Bitcoin Forum
May 07, 2024, 05:27:34 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 [2300] 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761529 times)
fmiboy
Full Member
***
Offline Offline

Activity: 189
Merit: 100


View Profile
March 19, 2014, 03:45:27 PM
 #45981

How?

Nxt transaction sigs only care about the account id's (not say something like the "genesis block id") so a "clone" (such a test net) in which account #'s that *match* main net (most likely due to using the same password) means that you can *steal* NXT by just broadcasting a test net tx on main net.

(this issue will also apply to "parallel chains" if and when implemented)


edit: did anyone tested this?
"Governments are good at cutting off the heads of a centrally controlled networks like Napster, but pure P2P networks like Gnutella and Tor seem to be holding their own." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715059654
Hero Member
*
Offline Offline

Posts: 1715059654

View Profile Personal Message (Offline)

Ignore
1715059654
Reply with quote  #2

1715059654
Report to moderator
NxtMinnow
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
March 19, 2014, 03:48:10 PM
 #45982

So if *more* NXT can be created by "broadcasting a test net tx on main net" then that is a security hole.

How?

Nxt transaction sigs only care about the account id's (not say something like the "genesis block id") so a "clone" (such a test net) in which account #'s that *match* main net (most likely due to using the same password) means that you can *steal* NXT by just broadcasting a test net tx on main net.

(this issue will also apply to "parallel chains" if and when implemented)


well, isn't testnet one kind ?!
Daedelus
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
March 19, 2014, 03:49:37 PM
 #45983

Result: U sold 50k NXT for 0.01 BTC. Smiley

Crazy!    Shocked     ...thnx brother...

Hey, just don't send NAS when he sends u 0.01 BTC.  Cheesy


Call me State-The-Obvious-Stan if you want but.... I just want to check


You would need 50,000NXT in your Nxt account for this to go through, right?



But I suppose they could look in your Nxt account, see you have 1500Nxt and say "hey, I'll buy 1500NAS for 0.01 BTC", right?
evanxxx
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
March 19, 2014, 03:49:42 PM
 #45984

I could post yours! ;-)

you don't know mine  Wink

It's not a problem as long as you don't do an outgoing transaction in the clone blockchain.

then you cannot sell the Nxt clone for Nxt, what's the benefit?
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
March 19, 2014, 03:51:12 PM
 #45985

Okay Nxt Community here is a quantum riddle;

My real NXT account number (Public Key) is 14730376987822377578 on NXT Mainnet. I have never used my real NXT passphrase on NXT testnet. However,   14730376987822377578 exists on NXT Testnet.

Yesterday, after I asked for TestNXT on this thread; 18232225178877143084 sent me a 1,000,000 + 1 TestNXT.

While testing this morning, I sent 1,000,000 + 1,000  TestNXT to 14730376987822377578 which showed as a valid public key and appeared to have transaction success.

Upon looking at the history of 14730376987822377578 from NxtTestnet, I see "This account has a balance of 1'063'416 NXT" ; 1,000,000 being the TestNXT transferred this morning and 63,416 an old real NXT balance of real NXT account 14730376987822377578.

And even more bizarre, looking down into the transaction history I find dozens of Asset transfers between 3/11/2014 and 3/14/2014 all to the same account number 18232225178877143084. WHICH is the SAME TestNXT account that sent me 1,000,000 TestNXT on 3/19/2014.

Maybe I need another cup of coffee.






did you take a ride with the ambien walrus?
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:51:33 PM
 #45986

How?

getTransactionBytes in Nas + broadcastTransaction in Nxt.

I guess after 1440 blocks it's no longer possible to do broadcastTransaction? (too old)?
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
March 19, 2014, 03:51:59 PM
 #45987

Call me State-The-Obvious-Stan if you want but.... I just want to check


You would need 50,000NXT in your Nxt account for this to go through, right?



But I suppose they could look in your Nxt account, see you have 1500Nxt and say "hey, I'll buy 1500NAS for 0.01 BTC", right?

