Bitcoin Forum
May 27, 2024, 03:41:37 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 [48] 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 ... 146 »
941  Bitcoin / Legal / Re: What happens if an NDA is in limbo? on: June 24, 2012, 03:44:36 AM
Thanks for pointing that out. The NDA had both my name and the owners name of the company with one line above each name(the area for signatures)
942  Other / Off-topic / Re: Facebook removes his "credits" and introduces local currencies on: June 24, 2012, 03:22:09 AM
I now know that value programmers attribute to their work... Interesting.
943  Bitcoin / Legal / What happens if an NDA is in limbo? on: June 24, 2012, 02:39:31 AM
Okay I doubt their are much lawyers in here but I'm sure their are people with experiences....

Suppose I sign an NDA and I send it to the other party but never receive a copy with their signature on it with a promise that I'll get a copy(soon lol).
From a legal stand point where is my obligation to abiding by an NDA at this moment in time?

I'm not asking because I'm an asshat and want to release information but I feel that the other party has some kind of "political"(probably not the best word to use) leverage over my actions and I say this because I was given information before I signed the NDA

What are you thoughts on this?
What are my rights?

(This was basically a general run of the mill NDA with the time frames changed as being the only alterations)
(I will take your reply as a comment and not any type of legal advice and you will not be held accountable for any of my actions for any advice or comments you present to me)
944  Other / Off-topic / Re: Facebook removes his "credits" and introduces local currencies on: June 24, 2012, 02:30:29 AM
Nice advice mates, Id just rather not spam my computer with folders or take up github space(for free, im no leech).
I have an odd ability to recall code line by line with little errors, but now when my friends or family ask me about <insert some moment here> it takes awhile before i can recall what they are talking about-- those who know me think i have bad memory but i just tell them they need say the right things to trigger my brain to recall what they are referring too. Its a curse in social situations but makes me highly efficient in programming situations.

You, my friend, are one exceptional person. (please don't take this the wrong way)

None taken  Cool

No need to use github or any other server. Git init creates a local source control system in a hidden directory in the project root. I use them all over my computer for little test projects, notebooks, docs etc. Git is much more lightweight than the server oriented svn and is great for random light weight junk.

I didn't think about strictly storing locally.
My situation is still the same though.
945  Bitcoin / Bitcoin Discussion / Re: Don't Buy Bitcoins Youtube video. on: June 22, 2012, 11:25:21 PM
I saw it a long time ago aswell and its funny how he trys to educate his audience what money is for and fails misrebly in the first minute not to mention his biased and unresearched opnions
946  Other / Off-topic / Re: Facebook removes his "credits" and introduces local currencies on: June 22, 2012, 07:05:59 PM
Nice advice mates, Id just rather not spam my computer with folders or take up github space(for free, im no leech).
I have an odd ability to recall code line by line with little errors, but now when my friends or family ask me about <insert some moment here> it takes awhile before i can recall what they are talking about-- those who know me think i have bad memory but i just tell them they need say the right things to trigger my brain to recall what they are referring too. Its a curse in social situations but makes me highly efficient in programming situations.

For serious project or open source projects of course i use source control its essential, in the event too many merges happened and the whole thing gets fubar'd
947  Bitcoin / Project Development / Re: BitDrop (or ShadyDeliveryNetwork), a non-robotic courier system on: June 22, 2012, 06:44:23 PM
I can supply a device that peroidically ping gps locations through the cellular network and these devices can be sold to either runners and/or customers to place in their package to make sure it gets their.

Basically someome needs to create a website that looks up the route of the package and then queries the nearest runners asking if they can full fill the order for X amount of btc(along with estimated amount of $$$).
Sounds simple

What if runners are unavailable to pick up packages like they promised? (family member died, rush to hospital , some other extreme reason?)
948  Bitcoin / Bitcoin Discussion / Re: [ANN] Cheaper In Bitcoins | Merchant Updates | Beta Phase on: June 22, 2012, 05:28:38 AM
*Customers can now view and edit their shopping cart
949  Bitcoin / Bitcoin Discussion / Re: [ANN] Cheaper In Bitcoins | Merchant Updates | Beta Phase on: June 21, 2012, 10:24:49 PM
*The product editor is a lot more intuitive and is a true WYSIWYG editor now.
--Still working on the product image uploader for the new WYSIWYG editor
950  Other / Off-topic / Re: Facebook removes his "credits" and introduces local currencies on: June 21, 2012, 08:11:56 PM
My knowledge and experience is constantly evolving, If I save my code how will I ever know my true potential if I'm always locked in the past of old problems?  Cool
But really, Its all in my head, if i wanted to rewrite the engine I could do it again in about a day(even though the engine took 3 months to build originally) since I've embedded everything to memory it s just better to recall my research and write code in real time so that way I can incorporate my older research with new experience.

