Bitcoin Forum
May 13, 2024, 09:56:07 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] NEX :: Nxt Reimagined - Imagine Fairness! on: January 25, 2014, 09:59:41 PM
Interested,

Cheers.
2  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] NEM : Descendant of NXT - 4 billion coins - Equal Shares for ALL on: January 25, 2014, 09:54:27 PM
How to join after page 50. Two ways

1. Pay a fee to join in
    
    Send 80 NXT to the address      14343293611098709683
    Send 0.008 BTC to the address  1Lk5Paws9T1YpoSeLeZT7ZeSQKW7UNq4TJ

    After you send the fee, include the transaction hash in your reply post in this thread, then you have reserved a stake spot.
    Donation is welcome but not necessary

Count me in, sent 0.008 BTC:
e1a0db2e63267594dac44a8a8df4cdf27bbb2a40f19ec91401de66abe8bd24fa
3  Bitcoin / Development & Technical Discussion / Re: NoBrainr - a secure and transparent cold address generator in 1024 bytes on: November 30, 2013, 11:56:34 PM

A user not familiar with the math of password strength, I believe, is highly likely to generate a set of passwords and then choose the most pleasing one. The result: Possibly a significant loss of entropy.


That makes no sense whatsoever. Except if the generator is broken.

Well, picking one favourite password out of 10 random ones adds human emotion, which isn't exactly random, is it?

Say, something like: "Hey, that one has my girlfriend's name in it, I'll choose that!".
4  Bitcoin / Development & Technical Discussion / Re: NoBrainr - a secure and transparent cold address generator in 1024 bytes on: November 30, 2013, 10:41:51 PM
One thing the generator doesn't (and probably can't?) guarantee is that the user actually took the password the generator first gave out.

A user not familiar with the math of password strength, I believe, is highly likely to generate a set of passwords and then choose the most pleasing one. The result: Possibly a significant loss of entropy.

Have you considered adding an output of instructions and warnings about how and how not to use the generator?
5  Bitcoin / Armory / Re: Does watch-only wallet have a Master Public Key you should keep safe? on: November 29, 2013, 09:40:58 PM
OK, thanks for clarifying.
6  Bitcoin / Armory / Re: Does watch-only wallet have a Master Public Key you should keep safe? on: November 29, 2013, 09:12:54 PM
How about any derived private key, which is not the root key? How serious a leak would that make? Does it compromise all the other private keys as well, if the attacker knows the chain code? (which I assumed is the same for both, private and public chains).
7  Bitcoin / Armory / Re: Does watch-only wallet have a Master Public Key you should keep safe? on: November 29, 2013, 07:55:20 PM
Revealing any private key for any type of Bitcoin wallet software kind of lets the person you revealed it to steal all your money.

I don't understand. I don't think you meant that non-deterministic wallet's keys have some kind of relationship that would allow revealing all the other private keys if any one of them is revealed, did you? And I wouldn't use only one private key in my wallet. More like one per transaction. Did you assume a single-key wallet when saying this?

I think that possibly the Bitcoin Magazine article has a mistake in it, or is maybe written in a way that gave you the wrong impression.

Did you have time to check out the article? If not, could you check it out, for example starting by searching for "crack_electrum_wallet(mpubkey,priv0,0)", a utility function Mr. Buterin mentions he has coded to demonstrate the issue?

Perhaps the subject of a hierarchical wallet is more interesting in this context, but if it applies to Armory's wallet, too, I still believe an arbitrary wallet user could easily think sharing a single private key with someone wouldn't add any risk, which actually would.

If you want to keep a backup for a gift to your friend, just keeping the private key won't be enough. You need the Chain Code too, as that determines all the addresses that the private key unlocks. The private key on it's own is like having a real-life key, but you don't know which lock it opens. When you know the house (think: address), and you have the key, then you can get through the door.

You are talking about deterministic wallets specifically, right? In case of Armory, I thought only the root key is something that fits all the wallet addresses. Do you mean that the rest of the private key chain can be figured out from any private address of the chain, even without the chain code? Or do you mean that Armory's wallet is hierarchical in such a way that not just the root key is something that works on multiple addresses, that any other private key had a similar property?
8  Bitcoin / Armory / Re: Does watch-only wallet have a Master Public Key you should keep safe? on: November 28, 2013, 10:04:01 PM
I think you're mixing up the definitions slightly.

