Bitcoin Forum
November 18, 2024, 04:21:40 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 [117] 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761608 times)
mcjavar
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
December 05, 2013, 10:11:07 PM
 #2321

Version 0.3.13 - https://dl.dropboxusercontent.com/u/67242472/nxt.zip

Added warning for secret phrases < 30 symbols.
Added extra transaction validation (@hacker: attempt ur trick again)

How about adding OTP Auth for sending coins? (should be optional)
Kyune
Sr. Member
****
Offline Offline

Activity: 287
Merit: 250


View Profile
December 05, 2013, 10:13:16 PM
 #2322

Added warning for secret phrases < 30 symbols.
This may help some, but it is worth noting that human brains are notoriously poor at generating enough entropy for a good brainwallet passphrase.   Bitcoin lore already has too many stories of brainwallets drained by attackers running dictionary attacks.  I've seen discussions here, on reddit, on on blogs that provide proof-of-concept code showing how attackers can maintain a local copy of a blockchain and execute a dictionary attack while entirely offline.  The operating assumption (for Bitcoin) is that these attacks are underway and increasingly sophisticated.  

Presumably, the same kind of attack could be tailored to the Nxt Java client here, particularly once the source code is released.  If the value of Nxt rises, Nxt brainwallets would become a more tempting target for any attackers that have already honed their skills on cracking bitcoin brainwallets in the past.

Unlike Bitcoin, Nxt presently relies solely on brainwallets as the means of user authentication.  There is no "cold storage" alternative offered.  I see this security model as a vulnerability, and as future PR problem hurting mainstream adoption if Nxt coin heists do start happening.   Brainwallets are surprisingly tough to get right for the unsophisticated user.


BTC:  1K4VpdQXQhgmTmq68rbWhybvoRcyNHKyVP
bizz
Hero Member
*****
Offline Offline

Activity: 492
Merit: 500


View Profile
December 05, 2013, 10:23:24 PM
 #2323

Added warning for secret phrases < 30 symbols.
Unlike Bitcoin, Nxt presently relies solely on brainwallets as the means of user authentication.  There is no "cold storage" alternative offered.  I see this security model as a vulnerability, and as future PR problem hurting mainstream adoption if Nxt coin heists do start happening.   Brainwallets are surprisingly tough to get right for the unsophisticated user.



I just disconnected from Internet, started the client & generated offline cold storage address (wallet).
nexern
Hero Member
*****
Offline Offline

Activity: 597
Merit: 500



View Profile
December 05, 2013, 10:29:16 PM
 #2324

So anybody who has a suggestion or offer for Nxt project, please post it here or preferably open a new thread and let people comment, discuss and decide about your idea there.
Not intending to intrude, but we may have quite a bunch of active folks lurking / setting up here in the Bounty requests & assignments at nextcoin.org. Soonish we will have a built in facility to send bounty NXT to each other WITHIN the forum.

nice, you have a ticker.
can i use this tickerdata on blockchain explorer?
showing the actual nxt quote there would be nice.
Drexme
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
December 05, 2013, 10:35:01 PM
 #2325

So anybody who has a suggestion or offer for Nxt project, please post it here or preferably open a new thread and let people comment, discuss and decide about your idea there.
Not intending to intrude, but we may have quite a bunch of active folks lurking / setting up here in the Bounty requests & assignments at nextcoin.org. Soonish we will have a built in facility to send bounty NXT to each other WITHIN the forum.
If you want to donate to the cause here's my address: 8333778433828768082

We need translators for:
Español (Spanish)
Türkçe (Turkish)
Magyar (Hungarian)
Lietuviai (Lithuania)
Polski (Polish)
Pyccкий (Russian)

For topics:
What is NXT?:               http://nextcoin.org/index.php/topic,104.0.html
Windows Install Guide:    http://nextcoin.org/index.php/topic,4.0.html
Mac OS X Installation:    http://nextcoin.org/index.php/topic,101.0.html
NXT Info:                     http://nextcoin.org/index.php/topic,14.0.html

I'm personally paying 250 per translations that are not already in the boards. Do not use Google Translate!

Just message PM me the link of the translated topic
with your NXT address.

