Bitcoin Forum
July 01, 2024, 08:02:46 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Shop directly on Amazon.com with Bitcoin  (Read 496 times)
TryNinja
Legendary
*
Offline Offline

Activity: 2884
Merit: 7134


Top Crypto Casino


View Profile WWW
February 26, 2019, 01:17:53 AM
Merited by IconFirm (2)
 #21

DON’T USE THIS SERVICE!
UNINSTALL IT RIGHT NOW AND REVOKE YOUR COINBASE API KEYS.

I just saw this while browsing through Reddit:

Quote
Dear members of the Ethereum community,

TL;DR: Uninstall Moon, Revoke your Coinbase API Keys NOW and PROTECT YOUR ETHEREUM

I was the co-founder and CTO at https://paywithmoon.com. Due to my discovery of the unethical business practices Moon Technologies, Inc. has been engaged in, I have left the company.

As of today, the moon browser extension manipulates the DOM of the users' browsers to give them an augmented shopping experience, one that allows them to shop online with cryptocurrency. Over the past couple of months, my co-founder, Kenneth Kruger, has ordered the collection of data belonging to users as a way to improve customer experiences. No users have ever been asked explicitly if they would prefer to opt-out of tracking, a feature which I regularly insisted should be added. If you are a user and look under at terms and conditions stated under https://paywithmoon.com/terms-conditions/ (dated 26 Feb 2019), you will find the agreement hidden under one of the terms and conditions. This is a huge breach of GDPR and privacy laws that are meant to protect user data.

From the moment a user installs the browser extension, the company will know exactly what pages are open on the user's browser, what the content of those pages are, and what the user is doing with them.
The biggest and most alarming issue of all, is the process of collection of how the browser extension works in the backend - Coinbase API keys. From the moment the user initiates the connection between the company and Coinbase, the company watches for changes in the user's current window, waiting for the user to complete the one-time passcode (OTP) verification process as required by Coinbase. Once that is done, the company programatically clicks the required permissions (scopes) required to create the API key as it sees fit.
The API key is then shown only once on the next screen, but the user does not know this (done via CSS manipulation). The company extracts the API keys into the backend, stored in plain text on the company's database on AWS. This is a definite security antipattern. This API key is then able to be used indefinitely until manually revoked by the individual user.

When I asked Kenneth Kruger why we should not encrypt the keys or create recursively locking IAM policies to prevent anyone in the management team to have personal access to users' API keys, Kenneth Kruger constantly avoided or redirected the discussion and prevented me from building any kind of system that would protect users.
Only two days ago, I have been locked out of my organization accounts including AWS and can no longer take preventive measures to protect users.

If you are a user of our browser extension today, ***PLEASE*** you need to uninstall the browser extension via chrome://extensions and go into https://www.coinbase.com/settings/api and revoke ALL your API keys NOW.
If you have not used the Moon browser extension, but know of a friend that might, please inform him or her to do so immediately.

You can read more about my experience in another post here https://np.reddit.com/r/startups/comments/au668p/what_to_do_in_the_event_you_get_zuckerberged_in_a/.

I had created Moon as I was crazy enough to think I was able to change the world with the single vision of bringing mass adoption to cryptocurrency, accelerating the future of the financial system. However, today is truly a sad day for crypto. Until we can find a way to completely decentralize and move away from the corporations, the no-accountability attitude and greed many executives possess, we cannot hope to bring forth the dream of cryptocurrency.

Until we meet on the moon again, please be safe, not sorry,


Alexander Ang
https://reddit.com/r/ethereum/comments/auqrhf/psa_on_moon_browser_extension/

Until this is solved, don’t trust them.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Kakmakr
Legendary
*
Offline Offline

Activity: 3472
Merit: 1963

Leading Crypto Sports Betting & Casino Platform


View Profile
February 26, 2019, 06:29:08 AM
 #22

Wow, just shows you how cunning some of these people can be.  Roll Eyes  The guy looked legit and he sounded very sincere with his explanations to most concerns in this thread. I was about to install this, because I wanted to pay for something on Amazon and other intermediary services that buys goods on your behalf is just too complicated. < Purse >  Roll Eyes

I will merit #TryNinja when this is validated and confirmed. <Let's give #binarytree an opportunity to explain his side of this story first>  Tongue

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
IconFirm
Hero Member
*****
Offline Offline

Activity: 1438
Merit: 574


Always ask questions. #StandWithHongKong


View Profile WWW
April 24, 2019, 04:14:26 PM
 #23

@TryNinja:  Great post with valuable info, thank you - merited.

