Dabs
Legendary
Offline
Activity: 3416
Merit: 1912
The Concierge of Crypto
|
|
May 27, 2014, 04:57:14 AM |
|
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
The topic about the TrueCrypt keylogger is called the Evil Maid attack. Do a little research, it's not as bad as it sounds, and it can easily be checked even if you leave your hardware unattended and quite possibly tainted.
As for cold wallets, just like passwords, it's a good idea to change it every now and then. The design of bitcoin is such that one layer of "protection" is removed when you spend anything from an unspent address.
But, for example, the best addresses to target are static ones that accept a lot of inputs, and have already spent some, since you now know the public key. Note that the public key is not the same as the bitcoin address.
Satoshidice comes to mind, I don't think they've ever changed their betting addresses, and if you manage to get the private key to any one, you'd have a lot of bitcoins. No one has ever cracked that one. (I think, I don't remember if it has been breached.)
|
|
|
|
Dabs
Legendary
Offline
Activity: 3416
Merit: 1912
The Concierge of Crypto
|
|
May 27, 2014, 04:59:46 AM |
|
So I can't use that machine any more. It goes into the pile marked 'possibly tainted'.
Is that laptop or hardware for sale? Run DBAN on it or something.
|
|
|
|
SebastianJu
Legendary
Offline
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
|
|
May 27, 2014, 01:21:31 PM |
|
Good to read you are cautious. Though it sounds a bit risky sending bitcoins around with scripts you work on. I mean im a coder myself and i really hope you never have a slight error in it... Though the worst risk lies in a walking bank itself and Rubber-hose cryptanalysis. I dont really like thinking about it and wouldnt know how to protect if im in your shoes.
|
Please ALWAYS contact me through bitcointalk pm before sending someone coins.
|
|
|
suchmoon
Legendary
Offline
Activity: 3864
Merit: 9090
https://bpip.org
|
|
May 27, 2014, 03:27:40 PM |
|
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
I do too. I still have no clue if there isn't anything lurking in the BIOS code or even hard drive firmware. Think about this: some of the "reputable" suppliers like Newegg or Amazon resell returned parts as new. So unless you have some sort of super-secure supply chain and absolute confidence in the manufacturer you can't really be sure.
|
|
|
|
conspirosphere.tk
Legendary
Offline
Activity: 2352
Merit: 1064
Bitcoin is antisemitic
|
|
May 27, 2014, 04:29:53 PM |
|
just a question: in the "Invest" tab the (profit)% (now at: 0.331741%) is relative to what period? monthly? since day 1?
|
|
|
|
Keyser Soze
|
|
May 27, 2014, 04:41:40 PM |
|
just a question: in the "Invest" tab the (profit)% (now at: 0.331741%) is relative to what period? monthly? since day 1?
That is the current site profit divided by the total wagered.
|
|
|
|
oda.krell
Legendary
Offline
Activity: 1470
Merit: 1007
|
|
May 27, 2014, 06:03:42 PM |
|
Let's just say it was a "security measure".
You got drunk and left your computer at the bar? :P Close. We were staying in a hotel for a few days. After checking out, about two hours away by then, I noticed I had accidentally left about 20 million dollars worth of bitcoin in the drawer of the bedside table. Found the nearest town, bought a new cold wallet machine, retrieved the wallet data from an encrypted backup, made new wallets (did I mention there were a couple of billion dogecoins in that drawer too?) and transferred the coins over. Everything on the cold wallet was encrypted so there was no risk, but it felt scary to be so far away from it. I'm told that even full-disk encryption is no protection if your hardware falls into the wrong hands, since they can install a keylogger in the code that prompts for the passphrase at boot time. So I can't use that machine any more. It goes into the pile marked 'possibly tainted'. So don't worry guys. Your coins are in safe hands. Most of the time. :) I'm not invested at the moment, or have funds on the site currently, but it's stuff like the above that makes me think of you as one of the most capable and trustworthy site owners in the Bitcoin ecosystem. If you ever decide to open, say, an exchange, let me know :D (and, yes, I'm serious)
|
Not sure which Bitcoin wallet you should use? Get Electrum!Electrum is an open-source lightweight client: fast, user friendly, and 100% secure. Download the source or executables for Windows/OSX/Linux/Android from, and only from, the official Electrum homepage.
|
|
|
dooglus (OP)
Legendary
Offline
Activity: 2940
Merit: 1333
|
|
May 27, 2014, 06:04:42 PM |
|
just a question: in the "Invest" tab the (profit)% (now at: 0.331741%) is relative to what period? monthly? since day 1?
