Bitcoin Forum
May 05, 2024, 06:34:39 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »
1  Bitcoin / Bitcoin Discussion / Re: how many pieces of BTC? on: February 12, 2016, 12:29:48 AM
It's already increasing.  Wink

25 BTC or 2,5 billion atomic units each 10 minutes.

It's possible to create new subdivisions in case of issues.
2  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [XMR] Monero - A secure, private, untraceable cryptocurrency on: February 11, 2016, 09:33:00 PM
WARNING: Always check you're using https when connecting to xmr.to, a malicious TOR exit node made a victim already.

Somebody was recently scammed of a significant amount of XMRs when he tried to use XMR.TO over TOR.
After a little investigation, we found out what happened: the TOR exit node was malicious, and created an order going to a different address than that requested by the victim. The victim payed the XMR, but never got the BTC, as they were sent by XMR.TO to the scammer address. XMR.TO had no way to know something wrong was going on.
This type of man-in-the-middle attack is not possible when you use https connection. What the exit node did is to downgrade the connection to a normal http, and sadly the victim must not have noticed the lack of secured connection in his browser.

The malicious exit node has the IP 109.201.154.186.

Be safe: ALWAYS check within your browser that your connection is secure when you connect to XMR.TO. If it's just http, that's a phishing version and you're not talking to XMR.TO directly.


This should always look like this:


SSL Labs says the mentioned website supports HSTS (HTTP Strict Transport Security) as well protection against downgrade protocol attacks and gives an A+ grade.

However, it isn't on the HTTPS Everywhere list ( https://www.eff.org/https-everywhere/atlas/?xmr.to ). Probably it would be a good idea to add that as well other Monero related websites. Since Tor Browser has this extension built-in, this could be helpful to avoid this type of incident again.
3  Economy / Services / Re: ❃❃ ▶▷ BETCOIN.ag ◁◀ ❃❃#Signature Campaign-High Pay, Monthly Bonus, Special Award on: February 11, 2016, 01:06:00 AM
Hello,

I would like to participate in this campaign too.

Thank you for the attention.
4  Bitcoin / Bitcoin Discussion / Re: Donald Trump On Bitcoin? on: February 10, 2016, 08:05:09 PM
I honestly doubt any republican would ever support the concept, since banks are among the main donators for their campaigns.


Rand Paul was accepting Bitcoin donations for runnig his campaign.
http://www.coindesk.com/rand-paul-presidential-campaign-bitcoin-donations/

And also participated in Bitcoin related events.
http://www.coindesk.com/rand-paul-new-york-bitcoin-event/
5  Economy / Exchanges / Re: BTER.com hacked| 7170 BTC stolen | DON'T KEEP YOUR MONEY ON AN EXCHANGE | on: February 08, 2016, 12:51:45 AM
Now also cryptsy was hacked , what the hell !!!!

Who knows if they were really hacked...
6  Economy / Speculation / Re: 10 BTC. Will I be a millionaire by 2030? on: February 08, 2016, 12:26:47 AM
No, you'll just have 10 BTC.

Bitcoin is still experimental. I think you should worry about today than waiting 14 years too see which happens.

But it will be a very interesting experince when we reach 2030 if you stop and think about how you were 14 years before...
7  Bitcoin / Electrum / Re: money dissapeared on: December 23, 2015, 05:06:08 AM
I just checked on blockchain. It shows proper balance on one of the addresses which I have in my wallet. Though it`s not the one which I used to receive money, but the one which is staying in the wallet under the title "change". Is that normal? I don`t know why is money moved from one address to another.

Change addresses are used with the purpose of rotating and to avoid the reuse of addresses when you do a transaction. When you send your BTC from the Electrum wallet, part of that is sent to the receiver, and another part is sent to a change addresses.

This is done because reusing addresses is bad for privacy and security (third parties can monitor your transactions easily).
8  Bitcoin / Development & Technical Discussion / Re: Which Bitcoin full node implementations does exist? on: December 23, 2015, 04:59:15 AM
Doesn't Armory count as a full node client?
9  Economy / Gambling / Re: ➫ ➬ ➫ ➬ LUCKYB.IT ★ +1.8M bets ★ +94000 BTC wagered on: December 23, 2015, 03:59:37 AM

SSL implementation is not a simple process. Getting a signed certificate, implementing security across the site and filtering for non-essential services such as the LuckyBit Community Hub are not a quick-switch option. These things take time and money that aren't justified by a "potential" threat that hasn't been realized and can be easily avoided by customers. Most of our players don't even depend on the site to provide the addresses; the information is available elsewhere and the majority of wallets also provide address-book services that would make this attack ineffective.

tl;dr: not worth the effort for an attacker, not worth the effort for us

For a website which claims to have more than 94000 BTC wagered, I don't think an argument like "not worth the effort for us" sounds plausible. You just don't want, admit it.

