Bitcoin Forum
November 03, 2024, 05:41:11 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: This is why you still shouldn't trust any 3rd party wallets. (Mt. Gox)  (Read 5662 times)
the founder
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
September 08, 2011, 12:28:56 AM
 #41

This is exactly why Flexcoin has a STRICT no links in e-mail policy.

If you get a link in an e-mail claiming to be from Flexcoin,  it's not legit.   We do not send out links in any e-mails.  Period.

Why Mt.Gox, Tradehilll and others didn't follow our lead is mind boggling.   Every bitcoin site should follow this policy as it completely removes the threat of phishing attacks as it's well known that our policy is no links, or images in e-mails.



I'd be even better if all you guys started OpenPGP-signing communications.  That makes it easy for people who care to verify the origin.

That's too complicated for Grandma to use.  I am not sure about the Exchange's mission... but flexcoin's goal is to have widespread adoption of bitcoin's .. that means making it simple to use.   I doubt Grandma is going to be using OpenPGP ..


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
legolouman
Hero Member
*****
Offline Offline

Activity: 504
Merit: 504


Decent Programmer to boot!


View Profile
September 08, 2011, 12:41:37 AM
 #42

This is exactly why Flexcoin has a STRICT no links in e-mail policy.

If you get a link in an e-mail claiming to be from Flexcoin,  it's not legit.   We do not send out links in any e-mails.  Period.

Why Mt.Gox, Tradehilll and others didn't follow our lead is mind boggling.   Every bitcoin site should follow this policy as it completely removes the threat of phishing attacks as it's well known that our policy is no links, or images in e-mails.



I'd be even better if all you guys started OpenPGP-signing communications.  That makes it easy for people who care to verify the origin.

That's too complicated for Grandma to use.  I am not sure about the Exchange's mission... but flexcoin's goal is to have widespread adoption of bitcoin's .. that means making it simple to use.   I doubt Grandma is going to be using OpenPGP ..



I also doubt Grandma will be using BTC. 99% of us are either geeks, or have everything managed by geeks. OpenPGP is a great way of authenticating, but so is the "no emails" policy. One obvious thing is there is only mtgox.com or etc. Just read the actual URL you are on, straight forward.

If you love me, you'd give me a Satoshi!
BTC - 1MSzGKh5znbrcEF2qTrtrWBm4ydH5eT49f
LTC - LYeJrmYQQvt6gRQxrDz66XTwtkdodx9udz
kgo
Hero Member
*****
Offline Offline

Activity: 548
Merit: 500


View Profile
September 08, 2011, 12:43:53 AM
 #43

This is exactly why Flexcoin has a STRICT no links in e-mail policy.

If you get a link in an e-mail claiming to be from Flexcoin,  it's not legit.   We do not send out links in any e-mails.  Period.

Why Mt.Gox, Tradehilll and others didn't follow our lead is mind boggling.   Every bitcoin site should follow this policy as it completely removes the threat of phishing attacks as it's well known that our policy is no links, or images in e-mails.



I'd be even better if all you guys started OpenPGP-signing communications.  That makes it easy for people who care to verify the origin.

That's too complicated for Grandma to use.  I am not sure about the Exchange's mission... but flexcoin's goal is to have widespread adoption of bitcoin's .. that means making it simple to use.   I doubt Grandma is going to be using OpenPGP ..



Well yes, Grandma isn't going to use OpenPGP, but she'll just ignore the sig.  Just like my mom, a grandma, does when I send her emails since I sign everything.  MagicalTux had a good point that someone who uses OpenPGP regularly probably wouldn't fall for a blatant phishing attempt.  But still, whenever I get an email about a security risk from an exchange, I currently need to double-check headers to verify it's validity.  It would be nice if I could let Enigmail do the work for me.
kokojie
Legendary
*
Offline Offline

Activity: 1806
Merit: 1003



View Profile
September 08, 2011, 02:21:32 AM
 #44

What The Fuck? I thought bitcoin users are pretty advanced users of technology, yet here we have multiple people fell for a simple phishing email. (btw I received the same phishing email today, laughed at it for a second, then threw it in the trash folder).

btc: 15sFnThw58hiGHYXyUAasgfauifTEB1ZF6
Meni Rosenfeld
Donator
Legendary
*
Offline Offline

Activity: 2058
Merit: 1054



View Profile WWW
September 08, 2011, 06:25:32 AM
 #45

This is exactly why Flexcoin has a STRICT no links in e-mail policy.

