Bitcoin Forum
April 30, 2024, 09:26:38 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Other / Serious discussion / Security Standards in the Crypto Community Sites (or the lack of them sometimes) on: February 01, 2018, 12:28:36 AM
Something has been bothering me. So, we're all really aware of the number of hacks, attacks and thefts from Exchanges & Online Wallets across the crypto scene, and you'd think that considering that cryptocurrency is crypto first, a currency second that the larger names would have a clue about digital security on the net. But, it's pretty clear they don't.

A basic, and personally I consider, a mandatory, set of security to ensure is set when you're setting up a web frontend is the security headers- it stops a lot of common attacks (Cross Site Scripting, preventing Framing a site to stop masquerading & keylogging, enforcing HTTPS, enforcing cross-origin, etc)- and it's pretty much default in high risk sectors like Financial Services or even the big Social Network sites- and it only requires setting a few simple header values. It turns out, a lot of them don't even do this basic thing and then people end up getting screwed.

This site was setup by a guy who was frustrated at the lack of Security Headers on a lot of e-commerce sites, so he came up with a really simple grading system based on whether sites have implemented adequate protection, and explains what each header does (NOTE: don't know the guy, but the site is legit from a Security and Computer Science perspective).

So, with that in mind, I decided to check some of the bigger names in Crypto. The results were:

SiteGradeNotes
GDaxA+ GradeThe best score here and best score possible.
KrakenA GradeOnly thing they haven't set is the Referrer Policy- which means it potentially could leak data to another site on navigation away. Otherwise, excellent work.
BitcoinTalkB GradeFor a forum, this is fine, but a Referrer Policy would be a nice to have.
Cex.ioC GradeNo STS, no CSP, no Referrer Policy- means HTTPS can potentially be circumvented, XSS is still possible and could leak information on navigation away.
BittrexE GradeHave at least set X-Frame-Options, but still vulnerable to an XSS attack, has no CSP, and can sniff content types- not good
ShapeShiftD GradeHave at least set X-Frame-Options, have set the X-XSS-Protection header but are still vulnerable to some XSS edge cases, has no CSP, and can sniff content types.
PoloniexC Grade
CoinbaseA GradeOnly reason it's not an A+ is that it uses 'unsafe-inline' in their CSP which isn't recommended but would require someone compromising their source.
LocalBitcoinC Grade
GeminiD GradeSeems that the Winklevoss twins can get licensed, but not set some pretty basic Security Headers. At least they have STS enabled.
Blockchain.infoB GradeMainly good, but could do with the Referrer Policy to not leak data about what you've been doing on their site.
MyEtherWalletF GradeLiterally doing nothing. Solution for the problem (move the hosting to Netlify and set headers- $0 cost) suggested to them 1 month ago. Great project, but the hosting really undermines it.


To give a comparison, this is the results for some of the bigger banks & sites on the net:

SiteGradeNotes
Chase (JPMC)A Grade
FacebookA Grade
Wells FargoB GradeGood, not perfect, but good.
HSBCC GradeNot great but there is worse...
Bank of AmericaD Grade... LOL
TwitterA Grade

Considering the money on the line, am I alone in thinking this needs to get better, quickly?

I'm really interested in everyone thoughts- including any of the site owners.
2  Alternate cryptocurrencies / Announcements (Altcoins) / [ANN][PRESALE][TRU] TRU REPUTATION NETWORK: Decentralized Proof Of Reputation 🚀 on: January 09, 2018, 02:23:32 AM









3  Alternate cryptocurrencies / Bounties (Altcoins) / [BOUNTY][PRESALE][TRU] TRU REPUTATION NETWORK - ⚡️ 160,000 TRU TOKENS/160 ETH ⚡️ on: January 09, 2018, 12:57:03 AM


TRU REPUTATION NETWORK BOUNTY CAMPAIGN


The Tru Reputation Network is the first decentralized Proof of Reputation Platform



Leveraging a patent-pending algorithm, the Tru Reputation Network eliminates the problem of fake reviews and feedback, and redresses the economic
balance of feedback- those who provide feedback earn, Platforms wanting to use that information, pay for their usage.


For more information, please see our ANN THREAD



Overview



As part of the Tru Reputation Network Pre-Sale, we have allocated 8% of our Token Pool for all bounty campaigns. We are currently offering 20% of this Pool (1.6% of total tokens) for our Pre-Sale Marketing Bounty Pool with the rest reserved for Post-Sale Bounties, additional Content Bounties and Security Bounties. This thread will cover the campaigns associated with the Tru Reputation Network Pre-Sale only- additional threads will be created for the other Bounty Pools in the coming days and weeks.

