bybitcoin
|
|
November 23, 2013, 09:57:10 AM |
|
@Come-from-Beyond: so if you get 1M Nxt donated on that faucet pool, you are going to give 1000 of it to each single click by any random guy there! (and one of these guys can play your faucet and empty your pool by repeating the action several times with a dynamic IP change, that is available in any wireless connection nowadays). If you are going to do that, we prefer to allocate those +4M Nxt to bounties (since your automatic faucet will neutralize our efforts to attract people advertising and spreading the word of Nxt to receive some coins). Ripple gave away 3000 coins to each member of this forum, and you know what happened There will be CAPTCHA. Do u think 1/1000 is too much? What about 1/10000 then? Why not just a 1Nxt fixed faucet, and if the donation pool got below 1000Nxt, then 0.1 Nxt and so on! CAPTCHA is a way, still people are able to manipulate it anyway. As I spoke with the guy, we prefer to allocate those 4M Nxt for more purposeful moves (promoting based giveaways and some bounties) than spreading them blindly among random users (who just want to receive and exchange to btc) BUT ONCE MORE: I am just one of these 101 stake holders here. I am trying to push things a bit forward but my free time is too limited and therefore we need some guys to run the giveaway thread and other things for us. As I said yesterday anyone interested to run the giveaway could pm me. But nobody did pm since yesterday. If I see nobody is willing to help in pushing, I ll leave it away too.
|
|
|
|
|
|
|
|
|
Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
|
|
|
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:01:49 AM |
|
Why not just a 1Nxt fixed faucet, and if the donation pool got below 1000Nxt, then 0.1 Nxt and so on! CAPTCHA is a way, still people are able to manipulate it anyway. As I spoke with the guy, we prefer to allocate those 4M Nxt for more purposeful moves (promoting based giveaways and some bounties) than spreading them blindly among random users (who just want to receive and exchange to btc) BUT ONCE MORE: I am just one of these 101 stake holders here. I am trying to push things a bit forward but my free time is too limited and therefore we need some guys to run the giveaway thread and other things for us. As I said yesterday anyone interested to run the giveaway could pm me. But nobody did pm since yesterday. If I see nobody is willing to help in pushing, I ll leave it away too.
NXT can't be fractional. Also, each transaction requires at least 1 NXT fee. I agree that a lot of users could just exchange NXT for BTC... This is a serious issue. I'll put the faucet on hold, let's do it ur way. Edit: I already generated a small account id (131110410587) for faucet. Burned a lot of electricity
|
|
|
|
bahamapascal
|
|
November 23, 2013, 10:02:36 AM |
|
@Come-from-Beyond: so if you get 1M Nxt donated on that faucet pool, you are going to give 1000 of it to each single click by any random guy there! (and one of these guys can play your faucet and empty your pool by repeating the action several times with a dynamic IP change, that is available in any wireless connection nowadays). If you are going to do that, we prefer to allocate those +4M Nxt to bounties (since your automatic faucet will neutralize our efforts to attract people advertising and spreading the word of Nxt to receive some coins). Ripple gave away 3000 coins to each member of this forum, and you know what happened There will be CAPTCHA. Do u think 1/1000 is too much? What about 1/10000 then? How about doing it with email requirment? Also I think 1k Nxt would be good when its with email protection, if its with out any real protection I would vote for 100 though.
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:04:23 AM |
|
@Come-from-Beyond: so if you get 1M Nxt donated on that faucet pool, you are going to give 1000 of it to each single click by any random guy there! (and one of these guys can play your faucet and empty your pool by repeating the action several times with a dynamic IP change, that is available in any wireless connection nowadays). If you are going to do that, we prefer to allocate those +4M Nxt to bounties (since your automatic faucet will neutralize our efforts to attract people advertising and spreading the word of Nxt to receive some coins). Ripple gave away 3000 coins to each member of this forum, and you know what happened There will be CAPTCHA. Do u think 1/1000 is too much? What about 1/10000 then? How about doing it with email requirment? Also I think 1k Nxt would be good when its with email protection, if its with out any real protection I would vote for 100 though. 10 minute mail et al. ruin this protection.