If you get a link in an e-mail claiming to be from Flexcoin,  it's not legit.   We do not send out links in any e-mails.  Period.

Why Mt.Gox, Tradehilll and others didn't follow our lead is mind boggling.   Every bitcoin site should follow this policy as it completely removes the threat of phishing attacks as it's well known that our policy is no links, or images in e-mails.



I'd be even better if all you guys started OpenPGP-signing communications.  That makes it easy for people who care to verify the origin.

That's too complicated for Grandma to use.  I am not sure about the Exchange's mission... but flexcoin's goal is to have widespread adoption of bitcoin's .. that means making it simple to use.   I doubt Grandma is going to be using OpenPGP ..



Well yes, Grandma isn't going to use OpenPGP, but she'll just ignore the sig.  Just like my mom, a grandma, does when I send her emails since I sign everything.  MagicalTux had a good point that someone who uses OpenPGP regularly probably wouldn't fall for a blatant phishing attempt.  But still, whenever I get an email about a security risk from an exchange, I currently need to double-check headers to verify it's validity.  It would be nice if I could let Enigmail do the work for me.
Grandma doesn't need to know she is using OpenPGP, anymore than she needs to know PayPal is using a Verisign extended validation SSL certificate. All she needs is the mail client to tell her "this message is legitimate" and the browser to tell her "this website is legitimate".

What The Fuck? I thought bitcoin users are pretty advanced users of technology, yet here we have multiple people fell for a simple phishing email. (btw I received the same phishing email today, laughed at it for a second, then threw it in the trash folder).
There's no Certified Advanced User of Technology (CAUT) training. People can be "advanced" and yet have gaps in knowledge in some areas, such as security. Also, even CAUTs with the necessary knowledge make mistakes.

Also, if people who are not advanced users of technology are using Bitcoin, that's a good thing.

1EofoZNBhWQ3kxfKnvWkhtMns4AivZArhr   |   Who am I?   |   bitcoin-otc WoT
Bitcoil - Exchange bitcoins for ILS (thread)   |   Israel Bitcoin community homepage (thread)
Analysis of Bitcoin Pooled Mining Reward Systems (thread, summary)  |   PureMining - Infinite-term, deterministic mining bond
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
September 08, 2011, 07:12:28 AM
 #46

lol great thread

~hover~

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
nmat
Hero Member
*****
Offline Offline

Activity: 602
Merit: 502


View Profile
September 08, 2011, 07:26:51 AM
 #47

Bitmarket.eu requires email confirmation to change the BTC withdrawal address. I like this feature. Does anyone know why none of the other exchanges have it?
The_Duke
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


Lead Core BitKitty Developer


View Profile
September 08, 2011, 08:02:54 AM
 #48

This is exactly why Flexcoin has a STRICT no links in e-mail policy.

If you get a link in an e-mail claiming to be from Flexcoin,  it's not legit.   We do not send out links in any e-mails.  Period.

Why Mt.Gox, Tradehilll and others didn't follow our lead is mind boggling.   Every bitcoin site should follow this policy as it completely removes the threat of phishing attacks as it's well known that our policy is no links, or images in e-mails.


You are the most convincing troll ever. You almost had me believing that you were a pompous, arrogant, self absorbed ('The founder'? really?) twit suffering from delusions of grandeur, but this time you broke routine by trying to claim that you-- not eBay, Paypal, Bank of America, or any other business predating Bitcoin-- were the one who came up with this idea. Oh wait, you really ARE that way in real life. Holy fuck.

Do you want to know why no one will follow your lead-- ever? Because you're desperate, untalented and delusional. FlexCoin could have been a real service with real customers under the following conditions:

1) MyBitcoin.com didn't explode a mountain of diarrhea on the entire community;

2) Your "bank" that is supposed to "lead" Mt. Gox and Tradehill wasn't just a Wordpress template ('Lexington Theme').

3) You weren't you.