Assuming the Hard Cap for the Pre-Sale is reached, a total of 160,000 TRU Tokens will be available in this pool with the value of these tokens, being 160 ETH/BTC12.256.





Campaigns:


The following campaigns are covered in this thread:


Campaign #1: Telegram  -   20% of Pre-Sale Marketing Bounty Pool
Campaign #2: YouTube   -   15% of Pre-Sale Marketing Bounty Pool
Campaign #3: Blogs & Articles   -   15% of Pre-Sale Marketing Bounty Pool
Campaign #4: Social Media   -   25% of Pre-Sale Marketing Bounty Pool
Campaign #5: BitcoinTalk Signatures   -   25% of Pre-Sale Marketing Bounty Pool



CAMPAIGN #1: TELEGRAM



CAMPAIGN OVERVIEW: Campaign #1: Telegram is a Telegram Group recruitment and engagement campaign to promote and raise awareness of
the Tru Reputation Network Pre-Sale.

CAMPAIGN POOL VALUE: Up to 32,000 TRU (32 ETH)


Campaign Notes:


                    Each week ends at Sunday 10am UTC
                    Stakes will be awarded each Sunday
                    Stakes are earned for joining and being active in the group or inviting additional members to the group.
                    Proactive accounts will receive a multiplier of their stakes at the close of the campaign (2-3x).
                    Maximum stakes for invites to the group is 1,000.



Campaign Rules:


                 1.   Vulgar or negative members will be removed.
                 2.   Only SFW content allowed.
                 3.   No advertising of other projects or groups.
                 4.   Spamming is not allowed.
                 5.   2 strikes rule- one warning, and then you will be removed.
                 6.   Inactive accounts will not receive any shares.
                 7.   Accounts with negative trust are not permitted to join this Campaign.
                 8.   The Tru Reputation Protocol Telegram Chat Group is English only at present.




Campaign Rates:








How to Join The Campaign:


       2.   Join the Telegram Group at https://t.me/truchat




CAMPAIGN #2: YOUTUBE



CAMPAIGN OVERVIEW: Campaign #2: YouTube is a bounty campaign for rewarding content creators for creating videos about the
Tru Reputation Network and using YouTube to spread the message about the Tru Reputation Network and the
Tru Reputation Network Pre-Sale.

CAMPAIGN POOL VALUE: Up to 24,000 TRU (24 ETH)



Campaign Notes:



                    This campaign is to drive high quality content creation for the Tru Reputation Network, the Tru Reputation Network Pre-Sale and
                 to actively attract more attention, and is not purely about creating additional social graph noise.
                    Each week ends at Sunday 10am UTC
                    Stakes will be awarded each Sunday
                    Stakes are awarded on the quality of the content as assessed by us, that compares both the quality of the video submission
                      as well as the audience reach it has achieved across the lifetime of the campaign. The categories are:
                          o   Low
                          o   Medium
                          o   High
                          o   Professional




Campaign Rules:



                 1.   Videos must be at least 2 minutes in length.
                 2.   Videos must include a link to the website (https://tru.ltd) and to the white paper (https://tru.ltd/whitepaper) in the description.
                 3.   Videos with no voice over will score lower on the quality assessment.
                 4.   Limit of 1 submission per week.
                 5.   English submissions will have a multiplier of 1. All other languages will have a multiplier of 0.5.
                        (Formula: Potential Stakes * Language Multiplier = Awarded Stakes)
                 6.   To combat any plagiarism, we only accept the first original video submission.





Campaign Rates:





How to Join The Campaign:

       1.   Create the content.




CAMPAIGN #3: BLOGS & ARTICLES





CAMPAIGN OVERVIEW: Campaign #3: Blogs & Articles is a bounty campaign for rewarding content creators for creating articles or blogs about the Tru Reputation Network and the Tru Reputation Network Pre-Sale.

