erase the memory of the device (using temporary signer option).
3. Blockstream doesn't know my address, nor my name, since I received the product elsewhere, where I don't have the ability to access now, so if I request a change, or buy a new one, I will need to use my real name and address.
4. I own other devices that I use for more frequent transactions.
5. I always know that my backups are safe.
6. I always use QR codes, which is safer than USB cables. Still, QR codes are not a panacea, but, you know, I feel more confident.
7. The Jade is a reputable device.

Warning:
Finally, always be very cautious when it comes to using browser-based products (software & updates). Always verify what you download. Always think twice before downloading something.
85  Bitcoin / Hardware wallets / Re: Jade DIY hardware wallet on: April 05, 2024, 06:24:42 AM
The worst thing I can think of from the top of my head is that it somehow starts generating addresses whose coins you can never spend (sign) because of a serious bug. Of course, I am just throwing ideas out there, and I don't think it's a realistic scenario.

It is a realistic scenario, but not a likely to happen scenario. I mean, bugs can be found in the code, but the address generation process is a core process, which, I hope, has been tested by both software unit tests and human tests. I can't believe that there will be a flaw in such an important aspect of the software.

What can happen though, is that someone can use a fake website to update their firmware and that the installed software can be malicious. This is a huge problem if it happens... I hope that the device won't work with the fake website, but since I am a developer and not a security person, I don't know how easy this scenario is.
86  Economy / Collectibles / Re: [FREE RAFFLE] - Custom eXch Cryptosteel Capsule (#5)! on: April 04, 2024, 07:32:37 PM
Our winner is apogio!! Congrats to you!  Cool

Oh my god. Normally I am the unluckiest person in the room, but today was my lucky day. Thanks paid2. Thanks everyone! Good luck in the next one!
87  Bitcoin / Development & Technical Discussion / Re: HELP! Loss of funds / Invalid address on: April 04, 2024, 06:31:10 AM
The following warning is a day late and a dollar short.

Let me share my point of view, having written some similar script myself: Don't! Don't! Don't use scripts that are not properly tested, qualified and used.

Open source is fantastic because it allows many pairs of eyes to review the same code. However, it's not a panacea. Most of the time, these pairs of eyes distinguish corner cases and issues. In your particular occasion, as DaveF said above, there was an open issue in the code. So, when using open source, we should at least check:
1. the open issues.
2. the number of forks / stars.
3. the number and quality of open merge requests.
4. the number of contributors.
88  Bitcoin / Bitcoin Technical Support / Re: Full Node Behind StarLink ISP, CGNAT? on: April 04, 2024, 06:13:44 AM
If TOR is set up, will that solve the possible problem with inbound connections?

TOR will allow you to have inbound connections without doing any network adjustments.

It is important to clarify the difference between an incoming and an outgoing connection though. An incoming connection doesn't mean that you don't receive anything from other nodes. It just means that the node that will initiate the connection process will always be yours. Once the connection between two nodes is established, it doesn't matter who initiated it or not. The transferring process will be the same.

Finally, TOR is often slow. This is just a side-note.
89  Other / Meta / Re: Save your nice merit records here - LAST UPDATE: 12/07/2023 on: April 03, 2024, 08:06:32 PM

Congratulations to apogio on his triple 8 record (888) just like his triple 7 recently also. Looking forward to a 999 merit score of which I will definitely make it 1000 Grin



Thanks Mia Chloe! I am very happy about it.
90  Economy / Games and rounds / Re: [Results 2nd Edition] 🥧 Bitcointalk Pie Baking Contest 🥧 on: April 02, 2024, 11:53:04 AM
Congrats to the winners.

Congrats to you Rick for managing this wonderful contest.

Thank you for managing my funds for this donation! You have been absolutely trustworthy.
91  Other / Beginners & Help / Re: In a discussion, you discuss! on: April 02, 2024, 10:12:33 AM
<snip>
I think the most important job for the manager is in the selection. Many of the users who apply have been in campaigns before anv how they posted there is still available on their profile, go through that and decide if the member is posting solely for the payment or offering quality to the forum. This way you don't have to keep judging their posts weekly, except it drops significantly in quality and effort.

Yes true. The only problem is that this leaves a narrow space for new members to join campaigns.
92  Other / Beginners & Help / Re: In a discussion, you discuss! on: April 02, 2024, 10:06:36 AM
It's also not a true test of quality and will drive some members to post outside their comfort zone if it doesn't get regular merits and can reduce the actual exposure the project is getting as everyone will be posting in the exact same boards.

But that's why I suggested different payments. So that a user can be paid upon unmerited posts as they used to, but they also have a chance to educate themselves more and to write more constructive posts to earn the extra merit and therefore, the extra bucks.

Why time frame will it be calculated on? Merits are earned weeks after a post is made.

