Bitcoin Forum
April 23, 2024, 09:30:31 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they believe that the creator of this topic displays some red flags which make them high-risk. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 ... 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 [65]
  Print  
Author Topic: Nxt source code flaw reports  (Read 113306 times)
Evil-Knievel
Legendary
*
Offline Offline

Activity: 1260
Merit: 1168



View Profile
March 22, 2014, 09:33:26 PM
Last edit: April 15, 2016, 02:31:48 PM by Evil-Knievel
 #1281

This message was too old and has been purged
1713864631
Hero Member
*
Offline Offline

Posts: 1713864631

View Profile Personal Message (Offline)

Ignore
1713864631
Reply with quote  #2

1713864631
Report to moderator
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713864631
Hero Member
*
Offline Offline

Posts: 1713864631

View Profile Personal Message (Offline)

Ignore
1713864631
Reply with quote  #2

1713864631
Report to moderator
1713864631
Hero Member
*
Offline Offline

Posts: 1713864631

View Profile Personal Message (Offline)

Ignore
1713864631
Reply with quote  #2

1713864631
Report to moderator
Eadeqa
Hero Member
*****
Offline Offline

Activity: 644
Merit: 500


View Profile
March 22, 2014, 09:34:13 PM
 #1282

@Twin: This is just a quick-and-dirty implementation, If we had a good structure (maybe some B-trees with a lookup complexity of O(log) ) where all NXT accounts were stored, we could mine them all parallely.
Thats what the github Repository is for ... let us make this "first approach" better ;-)

I am not doubting that.

We could make a mining pool/mining list where we add account numbers, where we are XX% sure that they are DarkNXT (not accessible because of lost/forgotten passphrase)

They would be "lost" if the sender sent them to wrong ID (mistyped, copy paste error, etc).

Nomi, Shan, Adnan, Noshi, Nxt, Adn Khn
NXT-GZYP-FMRT-FQ9K-3YQGS
https://github.com/Lafihh/encryptiontest
Evil-Knievel
Legendary
*
Offline Offline

Activity: 1260
Merit: 1168



View Profile
March 22, 2014, 09:47:22 PM
Last edit: April 15, 2016, 01:07:46 PM by Evil-Knievel
 #1283

This message was too old and has been purged
LiQio
Legendary
*
Offline Offline

Activity: 1181
Merit: 1002



View Profile
March 22, 2014, 09:47:44 PM
 #1284

16386134630970163904:  Not a bad account if you're just targeting one...  (30,002,058 NXT)

http://www.mynxt.info/blockexplorer/details.php?action=ac&ac=16386134630970163904

I'm not sure what I missed, but why is 16386134630970163904 HiberNXT?

http://localhost:7876/nxt?requestType=getAccountPublicKey&account=16386134630970163904
TwinWinNerD
Legendary
*
Offline Offline

Activity: 1680
Merit: 1001


CEO Bitpanda.com


View Profile WWW
March 22, 2014, 09:50:11 PM
 #1285

16386134630970163904:  Not a bad account if you're just targeting one...  (30,002,058 NXT)

http://www.mynxt.info/blockexplorer/details.php?action=ac&ac=16386134630970163904

I'm not sure what I missed, but why is 16386134630970163904 HiberNXT?

http://localhost:7876/nxt?requestType=getAccountPublicKey&account=16386134630970163904


It isn't. Someone just thought that 0 outgoing transaction equals no public key. But forging counts as creating a public key too!

LiQio
Legendary
*
Offline Offline

Activity: 1181
Merit: 1002



View Profile
March 22, 2014, 09:52:47 PM
 #1286

16386134630970163904:  Not a bad account if you're just targeting one...  (30,002,058 NXT)

http://www.mynxt.info/blockexplorer/details.php?action=ac&ac=16386134630970163904

I'm not sure what I missed, but why is 16386134630970163904 HiberNXT?

http://localhost:7876/nxt?requestType=getAccountPublicKey&account=16386134630970163904


It isn't. Someone just thought that 0 outgoing transaction equals no public key. But forging counts as creating a public key too!

I know - we just saved some trees here  Grin
Evil-Knievel
Legendary
*
Offline Offline

Activity: 1260
Merit: 1168



View Profile
March 22, 2014, 09:54:32 PM
Last edit: April 15, 2016, 02:13:31 PM by Evil-Knievel
 #1287

This message was too old and has been purged
allwelder
Legendary
*
Offline Offline

Activity: 1512
Merit: 1004



View Profile
March 23, 2014, 02:14:57 AM
 #1288



WOOOOOOOOOOOOOOOOOOOOOOOOOOOW! THANKS!

Appreciate that bounty,
my account is: 15421585458835302363
congratulate

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
rlh
Hero Member
*****
Offline Offline

Activity: 804
Merit: 1004


View Profile
March 23, 2014, 02:35:57 AM
 #1289

Yes, congratulations.  I didn't realize this bounty was still open.  I would have never caught that, even when I had the time to study the code.