Right
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:52:16 PM
 #45988

How?

Nxt transaction sigs only care about the account id's (not say something like the "genesis block id") so a "clone" (such a test net) in which account #'s that *match* main net (most likely due to using the same password) means that you can *steal* NXT by just broadcasting a test net tx on main net.

(this issue will also apply to "parallel chains" if and when implemented)


Should not if you add some kind of field to transaction that signifies the chain it is on.
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:53:24 PM
 #45989

So if *more* NXT can be created by "broadcasting a test net tx on main net" then that is a security hole.

How?

Nxt transaction sigs only care about the account id's (not say something like the "genesis block id") so a "clone" (such a test net) in which account #'s that *match* main net (most likely due to using the same password) means that you can *steal* NXT by just broadcasting a test net tx on main net.

(this issue will also apply to "parallel chains" if and when implemented)


well, isn't testnet one kind ?!

You can't create new nxt, it has to be in the withdrawal account.
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
March 19, 2014, 03:54:58 PM
 #45990

How?

getTransactionBytes in Nas + broadcastTransaction in Nxt.

I guess after 1440 blocks it's no longer possible to do broadcastTransaction? (too old)?

Depends on deadline. Default 24h is long enough to do the attack successfully in 99.9%.
NxtMinnow
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
March 19, 2014, 03:57:07 PM
 #45991

That's not funny opticalcarrier  Grin and no I did not as a matter of fact. Now I am starting to question whether we are in a simulation.
and What is up with all the Asset Transfers? And I couldn't send testNXT last night or this morning from a newly created account, getting the "Unknown Account" error.



Okay Nxt Community here is a quantum riddle;

My real NXT account number (Public Key) is 14730376987822377578 on NXT Mainnet. I have never used my real NXT passphrase on NXT testnet. However,   14730376987822377578 exists on NXT Testnet.

Yesterday, after I asked for TestNXT on this thread; 18232225178877143084 sent me a 1,000,000 + 1 TestNXT.

While testing this morning, I sent 1,000,000 + 1,000  TestNXT to 14730376987822377578 which showed as a valid public key and appeared to have transaction success.

Upon looking at the history of 14730376987822377578 from NxtTestnet, I see "This account has a balance of 1'063'416 NXT" ; 1,000,000 being the TestNXT transferred this morning and 63,416 an old real NXT balance of real NXT account 14730376987822377578.

And even more bizarre, looking down into the transaction history I find dozens of Asset transfers between 3/11/2014 and 3/14/2014 all to the same account number 18232225178877143084. WHICH is the SAME TestNXT account that sent me 1,000,000 TestNXT on 3/19/2014.

Maybe I need another cup of coffee.






did you take a ride with the ambien walrus?
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:58:13 PM
 #45992

How?

getTransactionBytes in Nas + broadcastTransaction in Nxt.

I guess after 1440 blocks it's no longer possible to do broadcastTransaction? (too old)?

Depends on deadline. Default 24h is long enough to do the attack successfully in 99.9%.

how come this type of thing doesn't work on bitcoin clones, what's different there? (Or does it?)
bidji29
Sr. Member
****
Offline Offline

Activity: 392
Merit: 250


View Profile
March 19, 2014, 03:58:57 PM
 #45993

How?

getTransactionBytes in Nas + broadcastTransaction in Nxt.

I guess after 1440 blocks it's no longer possible to do broadcastTransaction? (too old)?

Depends on deadline. Default 24h is long enough to do the attack successfully in 99.9%.

how come this type of thing doesn't work on bitcoin clones, what's different there? (Or does it?)

Because there is no brainwallet, so all addresses are different.

Btw, any advancment on the wallet system?

http://www.freebieservers.com/  100% FREE GAME SERVERS
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:59:00 PM
 #45994

That's not funny opticalcarrier  Grin and no I did not as a matter of fact. Now I am starting to question whether we are in a simulation.
and What is up with all the Asset Transfers? And I couldn't send testNXT last night or this morning from a newly created account, getting the "Unknown Account" error.