|
|
|
|
bahamapascal
|
|
November 23, 2013, 10:19:20 AM |
|
@Come-from-Beyond: so if you get 1M Nxt donated on that faucet pool, you are going to give 1000 of it to each single click by any random guy there! (and one of these guys can play your faucet and empty your pool by repeating the action several times with a dynamic IP change, that is available in any wireless connection nowadays). If you are going to do that, we prefer to allocate those +4M Nxt to bounties (since your automatic faucet will neutralize our efforts to attract people advertising and spreading the word of Nxt to receive some coins). Ripple gave away 3000 coins to each member of this forum, and you know what happened There will be CAPTCHA. Do u think 1/1000 is too much? What about 1/10000 then? How about doing it with email requirment? Also I think 1k Nxt would be good when its with email protection, if its with out any real protection I would vote for 100 though. 10 minute mail et al. ruin this protection. I am not sure but we might be abel to conquer this 10min mail How about that the fourcet will send out a eMail with a uniqe generatet link for claiming the Nxt, but this Link will only be send (to the email address) 24 hours after using the fourcet) ?
|
|
|
|
bybitcoin
|
|
November 23, 2013, 10:21:19 AM Last edit: November 23, 2013, 10:34:15 AM by bybitcoin |
|
Why not just a 1Nxt fixed faucet, and if the donation pool got below 1000Nxt, then 0.1 Nxt and so on! CAPTCHA is a way, still people are able to manipulate it anyway. As I spoke with the guy, we prefer to allocate those 4M Nxt for more purposeful moves (promoting based giveaways and some bounties) than spreading them blindly among random users (who just want to receive and exchange to btc) BUT ONCE MORE: I am just one of these 101 stake holders here. I am trying to push things a bit forward but my free time is too limited and therefore we need some guys to run the giveaway thread and other things for us. As I said yesterday anyone interested to run the giveaway could pm me. But nobody did pm since yesterday. If I see nobody is willing to help in pushing, I ll leave it away too.
NXT can't be fractional. Also, each transaction requires at least 1 NXT fee. I agree that a lot of users could just exchange NXT for BTC... This is a serious issue. I'll put the faucet on hold, let's do it ur way. Edit: I already generated a small account id (131110410587) for faucet. Burned a lot of electricity Yes let's do it the other way which I discussed with the 4M Nxt donator, until the 3rd of January 2014. (the probable date of open source) After 3rd of January we can make another giveaway or a well thought faucet based on the market condition and also our donated resources! Upon coins release we can open a bounty thread and post these bounties as well: 500K Nxt for a video-100K Nxt for an article-50K Nxt for the chineese translation. @Bahama: instead of throwing random pass of suggestions, you can come ahead and help (to run the giveaway or write an article about Nxt or anything else). For Nxt success we don't need random thoughts, we need collective decided actions. So all the respected stake holders, come ahead and help!
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:22:54 AM |
|
I am not sure but we might be abel to conquer this 10min mail How about that the fourcet will send out a eMail with a uniqe generatet link for claiming the Nxt, but this Link will only be send (to the email address) 24 hours after using the fourcet) ? Won't work. 10 minute mail account can be active even 24 hours.
|
|
|
|
Jean-Luc
|
|
November 23, 2013, 10:26:37 AM |
|
Please, can you start publishing sha256 hashes and/or gpg signatures of the client binaries? I would feel more comfortable running a closed source binary if I at least know that it hasn't been tampered with in transit. I do agree that publishing the source has to wait for now.
I have a few other security concerns. I would caution everyone to run a local version of the client instead of going to one of the public nodes. Not only you have to trust the operator of the node, but your password (secret phrase) is being submitted in a GET request over a plain http connection, so your ISP, or tor exit node operator, have no problem capturing it. I didn't see a way to change the password later, the account number seems to be derived from it in a one way function. What should one do if he suspects his password may be compromised (e.g., it was already sent once over the internet in the clear)?
The java client is listening on all interfaces, i.e. for a machine exposed directly to the internet ports 7875 (http interface) and 7876 (json api) could be accessed by anyone. Please, consider binding those only to the localhost (127.0.0.1) interface by default, since most people running the client will not intend to run it as a public service. (Port 7874 should obviously listen on all, for peer connections).
|
|
|
|
slavo
|
|
November 23, 2013, 10:31:34 AM |
|
I made everything u said but it shows Account "0" = 583546 XNT I don't know where I screwed it
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:34:35 AM |
|
Please, can you start publishing sha256 hashes and/or gpg signatures of the client binaries? I would feel more comfortable running a closed source binary if I at least know that it hasn't been tampered with in transit. I do agree that publishing the source has to wait for now.
