Bitcoin Forum
May 08, 2024, 01:39:48 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 [599] 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761529 times)
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 01, 2014, 08:04:39 PM
Last edit: January 01, 2014, 09:13:33 PM by opticalcarrier
 #11961

All,  I would immediately stop downloading clients from mega.co links, and only download from versions Jeanluc posts on info.crypto.org or on forums.nxtcrypto.org.  There should also be a mirror site on www.nxtcrypto.org.

If your funds were stolen and you have a 30+ long passphrase consisting of upper/lower/number characters and is not anything in print or spoken, then you have a keylogger on your PC that saw your password.  One was recently made and released as some IM app that stole funds.


Method to freeze funds into a new acct. (You will not be able to forge with these funds)

1. Boot to linux live CD.  Use one a few months old.  The live CD must have java jre 1.7
2. install latest client from forums.nxtcrypto.org/client.zip
3. write your new complex passphrase on a piece of paper
4. unlock the client with passphrase.
5. write down the new account number
6. lock it and unlock again.
7. verify account number.
8.  do 6 & 7 again once more to verify.
9. write long passphrase on a piece of paper. (paper wallet)
10. open old account, send funds to new account
11. close old account, open new account
12. wait for a few confirmations of the transfer to the new account

discussion of this method here: https://forums.nxtcrypto.org/viewtopic.php?f=17&t=267
1715132388
Hero Member
*
Offline Offline

Posts: 1715132388

View Profile Personal Message (Offline)

Ignore
1715132388
Reply with quote  #2

1715132388
Report to moderator
Once a transaction has 6 confirmations, it is extremely unlikely that an attacker without at least 50% of the network's computation power would be able to reverse it.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
marcus03
Full Member
***
Offline Offline

Activity: 224
Merit: 100


View Profile
January 01, 2014, 08:05:26 PM
 #11962

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip

Hmm... post by Drexme.
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
January 01, 2014, 08:06:50 PM
 #11963

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip

Hmm... post by Drexme.

Latest client links are updated by someone else, not drexme. (But I doubt that's the issue).
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 08:07:59 PM
 #11964

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip

Hmm... post by Drexme.

Dun dun DUN. (music)
PaulyC
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile WWW
January 01, 2014, 08:10:13 PM
 #11965

Gonna take off for a min.
Btw. asked earlier, I have the latest ESET 64 antivirus software, running always, but I'll run a full scan, thanks again.

Doge Mars Landing Foundation
(founder) Coined the phrase, "Doge to the Mars" and "Check that Hash!". Discoverer of the 2013 NXT nefarious wallet.  Admin. FameMom [FAMOM]
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 08:13:04 PM
 #11966

OK, look, I'm not a heavy hitter coder to pitch in and help here, and I wish I was.  But this security stuff is serious with major psychological/political overtones for the acceptance of NXT.  I really want to get a consensus here on a proposed course of action.  Many pages back on this thread there was a prioritized list of what was to be added to NXT in the way of features.  Where does my proposed account withdrawal freeze code idea (or something similar) rank on this in the eyes of the community, and what is the path we take to either reject it from consideration as an add-on or agree that yes, it will be implemented?

Not trying to be pushy, I just think this is too important to let it fade out when we go off chasing the next squirrel topic ten pages from now (an allusion to the dog in Up).
laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 08:14:35 PM
 #11967

OK, look, I'm not a heavy hitter coder to pitch in and help here, and I wish I was.  But this security stuff is serious with major psychological/political overtones for the acceptance of NXT.  I really want to get a consensus here on a proposed course of action.  Many pages back on this thread there was a prioritized list of what was to be added to NXT in the way of features.  Where does my proposed account withdrawal freeze code idea (or something similar) rank on this in the eyes of the community, and what is the path we take to either reject it from consideration as an add-on or agree that yes, it will be implemented?

Not trying to be pushy, I just think this is too important to let it fade out when we go off chasing the next squirrel topic ten pages from now (an allusion to the dog in Up).

Would your solution help from keyloggers and trojans?
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 01, 2014, 08:15:36 PM
 #11968

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip



its unforunate that one of the links there is a mega.co server.  paulyc please tell us if you downloaded from the mega.co link or not.
in fact, can you please look on your HD and get the zipfile and post it somewhere for us to look at.
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:16:05 PM
 #11969

I've got PaulyC's password. It's uncrackable and matches the account. If he is not trolling then we have 4 explanations:

- Someone cracked SHA256 and Curve25519 (why then multi-million accounts not hacked?)
- Someone distributes modified NRS (someone should decompile PaulyC's software)
- Keylogger
- He used online node that records entered passphrases

He should calculate the SHA256 Hash of the class files, no need to decompile.

So, keylogger or sniffing node or modified NRS.

1. Keylogger

NXT is too young to understand for hackers that random password for 127.0.0.1 is something good. I am sure it was not because of keylogger.

2. Sniffing node

Lets ask victim - which node did he use to access his account? Did he ever use 3rd party online wallet atleast once to access his account?