CAMPAIGN POOL VALUE: Up to 24,000 TRU (24 ETH)




Campaign Notes:



                    This campaign is for generating high quality articles and blogs that either mention the Tru Reputation Network,
                 Tru Reputation Network Pre-Sale, or are directly about the Tru Reputation Network.
                    Each week ends at Sunday 10am UTC
                    Stakes will be awarded each Sunday
                    Stakes are awarded on the quality of the content as assessed by us, that compares both the quality of the submission as well as the
                 audience reach it has achieved across the lifetime of the campaign. The categories are:
                      o   Low
                      o   Medium
                      o   High
                      o   Professional



Campaign Rules:




                 1.   Blogging platforms such as SteemIt or Medium are limited to 1 post per week.
                 2.   Articles about the Tru Reputation Network require a link to the website (https://tru.ltd) and to the white paper
                 (https://tru.ltd/whitepaper).
                 3.   Videos with no voice over will score lower on the quality assessment.
                 4.   English articles will have a multiplier of 1. All other languages will have a multiplier of 0.5.
                 (Formula: Potential Stakes * Language Multiplier = Awarded Stakes)
                 6.   To combat any plagiarism, we only accept the first original article.
                 7.   No negative articles can be submitted to this campaign.





Campaign Rates:






How to Join The Campaign:

       1.   Create the content.



CAMPAIGN #4: SOCIAL MEDIA



CAMPAIGN OVERVIEW: Campaign #4: Social Media is a bounty campaign for generating social reach and buzz
for the Tru Reputation Network and the Tru Reputation Network Pre-Sale on popular and social media platforms.

CAMPAIGN POOL VALUE: Up to 40,000 TRU (40 ETH)




Campaign Notes:



                    This campaign is for creating high quality engagement and buzz for the Tru Reputation Network
                       and the Tru Reputation Network Pre-Sale.
                    Each week ends at Sunday 10am UTC
                    Stakes will be awarded each Sunday
                    The following social media platforms are included in this campaign:
                      o   Twitter
                      o   Facebook
                      o   LinkedIn
                      o   Reddit
                      o   Instagram
                    You can join any or all of the social media platforms in this campaign.



Campaign Rules:

Each sub-campaign has rules that are unique to each of the Social Media Platforms and are as follows:


Twitter Campaign:


                 1.   Must have a minimum of 200 real followers.
                 2.   Accounts must be more than 3 months old.
                 3.   All accounts will need to generate a Twitter Audit (https://wwww.twitteraudit.com) before registration.
                 4.   Must follow @tru_ltd for the duration of the campaign.
                 5.   No negative tweets.
                 6.   Retweet Stakes are capped at a maximum of 2 per day, and must be spread out in time across the day.
                 7.   Likes Stakes are capped at a maximum of 1 per day.
                 8.   Tweet Stakes are capped at a maximum of 1 per day and must include either #TRURep,
                       @tru_ltd and $TRURep tags.




Facebook Campaign:


                 1.   Must have a minimum of 500 friends or belong to a group with more than 200 members.
                 2.   Accounts must be more than 3 months old.
                 3.   Must follow the Tru Ltd Facebook page for the duration of the campaign.
                 4.   Must like the Tru Ltd Facebook page.
                 5.   No negative posts.
                 7.   Share Stakes are capped at a maximum of 2 per day, and must be spread out in time across the day.
                 8.   Likes Stakes are capped at a maximum of 1 per day.
                 9.   Post Stakes are capped at a maximum of 1 per day and must include #TRURep and @trultd tags.




LinkedIn Campaign:



                 1.   Must have a minimum of 100 connections or belong to a group with more than 200 members.
                 2.   Accounts must be more than 3 months old.
                 3.   Must follow the Tru Ltd LinkedIn page for the duration of the campaign.
                 4.   No negative posts.
                 5.   Share Stakes are capped at a maximum of 2 per day, and must be spread out in time across the day.
                 6.   Likes Stakes are capped at a maximum of 1 per day.
                 7.   Post Stakes are capped at a maximum of 1 per day and must include tagging the Tru Ltd LinkedIn page.




Reddit Campaign:



                 1.   Accounts must be more than 3 months old.
                 2.   Accounts must have over 20 Comment Karma.
                 3.   Must subscribe to the Tru Reputation Network Sub-Reddit for the duration of the campaign.
                 4.   No negative posts.
                 5.   Upvote Stakes are capped at a maximum of 1 per day.
                 6.   Post Stakes on the Tru Reputation Network Sub-Reddit are capped at a maximum of 1 per day.
                 7.   Post Stakes outside of the Tru Reputation Network Sub-Reddit are capped at a maximum of 1 per week.




