|
Remember remember the 5th of November
Legendary
Offline
Activity: 1862
Merit: 1011
Reverse engineer from time to time
|
|
July 17, 2013, 09:20:21 AM |
|
Cool, where is the source located at?
|
BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 09:25:45 AM |
|
Cool, where is the source located at?
On my SSD, SVN and my Backup NAS. I need to pay for food somehow...
|
|
|
|
Remember remember the 5th of November
Legendary
Offline
Activity: 1862
Merit: 1011
Reverse engineer from time to time
|
|
July 17, 2013, 09:27:05 AM |
|
So no source? How do you expect people will trust you with their Bitcoins without it?
|
BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 09:38:38 AM |
|
So no source? How do you expect people will trust you with their Bitcoins without it?
Good question, but it seems you didn't saw the App description in the Play Store. The App only needs "trade" and "get_info" permissions, you can choose this, when you create an application access key in the mtgox security center. There is a tutorial after starting the app, including pictures, which describes exactly how to accomplish this. So there is no way, this app can withdraw your bitcoins. Plus, you can track me down easily. You will see the App was listed by my Swiss Company "Nextgen Computing GmbH". I have nothing to hide.
|
|
|
|
|
31337157
Member
Offline
Activity: 111
Merit: 10
|
|
July 17, 2013, 12:45:46 PM |
|
Awesome app! My goodness, it does everything needed for quick day trading. I just loaded it up and connected acct, no trading yet but I am looking forward to it. Thank you.
|
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 02:30:45 PM |
|
It is based on stock-chart with a few modifications.
|
|
|
|
Remember remember the 5th of November
Legendary
Offline
Activity: 1862
Merit: 1011
Reverse engineer from time to time
|
|
July 17, 2013, 02:38:08 PM |
|
It is based on stock-chart with a few modifications. Would you be willing to provide these changes to stock-chart for free? I know it's MIT license, but no harm in asking . I was interested(before this thread) in making a similar application for executing trades on Bitstamp, as it is the superior exchange.
|
BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 02:39:22 PM |
|
Awesome app! My goodness, it does everything needed for quick day trading. I just loaded it up and connected acct, no trading yet but I am looking forward to it. Thank you.
Thank you very much! Feedback like yours are motivating me to make it even better . Please consider it is still in the beta phase and I'm working almost every day on it. I have a few more cool features planned for it .
|
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 02:59:58 PM |
|
Would you be willing to provide these changes to stock-chart for free? I know it's MIT license, but no harm in asking . I was interested(before this thread) in making a similar application for executing trades on Bitstamp, as it is the superior exchange. Since I don't have any other job/income, it is kind a conflict of interest. I hope you can understand that. But on the other side; I didn't change much or mostly cosmetic aspects. The part which included more work, is to pre-process the data before feeding it to stock-chart and that part is done server side.
|
|
|
|
foggyb
Legendary
Offline
Activity: 1736
Merit: 1006
|
|
July 17, 2013, 03:22:40 PM |
|
this could be a good app to find accounts that are ripe for hacking.
Not saying you're a criminal, but if its not open source.... who knows?
|
Hey everyone! 🎉 Dive into the excitement with the Gamble Games Eggdrop game! Not only is it a fun and easy-to-play mobile experience, you can now stake your winnings and accumulate $WinG token, which has a finite supply of 200 million tokens. Sign up now using this exclusive referral link! Start staking, playing, and winning today! 🎲🐣
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 04:01:33 PM |
|
this could be a good app to find accounts that are ripe for hacking.
Not saying you're a criminal, but if its not open source.... who knows?
Whats the difference to the official mtgox mobile trading app or any other trading app? They all use application access (without withdrawal permissions). - One connection is a simple http GET request for getting the history candlestick data (feel free to intercept and review it). - All other connections are only made to mtgox. Regards, Christian Strässle Founder of Nextgen Computing GmbH - www.nextgen.ch - A registered Company in Switzerland.
|
|
|
|
giszmo
Legendary
Offline
Activity: 1862
Merit: 1114
WalletScrutiny.com
|
|
July 17, 2013, 04:44:39 PM |
|
Any Bitcoin-Related Android App might just sit there, waiting for the next 0day to become available to wipe all my Spinners, Myceliums, Schildbachs, MtGoxes that have more access than the app originally asked for. A criminal could empty all these in one second with code he introduces in the next update and that is triggered by a timestamp. No prior wrong behavior can help you assess the security of this app.
