ErebusBat
|
|
April 18, 2013, 08:49:38 PM |
|
To those who have lost coins from blockchain.info accounts; are you certain that you didn't enter your identifier and password into a phishing site? I saw an extremely sophisticated on many months ago, on a typo domain. I suspect that accounts for more lost coins than any actual hacking.
Yet another reason to use lastpass
|
|
|
|
justusranvier
Legendary
Offline
Activity: 1400
Merit: 1013
|
|
April 18, 2013, 11:20:48 PM |
|
To those who have lost coins from blockchain.info accounts; are you certain that you didn't enter your identifier and password into a phishing site? I saw an extremely sophisticated on many months ago, on a typo domain. I suspect that accounts for more lost coins than any actual hacking.
Yet another reason to use lastpass Exactly
|
|
|
|
JordanL
Donator
Sr. Member
Offline
Activity: 294
Merit: 250
|
|
April 18, 2013, 11:35:30 PM |
|
To those who have lost coins from blockchain.info accounts; are you certain that you didn't enter your identifier and password into a phishing site? I saw an extremely sophisticated on many months ago, on a typo domain. I suspect that accounts for more lost coins than any actual hacking.
Yet another reason to use lastpass Or a yubikey, which is my preferred method.
|
|
|
|
centove
|
|
April 18, 2013, 11:58:35 PM |
|
Is this a part of the recovery as well but: http://markets.blockchain.info/Oops! Google Chrome could not connect to markets.blockchain.info Something get lost in the shuffle?
|
|
|
|
ErebusBat
|
|
April 19, 2013, 12:24:53 AM |
|
To those who have lost coins from blockchain.info accounts; are you certain that you didn't enter your identifier and password into a phishing site? I saw an extremely sophisticated on many months ago, on a typo domain. I suspect that accounts for more lost coins than any actual hacking.
Yet another reason to use lastpass Or a yubikey, which is my preferred method. Actually I was referring to the fact that lasts as remembers the URL for me, so typos are non existent.
|
|
|
|
organofcorti
Donator
Legendary
Offline
Activity: 2058
Merit: 1007
Poor impulse control.
|
|
April 19, 2013, 12:26:18 AM |
|
To those who have lost coins from blockchain.info accounts; are you certain that you didn't enter your identifier and password into a phishing site? I saw an extremely sophisticated on many months ago, on a typo domain. I suspect that accounts for more lost coins than any actual hacking.
Yet another reason to use lastpass Or a yubikey, which is my preferred method. Or a yubikey with lastpass.
|
|
|
|
glitch003
|
|
April 19, 2013, 04:12:16 PM |
|
Hey piuk, when I try to use the payment API I get this error: "Error Http Notifications Are Currently Disabled". Just curious, how long until they're enabled?
Thanks!
|
|
|
|
giantdragon
Legendary
Offline
Activity: 1582
Merit: 1002
|
|
April 19, 2013, 04:15:40 PM |
|
Receive payments API don't work, I am getting an error: "Error Http Notifications Are Currently Disabled".
|
|
|
|
ingrownpocket
Legendary
Offline
Activity: 952
Merit: 1000
|
|
April 19, 2013, 06:30:21 PM |
|
Hey piuk, when I try to use the payment API I get this error: "Error Http Notifications Are Currently Disabled". Just curious, how long until they're enabled?
Thanks!
Receive payments API don't work, I am getting an error: "Error Http Notifications Are Currently Disabled".
Confirmed.
|
|
|
|
dooglus
Legendary
Offline
Activity: 2940
Merit: 1333
|
|
April 19, 2013, 07:11:24 PM |
|
I've seen advice recently both in this thread and on twitter that instead of validating callback requests using the IP address (since it keeps changing) I should include a per-user secret in the callback URL. The problem with this is the callback URL appears in the source-code of the page presented to the user, so it won't stay secret for long. http://blockchain.info/api/api_receive says: Where you would like the pay now button to appear include the following code <div style="font-size:16px;margin:10px;width:300px" class="blockchain-btn" data-address="1A8JiWcwvpY7tAopUkSnGuEYHmzGYfZPiq" data-callback="https://mydomain.com/callback_url"> I assume you're suggesting putting the 'secret' in the data-callback attribute? But then the user just views the HTML source and sees the secret, and can then fake their own callback visit. And like others have said, callbacks seem to be currently broken anyway. Clicking the demo 'javascript buttons' on http://blockchain.info/api/api_receive tells me: "Error Http Notifications Are Currently Disabled"
|
Just-Dice | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | Play or Invest | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | 1% House Edge |
|
|
|
ingrownpocket
Legendary
Offline
Activity: 952
Merit: 1000
|
|
April 19, 2013, 08:48:57 PM |
|
I've seen advice recently both in this thread and on twitter that instead of validating callback requests using the IP address (since it keeps changing) I should include a per-user secret in the callback URL. The problem with this is the callback URL appears in the source-code of the page presented to the user, so it won't stay secret for long. http://blockchain.info/api/api_receive says: Where you would like the pay now button to appear include the following code <div style="font-size:16px;margin:10px;width:300px" class="blockchain-btn" data-address="1A8JiWcwvpY7tAopUkSnGuEYHmzGYfZPiq" data-callback="https://mydomain.com/callback_url"> I assume you're suggesting putting the 'secret' in the data-callback attribute? But then the user just views the HTML source and sees the secret, and can then fake their own callback visit. And like others have said, callbacks seem to be currently broken anyway. Clicking the demo 'javascript buttons' on http://blockchain.info/api/api_receive tells me: "Error Http Notifications Are Currently Disabled" The secret works if you use PHP to get the address and then print it on the page.