Seriously, accept what I've already accepted-- that I have no chance of creating anything intelligent and successful ever so long as I represent my projects. Step down as owner of FlexCoin and work on damage control.

Jesus christ, someone had to say it.

TRO...no wait... he's right.

NOT a member of the so called ''Bitcoin Foundation''. Choose Independence!

Donate to the BitKitty Foundation instead! -> 1Fd4yLneGmxRHnPi6WCMC2hAMzaWvDePF9 <-
nmat
Hero Member
*****
Offline Offline

Activity: 602
Merit: 502


View Profile
September 08, 2011, 08:44:45 AM
 #49

Did I miss something? Wasn't this thread about MtGox phishing emails and countermeasures?  Roll Eyes

Matthew N. Wright, you should open a new thread to trash people individually. It's common practice here at the forums.
oOoOo (OP)
Full Member
***
Offline Offline

Activity: 238
Merit: 100


View Profile
September 08, 2011, 10:32:30 AM
 #50

What The Fuck? I thought bitcoin users are pretty advanced users of technology, yet here we have multiple people fell for a simple phishing email. (btw I received the same phishing email today, laughed at it for a second, then threw it in the trash folder).

Yes, you say this right now, while you are fully aware. I've gotten 100s of similar spam e-mails over the years (fake ebay, fake paypal etc.) and always laughed them off.

The problem is I got this mtgox fake mail at a time I just got home from a long day at work (I work in manual labor!) and I wasn't at it 100%.

See, at any other point in time this wouldn't have happened. This just got me at the wrong time. Stupid, I know, but what can you do?
.
Vladimir
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1001


-


View Profile
September 08, 2011, 10:38:45 AM
Last edit: September 11, 2011, 06:06:21 AM by Vladimir
 #51

Due to breach of trust and gross negligence by Sirius and Theymos who recklessly transferred my private and personal data on this forum to a Japaneze company without my permission I am leaving this forum and deleting all my posts. Goodbye.

-
BitcoinPorn
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500


Posts: 69


View Profile WWW
September 08, 2011, 12:59:12 PM
 #52

lol, oh my.  I always find the Flexcoin happening to find a way to promote in the worst situations for others sad, this is all new levels of Flexcoin sadness I never even checked into.


See, at any other point in time this wouldn't have happened. This just got me at the wrong time. Stupid, I know, but what can you do?.

Quit being an ass and change the title of the thread to reflect the reality instead of singling out "Mt Gox" giving an impression that they did something here.  Quit trolling.   Forums have the ability to edit posts just for this reason and you seem to be straight up refusing to at this time.  Not sure why you called me a troll because all it did was make me notice how bad you are trolling and still are.  Every post you make and leave this initial one unchanged is nearly an attack, as at this point you have even acknowledged fault.

The_Duke
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


Lead Core BitKitty Developer


View Profile
September 08, 2011, 01:28:17 PM
 #53


Note how all this was obvious long before "mybitcoin" incident.




Can you point us to one of your posts where you warned people about this "obvious" risk in storing your bitcoins at mybitcoin (or MtGox, or TH for that matter)? If you can't than this was just another captain-hindsight post.

NOT a member of the so called ''Bitcoin Foundation''. Choose Independence!

Donate to the BitKitty Foundation instead! -> 1Fd4yLneGmxRHnPi6WCMC2hAMzaWvDePF9 <-
Vladimir
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1001


-


View Profile
September 08, 2011, 01:44:01 PM
Last edit: September 11, 2011, 06:03:07 AM by Vladimir
 #54

Due to breach of trust and gross negligence by Sirius and Theymos who recklessly transferred my private and personal data on this forum to a Japaneze company without my permission I am leaving this forum and deleting all my posts. Goodbye.

-
The_Duke
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


Lead Core BitKitty Developer


View Profile
September 08, 2011, 01:48:40 PM
 #55


Note how all this was obvious long before "mybitcoin" incident.


Can you point us to one of your posts where you warned people about this "obvious" risk in storing your bitcoins at mybitcoin (or MtGox, or TH for that matter)? If you can't than this was just another captain-hindsight post.

