Bitcoin Forum
May 10, 2024, 11:05:45 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
Author Topic: Instawallet/Bitcoin-Central Security Breach  (Read 85268 times)
Rampion
Legendary
*
Offline Offline

Activity: 1148
Merit: 1018


View Profile
April 02, 2013, 03:16:27 PM
 #141

FACTS:

1) Google is evil, and will spy on you in order to have as much information possible to cash it in form of advertisments
2) sending your funds to a wallet consisting in an non-password protected URL is RIDICOLOUS

3. Spelling is a lost art.

4. I would like to see your spelling skills in Turkish.

1715382345
Hero Member
*
Offline Offline

Posts: 1715382345

View Profile Personal Message (Offline)

Ignore
1715382345
Reply with quote  #2

1715382345
Report to moderator
1715382345
Hero Member
*
Offline Offline

Posts: 1715382345

View Profile Personal Message (Offline)

Ignore
1715382345
Reply with quote  #2

1715382345
Report to moderator
In order to get the maximum amount of activity points possible, you just need to post once per day on average. Skipping days is OK as long as you maintain the average.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
DobZombie
Hero Member
*****
Offline Offline

Activity: 896
Merit: 532


Former curator of The Bitcoin Museum


View Profile
April 02, 2013, 03:46:37 PM
 #142

/flameon

I love google, I haven't been lost ANYWHERE in like 4 years!

I WANT my browser to know what I'm thinking, and web searches to sell me shit that interests me!

I LOVE the fact if I don't know something, I can just GOOGLE it!

/flameoff

Tip Me if believe BTC1 will hit $1 Million by 2030
1DobZomBiE2gngvy6zDFKY5b76yvDbqRra
gbl08ma
Sr. Member
****
Offline Offline

Activity: 306
Merit: 250


Donations: http://tny.im/nx


View Profile WWW
April 02, 2013, 04:01:57 PM
 #143


First rule, don't trust that number Google gives you. It is always way off all the results one can get (some guy did a research on that, turns out you only have access to the first 1000 results or so). And second, you don't know how many of these results are the same wallet URL appearing on multiple pages.

Arthur Randolph
Newbie
*
Offline Offline

Activity: 29
Merit: 0


View Profile
April 02, 2013, 04:09:13 PM
 #144

What about we try and stay on topic?

Has anyone been able to contact the people at Paymium, the company behind instawallet and bitcoin-central?
Grinder
Legendary
*
Offline Offline

Activity: 1284
Merit: 1001


View Profile
April 02, 2013, 04:10:50 PM
 #145

None of them are actually on instawallet, though. https://www.google.com/search?q=%22instawallet.org/w/%22+site:instawallet.org

I realise that this may be because they have now removed direct links from Google, but the number is meaningless.
Raoul Duke
aka psy
Legendary
*
Offline Offline

Activity: 1358
Merit: 1002



View Profile
April 02, 2013, 04:20:06 PM
 #146


At least do it properly: https://www.google.com/search?q=inurl%3A%2Fw%2F+site%3Ainstawallet.org Wink
ingrownpocket
Legendary
*
Offline Offline

Activity: 952
Merit: 1000


View Profile
April 02, 2013, 04:35:08 PM
 #147

I wanted to do the exact opposite of that.
Trying to show him where Google got those addresses.  Wink
Jan
Legendary
*
Offline Offline

Activity: 1043
Merit: 1002



View Profile
April 02, 2013, 04:56:17 PM
 #148

either way the lesson will be "trust no one to hold your coins".
Seconded

Apparently every new batch of Bitcoiners will need to learn this valuable lesson.

If you aren't the sole controller of your private keys, you don't have any bitcoins.

Take whatever steps necessary to be the sole controller of your private keys people!
In short "Keep your private keys private". Rule number ONE in Bitcoin land.