Claiming the information is available in other parts isn't a valid excuse too. Is there some place in the website saying this? No? And what about new users?


Man in the middle attack isn't a problem for luckybit because:

1.- MITM is a LAN attack. That mean the only users who will be affected are those who are on the local area network of the attacker. Users access point is users responsability, if you are on a not secure network better don't use bitcoin, because if you are under MITM attack, the hacker will not change the betting addys, he will get your blockchain.info wallet access information.

It depends on the wallet. blockchain.info uses an HTTPS conection, so it's unlikely to be affected. Even if you're affected, the HTTPS conection will be gone and the lock in address box of the browser won't appear.

About the LAN attack, well, you can take care about your network, but when this goes to your ISP, international routes and so, you lose the control of what goes on.



2.- MITM can be detected by users with tools like wireshark. But is responsability of the user to verify if the network is secure.

Do you really expect average people to use wireshark in order to detect if there's a MITM happening?

It's much more simple having an HTTPS website. If it isn't encrypted, there will be lock on the browser. If it presents an invalid certificate, you'll receive an alert.

3.- MITM have a tool called sslstrip to bypass the SSL connection, so, change the site to SSL will fix nothing about the attack.

sslstrip turns HTTPS traffic in HTTP. But to be effective, the user needs to go further and ignore the lack of HTTPS. Aside of this, there are tools and settings to avoid these types of downgrading, like HSTS.


Make a man in the middle to change luckybit addys, is one of the worst things you can do with this attack. Because if the users don't see the bets rolling they will ask to support what happen?, then we will ask for the TX ID, and in that moment we will see the fake addy. How much the hacker get? 0.005? 0.01?... not really a big lost. So, that attack is just a waste of time if some one is thinking about use it that way.

I want to make emphasis on the point of; This has never happened to luckybit and isn't something to worry about.

Well, a more sophisticated attack can try to replace the entire game too.

And again, the "this never happened" isn't a good reason. You need to consider the possibilities and risks, not the "it never happened".

But it seems you think it's more simple to deal with an eventual problem than fixing the origin of it. OK, it's your choice. A bad choice, I think, but, well...
10  Economy / Service Discussion / Re: A website that compares your wallet to all wallets? on: December 22, 2015, 04:14:06 AM
Like this?
http://ondn.net:800/search

Just to notice, the information here is about addresses. But you can have an "infinite" number of addresses.
11  Local / Português (Portuguese) / Re: Whatsapp bloqueado com uma simples canetada ! Agora tentem bloquear o Bitcoin :D on: December 21, 2015, 10:49:35 PM
O triste é que a definição de VPN pra as pessoas leigar é: Aplicativo que faz o whatsapp voltar a funcionar  Sad

Hahahaha pois é. Todo mundo que me pergutava pela VPN eu indicava para nao baixar... melhor esperar ou usar o telegram do que deixar todas as informacoes da tua rede passando por computadores de terceiros.
è a parte ruim é esse detalhe da segurança né

Se o tráfego é criptografado em trânsito desde a origem, a princípio  não há problema, independentemente do VPN.

Mas de fato o pessoal se meteu a indicar VPNs de origem duvidosa, e ainda com TLS, isso não é uma boa ideia. Bons VPNs geralmente são pagos, têm suporte ao OpenVPN e política anti-logs.

Uma outra alternativa seria o uso da rede Tor.
12  Economy / Investor-based games / Re: CryptoPayouts - Up to 112% After 75 Hours - Working Capital for Longevity on: December 21, 2015, 05:05:25 AM
Quote
We began earning and investing funds in many online revenue share companies using any additional profits now for our own projects and more. Bitcoin is a new online cryptocurrency that we have began buying and trading in June 2012. With unleveled business measures and working capital to operate our own investment fund business, we have the full ability to run our bitcoin earning platform.

With over 9,000 online revenue shares earning consistent profits for us, we are set to purchase more revenue shares to grow more working capital for our investors. Being able to produce more funds by growing our online revenue shares makes our cryptocurrency platform become a very sustainable investment business.

http://cryptopayouts.com/about_us.php

We? Who are you, scammers? Oh, of course, you put something to working with "capital" but you don't say anything about who you are. Hey, people, look at what you're "investing". Nothing about those "ad shares".

https://whois.domaintools.com/cryptopayouts.com

Oh, and no HTTPS. Even if this was legit, it wouldn't be considered secure.