I have a few other security concerns. I would caution everyone to run a local version of the client instead of going to one of the public nodes. Not only you have to trust the operator of the node, but your password (secret phrase) is being submitted in a GET request over a plain http connection, so your ISP, or tor exit node operator, have no problem capturing it. I didn't see a way to change the password later, the account number seems to be derived from it in a one way function. What should one do if he suspects his password may be compromised (e.g., it was already sent once over the internet in the clear)?
The java client is listening on all interfaces, i.e. for a machine exposed directly to the internet ports 7875 (http interface) and 7876 (json api) could be accessed by anyone. Please, consider binding those only to the localhost (127.0.0.1) interface by default, since most people running the client will not intend to run it as a public service. (Port 7874 should obviously listen on all, for peer connections).
029baeb69fce837cd36dc4fea7822de04dc18a28c8bf36eccd90e0480835e2aa. This is SHA256 of http://88.198.210.245/Nxt.zip. 7875 and 7876 shouldn't be visible from outside. I left it open coz I don't care if someone sees what peers my node is connected to.
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:36:07 AM |
|
I made everything u said but it shows Account "0" = 583546 XNT I don't know where I screwed it Have u seen "Done" message after u opened the link with appropriate "key" and "account"? Try CTRL+F5 to bypass cached HTML.
|
|
|
|
slavo
|
|
November 23, 2013, 10:38:29 AM |
|
no; haven't seen that.
i made all the steps twice that's strange.
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:39:14 AM |
|
no; haven't seen that.
i made all the steps twice that's strange.
PM me with ur key and account. I'll try to do it.
|
|
|
|
starik69
Legendary
Offline
Activity: 1367
Merit: 1000
|
|
November 23, 2013, 10:50:33 AM |
|
Edit: I already generated a small account id (131110410587) for faucet. Burned a lot of electricity How can i generate some vanity account id?
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:51:58 AM |
|
Is anyone going to create an automatic NXT/BTC exchange? If not then I will think about creating it by myself. It's necessary to do to bring more users to Nxt.
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 10:52:47 AM |
|
Edit: I already generated a small account id (131110410587) for faucet. Burned a lot of electricity How can i generate some vanity account id? If u have Java installed then I can release my program.
|
|
|
|
starik69
Legendary
Offline
Activity: 1367
Merit: 1000
|
|
November 23, 2013, 11:02:48 AM |
|
Edit: I already generated a small account id (131110410587) for faucet. Burned a lot of electricity How can i generate some vanity account id? If u have Java installed then I can release my program. Yes, i have java
|
|
|
|
bybitcoin
|
|
November 23, 2013, 11:09:41 AM |
|
Is anyone going to create an automatic NXT/BTC exchange? If not then I will think about creating it by myself. It's necessary to do to bring more users to Nxt.
That will help a lot Come-from-Beyond, please do it! (this was promised by BCNext, but BCNext seems busy hiding his ass now) It will be a headache to provide escrow for Nxt at initial steps, and your automatic NXT/BTC will help a lot! Just two questions: will it be placed in the java or web client? And how to show the bid/ask offers?
|
|
|
|
Come-from-Beyond
Legendary
Offline
Activity: 2142
Merit: 1009
Newbie
|
|
November 23, 2013, 11:17:36 AM |
|
Is anyone going to create an automatic NXT/BTC exchange? If not then I will think about creating it by myself. It's necessary to do to bring more users to Nxt.
That will help a lot Come-from-Beyond, please do it! (this was promised by BCNext, but BCNext seems busy hiding his ass now) It will be a headache to provide escrow for Nxt at initial steps, and your automatic NXT/BTC will help a lot! Just two questions: will it be placed in the java or web client? And how to show the bid/ask offers? Creating an exchange is a lot of work. I prefer if someone else creates it. If I do it the exchange will be an ugly looking website. Something similar to BTC-e.com.
|
|
|
|
bahamapascal
|
|
November 23, 2013, 11:18:05 AM |
|
@Bahama: instead of throwing random pass of suggestions, you can come ahead and help (to run the giveaway or write an article about Nxt or anything else). For Nxt success we don't need random thoughts, we need collective decided actions. So all the respected stake holders, come ahead and help!
LoL, I think random thoughts are productive as well But I can of course run a giveaway thread, though I will first wont to wait until the actual release, as of now I have some problems understanding how the client works, I would not want to be responsible to lose 1M Nxt that arn´t mine But as soon as every thing is released, I have my Nxt in my wallet and understand how to send/resive them, I can run a giveaway thread
|
|
|
|
|