ErebusBat
|
|
June 21, 2012, 03:08:08 PM |
|
Google Chrome is telling me that the wallet verifier app needs new permissions. What's the story?
I'm seeing this too. Oddly I saw the message first on a totally unrelated site.That is because it now wants access to EVERY site and not just blockchain.info. Not sure why, maybe piuk can enlighten us.
|
|
|
|
HostFat
Staff
Legendary
Offline
Activity: 4270
Merit: 1209
I support freedom of choice
|
|
June 21, 2012, 03:10:48 PM |
|
I think that it's going to catch all bitcoin URIs ...
|
|
|
|
piuk (OP)
|
|
June 21, 2012, 03:13:27 PM |
|
Google Chrome is telling me that the wallet verifier app needs new permissions. What's the story?
It's for a new feature which allows you to import and export keys to Bitcoin-Qt without needing to use pywallet or command line. The problem is talking with the Bitcoind RPC server is a violation of the browser's Same origin policy and most browsers won't let you do it without special CORS HTTP headers. I made a pull request to add CORS headers to the RPC interface but the Bitcoin devs have dismissed the idea previously. As a workaround the Verifier browser extension can be used to circumvent the restrictions - as extensions have the ability to bypass the same origin policy if requested. 1) If you are not running Bitcoind-Qt there is no risk. 2) If you have not enabled the RPC server (by default it is off) there is no risk. 3) If you have the RPC server enabled the web interface will be able to talk with Bitcoin-QT so be sure the username and password is set. 4) The extension only runs on blockchain.info or www.blockchain.info.
|
|
|
|
piuk (OP)
|
|
June 21, 2012, 07:03:23 PM |
|
Desktop sync Now Active. It can be found in [Import / Export].
It allows you to easily import keys from Bitcoin-QT if you would like to switch to My Wallet or export keys if you want to switch to the Desktop client.
However it is not recommended for everyday use if you want to keep your wallets separate as by entering your RPC username, password and wallet password you are giving the javascript full access to your Bitcoin-Qt wallet. The username and password for the Bitcoin-Qt wallet is not saved.
|
|
|
|
LightRider
Legendary
Offline
Activity: 1500
Merit: 1022
I advocate the Zeitgeist Movement & Venus Project.
|
|
June 22, 2012, 08:45:40 AM |
|
That is wonderful and terrifying feature.
|
|
|
|
Peter Todd
Legendary
Offline
Activity: 1120
Merit: 1164
|
|
June 22, 2012, 12:39:22 PM |
|
Google Chrome is telling me that the wallet verifier app needs new permissions. What's the story?
It's for a new feature which allows you to import and export keys to Bitcoin-Qt without needing to use pywallet or command line. The problem is talking with the Bitcoind RPC server is a violation of the browser's Same origin policy and most browsers won't let you do it without special CORS HTTP headers. I made a pull request to add CORS headers to the RPC interface but the Bitcoin devs have dismissed the idea previously. As a workaround the Verifier browser extension can be used to circumvent the restrictions - as extensions have the ability to bypass the same origin policy if requested. 1) If you are not running Bitcoind-Qt there is no risk. 2) If you have not enabled the RPC server (by default it is off) there is no risk. 3) If you have the RPC server enabled the web interface will be able to talk with Bitcoin-QT so be sure the username and password is set. 4) The extension only runs on blockchain.info or www.blockchain.info. I really think you should use a separate extension for this. I have no need for this feature - it is a niche use case - and I'd much rather be running a verifier with fairly limited privileges than one that in itself represents a security risk.
|
|
|
|
|
HostFat
Staff
Legendary
Offline
Activity: 4270
Merit: 1209
I support freedom of choice
|
|
June 22, 2012, 02:28:20 PM |
|
You should add a link to the RPC Communicator in the import/export page
|
|
|
|
|
hazek
Legendary
Offline
Activity: 1078
Merit: 1003
|
|
June 22, 2012, 11:21:12 PM |
|
May I suggest you rename it to trail analysis or something else. Taint has unfortunately become a pretty loaded word and will probably give the wrong idea to quite a few people.
|
My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)
If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
|
|
|
k
|
|
June 22, 2012, 11:45:00 PM |
|
agree with hazek, try to avoid calling it taint analysis. Maybe coin history/origin analysis or something else.
|
|
|
|
Red Emerald
|
|
June 23, 2012, 01:30:17 AM Last edit: June 23, 2012, 04:43:38 AM by Red Emerald |
|
agree with hazek, try to avoid calling it taint analysis. Maybe coin history/origin analysis or something else.