Instagram Campaign:


                 1.   Accounts must be more than 3 months old.
                 2.   Accounts must have more than 500 followers.
                 3.   Must follow and like the Tru Reputation Network Instagram Account for the duration of the campaign.
                 4.   No negative posts.
                 5.   Share Stakes are capped at a maximum of 2 per day, and must be spread out in time across the day.
                 6.   Like & Comment Stakes are capped at a maximum of 2 per post.
                 7.   Post Stakes are capped at a maximum of 1 per day and must include the #TRURep tag.
                 8.   Comments must not spam hashtags, and must be at least one full sentence/thought. Low effort comments
                       will not gain Stakes.





Campaign Rates:


Twitter:





Facebook:





LinkedIn:





Reddit:





Instagram:






How to Join The Campaigns:

Twitter:

       1.   Obtain a Twitter Audit Report
       3.   Submit a report each week to this thread of all your activity to ensure accurate Stake distribution. Include URLs to the Tweets
              in question and what activity was performed.


Facebook:

       2.   Submit a report each week to this thread of all your activity to ensure accurate Stake distribution. Include URLs to the posts
              in question and what activity was performed.

LinkedIn:

       2.   Submit a report each week to this thread of all your activity to ensure accurate Stake distribution. Include URLs to the posts
              in question and what activity was performed.

Reddit:

       2.   Submit a report each week to this thread of all your activity to ensure accurate Stake distribution. Include URLs to the posts
              in question and what activity was performed.

Instagram:

       2.   Submit a report each week to this thread of all your activity to ensure accurate Stake distribution. Include URLs to the posts
              in question and what activity was performed.




CAMPAIGN #5: BITCOINTALK SIGNATURES


CAMPAIGN OVERVIEW: Campaign #5: BitcoinTalk Signatures is a BitcoinTalk signatures and avatars campaign to promote and raise awareness of
the Tru Reputation Network Pre-Sale.

CAMPAIGN POOL VALUE: Up to 40,000 TRU (40 ETH)



Campaign Notes:


                 •   Each week ends at Sunday 10am UTC
                 •   Stakes will be awarded each Sunday
                 •   Bumping our threads is not necessary, but is appreciated if good quality posts.
                 •   If you are leaving our campaign for another, please post in this thread to let us know before doing so or stakes may be lost.



Campaign Rules:


                 1.   Participants must be at least a Jr. Member or Copper Member.
                 2.   Every participant must place signature and personal text for the duration of the Pre-Sale. If removed before the end, stakes will be honoured to the number of weekly periods successfully completed.
                 3.   Use of multiple accounts will result in a loss of stakes and the accounts being banned.
                 4.   Spamming is not allowed.
                 5.   Minimum of 10 good quality posts each week. Minimum of 75 characters per post.
                 6.   Boards excluded from post count are: Off-Topic, Politics, Meta, Press, Lending, Auctions, Beginners and Help, Archival, Investor based games or Micro Earning.
                 7.   Trust cannot be negative either before signing up or for the duration of the campaign.
                 8.   Multiple signatures are not allowed for non-Hero or Legendary accounts. If you are Hero/Legendary and want to use multiple signatures DM me before signing up so we can discuss the format and placement.
                 9.   Bonus 30 stakes if your post count is above 30 for the week.





Campaign Rates:






Avatars and Signatures:



Avatars:


80x80 Avatars:
Option 1
Option 2
Option 3
Option 4
Option 5
Option 6

120x80 Avatars:
Option 1
Option 2
Option 3
Option 4
Option 5
Option 6

Signatures:

Jr. Member:

★ ★ ★ ★ ★ TRU REPUTATION NETWORK ★ ★ ★ ★ ★
PRE-SALE OPEN UNTIL 5th MARCH 2018 | PROOF OF REPUTATION


Code:
[center][url=http://tru.ltd/tokensale]★ ★ ★ ★ ★ TRU REPUTATION NETWORK ★ ★ ★ ★ ★
PRE-SALE OPEN UNTIL 5th MARCH 2018 | PROOF OF REPUTATION [/url]

Copper Member or Member:


Code:
[center][font=Avenir][url=https://tru.ltd] [b]TRU REPUTATION NETWORK[/b] ★★  [/url][url=https://tru.ltd/tokensale][b]PRE-SALE NOW OPEN [/b]  ★★  [b] PROOF OF REPUTATION[/b][/url][/font]
[font=Avenir][url=https://bitcointalk.org/index.php?topic=2712535.0][b]ANN[/b] [/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://bitcointalk.org/index.php?topic=2711981.0] [b]BOUNTY[/b] [/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://tru.ltd/whitepaper] [b]WHITE PAPER[/b] [/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://tru.ltd/tokensale] [b]PRE-SALE[/b] [/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://t.me/truchat] [b]TELEGRAM GROUP[/b] [/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://tru.ltd/whitepaper] [b]INFO SHEET[/b] [/url][/font][font=Avenir][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://blog.tru.ltd] [b]BLOG[/b][/url][/font][font=Avenir] [b]|[/b] [/font][font=Avenir][url=https://github.com/trultd] [b]GITHUB[/b][/url][/font][/center]