Since day 1. This chart explains why (click for a larger version): The top-most red line is the expected profit - 1% of the total amount wagered. The black line is the actual profit. It mostly runs parallel to the expected profit, but is far below it due almost entirely to a player called nakowa who won big in mid July and at the end of September. The site's profit is now sitting between the 0.3% and 0.35% lines, is slowly climbing up through the red lines, but is expected to remain ~35k below the 1% line.
|
Just-Dice | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | Play or Invest | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | 1% House Edge |
|
|
|
ranlo
Legendary
Offline
Activity: 1988
Merit: 1007
|
|
May 28, 2014, 02:55:45 AM |
|
just a question: in the "Invest" tab the (profit)% (now at: 0.331741%) is relative to what period? monthly? since day 1?
Since day 1. This chart explains why (click for a larger version): The top-most red line is the expected profit - 1% of the total amount wagered. The black line is the actual profit. It mostly runs parallel to the expected profit, but is far below it due almost entirely to a player called nakowa who won big in mid July and at the end of September. The site's profit is now sitting between the 0.3% and 0.35% lines, is slowly climbing up through the red lines, but is expected to remain ~35k below the 1% line. Is there a link that we can view that chart on whenever we want (an updated one) or did you have to generate it? I've seen a couple others you've posted that I wanted to follow as well. If you're generating them, is there any chance of you posting like monthly on the blog or something?
|
|
|
|
coldguy
Member
Offline
Activity: 69
Merit: 10
|
|
May 28, 2014, 07:20:47 AM |
|
I used to write a crawler to fetch each bet's data, and want to do some analysis. But Doog use CloudFlare to protect the site again this... I think unless doog generate this plot for you, there is no other way you can do instead. Maybe doog has the design of the API of the site in his mind? just a question: in the "Invest" tab the (profit)% (now at: 0.331741%) is relative to what period? monthly? since day 1?
Since day 1. This chart explains why (click for a larger version): The top-most red line is the expected profit - 1% of the total amount wagered. The black line is the actual profit. It mostly runs parallel to the expected profit, but is far below it due almost entirely to a player called nakowa who won big in mid July and at the end of September. The site's profit is now sitting between the 0.3% and 0.35% lines, is slowly climbing up through the red lines, but is expected to remain ~35k below the 1% line. Is there a link that we can view that chart on whenever we want (an updated one) or did you have to generate it? I've seen a couple others you've posted that I wanted to follow as well. If you're generating them, is there any chance of you posting like monthly on the blog or something?
|
|
|
|
qxzn
|
|
May 28, 2014, 07:47:59 AM |
|
I used to write a crawler to fetch each bet's data, and want to do some analysis. But Doog use CloudFlare to protect the site again this... I think unless doog generate this plot for you, there is no other way you can do instead. Maybe doog has the design of the API of the site in his mind? You can use phantomjs to scrape / monitor the page. That's what I do for Litecoin Widget.
|
|
|
|
seuntjie
Legendary
Offline
Activity: 1717
Merit: 1125
|
|
May 28, 2014, 09:42:00 AM |
|
I used to write a crawler to fetch each bet's data, and want to do some analysis. But Doog use CloudFlare to protect the site again this... I think unless doog generate this plot for you, there is no other way you can do instead. Maybe doog has the design of the API of the site in his mind? This is a bad idea.... The amount of data you get (in bytes) for requesting bet info is much more than placing a bet or doing just about anything else on the site, so crawling for all bets will increase traffic to the server immensely. Besides, it's extremely hard to pull data for 50 bets every second. There is a site that has charts, https://bitcoinproject.net/justdice.php . This should show almost everything you need except the actual bet data. There is an api link where you can get data like amount of rolls, invested amount, profit, etc, but i cannot remember what the link is. I'm sure Doog will give it to you if you ask.
|
|
|
|
Phrenico
Member
Offline
Activity: 75
Merit: 10
|
|
May 28, 2014, 05:40:23 PM |
|
A couple questions for any of you more informed than I am:
Does anybody know where the just-dice servers are located, or the real names of anybody involved? Has dooglus taken precautions against being shut down by various governments if the site attracts too much attention, and is there any fail-safe if that happens?
I see there's an emergency withdrawal address. Do we know how/under what circumstances dooglus expects to use it?
Thanks guys.
|
|
|
|
GoofyUK
Newbie
Offline
Activity: 28
Merit: 0
|
|
May 28, 2014, 06:16:36 PM |
|
A couple questions for any of you more informed than I am:
Does anybody know where the just-dice servers are located, or the real names of anybody involved? Has dooglus taken precautions against being shut down by various governments if the site attracts too much attention, and is there any fail-safe if that happens?