+1 So something weird is going on with my vanity address. http://blockchain.info/taint/11235813yoNV9F45KjwRiBYnYFufMunTj8Apparently there is only a 5.7942159848% that this address is connected to itself. That seems wrong. Also I think you have a typo here: "The more "taint" the worse the stronger the link that remains."
|
|
|
|
ErebusBat
|
|
June 23, 2012, 02:17:44 AM |
|
New Feature: Taint Analysis
Seriously cool!
|
|
|
|
unclescrooge
|
|
June 23, 2012, 08:05:06 AM |
|
Not as a tool for blacklisting bitcoins which is a terrible idea. +1 Very very bad idea. All coins are eventually tainted. As all the dollars bills anyway
|
|
|
|
ErebusBat
|
|
June 23, 2012, 12:17:50 PM |
|
Anyone know off hand which address the coins in the genesis block were paid to? That would be interesting.
|
|
|
|
|
piuk (OP)
|
|
June 23, 2012, 10:59:06 PM Last edit: June 23, 2012, 11:45:42 PM by piuk |
|
May I suggest you rename it to trail analysis or something else. Taint has unfortunately become a pretty loaded word and will probably give the wrong idea to quite a few people.
Taint is already a word i've heard mentioned a few times when discussing coin origins. Maybe Source Analysis. Apparently there is only a 5.7942159848% that this address is connected to itself. That seems wrong.
I tweaked the algorithm a bit and not it correctly(?) shows 1HZY2Bks6HjTXFxXSj8ivhWCnkosypiUxR as the top source address. The branch column attempts to colour code related transactions and if numbered shows the number of unique root branches that address has appeared in. By unique branches I mean descendants of transactions which directly pay into to the address. Anything with a count > 0 usually indicates a stronger relationship with the target address. For example My Address: http://blockchain.info/taint/1A8JiWcwvpY7tAopUkSnGuEYHmzGYfZPiq shows branch counts > 0 for these addresses. These are addresses I also commonly use for testing and such and are in the same wallet. It does also show a high branch count for Deppbit (1VayNert3x1KzbpzMGt2qdqrAThiRovi8) which you will find to be true of many addresses as a large % of coins tend to originate from deepbit. Also the top ip is listed as 127.0.0.1 because I use My Wallet to make transactions so they are broadcast from localhost. The genesis transaction will be rather interesting as it has no history. It would be interesting to do an analysis on the first few thousand generation transactions, at least some of them must have moved. P.S. Thank you to the recent donators.
|
|
|
|
Jan
Legendary
Offline
Activity: 1043
Merit: 1002
|
|
June 23, 2012, 11:26:34 PM |
|
How about calling it traceroute? Resembles the unix command for tracing IP router hops.
|
Mycelium let's you hold your private keys private.
|
|
|
hazek
Legendary
Offline
Activity: 1078
Merit: 1003
|
|
June 24, 2012, 12:03:55 AM |
|
May I suggest you rename it to trail analysis or something else. Taint has unfortunately become a pretty loaded word and will probably give the wrong idea to quite a few people.
Taint is already a word i've heard mentioned a few times when discussing coin origins. Maybe Source Analysis. Excellent choice, I like it a lot!
|
My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)
If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
|
|
|
rjk
Sr. Member
Offline
Activity: 448
Merit: 250
1ngldh
|
|
June 24, 2012, 01:29:30 AM |
|
Please please please.... Even if you don't make any other changes, could you add this note to the chart of the network hash distribution?:
"The "Unknown" section does not represent a single entity."
That would prevent many topics about the network being taken over by some mystery miner or something from being started in the first place.
|
|
|
|
|