Thanks in advance  Grin

starik69
Legendary
*
Offline Offline

Activity: 1367
Merit: 1000


View Profile
December 05, 2013, 10:46:19 PM
 #2326

There is no "cold storage" alternative offered.
You are wrong. The code that transforms passphrase into account number is open. Moreover, on this forum were presented two offline programs to generate "nice" account numbers like vanitygen for bitcoin. You can ever make an analog of directory.io with all passphrases and corresponding account numbers.
It is cryptogtaphy, baby  Grin
nexern
Hero Member
*****
Offline Offline

Activity: 597
Merit: 500



View Profile
December 05, 2013, 10:50:43 PM
 #2327

So anybody who has a suggestion or offer for Nxt project, please post it here or preferably open a new thread and let people comment, discuss and decide about your idea there.
Not intending to intrude, but we may have quite a bunch of active folks lurking / setting up here in the Bounty requests & assignments at nextcoin.org. Soonish we will have a built in facility to send bounty NXT to each other WITHIN the forum.

btw, the output is a valid json standard or is there a missing comma after each array?
one more thing, if you add a unix timestamp to each array, time math and aggregations
for data visualisations are much easier and faster. could you add this to your cgi output?
GCInc.
Hero Member
*****
Offline Offline

Activity: 566
Merit: 500


View Profile WWW
December 05, 2013, 11:00:55 PM
 #2328

btw, the output is a valid json standard or is there a missing comma after each array?
one more thing, if you add a unix timestamp to each array, time math and aggregations
for data visualisations are much easier and faster. could you add this to your cgi output?
Yes, feel free to use the ticker. Timestamp added, please use a less resource intensive version at

http://dgex.com/API/trades.json

It updates on the server once every minute.

nexern
Hero Member
*****
Offline Offline

Activity: 597
Merit: 500



View Profile
December 05, 2013, 11:04:24 PM
 #2329

btw, the output is a valid json standard or is there a missing comma after each array?
one more thing, if you add a unix timestamp to each array, time math and aggregations
for data visualisations are much easier and faster. could you add this to your cgi output?
Yes, feel free to use the ticker. Timestamp added, please use a less resource intensive version at

http://dgex.com/API/trades.json

It updates on the server once every minute.


great, this one looks fine. a poll intervall of 3 min. is ok?
GCInc.
Hero Member
*****
Offline Offline

Activity: 566
Merit: 500


View Profile WWW
December 05, 2013, 11:10:28 PM
 #2330

great, this one looks fine. a poll intervall of 3 min. is ok?
Yea no problem with that, a static file it's hopefully gonna carry some decent load before throttle limiting needs to be considered.

demols
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 05, 2013, 11:19:35 PM
 #2331

Added warning for secret phrases < 30 symbols.
Unlike Bitcoin, Nxt presently relies solely on brainwallets as the means of user authentication.  There is no "cold storage" alternative offered.  I see this security model as a vulnerability, and as future PR problem hurting mainstream adoption if Nxt coin heists do start happening.   Brainwallets are surprisingly tough to get right for the unsophisticated user.



I just disconnected from Internet, started the client & generated offline cold storage address (wallet).

How to change the secret phrases ?
nexern
Hero Member
*****
Offline Offline

Activity: 597
Merit: 500



View Profile
December 05, 2013, 11:19:46 PM
 #2332

great, this one looks fine. a poll intervall of 3 min. is ok?
Yea no problem with that, a static file it's hopefully gonna carry some decent load before throttle limiting needs to be considered.

very good, thanks. tomorrow i will process this data and link to your site.
please give me a note if poll frequency need to be lowered to save your
bandwith.
idev
Hero Member
*****
Offline Offline

Activity: 860
Merit: 1004


BTC OG and designer of the BitcoinMarket.com logo


View Profile
December 05, 2013, 11:21:42 PM
 #2333

Added warning for secret phrases < 30 symbols.
Unlike Bitcoin, Nxt presently relies solely on brainwallets as the means of user authentication.  There is no "cold storage" alternative offered.  I see this security model as a vulnerability, and as future PR problem hurting mainstream adoption if Nxt coin heists do start happening.   Brainwallets are surprisingly tough to get right for the unsophisticated user.



