Bitcoin Forum
December 14, 2024, 12:54:40 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 [116] 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 ... 173 »
  Print  
Author Topic: Blockchain.info - Bitcoin Block explorer & Currency Statistics  (Read 482661 times)
Timbo925
Sr. Member
****
Offline Offline

Activity: 352
Merit: 250



View Profile
April 21, 2013, 12:02:03 PM
 #2301

Put a warning up about enabling 2 factor auth - I lost 1.2 BTC due to a "It would take a desktop PC about 175 years to crack your password" password. (http://howsecureismypassword.net)


Dont test your password at these kind of sites. Just plain stupid to enter it somewhere online to test the strengt ...
rme
Hero Member
*****
Offline Offline

Activity: 756
Merit: 504



View Profile
April 21, 2013, 12:24:58 PM
 #2302

Put a warning up about enabling 2 factor auth - I lost 1.2 BTC due to a "It would take a desktop PC about 175 years to crack your password" password. (http://howsecureismypassword.net)


Dont test your password at these kind of sites. Just plain stupid to enter it somewhere online to test the strengt ...
The website uses only Javascript.
rme
Hero Member
*****
Offline Offline

Activity: 756
Merit: 504



View Profile
April 21, 2013, 12:26:10 PM
 #2303

Please Blockchain.info redirect HTTP to HTTPS always like Bitcointalk and MtGox do.
Also in the wallet login page warn users to check the green bar in the url.
internationalaw
Member
**
Offline Offline

Activity: 78
Merit: 10


Community Manager at Letstalkbitcoin.com


View Profile WWW
April 21, 2013, 05:51:51 PM
 #2304

Thanks for the reset piuk!!!!!!

ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
April 21, 2013, 11:45:19 PM
 #2305

Put a warning up about enabling 2 factor auth - I lost 1.2 BTC due to a "It would take a desktop PC about 175 years to crack your password" password. (http://howsecureismypassword.net)


Dont test your password at these kind of sites. Just plain stupid to enter it somewhere online to test the strengt ...
I would trust https://www.grc.com/haystack.htm

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 23, 2013, 02:31:19 PM
 #2306

PS: The site's having problems again:

Code:
Got error 157 'Unknown error code' from NDBCLUSTER
Trillian
Newbie
*
Offline Offline

Activity: 23
Merit: 0


View Profile
April 23, 2013, 02:35:55 PM
 #2307

Yup, latest transaction shown is now 15 mins old. Can't login to my wallet.
piuk (OP)
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1005



View Profile WWW
April 23, 2013, 02:59:39 PM
 #2308

Any problems with the site please check twitter as https://twitter.com/blockchain as a first port of call.

John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 23, 2013, 03:03:56 PM
 #2309

Any problems with the site please check twitter as https://twitter.com/blockchain as a first port of call.
Okay, thanks.
willphase
Hero Member
*****
Offline Offline

Activity: 767
Merit: 500


View Profile
April 23, 2013, 03:37:21 PM
 #2310

Piuk, can you comment on the Amazon S3 backup regime for deleted private keys - i.e. if I were to upload a private key and then later on delete it - are old copies of the encrypted wallet file still stored on S3 - and if so, for how long?

Regards,

Will

piuk - I wondered if you had a moment to answer my question about the S3 backups...?

Will

hazek
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003


View Profile
April 24, 2013, 09:36:11 AM
 #2311

I was just suggested to pay a 0.005 fee by the blockchain app. The app is really great however I really miss the option to enter a specific fee. The choice right now seems to be to either not pay anything or to pay what the app suggests..

My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)

If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
piuk (OP)
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1005



View Profile WWW
April 24, 2013, 12:03:26 PM
Last edit: April 24, 2013, 01:43:24 PM by piuk
 #2312

Changes to Alias Resolving

When a wallet is accessed using an alias if the browser does not already have the wallet identifier saved or have an authorised login session email authorisation will now be required.



If the browser is perviously recognised by blockchain no authorisation is required. Wallets can still be accessed directly by identifier, which provides 128 bits of entropy and should always be kept secret.

For example if you visit my personal wallet: https://blockchain.info/wallet/piuk if will appear as if no wallet exists however I will receive an authorisation email.

A number of users have reported their wallet being compromised to me, the exact cause is unknown (I suspect malware) however in pretty much all cases the user has set a wallet alias which is the same as their bitcointalk username (and used on other sites). This is common practice, however it much more secure if the wallet identifier and alias are kept secret. The above changes are meant to address this problem.

I will respond to the above posts shortly, apologies for the delay.

ghostshirt
Full Member
***
Offline Offline

Activity: 216
Merit: 100



View Profile
April 24, 2013, 12:31:22 PM
 #2313

Hello,

How does Blockchain.info calculate a transaction fee? I've made a 2420-byte transaction and paid 0.0015 BTC, I thought 0.0005 is the norm for Bitcoin network (for now).

ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
April 24, 2013, 12:31:50 PM
 #2314

A number of users have reported their wallet being compromised to me, the exact cause is unknown (I suspect malware) however in pretty much all cases the user has set a wallet alias which is the same as their bitcointalk username (and used on other sites). This is common practice, however it much more secure if the wallet identifier and alias are kept secret. The above changes are meant to address this problem.

I will respond to the above posts shortly, apologies for the delay.
I love this.  I will let you know if I start to get a ton of emails from unknown browsers.

HOWEVER if this is indeed malware targeted at BCI it would be a very trivial task to either just steal the wallet identifier/blob from the browser (we already know they have the password).  So we may not see a decline in these reports if this is the cause (however this is still a great feature!).  PLEASE ENABLE TWO FACTOR AUTHENTICATION PEOPLE!

Ben:  Has anyone ever reported a theft from BCI while 2FA was enabled on their account?

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
April 24, 2013, 12:32:31 PM
 #2315

Hello,

How does Blockchain.info calculate a transaction fee? I've made a 2420-byte transaction and paid 0.0015 BTC, I thought 0.0005 is the norm for Bitcoin network (for now).
It depends on how big (BTC wise) and how old the inputs are.

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
bizz
Hero Member
*****
Offline Offline

Activity: 492
Merit: 500


View Profile
April 24, 2013, 01:07:00 PM
 #2316


Ben:  Has anyone ever reported a theft from BCI while 2FA was enabled on their account?

Today: http://www.reddit.com/r/Bitcoin/comments/1czrua/just_lost_160_btc_from_address_managed_with/
Gaff
Hero Member
*****
Offline Offline

Activity: 924
Merit: 502


View Profile
April 24, 2013, 01:12:43 PM
 #2317

Changes to Alias Resolving

When a wallet is accessed using an alias if the browser does not already have the wallet identifier saved or have an authorised login session email authorisation will now be required.



If the browser is perviously recognised by blockchain no authorisation is required. Wallet can still be accessed directly by identifier, which provides 128 bits of entropy and should always be kept secret.

For example if you visit my personal wallet: https://blockchain.info/wallet/piuk if will appear as if no wallet exists however I will receive an authorisation email.

A number of users have reported their wallet being compromised to me, the exact cause is unknown (I suspect malware) however in pretty much all cases the user has set a wallet alias which is the same as their bitcointalk username (and used on other sites). This is common practice, however it much more secure if the wallet identifier and alias are kept secret. The above changes are meant to address this problem.

I will respond to the above posts shortly, apologies for the delay.


I like this change - but blockchain.info assumes my email is secure. I don't think this is a great assumption.

Question: Shouldn't 2-factor authentication be sufficient here? If I have the right identifier and I pass the 2-factor check *then* you can send me the encrypted wallet?
Gaff
Hero Member
*****
Offline Offline

Activity: 924
Merit: 502


View Profile
April 24, 2013, 01:21:19 PM
 #2318

Changes to Alias Resolving

...Also given the recent scandal with Instawallet URLs being searchable via Google - can you send a one-time-alias URL rather than the real identifier?
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
April 24, 2013, 03:16:29 PM
Last edit: April 24, 2013, 03:34:44 PM by ErebusBat
 #2319


For those that just want the story without the reddit follow through:
Quote
I just had 160 bitcoins stolen by this transaction: https://blockchain.info/tx/5abb271eb6e2d0da1855b06282c84dcf7467dda9da6da9090cad10ddae957fc7
I use the blockchain.info wallet service to manage that address. My password was a random 18 character password with punctuation, upper/lower case etc. I had two-factor authentication with Google Authenticator turned on and a second password on the account that was a random 8 characters.
I had logged into the account with my laptop at home to send a small transaction of 0.937 bitcoins half an hour earlier. I haven't left the house since so no one has had access to my laptop. I'm on WPA2 secured wifi but not using a VPN. Laptop is running Ubuntu. I also have the blockchain.info app on my phone. It doesn't use the 2-factor authentication or the main password but does prompt for the second password.
I'm at a loss. This is my worst fear realized. Anyone have any suggestions? Sad


EDIT:  This is a quote from that thread:
Quote
The phone app stores your primary password in plain text, relying on the sandboxing mechanism of the phone OS. And it doesn't support 2-factor. Your secondary 8 character password could be cracked.

I just looked on my phone using iExplorer and didn't see anything, can anyone else (Ben) confirm or deny how this actually works?

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 24, 2013, 03:41:33 PM
 #2320

Missing "Refresh" and "Logoff" GUI buttons that were in the top right corner previously. Is it just me, or something changed in the GUI?

What, no one else lost Refresh/Logoff buttons, just me? I'm on Chrome, and cleared my browser data recently. Now my buttons disappeared, and I miss them!

I lose the buttons regularly on my small netbook when I use blockchain.info to push tx's through MyWallet. I'm running Chrome too.
Pages: « 1 ... 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 [116] 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 ... 173 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!