I was sceptical about this whole thing & how it worked, you have confirmed my concerns with this post.

@OP:  I & the community would like your views on this please.

PIA went evil: https://bitcointalk.org/index.php?topic=5203968.msg53160131#msg53160131 Unofficial & Uncensored SYSCOIN thread: https://bitcointalk.org/index.php?topic=4748031.0    Do not trust Yobit/HitBTC/BiteBTC/coinsbit/p2pb2b/Mercatox/C-cex/Poloniex/WEX/KuCoin/LiveCoin/TheRockTrading/Bitfinex/ADAB/Okex/TradeSatoshi/Gate.io/Changelly/Freewallet.org/crex24 scam exchanges or ICO's by known scammers like HashCoins/Ambisafe/Bountyhive - they WILL scam you! Use diligence & research. Buy coins, sell coins - don't invest in stupid shit. If your questions aren't answered - don't touch it.
_Django05_
Sr. Member
****
Offline Offline

Activity: 403
Merit: 257



View Profile
April 27, 2019, 06:29:15 AM
 #24

Hey everyone,

We've launched Moon, a Chrome browser extension that lets you shop directly on Amazon.com with Bitcoin, Litecoin, Ether and Bitcoin Cash. Purchases are instant, secure and free.
Currently it works by connecting your Coinbase account, but we are adding the functionality to pay from any wallet.
Currently it only works on Amazon.com, but we are going to have it work on every site.

It is not a bad idea that someone has created something like this. But we're are dealing with money here, how can we be sure that, that extension of yours does not bug our computers with tracking or sort of that thing. Especially if we are to connect our "money" accounts to an unknown program right? If we do that, we are giving you free access also.


Piggy
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1416



View Profile WWW
April 27, 2019, 10:44:30 AM
 #25

They have removed now that reddit comment, was it just somebody trolling? in any case is a bit too much trust you need to give to this chrome extension in order to process the payment, for my personal taste.

Anybody here tried it?
malevolent
can into space
Legendary
*
Offline Offline

Activity: 3472
Merit: 1721



View Profile
April 28, 2019, 02:28:29 AM
 #26

In a different reddit thread the ex-CTO sounds like he's willing to eventually start a competing service, anyone know of similar LN-ready services?

They have removed now that reddit comment, was it just somebody trolling? in any case is a bit too much trust you need to give to this chrome extension in order to process the payment, for my personal taste.

Anybody here tried it?

It was probably removed because it contained personal information which is against reddit rules against doxxing.

Signature space available for rent.
Initscri
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 759


View Profile WWW
April 28, 2019, 02:40:47 AM
 #27

I want to be totally transparent with who we are.
That's nice, but I think what we actually want from you, is not your credentials but rather the source code of this service.
Without Moon being open-source, there is noting that could make you appear as more legitimate service.
Nice graphics, logos or utilities won't help much, people here generally value their privacy and safety.
Forgive me for being sceptical but I bet you can understand how important that is.
I would be more keen to use Moon if it was a stand-alone, lightning ready, micro wallet separated from coinbase, which I don't like any way. I think no one would complain on you taking fees if this service would actually work.  
As of right now it looks and feels like massive security breach.

They can probably release the source code of the extension, but not the API.

I'm still pondering how this actually connects in with Amazon. A few questions:

1. Does the order stay on your Amazon account? And is trackable via your Amazon account, or does it get processed by an account operated by Moon. I know your website says you are not a Custodial service, so I assume it does stay within your account.
2. Does any billing info get changed on the order itself?
3. How exactly is this connection facilitated to Amazon. Is a specific bank/credit card attached to the invoice in place of the BTC, with your company providing the conversion in collab with your partners?


Edit, nvm. Just saw the second post of the 2nd page. Cry

@TryNinja, still interested to learn about the questions above.

----------------------------------
Web Developer. PM for details.
----------------------------------
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!