Full Member:


Code:
[center][font=Avenir][url=https://tru.ltd] [b][color=#4173b8]TRU[/color] [color=#65C7F1]REPUTATION[/color] [color=#4173b8]NETWORK[/color][/b]  [color=#65C7F1]  [b]|[/b]  [/color][/url][url=https://tru.ltd/tokensale][color=#444c5c][b]PRE-SALE NOW OPEN [/b][/color][color=#4173b8]  [b]|[/b]  [/color][b][color=#4173b8] DECENTRALIZED PROOF OF REPUTATION[/color][/b][/url][/font]
[font=Avenir][url=https://bitcointalk.org/index.php?topic=2712535.0][color=#65C7F1][b]ANN[/b] [/color][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://bitcointalk.org/index.php?topic=2711981.0][color=#4173b8] [b]BOUNTY[/b] [/color][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://tru.ltd/whitepaper][color=#65C7F1] [b]WHITE PAPER[/b] [/color][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://tru.ltd/tokensale][color=#4173b8] [b]PRE-SALE[/b] [/color][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://t.me/truchat][color=#65C7F1] [b]TELEGRAM GROUP[/b] [/color][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://tru.ltd/whitepaper][color=#4173b8] [b]INFO SHEET[/b] [/color][/url][/font][font=Avenir][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://blog.tru.ltd][color=#65C7F1] [b]BLOG[/b][/url][/font][font=Avenir][color=#444c5c] [b]|[/b] [/color][/font][font=Avenir][url=https://github.com/trultd][color=#4173b8] [b]GITHUB[/b][/url][/font][/center]


Snr. Member:



Code:
[center][size=10pt][font=Avenir][b][url=https://tru.ltd/][size=10pt]                                             [/size][size=10pt][color=#4173b8]★[/color][color=#65C7F1]★[/color][color=#4173b8]★[/color][color=#65C7F1]★[/color][color=#4173b8]★[/color][size=10pt]             [/size][size=12pt][color=#4173b8]TRU [/color][color=#65C7F1]REPUTATION[/color] [color=#4173b8]NETWORK [/color]            [color=#4173b8]★[/color][color=#65C7F1]★[/color][color=#4173b8]★[/color][color=#65C7F1]★[/color][color=#4173b8]★[/color][size=10pt]                                              [/size][size=18pt][/url][/b][/font][/size]
[size=10pt][size=10pt][font=Avenir][b][url=https://bitcointalk.org/index.php?topic=2712535.0][color=#65C7F1]  ANN  [/color][/url][url=https://bitcointalk.org/index.php?topic=2711981.0][color=#4173b8]  BOUNTY [/color][/url][url=https://tru.ltd/whitepaper][color=#65C7F1]  WHITE PAPER [/color][/url][url=https://t.me/truchat][color=#4173b8]  TELEGRAM [/color][/url][url=https://tru.ltd/tokensale][color=#444c5c]   PRE-SALE OPEN UNTIL 5th MARCH 2018  [/color][color=#65C7F1]  DECENTRALIZED PROOF OF REPUTATION[size=10pt]    [/size][/color][/url][/b][/font][/size][/size][/center]


Hero or Legendary Option 1:


Code:
[center][font=Avenir][url=https://tru.ltd/][glow=#65C7F1,2,0][size=10pt][/size][size=10pt]                                         [b][color=#4173b8]★[/color][color=#fff]★[/color][color=#4173b8]★[/color][color=#fff]★[/color][color=#4173b8]★[/color][/b][/size][size=14pt]             [/size][size=12pt][b][color=#4173b8]TRU [/color][color=#fff]REPUTATION[/color] [color=#4173b8]NETWORK [/color][/b]            [/size][size=10pt][color=#4173b8]★[/color][color=#fff]★[/color][color=#4173b8]★[/color][color=#fff]★[/color][color=#4173b8]★[/color][/size][size=10pt]                       [/size][/glow][/url][/font]
[font=Avenir][url=https://bitcointalk.org/index.php?topic=2712535.0][glow=#65C7F1,2,0][color=#fff][size=10pt]  [b]ANN[/b]  [/size][/color][/glow][/url][url=https://bitcointalk.org/index.php?topic=2711981.0][glow=#4173b8,2,0][color=#fff][size=10pt]  [b]BOUNTY[/b] [/size][/color][/glow][/url][url=https://tru.ltd/whitepaper][glow=#65C7F1,2,0][color=#fff][size=10pt]  [b]WHITE PAPER[/b]  [/size][/color][/glow][/url][url=https://t.me/truchat][glow=#4173b8,2,0][color=#fff][size=10pt]  [b]TELEGRAM[/b]  [/size][/color][/glow][/url][url=https://tru.ltd/tokensale][color=#65C7F1][glow=#444c5c,2,0][size=10pt]  [b]PRE-SALE OPEN![/b]   [/size][/glow][/color][glow=#65C7F1,2,0][color=#fff][size=10pt]  [b]DECENTRALIZED PROOF OF REPUTATION[/b][/size][size=9pt]    [/size][/color][/glow][/url][/font][/center]

Hero or Legendary Option 2:


Code:
[center][font=Avenir][url=https://tru.ltd/][glow=#4173b8,2,0][size=10pt][/size][size=10pt]                                         [b][color=#65C7F1]★[/color][color=#fff]★[/color][color=#65C7F1]★[/color][color=#fff]★[/color][color=#65C7F1]★[/color][/b][/size][size=14pt]             [/size][size=12pt][b][color=#65C7F1]TRU [/color][color=#fff]REPUTATION[/color] [color=#65C7F1]NETWORK [/color][/b]            [/size][size=10pt][color=#65C7F1]★[/color][color=#fff]★[/color][color=#65C7F1]★[/color][color=#fff]★[/color][color=#65C7F1]★[/color][/size][size=10pt]                       [/size][/glow][/url][/font]
[font=Avenir][url=https://bitcointalk.org/index.php?topic=2712535.0][glow=#4173b8,2,0][color=#fff][size=10pt]  [b]ANN[/b]  [/size][/color][/glow][/url][url=https://bitcointalk.org/index.php?topic=2711981.0][glow=#65C7F1,2,0][color=#fff][size=10pt]  [b]BOUNTY[/b] [/size][/color][/glow][/url][url=https://tru.ltd/whitepaper][glow=#4173b8,2,0][color=#fff][size=10pt]  [b]WHITE PAPER[/b]  [/size][/color][/glow][/url][url=https://t.me/truchat][glow=#65C7F1,2,0][color=#fff][size=10pt]  [b]TELEGRAM[/b]  [/size][/color][/glow][/url][url=https://tru.ltd/tokensale][color=#65C7F1][glow=#444c5c,2,0][size=10pt]  [b]PRE-SALE OPEN![/b]   [/size][/glow][/color][glow=#4173b8,2,0][color=#fff][size=10pt]  [b]DECENTRALIZED PROOF OF REPUTATION[/b][/size][size=9pt]    [/size][/color][/glow][/url][/font][/center]



How to Join The Campaign:

       2.   Start whenever you want.




Stake Tracking:
[/hr]



Questions:


If you have any questions regarding the Bounty Program, either DM me, post on this thread or join our Bounty Support Telegram Group.
4  Alternate cryptocurrencies / Altcoin Discussion / Lax Security on a lot of Crypto Sites- be careful everyone- a nice simple check. on: January 04, 2018, 11:49:41 AM
Posting this here because it's really starting to bug me.

I got asked by a friend why he keeps seeing Google Ads that are clones of known exchanges- sent me a few URLs, and each and every single one was operating not as a clone, but as a XSS attack because the exchanges didn't have the basic security headers set. Some examples of bad offenders:

Binance Header Report - No CSP policy, no XSS blocks, no referrer policy

MyEtherWallet Header Report - Literally embarrassing, doesn't have anything set at all. Despite being told in their GitHub repo how to fix it and being given a pull request.

Everyone- be careful, and scan the sites you use before you get ripped off by someone doing a drive by.
5  Other / Meta / Account Locked- No reply from Admins for over 3 months on: October 16, 2017, 08:24:44 PM
Hi

My personal account got locked (likely because I logged on from NY when I was originally from the UK- account is that old), I've emailed and DM'd the mods and admins of the site multiple times since- is there anyway to get my account recovered?
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!