Bitcoin Forum
May 22, 2024, 02:16:27 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 [146] 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 ... 291 »
2901  Other / Meta / Re: You have exceeded the limit of 10 personal messages per hour. on: May 11, 2012, 09:15:05 PM
I run 1.1.16 on both my forums.
My bad then, I was going off faulty information it seems.
2902  Alternate cryptocurrencies / Mining (Altcoins) / Re: Quad XC6SLX150 Board - Initial Price £400/$640/520€ on: May 11, 2012, 09:08:43 PM
Quote
... Again, I just said you can get a 0.5C/W or lower heatsink if you go large or loud enough....
But no one wants to do that Wink The whole idea about FPGAs is that they are smaller, cooler, less noiser than GPUs. Even if you achieve 2.7C/W top power draw shouldn't be more than 17W, commercial grade chips, 25W industrial grade chips at 25C ambient temp. Compared to 40W of one chip in BFL Single is damn small value. And we have to remember that propagation delays thru silicon raises when temperature raise. More power draw, faster MHz limit = less MH/s. There is somwhere a sweet spot and it's defenitevely below 17W thanks to high Rthjc... Are we agreed?

Yes, definitely. I wouldn't want to get nearly that close to the limit. That being said, if someone like eldentyrell releases a bitstream that does 250MH/s on an LX150 but pushes power consumption up to 15W, there are options out there that might be worthwhile to deal with that. Smiley

Thats up from 200 mhash, right? I wonder how many of these boards should have been equipped with big copper heatsinks instead.
Watercool that shit.
2903  Bitcoin / Mining software (miners) / Re: CGMINER GPU FPGA overclock monitor fanspeed GCN RPC linux/windows/osx 2.4.1 on: May 11, 2012, 09:06:29 PM
Well, it's basically up to over 6000 outbound connections at the same instant on one server right now... how does Slush determine who gets LP priority?
LP priority is based on hashrate.

EDIT: Link: https://bitcointalk.org/index.php?topic=1976.msg611014#msg611014
2904  Bitcoin / Mining software (miners) / Re: CGMINER GPU FPGA overclock monitor fanspeed GCN RPC linux/windows/osx 2.4.1 on: May 11, 2012, 08:03:30 PM
I can't see a workable solution either at the moment, which is why I'm trying to just shore up the EMC servers to handle LPs better.  Maybe if there's some way to identify a "backup" LP request to the server, so the server can prioritize active LPs and backup LPs in a QoS fashion or something... that way LPs can be pushed out as best effort for the backup LPs.  It would obviously require some changes to pool software, but I don't think they'd be that drastic and it would help out everyone.


Slush prioritizes his LPs already, it sounds like a good idea.
Also, what is the bottleneck with many LPs? Is it processing power? Memory hog? Disk reads/writes blocking? Running out of sockets? I wonder if it could or should be offloaded onto a dedicated box, if it is that much of a load issue.
2905  Economy / Trading Discussion / Re: [SCAMMER] MegaHustlr on: May 11, 2012, 08:00:25 PM
His name on Dwolla is Tyler Kurz, ID 812-486-5994. There aren't very many Tyler Kurzes on the internet, turns out. Dwolla is now monitoring his account.
Not sure who "CV" is, but his name on this public profile http://www.1up.com/do/my1Up?publicUserId=6007868 is "TJ&CV" and it shows the location as Ridgefield, CT

Also http://www.facebook.com/permalink.php?story_fbid=10150723629489736&id=249899034735&comment_id=21802910&offset=0&total_comments=100 Grin
Don't forget: http://webcache.googleusercontent.com/search?q=cache:cBGeCgCY4hkJ:esea.net/users/214386%3Ftab%3Dreferrals+&cd=11&hl=en&ct=clnk&gl=us&client=firefox-a (AKA XxxRapturexx age 22 as of 2006)

2906  Bitcoin / Bitcoin Discussion / Re: Frighteningly Ambitious Bitcoin Startup Ideas on: May 11, 2012, 07:43:44 PM
Nuclear mining operation either in a power plant or in a submarine. It will already have a water cooling system set up for the fuel rods which can be used for the mining rigs as well. Any excess electricity generated can also be sold for more profit.
Radioactive video cards FTW. Also, nuclear power plants use steam cooling, which is kind of hot for a video card.
2907  Other / Meta / Re: You have exceeded the limit of 10 personal messages per hour. on: May 11, 2012, 07:31:08 PM
Even the admins and mods are subject to that limit. Sorry.

I admin a couple of my own SMF forums, it's changeable by default and with modification packages you can change it per user/group: (mods are also exempt by default)


Is that SMF 2.0 or 1.1.16?
2908  Economy / Goods / Re: [WTS] $250 in Amazon gift codes for BTC on: May 11, 2012, 07:30:30 PM
PM sent
With a scammer tag, why did you even bother?
2909  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 06:24:35 PM
ROFL! cool story bro.  You clearly know this is it for Bitcoinica what stake do you have in this ?
We have over 80% of our Bitcoins in offline wallets at the moment before the attack.
Offline == not stolen. Try again.
2910  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 06:21:05 PM
I don't keep my real wallet in a public lockbox at a train station and I wouldn't keep a bitcoin wallet on public server at a datacenter.