Here you go my friend. https://bitcointalk.org/index.php?topic=20427.msg255690#msg255690 It is directed to another person, but in a scenario of some early idea of anonymous person handling someone else's bitcoins.


That is also in hindsight of someone getting his mybitcoin account compromised. Where have you been actively telling people NOT to use 3rd party wallets? Going "I told you so" only works if you actually told people so.

NOT a member of the so called ''Bitcoin Foundation''. Choose Independence!

Donate to the BitKitty Foundation instead! -> 1Fd4yLneGmxRHnPi6WCMC2hAMzaWvDePF9 <-
the founder
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
September 08, 2011, 02:18:30 PM
 #56

Did I miss something? Wasn't this thread about MtGox phishing emails and countermeasures?  Roll Eyes

Matthew N. Wright, you should open a new thread to trash people individually. It's common practice here at the forums.

I was under the impression this thread was an attack based on personal error, followed by a retraction, and then beating up of said attacker, but in looking at the title "This is why you still shouldn't trust any 3rd party wallets." it's pretty clear that my trashing of FlexCoin, a "3rd party wallet" site is warranted.

Apologies for the explosion. It has been building since his first post, which was 362 posts ago. I vote that we take all my aggression towards 'the founder' quantified by the running post count to back Bitcoin. Since he's bound to spam FlexCoin in each and every thread he participates in, the value can only go up UP UP!

Matt,  seriously get off your high horse...  Troll somewhere else...   Lexicon theme was developed internally for the blogging side. We built it internally... I hope you understand that...  then of course we offered it on a theme site for additional revenue.  

The banking area is not based on wordpress.. but you wouldn't know that because you only know how to bash but not research?  The chances are you don't even have an account to be educated enough on how the system works.   So No your trashing isn't warranted...   not even close.

Whatever... I don't care much at all what you say.. we're building a service.. don't use it...  In fact it appears that most of your posts are attacking people personally..  I just happened to be the next one in line.  

If you must know, I found the title offensive because it's not all 3ed party wallets,  it was Mt.Gox that DIDN'T follow the proper procedure in my opinion (no links).

Start your own bitcoin business then...  hopefully I'll find your posts somewhere and bash you for kicks.

Quote
Apologize without explaining yourself, and let us all get back to picking on FlexCoin.

Actually I would like to start picking on you... after researching your posts it appears that the majorty of them are bashing and not contributing?   

Seriously are you EVER going to help the bitcoin community or just run around trolling?   Seriously Matthew N. Wright do you have anything to contribute?


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
the founder
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
September 08, 2011, 02:47:24 PM
Last edit: September 08, 2011, 03:10:19 PM by the founder (FlexCoin)
 #57

I also doubt Grandma will be using BTC. 99% of us are either geeks, or have everything managed by geeks. OpenPGP is a great way of authenticating, but so is the "no emails" policy. One obvious thing is there is only mtgox.com or etc. Just read the actual URL you are on, straight forward.

I know man.. but I think that's the problem.  We have to widen the appeal of the technology to spread beyond us to reach sustainability. All the bitcoin services and the default client need to be easy to use and easy to understand.


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
oOoOo (OP)
Full Member
***
Offline Offline

Activity: 238
Merit: 100


View Profile
September 08, 2011, 04:43:00 PM
 #58


Quit being an ass and change the title of the thread to reflect the reality instead of singling out "Mt Gox" giving an impression that they did something here.  Quit trolling.   Forums have the ability to edit posts just for this reason and you seem to be straight up refusing to at this time.  Not sure why you called me a troll because all it did was make me notice how bad you are trolling and still are.  Every post you make and leave this initial one unchanged is nearly an attack, as at this point you have even acknowledged fault.


There. You happy now?? What you wanna do me next? Bend over?!?! lol

/trololol

p.s. I aint gonna delete that post, gonna stay there for reference.

bye,
oOo
Xiong Zhuang
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
September 17, 2011, 11:15:30 AM
 #59

We try to push yubikey usage a lot, to avoid this. That's why we offered more than 1000 free yubikeys so far, and hope people understand that security is not that simple.

I recieve a mail about free yubikey yesterday, I thought it's another phishing mail at first. Thanks you very much!

Did you get my PM? I really need your help.
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!