But to be realistic: I use Mycelium and the fact it is open source makes it about 1% safer than your app as I doubt that more than 1% of the users actually compiled it themselves. I don't know if there is a way but theoretically it should be possible to sign an app with a merchant key and still allow others to review if the APK is in fact compiled from the open source code, so with updates that don't come from the repository could sound an alarm with people who prefer using the market.
|
ɃɃWalletScrutiny.com | Is your wallet secure?(Methodology) WalletScrutiny checks if wallet builds are reproducible, a precondition for code audits to be of value. | ɃɃ |
|
|
|
sacrelege (OP)
Newbie
Offline
Activity: 9
Merit: 0
|
|
July 17, 2013, 08:19:39 PM |
|
Any Bitcoin-Related Android App might just sit there, waiting for the next 0day to become available to wipe all my Spinners, Myceliums, Schildbachs, MtGoxes that have more access than the app originally asked for. A criminal could empty all these in one second with code he introduces in the next update and that is triggered by a timestamp. No prior wrong behavior can help you assess the security of this app.
I think your right. It might help if the other Apps (Spinners, Myceliums, Schildbachs, MtGoxes..) are prepared for unauthorized access. For example by an encryption process besides the default android internal storage one. But to be realistic: I use Mycelium and the fact it is open source makes it about 1% safer than your app as I doubt that more than 1% of the users actually compiled it themselves. I don't know if there is a way but theoretically it should be possible to sign an app with a merchant key and still allow others to review if the APK is in fact compiled from the open source code, so with updates that don't come from the repository could sound an alarm with people who prefer using the market.
What if you compiled yourself, but didn't read through the complete source code? Did you check the checksum after downloading? What if the server got compromised and the checksum is already up to date? What if the server checking the key gets compromised too? Maybe you read the code but didn't find the security hole? How do the most open source projects check, what and by whom is checked into the repository? Is there an established process / guide line for doing that? 1% more or less security is for nothing if you loose your bitcoins. :-/ maybe we shouldn't use anything at all. :-o
|
|
|
|
giszmo
Legendary
Offline
Activity: 1862
Merit: 1114
WalletScrutiny.com
|
|
July 18, 2013, 02:46:38 AM |
|
Any Bitcoin-Related Android App might just sit there, waiting for the next 0day to become available to wipe all my Spinners, Myceliums, Schildbachs, MtGoxes that have more access than the app originally asked for. A criminal could empty all these in one second with code he introduces in the next update and that is triggered by a timestamp. No prior wrong behavior can help you assess the security of this app.
I think your right. It might help if the other Apps (Spinners, Myceliums, Schildbachs, MtGoxes..) are prepared for unauthorized access. For example by an encryption process besides the default android internal storage one. But to be realistic: I use Mycelium and the fact it is open source makes it about 1% safer than your app as I doubt that more than 1% of the users actually compiled it themselves. I don't know if there is a way but theoretically it should be possible to sign an app with a merchant key and still allow others to review if the APK is in fact compiled from the open source code, so with updates that don't come from the repository could sound an alarm with people who prefer using the market.
What if you compiled yourself, but didn't read through the complete source code? Did you check the checksum after downloading? What if the server got compromised and the checksum is already up to date? What if the server checking the key gets compromised too? Maybe you read the code but didn't find the security hole? How do the most open source projects check, what and by whom is checked into the repository? Is there an established process / guide line for doing that? 1% more or less security is for nothing if you loose your bitcoins. :-/ maybe we shouldn't use anything at all. :-o Google (Mike Hearn? Ping!) should have a feature to distribute trusted open source apps. Some mechanism where they directly upon request by a maintainer pull the head of the master branch from a githubcode.google repo. Sure, I don't read all the code but: If a repo lays untouched for months on github I feel quite confident some other dev would have noticed malicious revisions, so as I generally trust github and their timestamps (I wanted to check if you can fake these), I feel safish when I compile from source.
|
ɃɃWalletScrutiny.com | Is your wallet secure?(Methodology) WalletScrutiny checks if wallet builds are reproducible, a precondition for code audits to be of value. | ɃɃ |
|
|
|
goebat
|
|
January 13, 2014, 02:44:00 PM |
|
How much is the subscription fee? It doesn't seem to be clearly advertised anywhere.
|
|
|
|
|