Bitcoin Forum
November 07, 2024, 07:58:26 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Monero VS dalek libraries VS Particl Security Audit Bulletproof & RingCT  (Read 180 times)
dadon (OP)
Legendary
*
Offline Offline

Activity: 1190
Merit: 1002


Pecvniate obedivnt omnia.


View Profile WWW
February 06, 2020, 11:15:01 AM
Last edit: February 07, 2020, 02:52:30 AM by dadon
 #1



Source: https://blog.quarkslab.com/tag/bulletproof.html
qwizzie
Legendary
*
Offline Offline

Activity: 2548
Merit: 1245



View Profile
February 06, 2020, 11:57:31 AM
Last edit: February 06, 2020, 12:15:59 PM by qwizzie
 #2

Only thing i am interested in with regards to Monero is knowing how hackers got into their boxed-off website and were able to replace their binaries with coin-stealing malware binaries.
As long as no answer has been provided in that particular area, i consider Monero compromised towards its users.

You can have strong security technology in a blockchain, but if you can not guarantee a secure website from which to download the binaries, then that will impact your reputation as a blockchain.
Link : https://arstechnica.com/information-technology/2019/11/official-monero-website-is-hacked-to-deliver-currency-stealing-malware/

To be absolutely clear, i am not interested in the specifics of the malware, that has been covered in great detail.
I am interested in knowing what happened with the closed-off box that fluffypony sent to a bunch of specialists to investigate the website breach.

 

Learn from the past, set detailed and vivid goals for the future and live in the only moment of time over which you have any control : now
dadon (OP)
Legendary
*
Offline Offline

Activity: 1190
Merit: 1002


Pecvniate obedivnt omnia.


View Profile WWW
February 06, 2020, 12:39:07 PM
 #3

I am aware of this incident but honestly wasn't aware of much of the details. I just knew something went down and some users who downloaded wallets from their official website were affected by it. Fluffypony has become a bit of a crypto celebrity over the years and I think people put their trust in individuals far too much and this is especially the case with celebrities of any type. It's a little alarming to start with that fluffy has such access for this to even be possible, and It is even more alarming that Monero's team is not encouraging users to download directly from their official GitHub accompanied by the use of checksums to validate the download.

As we take our users security seriously at particl we encourage users to take their own security seriously as well. Our files are hosted on GitHub and we encourage users to verify the checksums. They are not gameable and We have a link to the wiki for such matters. https://particl.wiki/tutorial/verify-downloads < Here anybody unfamiliar with checksums and validating download sources can find explanations and guides for everything relating to this matter. We do this to keep our users safe and we have always practiced in this manner as is the responsibility of the project to do so, If Monero would follow such protocol to protect their users maybe their reputation wouldn't be in question.

(NOTE: Monero could be encouraging the use of checksums now I honestly don't follow their development/News/Updates very closely anymore)
qwizzie
Legendary
*
Offline Offline

Activity: 2548
Merit: 1245



View Profile
February 06, 2020, 01:07:41 PM
 #4

I am aware of this incident but honestly wasn't aware of much of the details. I just knew something went down and some users who downloaded wallets from their official website were affected by it. Fluffypony has become a bit of a crypto celebrity over the years and I think people put their trust in individuals far too much and this is especially the case with celebrities of any type. It's a little alarming to start with that fluffy has such access for this to even be possible, and It is even more alarming that Monero's team is not encouraging users to download directly from their official GitHub accompanied by the use of checksums to validate the download.

As we take our users security seriously at particl we encourage users to take their own security seriously as well. Our files are hosted on GitHub and we encourage users to verify the checksums. They are not gameable and We have a link to the wiki for such matters. https://particl.wiki/tutorial/verify-downloads < Here anybody unfamiliar with checksums and validating download sources can find explanations and guides for everything relating to this matter. We do this to keep our users safe and we have always practiced in this manner as is the responsibility of the project to do so, If Monero would follow such protocol to protect their users maybe their reputation wouldn't be in question.

(NOTE: Monero could be encouraging the use of checksums now I honestly don't follow their development/News/Updates very closely anymore)

I could be mistaken here, but so far i know Github is not encouraged for Monero users to download their binaries. They do encourage the use of checksums, but that still does not explain how
their closed-off box of their official website got compromised in the first place and if things have been properly patched up on that server / closed-off box.

Ever since fluffypony send that closed-off box out for investigation two months ago, there has been a total silence on that part.
This creates rumors that it could have been the work of inside developers who either went rogue or were really negligent with their security access.

Learn from the past, set detailed and vivid goals for the future and live in the only moment of time over which you have any control : now
dadon (OP)
Legendary
*
Offline Offline

Activity: 1190
Merit: 1002


Pecvniate obedivnt omnia.


View Profile WWW
February 06, 2020, 01:16:32 PM
 #5

I am aware of this incident but honestly wasn't aware of much of the details. I just knew something went down and some users who downloaded wallets from their official website were affected by it. Fluffypony has become a bit of a crypto celebrity over the years and I think people put their trust in individuals far too much and this is especially the case with celebrities of any type. It's a little alarming to start with that fluffy has such access for this to even be possible, and It is even more alarming that Monero's team is not encouraging users to download directly from their official GitHub accompanied by the use of checksums to validate the download.

As we take our users security seriously at particl we encourage users to take their own security seriously as well. Our files are hosted on GitHub and we encourage users to verify the checksums. They are not gameable and We have a link to the wiki for such matters. https://particl.wiki/tutorial/verify-downloads < Here anybody unfamiliar with checksums and validating download sources can find explanations and guides for everything relating to this matter. We do this to keep our users safe and we have always practiced in this manner as is the responsibility of the project to do so, If Monero would follow such protocol to protect their users maybe their reputation wouldn't be in question.

(NOTE: Monero could be encouraging the use of checksums now I honestly don't follow their development/News/Updates very closely anymore)

I could be mistaken here, but so far i know Github is still not encouraged for Monero users to download their binaries. They do encourage the use of checksums, but that still does not explain how
their closed-off box of their official website got compromised in the first place and if things have been properly patched up on that server / closed box side.

Ever since fluffypony send that closed-off box out for investigation two months ago, there has been a total silence on that part.      
I can not understand why they would not encourage users to use a trusted source like Github for something as important as this and I am pretty sure this would(could)not have happened if they did encourage only to use Github for binary downloads.(silly) As for the other stuff it sounds really strange and I hope answers can be found to these questions in a timely manner, sounds like fluffy needs to give some explanations as it is not fair to keep people in the dark like that when the matter at hand is so serious.
rustynailer
Hero Member
*****
Offline Offline

Activity: 725
Merit: 501


Boycott Qatar 2022


View Profile
February 07, 2020, 02:10:46 AM
 #6

I dont want to throw any shade on fluffypony or Monero but it looks like someone made a booboo. I hope they figure it out soon because if they cant, then we wont know if or when this will happen again.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!