Yes that was already covered extensively before you went off with a derail involving your "non solution".

If Bitcoinica had avoided the attackers gaining access to the server containing the private keys then the theft wouldn't have occured.  No custom protocol was required.

If the attackers gained access to the server containing the private keys then the theft still would have happened.  No custom protocol would have helped.

Hence the whole point about your "custom timed delayed protocol" being of dubious value.  Most (all ?) major thefts involving bitcoins was a result of attacker gaining access to the private keys.

Not sure how the hacker would gain access to the server when the only network-accessible thing is the custom interface as previously stated. Did you think I was trying to come up with a solution to stop the hacker after he already gained access or something?
Yes it sounded like that, because that's what happened. The "only network accessible things" extend to the control panel as well as the server itself. Sure, if you are in complete control of the hardware, making that interface difficult to access is common sense (actually it is always common sense), but when someone can reset the root password at the click of a button, that isn't going to help you.

In that case there is no possible solution. Not even an encrypted filesystem will help because it will still be mounted.
You can't reset the root password on a mounted filesystem, and you can't access an encrypted filesystem after a reboot without the password.
EDIT: I might as well make it crystal clear that you can't reset the root password on a mounted filesystem externally without access to the password itself.
2911  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 06:20:20 PM
ding dong MR Z i see you online where are the updates Huh

No updates. They are probably busy packing up. Why wouldn't they ? BTC is 0 value in legal system Cry

As long as they give you all the USD / fiat back then they are 100% clean legally.

Very funny putting the meatspin crap up AFTER the BTC was stolen ... real clever proof of you getting hacked zhoutong !

What a joke !

Dude, what is up with your profile on this forum ? what a mess lol

I am celebrating my 1 year anniversary on this forum with a proud scammer tag.

Soon zhoutong will join me, by the looks of things Cheesy

ROFL!!!   Whole bunch of these guys are going to be given scammer tags LOL     either that or long prison sentences!

Who are these "founders"  can someone list them here ?
WTF you idiots, shut the fuck up about a scammer tag already. It hasn't even been 12 hours for them to review the security of the system, and you think that it is all gone. No it isn't all gone it just takes a while to get things back into a secure and operational state.
2912  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 06:11:14 PM
I don't keep my real wallet in a public lockbox at a train station and I wouldn't keep a bitcoin wallet on public server at a datacenter.

Yes that was already covered extensively before you went off with a derail involving your "non solution".

If Bitcoinica had avoided the attackers gaining access to the server containing the private keys then the theft wouldn't have occured.  No custom protocol was required.

If the attackers gained access to the server containing the private keys then the theft still would have happened.  No custom protocol would have helped.

Hence the whole point about your "custom timed delayed protocol" being of dubious value.  Most (all ?) major thefts involving bitcoins was a result of attacker gaining access to the private keys.

Not sure how the hacker would gain access to the server when the only network-accessible thing is the custom interface as previously stated. Did you think I was trying to come up with a solution to stop the hacker after he already gained access or something?
Yes it sounded like that, because that's what happened. The "only network accessible things" extend to the control panel as well as the server itself. Sure, if you are in complete control of the hardware, making that interface difficult to access is common sense (actually it is always common sense), but when someone can reset the root password at the click of a button, that isn't going to help you.
2913  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 06:08:38 PM
I don't keep my real wallet in a public lockbox at a train station and I wouldn't keep a bitcoin wallet on public server at a datacenter.

Yes that was already covered extensively before you went off with a derail involving your "non solution".

If Bitcoinica had avoided the attackers gaining access to the server containing the private keys then the theft wouldn't have occured.  No custom protocol was required.

If the attackers gained access to the server containing the private keys then the theft still would have happened.  No custom protocol would have helped.

Hence the whole point about your "custom timed delayed protocol" being of dubious value.  Most (all ?) major thefts involving bitcoins was a result of attacker gaining access to the private keys.

What about a setup where hot wallet is on separate machine which periodically fetches instructions for transfers. Attacker would have to reverse engineer the setup in short time from obtaining access to alarm being raised. The main server can be collocated while hot wallet server can be in a basement of undisclosed private home.
You can do this with multisig transactions.
2914  Bitcoin / Bitcoin Discussion / Re: On Bitcoin mining on: May 11, 2012, 05:54:44 PM
We're already seeing Quad FPGA chips on a single board for $1k and other designs with expandable daughterboards etc similarly priced for the number of chips and total hashing power. And they will have to compete with each other for customers thus lowering the price of FPGAs. Then we'll see some custom FGPA multicore processor maybe with 4, 8, or maybe 4096 FPGAs all in a single chip. And then maybe the first quantum computer that can be used to solve sha256 will get purposed for Bitcoin mining. And every increment of overall tech performance will push up the difficulty, and force people who want to keep being competitive at mining to upgrade their hardware, and the network will end up more secured as a result.
And even when quantum computers are mining, and the difficulty is 1 billion, there will always be some poor noob mining away on his Pentium 4 in his mother's basement, hoping to strike it rich. Grin
2915  Other / Off-topic / Re: Last post before 6/1/2012 wins 5 BTC... and who knows how much that will be on: May 11, 2012, 05:51:51 PM
Perhaps while everyone is distracted with the bitcoinica debacle... Wink
Not me!
2916  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 05:51:25 PM
There is nothing to reverse if the transaction is canceled during the grace time before it is executed on bitcoind. There is no server to hack into when the only network-accessible thing is the custom interface.