|
|
|
|
internationalaw
Member
Offline
Activity: 78
Merit: 10
Community Manager at Letstalkbitcoin.com
|
|
April 19, 2013, 09:41:36 PM |
|
Hey @piuk, could you comment on how long it takes to get your 2 factor authentication reset? I've been locked out for over a week now and I've already submitted a form. I have some things I need to do with my BTC.
|
|
|
|
dooglus
Legendary
Offline
Activity: 2940
Merit: 1333
|
|
April 20, 2013, 03:00:22 AM |
|
The secret works if you use PHP to get the address and then print it on the page.
Interesting. Do you have some example code to show what you mean? Is this instead of using the javascript buttons that blockchain.info provide, or some modification to their code?
|
Just-Dice | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | Play or Invest | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | 1% House Edge |
|
|
|
giantdragon
Legendary
Offline
Activity: 1582
Merit: 1002
|
|
April 20, 2013, 03:33:55 AM |
|
The secret works if you use PHP to get the address and then print it on the page.
Do you have some example code to show what you mean? A working example: $callback = urlencode("http://example.com/deposit.php?username={$_SESSION['username']}&secret={$depositSecret}"); $url = "https://blockchain.info/api/receive?method=create&address={$depositAddress}&shared=false&callback={$callback}";
$response = @file_get_contents($url); $json = json_decode($response, true);
if(($json === false) || (is_null($json)) || (!isset($json['input_address']))) //error else redirect("page.php?address={$json['input_address']}");
|
|
|
|
BitPirate
Full Member
Offline
Activity: 238
Merit: 100
RMBTB.com: The secure BTC:CNY exchange. 0% fee!
|
|
April 20, 2013, 05:25:38 AM |
|
Hi,
The JSON-RPC API is again giving me "lock timeout exceeded, try restarting transaction" on all requests.
Looks like a MySQL error -- I guess you're missing a rollback() or commit() somewhere...
|
|
|
|
elgreco
|
|
April 20, 2013, 02:10:47 PM |
|
Any idea when the satoshidice send option will work again?
|
1E1GrECoNP1RpvWe72kS5cDZozA47nUFs4
|
|
|
paraipan
In memoriam
Legendary
Offline
Activity: 924
Merit: 1004
Firstbits: 1pirata
|
|
April 20, 2013, 05:29:08 PM |
|
Don't know if bug or PEBCAK issue here, PM sent anyways.
|
BTCitcoin: An Idea Worth Saving - Q&A with bitcoins on rugatu.com - Check my rep
|
|
|
ingrownpocket
Legendary
Offline
Activity: 952
Merit: 1000
|
|
April 20, 2013, 05:34:58 PM |
|
The secret works if you use PHP to get the address and then print it on the page.
Do you have some example code to show what you mean? A working example: $callback = urlencode("http://example.com/deposit.php?username={$_SESSION['username']}&secret={$depositSecret}"); $url = "https://blockchain.info/api/receive?method=create&address={$depositAddress}&shared=false&callback={$callback}";
$response = @file_get_contents($url); $json = json_decode($response, true);
if(($json === false) || (is_null($json)) || (!isset($json['input_address']))) //error else redirect("page.php?address={$json['input_address']}");
Yes, that.
|
|
|
|
|
whiskers75
|
|
April 21, 2013, 10:04:56 AM |
|
Put a warning up about enabling 2 factor auth - I lost 1.2 BTC due to a "It would take a desktop PC about 175 years to crack your password" password. ( http://howsecureismypassword.net)
|
|
|
|
|