3. modified NRS

Send your copy of NRS to CfB or me and we 'll check each file's SHA/CRC against the stock version.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Patel
Legendary
*
Offline Offline

Activity: 1321
Merit: 1007



View Profile WWW
January 01, 2014, 08:16:47 PM
 #11970

Finding the latest client from this thread is difficult. I think CFB should start another thread just with client update download links
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:17:33 PM
 #11971

We haven't looked at this possibility...updating client from the blockchain would solve this.

It's enough to modify only JavaScript part to send entered passphrases to adversary's server.

Edit: It's only 10 lines of JS code.

so how do we protect again this.

After downloading NRS check SHA256 checksum.
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:18:03 PM
 #11972

OK, look, I'm not a heavy hitter coder to pitch in and help here, and I wish I was.  But this security stuff is serious with major psychological/political overtones for the acceptance of NXT.  I really want to get a consensus here on a proposed course of action.  Many pages back on this thread there was a prioritized list of what was to be added to NXT in the way of features.  Where does my proposed account withdrawal freeze code idea (or something similar) rank on this in the eyes of the community, and what is the path we take to either reject it from consideration as an add-on or agree that yes, it will be implemented?

Not trying to be pushy, I just think this is too important to let it fade out when we go off chasing the next squirrel topic ten pages from now (an allusion to the dog in Up).

Would your solution help from keyloggers and trojans?

It's very easy to add a special KEYFILE additional to password, which 'll be used against keyloggers. Once again, protocol change is not required.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
BloodyRookie
Hero Member
*****
Offline Offline

Activity: 687
Merit: 500


View Profile
January 01, 2014, 08:18:40 PM
 #11973

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip

Hmm... post by Drexme.

The SHA256 Hash from the forum file is the same as the SHA256 Hash from the zip I used. That file is ok.

Nothing Else Matters
NEM: NALICE-LGU3IV-Y4DPJK-HYLSSV-YFFWYS-5QPLYE-ZDJJ
NXT: 11095639652683007953
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:19:03 PM
 #11974

Wouldn't it be pretty easy to restrict transactions to a specific MAC address? You register a MAC address for your account via a transaction. Only if the MAC address is the specified one, the transaction is executed. Just an idea.

It's impossible.

why?

Coz it's unknown what MAC address a transaction was sent from.
NxtChg
Hero Member
*****
Offline Offline

Activity: 840
Merit: 1000


Simcoin Developer


View Profile WWW
January 01, 2014, 08:19:21 PM
 #11975

So, keylogger or sniffing node or modified NRS.

1. Keylogger
2. Sniffing node
3. modified NRS


4. Error in the client that allows remote connect and emptying of the account.

Simcoin: https://simtalk.org:444/ | The Simplest Bitcoin Wallet: https://tsbw.io/ | Coinmix: https://coinmix.to | Tippr stats: https://tsbw.io/tippr/
--
About smaragda and his lies: https://medium.com/@nxtchg/about-smaragda-and-his-lies-c376e4694de9
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:20:47 PM
 #11976

Finding the latest client from this thread is difficult. I think CFB should start another thread just with client update download links

Last client is always available for download at info.nxtcrypto.org , we receive the file and SHA checksum directly from developers and it's hosted on our secure server and not some 3rd party file sharing service.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:21:16 PM
 #11977

So, even password "Alisa" 'll be quite secure when using with login "mrbober777", so the final password is   "mrbober777Alisa"     which is much more protected thay plain "Alisa". Attacker should spend MUCH more resources for brute-forcing passwords with a login added to the password field.

CfB ?

We can start prepending "Alisa" to our passphrases right now. (Need to create a new account though. And don't use "Alisa" plz.)
bitcoinpaul
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1000



View Profile
January 01, 2014, 08:21:43 PM
 #11978

I've got PaulyC's password. It's uncrackable and matches the account. If he is not trolling then we have 4 explanations:

- Someone cracked SHA256 and Curve25519 (why then multi-million accounts not hacked?)
- Someone distributes modified NRS (someone should decompile PaulyC's software)
- Keylogger
- He used online node that records entered passphrases

While I may give PaulyC the benefit of doubt, it can't be ruled out that it is a legit transaction authorized by PaulyC himself.

What about this?
nadrimajstor
Newbie
*
Offline Offline

Activity: 30
Merit: 0



View Profile
January 01, 2014, 08:21:58 PM
 #11979

Please consider running a non-proprietary OS...
There are many flavours of Linux/BSD that one can easily run live from a CD / USB drive.
It is not a panacea for all attack vectors but it is helpful.
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:22:25 PM
 #11980

So, even password "Alisa" 'll be quite secure when using with login "mrbober777", so the final password is   "mrbober777Alisa"     which is much more protected thay plain "Alisa". Attacker should spend MUCH more resources for brute-forcing passwords with a login added to the password field.

CfB ?

We can start prepending "Alisa" to our passphrases right now. (Need to create a new account though. And don't use "Alisa" plz.)

Nobody prepend now, but with additional login field, they 'll be forced to prepend.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Pages: « 1 ... 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 [599] 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!