There always is a server.  Some custom protocol doesn't change the fact that a server exists.  When you send a command using the costom protocol where is going?  Obviously bitcoind is running somewhere.  Your solution is no solution.  Attacker would simply bypass the stupid "interface" hit the real server and steal the private keys.

You do understand the private keys are simply numbers right?  If you have the numbers you have the funds.  Thieves don't need to use the lockdown bitcoind.  They steal the private keys and execute a transaction from anywhere in the world.

Why would you have a custom interface but leave the bitcoind rpc port and ssh open to the public?

Are you intentionally missing their point?

Are they implying the hacker had physical access to the machine?
Yes, close enough when the machine is a VM on a cloud somewhere.
2917  Economy / Securities / Re: GLBSE better, harder, stronger, faster, cheaper now with MAKER/TAKER on: May 11, 2012, 05:50:25 PM
& just to clarify, with the new site we can now reuse the 4 deposit addresses that we are initially given with np I assume, instead of needing to generate new ones each time I assume, much handier for me to just keep 1 or 2 of these in a wallet labelled for GLBSE deposit address, thanks for the improvements & hope that the doors can open again soon for buisness 
While this is handy, ALWAYS confirm the address on the site before sending funds to it. Remember when Bitcoinica was hacked the first time? The deposit addresses were compromised, and some people continued to send funds to the old addresses because they didn't log in to check and see if it had changed.
2918  Economy / Trading Discussion / Re: How to prove that you own/control a private key after it has been stolen on: May 11, 2012, 05:45:07 PM
How do you intend to prove that you didn't deliberately give someone the private key? Private keys have become a form of payment in their own right; for example, you can provide one to MtGox to fund your account. A key isn't necessarily "stolen" just because you had it first, and now someone else also has it.

So far as the bitcoin system is concerned, possession of the private key is ownership. The damage is in the unauthorized access to your computer, and for that you need to show that the key was copied without your consent.
That is where the RSA/PGP/GPG/etc key comes in. If you for some reason wanted to give a private key to someone (why?) you could create a message with your signing key to say that it was authorized.
You could, but the absence of such a message does not mean the transfer was not authorized. Moreover, unless everyone timestamps their keys this way, anyone who does not have such a timestamp is left with the task of proving a negative--that they do not have a timestamp to sign over. Actually, that could be a problem even if you do sign over a timestamp, since nothing prevents you from having more than one, dated earlier than the one you signed over, which you've been keeping to yourself.

You could mitigate this by only considering timestamps which have already been made public, but it seems easier to me to simply secure your private keys.
Quite so. I brought this up because the last time Bitcoinica was hacked, there were those that were saying that they should not be pursuing the recovery of their funds because it would not be possible to prove in court that they had ownership of the funds/keys first. This provides a way for a public entity to prove ownership based on a timestamp, and as we saw this morning, private keys can get stolen from large public entities too. I would love to see better security on everyone's private keys.
2919  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 05:35:04 PM
There is nothing to reverse if the transaction is canceled during the grace time before it is executed on bitcoind. There is no server to hack into when the only network-accessible thing is the custom interface.
If the keys are stolen, ANY bitcoind can make the transaction, doesn't have to be on the compromised server.
2920  Bitcoin / Bitcoin Discussion / Re: [Emergency ANN] Bitcoinica site is taken offline for security investigation on: May 11, 2012, 05:28:29 PM
This could have been avoided by not using the standard bitcoind rpc interface. If you have your own custom interface in between you can add large amounts of security measures such as withdraw verification and grace time. The hacker will also not be able to look up how your interface works by going to Google.
How do you know? From what we have heard, it has nothing whatsoever to do with the cracking that took place. Or do you have some inside info?

18,000 BTC was withdrawn. If you had a custom interface you could make it piss red flags when it sees a transaction with such a large amount.

Which does nothing since Bitcoin is irreversible. Smiley

The most likely attack vector was
a) gain access to rackspace admin console
b) reset root password
c) login as root
d) steal private keys

So what exactly would a custom RPC do about that?
And to add more flames to this raging inferno, Rackspace maintains backdoor root accounts on their managed servers to perform backups and maintenance. I'm not sure whether this applies to the cloud servers or not.
Pages: « 1 ... 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 [146] 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 ... 291 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!