Armory wallet (offline or online) contains:


x1 private key
x1 chain code
infinite public keys (derived from the chain code)

Armory watching only wallet contains:

x1 chain code
infinite public keys (derived from the chain code)


Plus stuff like transaction comments and so on, but I'm sticking to the keys here. If you give someone else the chain code, they can indeed determine the amount of Bitcoin at every address in the wallet. But the Chain Code is always packaged up together with the private key, either in the same wallet file or in the same paper backup. You need both the private key and chain code for a paper backup.

Is the chain code the same thing as the "master public key"?

Quote
In the case of the situation you're describing, there is no real need to panic.

If you're providing an individual public key to someone to pay you with, they know nothing about the rest of the wallet except that one address (represented by the one public key. "Public key" and "address" = same thing).

I meant revealing a private key. Say, I wanted to give my yet unenlightened friend a gift and keep the private key myself as well, for my friend's backup.

Quote
There's no way to make a mistake and accidentally give them the Chain Code, it's not accessible in any part of the Armory application except for the paper backup feature. You'd never make that mistake.

I could have been more specific. What I was worried about was the issue mentioned in the article: Any one private key plus the master public key in single, wrong hands could compromise a whole deterministic wallet.

Why I thought this was worth keeping in mind was that you probably should assume online wallet is pretty open to exposure eventually (therefore, the MPK/CC as well) and any private keys you shared aren't anymore under your control.
9  Bitcoin / Armory / Does watch-only wallet have a Master Public Key you should keep safe? on: November 28, 2013, 08:32:19 PM
After reading about the drawbacks of deterministic wallets from http://bitcoinmagazine.com/8396/deterministic-wallets-advantages-flaw/, it seems to me like Armory's watch-only wallets (and offline wallets as well, actually) have the "master public key" mentioned in the article, easily obtainable.

Does this mean I should never reveal any of the private keys of my deterministic Armory wallet? If I did, I would risk compromising all the private keys when someone gets hold of both, the master public key and any single private key of my wallet.

Someone, please verify!
10  Alternate cryptocurrencies / Altcoin Discussion / Re: Cloud Mining CPU Coins on: September 27, 2013, 06:17:33 AM
Editing the previous message seemed to mess up the embedded url, here's a retry:

https://hackitechi.wordpress.com/2013/09/26/cloud_mining/

Just changed it from http to https.
11  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][SRC] SecureCoin | A Fast and Secure Version of Bitcoin | LAUNCHED on: September 26, 2013, 08:33:46 PM
Just a quick tip:
I wrote something down about cost efficient cloud mining, check it out if interested:

https://bitcointalk.org/index.php?topic=303122.0
12  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] [QRK] Quark | Super secure hashing | CPU mining on: September 26, 2013, 08:25:36 PM
Just a quick tip:
I wrote something down about cost efficient cloud mining, check it out if interested:

https://bitcointalk.org/index.php?topic=303122.0
13  Alternate cryptocurrencies / Altcoin Discussion / Cloud Mining CPU Coins on: September 26, 2013, 08:12:17 PM
Hello fellow alt-coiners,

I'd like to share you what I came across in my quest for The Holy Cheapest Possible VPS Grail Out There.

The article outline:
    Cloud mining in general, briefly (why, availability, profitability)
    Cloud service comparison table
    Detailed description of each service presented (five services)
    Performance charts of a couple of those services

The article:
    <see then link in 2nd below post>

Peace.
14  Alternate cryptocurrencies / Altcoin Discussion / Re: Ripple Giveaway! on: February 27, 2013, 10:27:34 PM
r4WZqfkuTk82BAFCgLgSPxgs9hyqMHcsjo
15  Other / Off-topic / Re: Let's Count to 21 Million with Images on: February 23, 2013, 11:39:51 PM
16  Other / Off-topic / Re: Let's Count to 21 Million with Images on: February 23, 2013, 11:30:24 PM
17  Other / Off-topic / Re: Let's Count to 21 Million with Images on: February 23, 2013, 11:22:55 PM
18  Other / Off-topic / Re: Let's Count to 21 Million with Images on: February 23, 2013, 11:18:15 PM
19  Other / Off-topic / Re: Let's Count to 21 Million with Images on: February 23, 2013, 11:15:51 PM
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!