Bitcoin Forum
June 25, 2024, 05:26:55 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 [600] 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761542 times)
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 08:23:48 PM
 #11981

OK, look, I'm not a heavy hitter coder to pitch in and help here, and I wish I was.  But this security stuff is serious with major psychological/political overtones for the acceptance of NXT.  I really want to get a consensus here on a proposed course of action.  Many pages back on this thread there was a prioritized list of what was to be added to NXT in the way of features.  Where does my proposed account withdrawal freeze code idea (or something similar) rank on this in the eyes of the community, and what is the path we take to either reject it from consideration as an add-on or agree that yes, it will be implemented?

Not trying to be pushy, I just think this is too important to let it fade out when we go off chasing the next squirrel topic ten pages from now (an allusion to the dog in Up).

Would your solution help from keyloggers and trojans?

I think that if you requested withdrawals from your account be frozen until you reenter the private key code, and the client software generates internally and displays to you that private key code for you to write down on paper with a pencil for use at a later date, then yes, I do not see how either a keylogger or a Trojan could get the private key unfreeze code.  
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:24:19 PM
 #11982


Hey CfB... shouldn't Page 1 client download link agree with the one given by Jean-Luc?

Thought I had this under control... but getting confused myself.   Huh

Since we all respect your opinion, please inform where we should be downloading the client from.

thnx   Smiley

We can download client from anywhere. Just make sure SHA256 checksum matches the one provided by Jean-Luc.
BloodyRookie
Hero Member
*****
Offline Offline

Activity: 687
Merit: 500


View Profile
January 01, 2014, 08:24:33 PM
 #11983

Wouldn't it be pretty easy to restrict transactions to a specific MAC address? You register a MAC address for your account via a transaction. Only if the MAC address is the specified one, the transaction is executed. Just an idea.

It's impossible.

why?

Coz it's unknown what MAC address a transaction was sent from.

No, you misunderstood me. I don't claim that other nodes have to verify the MAC address. It's just a test that the server on your computer locally performs before he releases the transaction to other nodes. The MAC address is a fingerprint of the device you are using to send nxt coins.

Edit: OK, I think I see your point.

Nothing Else Matters
NEM: NALICE-LGU3IV-Y4DPJK-HYLSSV-YFFWYS-5QPLYE-ZDJJ
NXT: 11095639652683007953
laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 08:25:10 PM
 #11984


I think that if you requested withdrawals from your account be frozen until you reenter the private key code, and the client software generates internally and displays to you that private key code for you to write down on paper with a pencil for use at a later date, then yes, I do not see how either a keylogger or a Trojan could get the private key unlock code.  

There are remote control trojans that can print screen and send it to the hacker.
nadrimajstor
Newbie
*
Offline Offline

Activity: 30
Merit: 0



View Profile
January 01, 2014, 08:27:01 PM
 #11985

Coz it's unknown what MAC address a transaction was sent from.
And nobody ever spoofed a MAC address.  Grin
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 01, 2014, 08:27:23 PM
 #11986

I agree it could be any of those 4 reasons CfB gave, but curiously why hasn't the hacker or whoever done anything with those stolen NXT? Isn't that a weird behavior or?

just so we don't go on a tangent here,
this is the client I used.
4.8
https://nextcoin.org/index.php/topic,4.0.html

nxt-client-0.4.8.zip

Hmm... post by Drexme.

The SHA256 Hash from the forum file is the same as the SHA256 Hash from the zip I used. That file is ok.

well the link could have been changed since his download.  but most likely not.  to be 100% sure paulyc will need to get the .zip from his PCs download folder and post it for us.

But most likely it was either a keylogger or he put his password into a remote node, with the latter being most likely IMO.
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:28:05 PM
 #11987

Nobody prepend now, but with additional login field, they 'll be forced to prepend.

And they'll be entering 1234 into the login field all the time Smiley
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 08:28:19 PM
 #11988


We can download client from anywhere. Just make sure SHA256 checksum matches the one provided by Jean-Luc.

not everyone can run this setup

2X84
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
January 01, 2014, 08:28:33 PM
 #11989

Could someone with an updated blockchain check on my account for me?

5341635214821841695

I'm in a developing country at the moment  Undecided...

It would be very much appreciated as the explorer is still down.
laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 08:29:22 PM
 #11990


We can download client from anywhere. Just make sure SHA256 checksum matches the one provided by Jean-Luc.

not everyone can run this setup

by the way, there are new custom automatic installer packages coming into light every day, I am sure nobody is checking those before recommending Smiley
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
January 01, 2014, 08:30:24 PM
 #11991

Could someone with an updated blockchain check on my account for me?