Mycelium let's you hold your private keys private.
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 02, 2013, 04:59:38 PM
 #149

either way the lesson will be "trust no one to hold your coins".
Seconded

Apparently every new batch of Bitcoiners will need to learn this valuable lesson.

If you aren't the sole controller of your private keys, you don't have any bitcoins.

Take whatever steps necessary to be the sole controller of your private keys people!
In short "Keep your private keys private". Rule number ONE in Bitcoin land.

bitcoin-central.net has updated its message

Still no mention of instawallet  Huh

pbtc
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
April 02, 2013, 05:41:07 PM
 #150


Since nobody commented on other thread, https://bitcointalk.org/index.php?topic=164638.0, thought it might be useful to mention that Easywallet has same problem with google.

About 1000 wallets visible from web. Balance seems to be zero on all.


lucb1e
Newbie
*
Offline Offline

Activity: 47
Merit: 0


View Profile WWW
April 02, 2013, 05:42:51 PM
 #151

Still no mention of instawallet  Huh
For some reason this feels intentional to me, I'm glad I wasn't on that service (only bitcoin-central).

Still though, instawallet's cold storage got transferred out with 82 confirmations last time I checked (hours ago), it should mostly be fine I guess.
Atruk
Hero Member
*****
Offline Offline

Activity: 700
Merit: 500



View Profile
April 02, 2013, 05:48:10 PM
 #152


Chrome is the ultimate spyware

And I love it for that.

I can google for a new movie on my desktop, then completely forget about it and weeks later my phone will automagically remind me that "hey that movie you googled a while ago is now running in that theater near you".
Without me doing anything.

Or I look up a restaurant at lunchtime and later at dinnertime i'm in the area and my phone goes "dude that steak restaurant you looked up is like 20 minutes away thought you should know duder".
Without me doing anything.

Or when it's like half an hour before I usually leave work to go home and my phone going "Yeah, here's the thing. You know how you drive at x pm and take that route usually? That's gonna bite you in the ass today. I mean, just look at that traffic jam. Look at this shit. You'd better drive this way. Just saying".

Without me doing anything.

It's perfect and exactly what my phone should do.

The lesson here is not: Google is evil.

The lesson is: Security through Obscurity does never ever work.

So true.

splat44
Sr. Member
****
Offline Offline

Activity: 384
Merit: 250



View Profile
April 02, 2013, 06:45:37 PM
 #153

Let's hope problems can be fixed in due time!
kakashi234
Sr. Member
****
Offline Offline

Activity: 367
Merit: 250



View Profile WWW
April 02, 2013, 07:45:09 PM
 #154

What do you think will happen with our purchase orders / sales going?

Personally, I have sales orders that I wanted to cancel because the btc was strong up, now if the website re-opens, my orders will be sent immediately without anulation possible ...

I hope they will think about it and cancel all those sales orders scheduled.

Free bitcoins: Surf4Bitcoin.com | Charity Ad: Make a good deed without paying a cent
BTC : 1BAyyQGoUGvpYbxao2C9zhzX3QVbftWiEn   ||     Cloud Mining : https://cex.io/r/0/kakashi234/0/
Injust (OP)
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
April 02, 2013, 07:47:12 PM
 #155

I hope that payments that our Instawallet addresses receive during the lack-of-service period will be credited Tongue
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 02, 2013, 08:01:48 PM
 #156

I hope that payments that our Instawallet addresses receive during the lack-of-service period will be credited Tongue

I just want whatever was in the wallets. Wink
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 02, 2013, 08:10:14 PM
 #157

Still no mention of instawallet  Huh
For some reason this feels intentional to me, I'm glad I wasn't on that service (only bitcoin-central).

Still though, instawallet's cold storage got transferred out with 82 confirmations last time I checked (hours ago), it should mostly be fine I guess.

I feel it is definitely intentional to not mention instawallet, the webpage is still the same too whereas the bit coin-central/paytunia page has been updated. Sad

However, if 42,000ish BTC was moved from their cold storage and is now "under their exclusive control" then surely they must not have lost everything. Maybe it is like some people have said, a problem with google that left some wallets searchable?