That's indeed an issue... But I guess it good work on a monthly basis. So, if a user had posted X posts in a month, then they could get paid monthly using the scheme I suggested above. I know it's not a great pattern, based on the argument you have mentioned. It needs some tweaking but we could find a way.
Anyway... Just a thought.
93  Other / Beginners & Help / Re: In a discussion, you discuss! on: April 02, 2024, 09:41:26 AM
You are not wrong and yes, I've noticed this behavior and who knows I may even be guilty of this. I just think that since this is a social space, there are different peeps with their behavioural patterns that don't really see it as much of a necessity to do something out side the box. This attitude is because they don't bother to read what the person before them said just as you keenly observed. This matter of users making repetitive words just to meet post count is something so many people have complained about, proffered solution for yet it still happens and this often occurs in the gambling section and I'm wondering if there will ever be lasting solution for it or will just have to make do?

There are solutions. The easiest one is to use text comparator. But if you want to go a step further, you can also read the whole discussion and use it to judge whether a post deserves to get paid or whether it doesn't.

However, this solution is not possible, because the most reputable campaign managers, manage a bunch of campaigns each. And each campaign has several members, so reading all the posts is a very time consuming task.

What I would do, if I were a campaign manager, would be to pay differently depending on if the post is merited or not. And to avoid merit exchanging I would put a requirement of being merited by at least 3 different members.

Imagine something like this:

Each post will be paid with X dollars.
Each post merited by at least 3 different accounts will be paid with Y dollars.
Each post merited by more than 10 people will be paid Z dollars.
94  Economy / Collectibles / Re: [FREE RAFFLE] - Custom eXch Cryptosteel Capsule (#5)! on: April 01, 2024, 05:45:22 PM
I 'd like to get 22, but if not available, then I 'd like 89, and then 39.

If more than one available, please include any of them you wish.
95  Other / Beginners & Help / Re: In a discussion, you discuss! on: April 01, 2024, 05:20:37 PM
You won't blame those sets of people because to them it's easier to 'rephrase' answers than make a different response especially if the question is the type that is a bit technical or might need researching. Some how the aim of coming into the forum and learning new things from information given is slowly being blindsided by these users who just sort of copy and paste what someone else has already talked about.

No, I am not blaming anyone, but I can't close my eyes when I see people posting with the obvious purpose of making some quick bucks by copy-pasting other peoples' posts. Am I wrong? Haven't you spotted this behaviour in the past?
96  Bitcoin / Hardware wallets / Re: Jade DIY hardware wallet on: April 01, 2024, 05:16:24 PM
I think, I wouldn't be as scared as fillippone is. After you can revive the device by re-flashing the firmware and it doesn't nag with further obvious instability or hangs, I'd dismiss the previous glitch as a one-time hiccup. Am I reckless?

You aren't. I don't care very much to be honest, but I understand fillippone's concern, because it's a natural behaviour to be concerned when things like this happen and especially when they happen to devices that are used to hold secrets of any type. Could be private keys, gpg keys, passwords, anything like that.
97  Bitcoin / Development & Technical Discussion / Re: What's the best way to create a super/meta/mother/master mnemonic seed? on: April 01, 2024, 05:13:03 PM
I have books that I've owned since childhood. They're fine. If I'd place a piece of paper between them, the mice would have to eat so many books that I'd have to notice. Or use a metal container, or a safe.

It can't happen. There is no way on earth, especially considering that we should check our backups every now and then. Bugs and mice will never eat a backup seed phrase.

BTW: I just noticed the "professional shitposter"  Tongue
98  Bitcoin / Hardware wallets / Re: Jade DIY hardware wallet on: April 01, 2024, 10:42:21 AM

Maybe a cosmic ray particle or photons incident at the wrong place and time affecting the startup process when apogio turned on his device? Speculation...


Wow, what's that? Sounds intriguing, my knowledge in physics sucks haha

As far a the backups are concerned. Yeah, obviously nothing bad happened. In fact, as I have said, my Jade is amnesiac. Every time I turn it off it erases its memory. So I always need to scan a QR code to load my wallet. Nothing is persisted once it's shut down.

99  Other / Meta / Re: Adjustments to Merit calculation on: April 01, 2024, 08:28:22 AM
It's funny but I kinda liked this system.  Tongue
100  Bitcoin / Development & Technical Discussion / Re: What's the best way to create a super/meta/mother/master mnemonic seed? on: March 31, 2024, 08:41:22 AM
You'll print this:
6PYS1nzuGgFB4WunA9xzHRWxd5xWhLBFxpgTGEQ2z7fggB767rLnKSYHQK (I created this one with a random private key as password, so there's absolutely no way this can ever be recovered (but the 6P-key is valid)).
An attacker has no idea what's in it. But for your own convenience, adding the address makes funding a lot easier. As always, it's a balancing act between security and convenience.

Or print a whole page filled with lines like this, and only one that works with your password. The attacker will have no idea which one is the real one, and if you forget, you can spend half an hour trying your password on all of them. I consider half an hour of typing a small price to pay for peace of mind.

Looks promising, I need to study it a bit more. Does it work only with encrypting single private keys? Or does it also work with seeds (HD wallets)?
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 ... 63 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!