5341635214821841695

I'm in a developing country at the moment  Undecided...

It would be very much appreciated as the explorer is still down.

{"balance":350997600,"effectiveBalance":350997600,"unconfirmedBalance":350997600}
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 01, 2014, 08:30:46 PM
 #11992

Could someone with an updated blockchain check on my account for me?

5341635214821841695

I'm in a developing country at the moment  Undecided...

It would be very much appreciated as the explorer is still down.

http://localhost:7874/nxt?requestType=getBalance&account=5341635214821841695
or
http://22k.io/-account/5341635214821841695
2X84
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
January 01, 2014, 08:34:07 PM
 #11993

Could someone with an updated blockchain check on my account for me?

5341635214821841695

I'm in a developing country at the moment  Undecided...

It would be very much appreciated as the explorer is still down.

http://localhost:7874/nxt?requestType=getBalance&account=5341635214821841695
or
http://22k.io/-account/5341635214821841695
Thanks CFB and Optical, I almost had a heart attack when I heard about the hack.
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 08:35:10 PM
 #11994


I think that if you requested withdrawals from your account be frozen until you reenter the private key code, and the client software generates internally and displays to you that private key code for you to write down on paper with a pencil for use at a later date, then yes, I do not see how either a keylogger or a Trojan could get the private key unlock code.  

There are remote control trojans that can print screen and send it to the hacker.

This is true.  I suggest the client software could display it as an animated gif perhaps  with random 3 to 5 second intervals between key fragment displays, so that a single screen grab or even multiple screen grabs wouldn't get it.  Whereupon the Trojan could be written to...

We can go a long way down this hall of mirrors.  I still think it is worthwhile to implement user account withdrawal freeze codes as I have described in the blockchain, for the psychological comfort aspect as well as the undeniable increased security aspect, hypothetical screengrabber Trojans or no.  

I will keep parrying about if this then that if you want.  Deciding as a community whether or not  to actually implement it is a completely separate issue that I still would like resolution upon.

intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:35:48 PM
 #11995

Nobody prepend now, but with additional login field, they 'll be forced to prepend.

And they'll be entering 1234 into the login field all the time Smiley

Most people 'll not. Better than nothing Smiley Requires only UI JS changes.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 08:36:20 PM
 #11996


We can download client from anywhere. Just make sure SHA256 checksum matches the one provided by Jean-Luc.

not everyone can run this setup


Please expand landomata.

meaning the average user shouldn't have to run this check.

Edit: there should one secured official source for client updates...preferably Blockchain to clients

laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 08:39:44 PM
 #11997

Isn't the party line not to use the word 'official' any more?  Cheesy
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 01, 2014, 08:41:00 PM
 #11998

Isn't the party line not to use the word 'official' any more?  Cheesy

Ignoring official download locations may lead to heart-attacks and loss of trust.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Jean-Luc
Sr. Member
****
Offline Offline

Activity: 392
Merit: 250



View Profile WWW
January 01, 2014, 08:41:18 PM
 #11999

I literally saw my client a few moments after it happened (it was open) so how this happened is odd!

My actual User account that has been stolen from is
NXT
16821029889165561706
I don't have any idea how this may have happened either. Just wanted to confirm, at the moment the theft happened your client was running and you had the browser window opened, and your account was unlocked (you were seeing your balance and the "send money" arrow), is that all correct?

Just trying to differentiate the possibilities, whether the hacker obtained you password via brute-force or some other way and initiated the transaction from another machine, or somehow your own machine was tricked to initiate the transaction.

And you were running 0.4.8 at the time, right? I added the second check for secret phrase before send money exactly to increase security, so that even if you account is unlocked in the browser you still need to enter your password again.

Another question, did you generate your random-looking password using some software - password manager, online service, or created it manually by typing at random?

lead Nxt developer, gpg key id: 0x811D6940E1E4240C
Nxt blockchain platform | Ardor blockchain platform | Ignis ICO
utopianfuture
Sr. Member
****
Offline Offline

Activity: 602
Merit: 268

Internet of Value


View Profile
January 01, 2014, 08:41:29 PM
 #12000

How to check SHA256 checksum ? and what should I expect ? I want to check my client right now .


░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
  TomoChain  •    •  TomoChain 
░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
Pages: « 1 ... 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 [600] 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!