I just disconnected from Internet, started the client & generated offline cold storage address (wallet).

How to change the secret phrases ?

Passwords can not be changed. You will need to create a new account with a new password.
Taxidermista
Legendary
*
Offline Offline

Activity: 1148
Merit: 1001



View Profile
December 05, 2013, 11:25:34 PM
 #2334

After 38 hours my NXT deposit at dgex.com is still PENDING.

mcjavar
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
December 05, 2013, 11:31:39 PM
 #2335

I am reading about NXT a lot, but still can´t understand how the calculation and validation is working?

Is my PC actually doint anything if I am running the client? Wht does it mean if I process a block? What happens in the background? (I would also try to summarize it and add it to the FAQ if I would understand that) Smiley

Could someone please answer this?
Chang Hum
Hero Member
*****
Offline Offline

Activity: 714
Merit: 502


View Profile
December 05, 2013, 11:33:55 PM
 #2336

Added warning for secret phrases < 30 symbols.
Unlike Bitcoin, Nxt presently relies solely on brainwallets as the means of user authentication.  There is no "cold storage" alternative offered.  I see this security model as a vulnerability, and as future PR problem hurting mainstream adoption if Nxt coin heists do start happening.   Brainwallets are surprisingly tough to get right for the unsophisticated user.



I just disconnected from Internet, started the client & generated offline cold storage address (wallet).

How to change the secret phrases ?

Passwords can not be changed. You will need to create a new account with a new password.

Why can't an address be created that you associate a password with like Bitcoin? aside from what's happened to my account which admittedly could have been due to my own failures/recent bitcointalk problems, if you want scale-ability the current set up will surely lead to problems as the user volume gets higher even with long phrases. You'll no doubt have phrases that will have been memorized by more than one user leading to a security floor. Even using Sha256, leads back to the original password or phrase!
Chang Hum
Hero Member
*****
Offline Offline

Activity: 714
Merit: 502


View Profile
December 05, 2013, 11:38:52 PM
 #2337

I am reading about NXT a lot, but still can´t understand how the calculation and validation is working?

Is my PC actually doint anything if I am running the client? Wht does it mean if I process a block? What happens in the background? (I would also try to summarize it and add it to the FAQ if I would understand that) Smiley

Could someone please answer this?

As I understand it running your client helps confirm transactions, confirming transactions rewards you from transaction fees based on how many coins you already have (more coins, higher reward).
mcjavar
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
December 05, 2013, 11:45:20 PM
 #2338

I am reading about NXT a lot, but still can´t understand how the calculation and validation is working?

Is my PC actually doint anything if I am running the client? Wht does it mean if I process a block? What happens in the background? (I would also try to summarize it and add it to the FAQ if I would understand that) Smiley

Could someone please answer this?

As I understand it running your client helps confirm transactions, confirming transactions rewards you from transaction fees based on how many coins you already have (more coins, higher reward).

But hw does the confirmation works? What is my client doing?
Chang Hum
Hero Member
*****
Offline Offline

Activity: 714
Merit: 502


View Profile
December 05, 2013, 11:58:32 PM
 #2339

I am reading about NXT a lot, but still can´t understand how the calculation and validation is working?

Is my PC actually doint anything if I am running the client? Wht does it mean if I process a block? What happens in the background? (I would also try to summarize it and add it to the FAQ if I would understand that) Smiley

Could someone please answer this?

As I understand it running your client helps confirm transactions, confirming transactions rewards you from transaction fees based on how many coins you already have (more coins, higher reward).

But hw does the confirmation works? What is my client doing?

In the client area you'll see strings of numbers constantly flickering and changing in the peers and blocks area. These set's of flickering numbers are like happy mini robots that will work day and night to make the chain successful. Sorry don't know.
lyynx
Sr. Member
****
Offline Offline

Activity: 380
Merit: 275



View Profile
December 06, 2013, 01:59:36 AM
 #2340

After 38 hours my NXT deposit at dgex.com is still PENDING.

This is not the dgex.com forum, either go to their dedicated forum thread http://nextcoin.org/index.php/topic,3.0.html or send them an email.

Pages: « 1 ... 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 [117] 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!