Ka peesh?

ps. now that i think about it im more mad at face book putting in that poclicy when i was finished then the fact that i deleted my source code.
951  Economy / Marketplace / Bitcoin Postal Service? on: June 21, 2012, 08:08:04 PM
Is there a way I can ship things with bitcoins? (Obviously by some means of converting it to UPS, FedEX, DHL, etc)
I got rid of all my bank accounts so now I kinda left thinking I should probably reapply Tongue
952  Bitcoin / Bitcoin Technical Support / Re: Encrypted cookie signs GET requests through HTTP to avoid XSRF on: June 20, 2012, 11:11:24 PM

Still, as long as ... you know what you're doing

Thats what i meant actually. that I've seen some php programmers rely completely on the safety of php sessions not realizing that its just really a cookie session and nothing more.
953  Other / Off-topic / Re: Facebook removes his "credits" and introduces local currencies on: June 20, 2012, 08:14:19 PM
I developed an MMO gaming engine that was an over head 2d flash game. It had zombies, survivors, shooting guns, lots of weapons, flame throwers, side missions, lag reduction algorithims, and anti hack check sums the game was open world with vast levels to explore.  Right when i was about release it facebook scraped the option to allow credit card and put in their policy that any one not using facebook credits would have their game removed so i made my own website to facilitate alt payments of course scince it wasnt on facebook any more no body was interested and all my beta testers dropped off and everyone lost interest. Lol no im kinda mad i didnt save my code now that they brought the policy back to normal. Maybe illl just use jmonkeyengine next time instead.
954  Economy / Lending / Re: [Withdrawed Offer] Butterfly labs & solar loan on: June 20, 2012, 07:58:56 PM
Doing my own research i feel there is propaganda to get less people to solar mine....
955  Bitcoin / Bitcoin Technical Support / Re: Encrypted cookie signs GET requests through HTTP to avoid XSRF on: June 20, 2012, 07:55:42 PM
I'm not sure it's been made very clear from the above argument (both parties obviously know what they're talking about, but it doesn't help Xenland if you're not familiar with the ideas already); PHP sessions are not sufficient on their own to prevent CSRF... in fact, PHP sessions are the thing that makes CSRF possible.

Let's say in tab1 I'm logged into bitcointalk.  "Logged in" means I have a session cookie on my browser that is sent with every request to the the server, allowing the server to access my server-side "state".  The stateless HTTP has become stateful.  The session cookie is usually some long, random number that can't be guessed and is known only to your browser and the server.

Now, in tab2, some malicious site runs javascript that sends a carefully crafted POST message to bitcointalk that makes the currently logged in account send a PM to the attackers bitcointalk account and a second POST to change the logged in account's password.  My browser, quite correctly, includes my PHP session cookie with both of these requests, which makes bitcointalk run them exactly as if I had intentionally performed those actions.  Now imagine that it's your bank account open in tab1.  (also note that the CSRF doesn't require the tab to be open, only that the session cookie is still valid, I've used tabs just to illustrate)

The solution is to make a session cookie necessary but insufficient to perform these actions.  In the server-side session you make up a random number, a session nonce.  You then include that nonce as an <input type=hidden> variable in any POST form.  If that number is not present in the POST request, then the request should be denied.

So, legitimate pages in tab1 will include this nonce because the server knows it and includes it in the <form>s it sends.  tab2's javascript is sandboxed away from tab1 and cannot read it's DOM and hence cannot read the nonce.  Any malicious POST requests it makes will be ignored.

Depending on what information is fetchable via a GET request, you may also consider adding that nonce to every URL your serverside code generates as well. For example, I wouldn't be surprised to find a web site that has "https://insecuresite.com/accountdetails.php" pre-load the account details form with your password.  tab2's javascript would then just read that page to get your password.

You see then that it isn't true that simply using PHP sessions stops CSRF (it's more true to say that your PHP session is what is being attacked in CSRF); but CSRF protection is definitely implemented using PHP sessions.
Thank you for taking the time to address my concerns with great detail. Finally someone who is a better communicator can explain why I don't like PHP sessions. Also I refuse to use sessions as when I merge my code with open source library becuase there are possibilites that a Cheaperinbitcoins library might be shared on the same VPS (2 diff websites on the same box) and i know php sessions are guessable to some extent with multiple websites running as the more users take up the total unique php session ids the eaiser it becomes to generate/guess a php session. Atleast with homegrown cookie sessions they are less guessable if done correctly.
956  Bitcoin / Bitcoin Technical Support / Re: Encrypted cookie signs GET requests through HTTP to avoid XSRF on: June 20, 2012, 05:59:39 AM
Thanks for the information mates! now I feel more confident implementing this.
957  Economy / Services / Re: Sponsors are needed for my next BeagleBone tutorial all are welcome! on: June 20, 2012, 05:55:56 AM
I couldn't find a contact page but i sent them a message through face book
958  Economy / Services / Re: Sponsors are needed for my next BeagleBone tutorial all are welcome! on: June 20, 2012, 02:30:32 AM
I'm creating a Knight Rider tutorial (which can oddly enough be turned into a Digital-to-analog driver aka Speaker as a follow up tutorial) if anyone would like to sponsor my next tutorial.  If you want me to say something custom it will cost 3 BTC.

My last sponsors tutorial looked like this: http://www.youtube.com/watch?v=HzYcRFoOVQ8

please PM me for inquiries and send me your logo.
959  Bitcoin / Bitcoin Technical Support / Re: Encrypted cookie signs GET requests through HTTP to avoid XSRF on: June 20, 2012, 12:53:03 AM
This is why I would Use php sessions then you can make sure the correct user is logged in and make the XSRF almost impossible to do.
I feel I'd have to rewrite my entire code to facilitate that on top of many of the negative experiences I've heard from php sessions.
960  Bitcoin / Bitcoin Technical Support / Re: Encrypted cookie signs GET requests through HTTP to avoid XSRF on: June 19, 2012, 10:42:15 PM
No Input?
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 [48] 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 ... 146 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!