A Personal Quote on BTT from 2011:
"I'd be willing to make a moderate "investment" if the value of the BTC went below $2.00.  Otherwise I'll just have to live with my 5 BTC and be happy. :/"  ...sigh.  If only I knew.
gimre
Legendary
*
Offline Offline

Activity: 866
Merit: 1002



View Profile WWW
March 23, 2014, 06:58:58 AM
Last edit: March 23, 2014, 09:53:31 AM by gimre
 #1290

funny, I knew ''k'' was picked, I wasn't aware haven't figured out it could be abused in such way:

Actually, there might be a bug in the C++ code. I compiled it and ran a few tests with sign, but the signature that gets generated is different each time i run the program (typically the sign of an uninitialized variable somewhere). The problem appears to happen somewhere in divmod.

It's a normal behavior, not a bug, don't waste too much time on that.

That depends on algo.
In case of Nxt's EC-KCDSA "k" value is picked not choosen randomly,
So if you feed it with the same data, sig should be te same...

(k is calculated from 1360-1365, that's Y in NXT code
https://bitbucket.org/JeanLucPicard/nxt-public/src/4073c21098076d3469b3f74d49e73ffabe3a2001/Nxt.java?at=master#cl-1360
and it's based on "sig priv key" (s based on user's pub key) and message
)



NemusExMāchinā
Catapult docs: https://docs.symbol.dev
github: https://github.com/symbol
Sh1n
Newbie
*
Offline Offline

Activity: 29
Merit: 0


View Profile
March 23, 2014, 11:16:38 AM
 #1291

Congrats, Evil-Knievel Cheesy Enjoy your reward and yes please, do stick around ^^
Eadeqa
Hero Member
*****
Offline Offline

Activity: 644
Merit: 500


View Profile
March 24, 2014, 06:05:13 PM
 #1292

WOOOOOOOOOOOOOOOOOOOOOOOOOOOW! THANKS!

Appreciate that bounty,
my account is: 15421585458835302363
Too bad you transfered the nxt to bter and left nxt completely already. I was going to donate you some NXT in order to motivate you to stay with us

That would be stupid. He will dump them too. Let it be. Donate them to some worthy cause

Nomi, Shan, Adnan, Noshi, Nxt, Adn Khn
NXT-GZYP-FMRT-FQ9K-3YQGS
https://github.com/Lafihh/encryptiontest
LiQio
Legendary
*
Offline Offline

Activity: 1181
Merit: 1002



View Profile
March 24, 2014, 07:33:47 PM
 #1293

WOOOOOOOOOOOOOOOOOOOOOOOOOOOW! THANKS!

Appreciate that bounty,
my account is: 15421585458835302363
Too bad you transfered the nxt to bter and left nxt completely already. I was going to donate you some NXT in order to motivate you to stay with us

Could be, but could also be, that he stores them on bter or that he moves them through bter to disguise the origin - don't jump to conclusions please
allwelder
Legendary
*
Offline Offline

Activity: 1512
Merit: 1004



View Profile
January 19, 2016, 02:12:22 PM
 #1294

Not sure if its logic flaw, but somebody could simply change initial allocation in genesis block to give themselves a lot of NXT.

We have seen a case of altered client already, so changing genesis block's hardcoding and hypnotizing jean-luc into signing it as the official release, would be an obvious but effective way to steal a lot of NXT

James

True, that's why noone knows who Jean-Luc is.

Maybe he is BCNext!

Well, BCNext, "Jean-Luc" and Come-from-Beyond are all three Russian.

I'm not entirely sure who is who or whether all three are one, but that makes it more exciting Grin
Confirmed.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Hachoir
Member
**
Offline Offline

Activity: 107
Merit: 10


View Profile
January 19, 2016, 02:44:34 PM
 #1295

What is confirmed

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
LINKBUILD asset • Join crowdfunding Linkbuilding.io • Dividend+commission+signature-rewards
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
box0214
Sr. Member
****
Offline Offline

Activity: 350
Merit: 251


View Profile
January 20, 2016, 04:38:47 AM
 #1296

What is confirmed

that satoshi ran away and came under the cover as bcnext.
Hachoir
Member
**
Offline Offline

Activity: 107
Merit: 10


View Profile
January 20, 2016, 06:49:13 AM
 #1297

What proves that ?

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
LINKBUILD asset • Join crowdfunding Linkbuilding.io • Dividend+commission+signature-rewards
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
mthcl
Sr. Member
****
Offline Offline

Activity: 376
Merit: 300


View Profile
January 20, 2016, 01:34:02 PM
 #1298

What proves that ?
It's one of those unprovable statements that are nevertheless true, see https://en.wikipedia.org/wiki/G%C3%B6del%27s_incompleteness_theorems
lurker10
Sr. Member
****
Offline Offline

Activity: 378
Merit: 250


View Profile
November 21, 2016, 12:12:10 PM
 #1299

FYI, newcomers!
Did you know you can mine NXT in the Lucky node project?
Computational and bandwidth requirements are very low - some users run it on a Raspberry Pi.
Run the node 24/7 or as often as you can while you work or play.
Join in with the over 100 nodes that are already in the project.

Pages: « 1 ... 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 [65]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!