Okay Nxt Community here is a quantum riddle;

My real NXT account number (Public Key) is 14730376987822377578 on NXT Mainnet. I have never used my real NXT passphrase on NXT testnet. However,   14730376987822377578 exists on NXT Testnet.

Yesterday, after I asked for TestNXT on this thread; 18232225178877143084 sent me a 1,000,000 + 1 TestNXT.

While testing this morning, I sent 1,000,000 + 1,000  TestNXT to 14730376987822377578 which showed as a valid public key and appeared to have transaction success.

Upon looking at the history of 14730376987822377578 from NxtTestnet, I see "This account has a balance of 1'063'416 NXT" ; 1,000,000 being the TestNXT transferred this morning and 63,416 an old real NXT balance of real NXT account 14730376987822377578.

And even more bizarre, looking down into the transaction history I find dozens of Asset transfers between 3/11/2014 and 3/14/2014 all to the same account number 18232225178877143084. WHICH is the SAME TestNXT account that sent me 1,000,000 TestNXT on 3/19/2014.

Maybe I need another cup of coffee.






did you take a ride with the ambien walrus?

The newly created account error was just a bug in my code Wink I will upload new version later today that fixes it.
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 03:59:23 PM
 #45995

How?

getTransactionBytes in Nas + broadcastTransaction in Nxt.

I guess after 1440 blocks it's no longer possible to do broadcastTransaction? (too old)?

Depends on deadline. Default 24h is long enough to do the attack successfully in 99.9%.

how come this type of thing doesn't work on bitcoin clones, what's different there? (Or does it?)

Because there is no brainwallet, so all address are different

That's what I thought. Though collisions are always possible Wink
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
March 19, 2014, 03:59:33 PM
 #45996

how come this type of thing doesn't work on bitcoin clones, what's different there? (Or does it?)

Bitcoin signs each input. Nxt doesn't have inputs.
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
March 19, 2014, 04:00:51 PM
 #45997

how come this type of thing doesn't work on bitcoin clones, what's different there? (Or does it?)

Bitcoin signs each input. Nxt doesn't have inputs.

What do you mean by input?
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1009

Newbie


View Profile
March 19, 2014, 04:02:31 PM
 #45998

What do you mean by input?

https://en.bitcoin.it/wiki/Transactions#Input
L5Society
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
March 19, 2014, 04:07:26 PM
 #45999

So I was brainstorming the decentralized sports betting idea with my friend yesterday, and I've got some new ideas. Can smarter people than me give me some feedback? These ideas might be really dumb, because I'm not a programmer and I don't fully understand how everything works.

1) A parallel blockchain that contains the history of scores generated by a crawler that pulls data from ESPN, Yahoo Sports, Google, etc and crosschecks the data against the sources. Users of the betting service must somehow reference the correct score history when placing bids for a new bet. After a certain number of confirmations (ie when the future bettors come to a consensus on the correct score history), the old bets are paid out.

2) A parallel blockchain that contains the history of scores generated by a crawler that pulls data from ESPN, Yahoo Sports, Google, etc and crosschecks the data against the sources. Users of the betting service must submit corrections to the blockchain, to be verified by "miners" which are rewarded for the verification (somehow, to be determined). If you submit a false claim for correction, you get penalized in a big way.

These two ideas are trying to decentralize the score reporting portion, so that payouts can be automated without trusting a 3rd party to correctly report the scores.
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1075


Ian Knowles - CIYAM Lead Developer


View Profile WWW
March 19, 2014, 04:14:08 PM
 #46000

These two ideas are trying to decentralize the score reporting portion, so that payouts can be automated without trusting a 3rd party to correctly report the scores.

The main problem is "how do you trust" the chains reporting?

Basically "block chain tech" can only accurately report on "other block chains".

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Pages: « 1 ... 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 [2300] 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!