One thing that is really pecking my head though is the fact that there has been no update and Davout has disappeared too. This seems a bit suss.

Finally, can anyone with some technical knowhow please set me straight on the problem below. Surely if the money was sent from pone address to another 48 hours before this debacle then it has to be safe? If so, why hasnt it shown up in my wallet?

I made two withdrawals from jnstawallet 2 nights ago around 1am GMT. The first one did not show up but the second one did. I messages Davout about the first one not showing up and I also emailed support at instawallet. I wasn't worried as it actually happened last time I withdrew money from them too. That took 24 hours. I also thought that as it was a bank holiday there might be a delay in support.

If this money was sent should I be sure to receive this whatever happens with the rest of instawallets issues?

So in regards to this, without being too technical. Why would a transaction take two days to confirm?

Is it something to do with instawallet being free?

Can anyone help with this?
TiagoTiago
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500


Firstbits.com/1fg4i :)


View Profile
April 02, 2013, 08:50:33 PM
 #158

So do we think it is only affecting chrome users or is this just speculation?

Aside from that there is no news is there?
You would be surprised how many people got Google as their home page and type URLs in the page's search box instead of the browser's URL bar...

(I dont always get new reply notifications, pls send a pm when you think it has happened)

Wanna gimme some BTC/BCH for any or no reason? 1FmvtS66LFh6ycrXDwKRQTexGJw4UWiqDX Smiley

The more you believe in Bitcoin, and the more you show you do to other people, the faster the real value will soar!

Do you like mmmBananas?!
MPOE-PR
Hero Member
*****
Offline Offline

Activity: 756
Merit: 522



View Profile
April 02, 2013, 09:23:58 PM
 #159

FACTS:

1) Google is evil, and will spy on you in order to have as much information possible to cash it in form of advertisments
2) sending your funds to a wallet consisting in an non-password protected URL is RIDICOLOUS

3. Spelling is a lost art.

4. I would like to see your spelling skills in Turkish.

Merhaba rahatsız etmemek için lütfen gel!

My Credentials  | THE BTC Stock Exchange | I have my very own anthology! | Use bitcointa.lk, it's like this one but better.
BubbleBoy
Sr. Member
****
Offline Offline

Activity: 504
Merit: 250



View Profile
April 02, 2013, 10:03:51 PM
 #160

Could it be that Instawallet went full "Tom Williams" on the user's accounts ? Or maybe something like this: trade the coins on mtgox, wait for the bubble to pop, buy coins back, profit.

                ████
              ▄▄████▄▄
          ▄▄████████████▄▄
       ▄██████▀▀▀▀▀▀▀▀██████▄
     ▄████▀▀            ▀▀████▄
   ▄████▀                  ▀████▄
  ▐███▀                      ▀███▌
 ▐███▀   ████▄  ████  ▄████   ▀███▌
 ████    █████▄ ████ ▄█████    ████
▐███▌    ██████▄████▄██████    ▐███▌
████     ██████████████████     ████
████     ████ ████████ ████     ████
████     ████  ██████  ████     ████
▐███▌    ████   ████   ████    ▐███▌
 ████    ████   ████   ████    ████
 ▐███▄   ████   ████   ████   ▄███▌
  ▐███▄                      ▄███▌
   ▀████▄                  ▄████▀
     ▀████▄▄            ▄▄████▀
       ▀██████▄▄▄▄▄▄▄▄██████▀
          ▀▀████████████▀▀
              ▀▀████▀▀
                ████
MIDEX
▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂ GET TOKENS ▂▂▂▂
▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂▂
BLOCKCHAIN BASED FINANCIAL PLATFORM                                # WEB ANN + Bounty <
with Licensed Exchange approved by Swiss Bankers and Lawyers           > Telegram Facebook Twitter Blog #
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!