Bitcoin Forum
May 04, 2024, 06:59:10 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 [9]  All
  Print  
Author Topic: PRIMEDICE COMPROMISED [RESOLVED]  (Read 4145 times)
lowbander80
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


View Profile
January 04, 2017, 11:10:36 PM
 #161

Just as a test and never touched the account but it took me 12 minutes to brute force a btcpop.co account (it had no 2fa engaged)
1714805950
Hero Member
*
Offline Offline

Posts: 1714805950

View Profile Personal Message (Offline)

Ignore
1714805950
Reply with quote  #2

1714805950
Report to moderator
1714805950
Hero Member
*
Offline Offline

Posts: 1714805950

View Profile Personal Message (Offline)

Ignore
1714805950
Reply with quote  #2

1714805950
Report to moderator
According to NIST and ECRYPT II, the cryptographic algorithms used in Bitcoin are expected to be strong until at least 2030. (After that, it will not be too difficult to transition to different algorithms.)
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714805950
Hero Member
*
Offline Offline

Posts: 1714805950

View Profile Personal Message (Offline)

Ignore
1714805950
Reply with quote  #2

1714805950
Report to moderator
maku
Legendary
*
Offline Offline

Activity: 1288
Merit: 1000



View Profile
January 04, 2017, 11:35:21 PM
 #162

Just as a test and never touched the account but it took me 12 minutes to brute force a btcpop.co account (it had no 2fa engaged)
There is no denying that passwords can be bruteforced and if you managed to do so then the password you used must have been weak.
 Would you be able to crack some of these passwords?


A good password with alphanumerics and symbols would look similar to these:
  • n<GV8YV/L&$K$[b
  • 937/o=92sW/G{5c
  • ~(=0,548_"2"/Ga
  • kZs75Upu]48j?6q
Anyway I don't see that this discussion is leading us somewhere. Stunna claims that this case has nothing to do with PD's security.
convertekk says something competently different - we reached a stalemate here.
convertekk (OP)
Member
**
Offline Offline

Activity: 84
Merit: 10

Javascript developer, Available for work


View Profile WWW
January 04, 2017, 11:42:27 PM
 #163

Just as a test and never touched the account but it took me 12 minutes to brute force a btcpop.co account (it had no 2fa engaged)
There is no denying that passwords can be bruteforced and if you managed to do so then the password you used must have been weak.
 Would you be able to crack some of these passwords?


A good password with alphanumerics and symbols would look similar to these:
  • n<GV8YV/L&$K$[b
  • 937/o=92sW/G{5c
  • ~(=0,548_"2"/Ga
  • kZs75Upu]48j?6q
Anyway I don't see that this discussion is leading us somewhere. Stunna claims that this case has nothing to do with PD's security.
convertekk says otherwise - we reached a stalemate here.


Three things here-

-When a user is playing with one ip address, its highly unlikely that he'd login to another ip at the same time. A possible 10 minute delay check between login to login would have prevented this from happening.
- If a user enters wrong passwords for more than, say 5 times, his account should have been locked for the next 10 or 15 minutes and the user should be notified over email stating that the login attempt from the particular ip failed. Even bitcointalk.org does that. Locking the account after 5 wrong attempts would definitely not result in false positives as Ryan was stating.
- Protect your site from DDOS and Bruteforce attacks. That's a must.

Still nothing to do with security ?

acholagi
Hero Member
*****
Offline Offline

Activity: 826
Merit: 500



View Profile
January 05, 2017, 01:00:14 AM
 #164

ouch sorry to hear that Sad
convertekk (OP)
Member
**
Offline Offline

Activity: 84
Merit: 10

Javascript developer, Available for work


View Profile WWW
January 05, 2017, 07:59:00 AM
Last edit: January 05, 2017, 08:11:55 AM by convertekk
 #165

Stunna has promised to refund my losses and fix the issues on their website. Marking this as resolved and will lock this thread in a couple of hours. A lot of people have contributed to this thread. Thanks.

robert05210
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
January 05, 2017, 08:30:21 AM
 #166

Looks like Stunna will probably never reply to me again.

Oh well. Atleast you get your funds back. Nice one mate  Smiley
Pages: « 1 2 3 4 5 6 7 8 [9]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!