Nice try, OP. But do a favor to yourself: get out from the internet and go to search for a serious job.
13  Economy / Gambling / Re: ➫ ➬ ➫ ➬ LUCKYB.IT ★ +1.8M bets ★ +94000 BTC wagered on: December 20, 2015, 09:39:30 PM
A MITM attack against LuckyBit could - at worst - replace the game addresses with malicious ones.

This is a sufficient reason to put HTTPS. The attacker has a financial incentive to repllace those addresses.

There has never been a report of MITM attacks against LuckyBit.

Until it happens. But why wait until an incident happens if you already can fix the issue?
14  Economy / Gambling / Re: ➫ ➬ ➫ ➬ LUCKYB.IT ★ +1.8M bets ★ +94000 BTC wagered on: December 20, 2015, 05:26:49 AM
Excuse me, but websites like this MUST work properly with HTTPS (and enabled by default). It's unacceptable the use of HTTP in this type of thing, due to the risk of MITM attacks.

Unfortunately, trying to use it with HTTPS (inserting 'https://' before the domain name) just redirects to the CloudFlare page with the 522 error.
15  Local / Economia & Mercado / Re: Quanto vale uma conta Hero Member aqui do fórum? on: December 20, 2015, 02:23:55 AM
Eu atualmente ganho bem mais com posts aqui do que ganharia com o genesis mining rsrsrsrs

Cara meu activity num faz o update. Jah to com 61 posts e ainda newbie  Undecided To querendo virar JR também pra ganhar uns satoshinhos  Cheesy Cheesy

A atividade aumenta apenas em um máximo de 14 pontos (não sei se "pontos" é o termo correto, mas enfim) a cada 2 semanas.
16  Economy / Investor-based games / Re: BTC invest | double your bitcoins in 1-2 weeks on: December 19, 2015, 08:35:05 PM
Clearly a scammer... Fresh website, anonymous operators...
https://whois.domaintools.com/bitcoin-doublers.com

Also no TOS.

And one of the deposit addresses was used prior to the register of the website!!!
https://blockchain.info/address/14qpqvmUmQ3ibh8PUVi1H5KdrapijWprue

https://i.imgur.com/NsqsXSN.png
17  Other / Off-topic / Re: How did you come to bitcointalk.org on: December 19, 2015, 07:46:06 PM
Typing bitcointalk.org in the web browser in a computer connected to the internet.  Tongue

I was looking about Bitcoin in multiple sources, probably one of those have mentioned bitcointalk.org.
18  Other / Off-topic / Re: Best antivirus? on: December 19, 2015, 07:38:35 PM
Antivirus sucks. Stay away from this type of software.
http://arstechnica.co.uk/security/2015/09/security-wares-like-kaspersky-av-can-make-you-more-vulnerable-to-attacks/

The security of the computer is responsible user and updated OS, browser and other softwares. BTW, some antivirus like Avast add their own SSL certificate into the OS and execute a MITM attack on HTTPS websites in order to scan the content.

AVG sends your personal information to third parties with commercial/advertising purposes.
19  Alternate cryptocurrencies / Altcoin Discussion / Re: [POLL] do you take anything out of Spoetnik mouth serious? on: December 15, 2015, 06:44:45 AM
This is ridiculous. People create topics just to ask about the behaviour of obvious trolls. There's nothing to ask here, unless you're just a sockpuppet account! Just put on the ignore list and stop to feed them.
20  Bitcoin / Bitcoin Discussion / Re: What unit do you find more comfortable when measuring BTC values? on: December 14, 2015, 05:15:52 PM
Satoshi and BTC.

Since the major part of the transaction happens with the fractions, I think it's more comfortable to talk about satoshi instead of trying to reading something with 8 decimal points using other units. If not, beeter to read the entire value.

But why someone would create a currency with 8 decimal points instead of using just atomic units is beyond me. Although I wouldn't to see this changing.

I believe that any measurement that uses the metric system is the easiest way to discuss values in general when discussing an amount of bitcoin with someone else.  I believe that slang terms like "millie" or "satoshi" should just be left out when trying to have an honest conversation.  Everyone tends to know the metric system universally since it's used for every type of scientific measurement, and I think that it should be kept that way since bitcoin is trying to become the first global currency.

Plus I mean think about it... while everyone on here knows what a "satoshi" is, is there any real reason to be measuring your bitcoin value in satoshis? There is literally no value in a satoshi, and it's misleading to say you have 1K satoshi's on hand when that still is in a sense, nothing.

I don't get the point, however. There was one day where even 1 BTC was just fraction of cent of one US dollar. Saying you had 1000 BTC didn't mean anything relevant.
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!