I see there's an emergency withdrawal address. Do we know how/under what circumstances dooglus expects to use it?
Thanks guys.
their hosted by Amazon i think, doog keeps the majority of the funds offline so even if the server was seized he could still distribute the majority of the funds back to the investors / playyers.
|
|
|
|
Phrenico
Member
Offline
Activity: 75
Merit: 10
|
|
May 28, 2014, 08:45:29 PM |
|
their hosted by Amazon i think, doog keeps the majority of the funds offline so even if the server was seized he could still distribute the majority of the funds back to the investors / playyers.
Good point. Though under some circumstances, say, if doog is discovered and issued a subpeona, he has reason not to distribute the funds because it will put him in harm's way.
|
|
|
|
Probably
Newbie
Offline
Activity: 56
Merit: 0
|
|
May 28, 2014, 09:29:27 PM |
|
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
This is completely false. Building a computer via parts is as easy as adding everything to a cart, purchasing it and snapping/screwing it all together when it arrives. That is totally irrelevant to if, say, you're aware that newegg shipped your motherboard to the NSA and they had fun with your bios.
|
|
|
|
ranlo
Legendary
Offline
Activity: 1988
Merit: 1007
|
|
May 28, 2014, 10:10:38 PM |
|
Quote from: Dabs on May 26, 2014, 11:57:14 PM
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
This is completely false. Building a computer via parts is as easy as adding everything to a cart, purchasing it and snapping/screwing it all together when it arrives.
That is totally irrelevant to if, say, you're aware that newegg shipped your motherboard to the NSA and they had fun with your bios.
This is my thought as well. Some people have bought hardware that was already used as well even though it was being sold as new. Posted From bitcointalk.org Android App
|
|
|
|
GoofyUK
Newbie
Offline
Activity: 28
Merit: 0
|
|
May 28, 2014, 10:19:13 PM |
|
Quote from: Dabs on May 26, 2014, 11:57:14 PM
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
This is completely false. Building a computer via parts is as easy as adding everything to a cart, purchasing it and snapping/screwing it all together when it arrives.
That is totally irrelevant to if, say, you're aware that newegg shipped your motherboard to the NSA and they had fun with your bios.
This is my thought as well. Some people have bought hardware that was already used as well even though it was being sold as new. Posted From bitcointalk.org Android App That's true. Posted From bitcointalk.org laptop
|
|
|
|
dooglus (OP)
Legendary
Offline
Activity: 2940
Merit: 1333
|
|
May 29, 2014, 01:22:06 AM |
|
Quote from: Dabs on May 26, 2014, 11:57:14 PM
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
This is completely false. Building a computer via parts is as easy as adding everything to a cart, purchasing it and snapping/screwing it all together when it arrives.
That is totally irrelevant to if, say, you're aware that newegg shipped your motherboard to the NSA and they had fun with your bios.
This is my thought as well. Some people have bought hardware that was already used as well even though it was being sold as new. Posted From bitcointalk.org Android App That's true. Posted From bitcointalk.org laptop Interesting. But it would never happen to me. Posted by malware on the new cold wallet.
|
Just-Dice | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | Play or Invest | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | 1% House Edge |
|
|
|
ranlo
Legendary
Offline
Activity: 1988
Merit: 1007
|
|
May 29, 2014, 01:29:43 AM |
|
Quote from: Dabs on May 26, 2014, 11:57:14 PM
I build systems from parts. (I mean, most miners do, right?) Motherboard, RAM, Graphics, Hard Drive, etc. If you can do that, most people who can, know if a system they are building is secure or not.
This is completely false. Building a computer via parts is as easy as adding everything to a cart, purchasing it and snapping/screwing it all together when it arrives.
That is totally irrelevant to if, say, you're aware that newegg shipped your motherboard to the NSA and they had fun with your bios.
This is my thought as well. Some people have bought hardware that was already used as well even though it was being sold as new. Posted From bitcointalk.org Android App That's true. Posted From bitcointalk.org laptop Interesting. But it would never happen to me. Posted by malware on the new cold wallet. HE JUST SAID HE HAS MALWARE. EVERYONE DIVEST RIGHT NOW!!!!!!!! But really, how do you know? The situation I was talking about was a guy who bought a premade computer that had a used HDD in it (it was a "brand new PC" and the HDD had been reformatted). He then got ahold of the owner and that person had sent it in for destruction but it apparently just got wiped and put in a brand new HP (I think it was). Makes me think it could happen with other hardware as well though.
|
|
|
|
|