Please, service providers... Use the best possible solution available! If you can use multiple SHA512 hashes with each different unique salts form different sections of passwords... do it! If you can run that same thing 5 passes... do it! Don't just go with MD5 + usalt because "no-one will ever get the database". Always prepare for the worst case scenario. HAve graceful hash updates! If a better hashing method becomes available, make users reset their password! (Or have it be done automatically on log in using submitted password for 30 days, and after that time, require reset.) Thanks for listening, do shout at me if you think this is stupid advice!  You're doing it wrong - making people change their passwords every 30 days results in them running out of quality passwords OR them writing their password down. Multiple hashes? If you want to be paranoid that's also the wrong way to go about things, you should use a system like bcrypt and make sure it's slow enough that GPU bruteforce is a no-go. Partition the database too, don't have one big MySQL database with full perms which every part of the site has access to - one exploit on any part and it's game over. Limit it tightly, VERY tightly. Even the human factor can be mitigated - don't give access to EVERYTHING to EVERY employee, restrict things tightly. Use whitelists, not blacklists. You're right, I am doing it wrong - I've only attempted to do it better than large companies do it - which turns out to be completely rubbishly! 
|
|
|
Clicked wrong one, howishot change? 
|
|
|
.202 until the 4 is broken! (Well, .5 as that's minimum entry!  )
|
|
|
I won't be touching this until someone ILDASMs it and proves it's safe  (Even in VM, hwo do you know it doesn't only work x days into the future on the xth second, or something silly, or if a certain transaction is in a block it picks up!) I don't want to be devils advocate, but I would argue that almost everybody uses (and trusts) closed code software. Even if you run Linux and you compiled the kernel yourself chances are that you didn't get the chance to read every line of code. In fact I've been using the official Bitcoin client for month and I haven't even glanced at the code yet, just because I don't have the time right now. I trust the official client because people would complain about it and stop using it if it would be a scam. Anyway I started to run Allbitcoin and transferred a very small amount of coins into it and it works great. I like the GUI. I like the wallet encryption and I think the JSON export/import feature is a fantastic idea to manage multiple wallets! Well done guys. Keep up the good work. I'm looking forward to your future releases!  Oliver. I'm allowed to be paranoid  If something is designed for use wiht bitcoin, only bitcoin users would use it = maximal impact if it did anything fishy bitcoin related.
|
|
|
How is it: based on 0.3.23, tracking changes as they come in and closed source? I won't be touching this until someone ILDASMs it and proves it's safe  (Even in VM, hwo do you know it doesn't only work x days into the future on the xth second, or something silly, or if a certain transaction is in a block it picks up!)
|
|
|
I fell this needs to be a new post to ensure anyone with fears sees it - Just updated, and a payment received, the creator hasn't disappeared! 
|
|
|
Is this still alive  LAst tiem it wans't updated the person put up a thing on the 'sheet reading "gone for 2-3 hours" or something - maybe just this again but forgot to say it?
|
|
|
 , running well
|
|
|
Would it be possible to move the entry time to make it slightly less rubbish for europeans? 
|
|
|
Read first post?
"Temporarily Down Until MyBitCoin.COM Comes Back!"
|
|
|
Pot is greater than the next needed to pay out? (0.625? :S)
|
|
|
If your room is at 90 degree(i guess fahrenheits) and your gpu is at 80 degree(with same scale) then your temp sensor is broken.
i have a coolmaster 932 full tower and the computer is cooler then the room cause of the fans inside it. Fans can't cool below ambient - your temp. sensors are broken!
|
|
|
done a while ago, pm'd at the time, and now in the spreadsheet  Thanks!
|
|
|
Thanks! 
|
|
|
Fail, I mis-sent 0.4... Can I send a 0.1, and get the 0.4 made intoa 0.5? 
|
|
|
Ah, well, time for a mass exodus to some other forum which will then end up having this happen again?
I can see at least getting rid of anything illegal in the country it's hosted in, so you can keep the forums, but getting rid of this = ...
:s
edit: Although, it may have been a bit provocative? I can't really see how that makes it good to get rid of it...
|
|
|
|