81
|
Economy / Service Announcements / Re: Inputs.io | Instant Payments | Easy API | Secure Wallet | Offchain | No fees
|
on: July 03, 2013, 06:48:59 PM
|
It seems you put a lot of thought into security measures. Still it seems the callback API is somehow lacking. The only proof that the callback is actually coming from your site is the IP-Address of the sender. There are possibilities to spoof the source IP of a TCP connection, especially in a case where the attacker has access to the subnet of the receiving system (see e.g. http://www.symantec.com/connect/articles/ip-spoofing-introduction). You should consider adding another security layer here. For example on bitcoinmonitor.net callback notifications I added a signature to the callback data which makes sure that the callback was created by the server and not someone else (see http://www.bitcoinmonitor.net/help/ -> section "security"). As the signed data does not contain a time component this is probably still prone to replay attacks of the same request with same signature and spoofed sourceIP, but at least raises the bar. And I am sure there are advanced cryptotechniques that could also close this attack vector.
|
|
|
85
|
Local / Deutsch (German) / Re: Just-Dice.com - Geniale neue Gamblingseite mit Investmentfunktion -
|
on: June 26, 2013, 09:14:40 PM
|
Also dooglus ist einer der wenigen hier denen ich ohne sie persönlich zu kennen 99% vertrauen würde. Jedenfalls genug um ein paar BTC zu investieren Ich hab eher Angst dass er selber von dem Erfolg überrant ist und vielleicht die site nicht die Sicherheitsvorkehrungen hat die sie bei solchen Beträgen haben sollte. Dooglus hat selber übrigens nur 250 BTC investiert. Was mich an dem Konzept etwas stört ist, dass durch diese riesige Investsumme der Gewinn prozentual immer kleiner wird. Also statistisch gesehen macht die Site 1% Gewinn über alle Wetten. Mein Invest ist inzwischen geschrumpft auf 0.16%. Damit krieg ich also nur noch 0.01*0.0016 von allen Wetten :-/ Das macht also auf Dauer keinen Spass. Das Problem ist dass die Wettsummen nicht genauso steigen wie die bankroll. Bloß weil man jetzt 116 BTC mit einer einzelnen Wette gewinnen kann machen steigt der durchschnittliche Wettbetrag nicht auf x BTC.
|
|
|
90
|
Local / Projektentwicklung / Re: Bitcoin Börsenprojekt
|
on: June 19, 2013, 11:15:49 AM
|
Klingt irgendwie interessant, aber ohne weitere Details zu wissen halte ich mich raus. Ich denke es wäre auch nicht schlimm schon jetzt mehr Details zu veröffentlichen. Wenn die Idee so einfach ist dass sie eh jeder Honk nachbauen kann macht es sowieso keinen Sinn. Falls mehr dahintersteckt wird es auch so schnell keinen Nachahmer geben.
|
|
|
92
|
Other / Meta / Re: "Important announcements"?!
|
on: June 17, 2013, 07:31:09 PM
|
Yep, it's a pretty good point, which is why I have requested deletion of my ad.
Damn decent of you. +1. (And sorry for mixing up Mods and VIP)
|
|
|
93
|
Other / Meta / Re: "Important announcements"?!
|
on: June 16, 2013, 08:42:03 PM
|
Yeah, there are actually quite a few "announcements" in there that I don't see very important at all and some (e.g. new releases of main bitcoin wallet software like bitcoin-qt or Armory or electrum) are not posted there...
Most threads are about hacks, compromises and lawsuits or their fallout. Is this really the impression that "important announcements" of the Bitcoin community wants to give of Bitcoin?
Posting threads about how one can earn some sub-cent amounts for using a centralized, closed source, proprietory version of IRC is also not the solution imho.
+1! I was just thinking wtf why is advertisement posted under important announcements. Then I realized that moderator also has it in his sig. Oookay. Nice way to abuse one's power.
|
|
|
97
|
Economy / Gambling / Re: bitbattle.me - instant bets, ZERO waiting! >140000 bets! U.S. player welcome ;)
|
on: June 02, 2013, 01:55:01 PM
|
Since bitcoin-Qt 0.8.2 has been released with updated default tx fee policy I changed the according policy also on bitbattle.me: - Transaction fee for payouts is calculated accordingly (minimum 0.0001 BTC instead of 0.0005)
Also the acceptance policy for unconfirmed transactions is adjusted: - If a transaction has fee >=
0.0005 0.0001, and all inputs are confirmed -> ALLOW - If a transaction has fee <
0.0005 0.0001, but all inputs are confirmed -> ALLOW - If a transaction has fee <
0.0005 0.0001, and at least one input is unconfirmed -> REJECT - If a transaction has at least one unconfirmed input but fee >=
0.0005 0.0001 -> ALLOW - If a transaction has at least one unconfirmed input and fee <
0.0005 0.0001 -> REJECT
Have fun
|
|
|
100
|
Economy / Gambling / Re: PrimeDice.com | The New Way to Roll | 1% House | Instant Betting
|
on: May 24, 2013, 09:09:47 PM
|
Just had a few rounds here (username Herbert) and have to say I'm impressed! The UI is totally slick, bets are rolling fast, everything works fine. So it looks like I need to figure out some new ways to get rich Have to say though from my own experience: I can't believe you are running with 1% house edge. The variance will kill you unless you have huge piles of bitcoin. I started bitbattle.me with 1.8% and raised to 1.9 after a few months and still on overall the real house edge I have is way below 1%
|
|
|
|