Bitcoin Forum
May 09, 2024, 05:58:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 6 7 »  All
  Print  
Author Topic: [END] [banned mixer] Premium Review and Suggestion Campaign  (Read 3401 times)
UniJoin
Copper Member
Full Member
***
Offline Offline

Activity: 173
Merit: 286


Your Bitcoin Mixer


View Profile
April 02, 2022, 11:48:21 AM
 #41

Premium review and suggestion spreadsheet #7

Hello DroomieChikito, we appreciate your feedback! Also here, all answers are in green font under your quotes.

I start with onion link with TOR.

And good to see UniJoin also accept taproot addresses

Quote


1. I just suggest to make Onion link with .onion behind. Because when I copy-paste it to TOR, I got only this: unijoinxaogdzmk3bonngoxxoaezkmsfdyrtfyximisungh2dnc2azad, so better to create complete link to : http://[banned mixer]



And it's not needed to create connect button because when I click it, the link still directing to my clearnet (default) browser not on TOR.

➡️ We will revise the Tor link in the footer. Thank you!

Quote


2. Order status link still direct to Clearnet link: https://[banned mixer]/en/order/... so this is not even better when people use TOR, I suggest creating a .onion link like http://[banned mixer]/en/order/...

➡️ Normally, it should be an onion link of course, if the site was visited with an onion link. We will check that too and amend it.

Quote


3. I don't have a problem with captcha, but if you don't mind better to use text captcha. Because sometimes, the TOR problem is the image does not currently appear.


➡️ We know that captchas sometimes make problems when using Tor browser. But this is more with Google captcha. With hCaptcha we never experienced and issues but will observe it of course.

Quote



I have the Question, What happens if the user lost Order ID/Link and LoQ (letter of guarantee), can still restore it and how?

➡️ If the user loses his order link and his Letter of Guarantee, it will be impossible to restore a session. The user simply needs to wait until the order is completed then. That's why we display many hints on the order process to save these data.


Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715234281
Hero Member
*
Offline Offline

Posts: 1715234281

View Profile Personal Message (Offline)

Ignore
1715234281
Reply with quote  #2

1715234281
Report to moderator
1715234281
Hero Member
*
Offline Offline

Posts: 1715234281

View Profile Personal Message (Offline)

Ignore
1715234281
Reply with quote  #2

1715234281
Report to moderator
hugeblack
Legendary
*
Offline Offline

Activity: 2506
Merit: 3649


Buy/Sell crypto at BestChange


View Profile WWW
April 02, 2022, 02:36:55 PM
Last edit: April 03, 2022, 10:07:45 AM by hugeblack
 #42

Premium review and suggestion spreadsheet#3


                                      [banned mixer] REVIEW



                                      Website/UI Design

                                      The site design is simple, Fonts are easy to read, Home page is a bit more detailed, Content could be understood on mobile devices (3440 x 1440 screens,) but there are a lot of animations and things that must be removed, the most important of which are:

                                      • Intro video: It doesn't talk about how to mix using [banned mixer], use the site etc, it's a general intro video.
                                      • About Us: It can be made in a separate page or in the Contact Us page.
                                      • Regain Your Privacy: I don't think anyone will read it.
                                      • Why People Choose Us: Again, too many words on the homepage without focusing on the nature of the service.
                                      • UniJoin Blog Articles: It is better to remove them.
                                      • Use UniJoin To Anonymize: It is better to remove them.
                                      • If it's a bitcoin mixer, why you have "Coins We Mix."


                                      What I like:

                                      • Support multiple languages.
                                      • Colors are attractive.

                                      Website/UI Design review:



                                      Website Readability


                                      • Fonts are easy to read
                                      • Site contains a lot of unnecessary pages
                                      • The site is perfect for fonts in Japanese, but the Russian language needs to be modified.
                                      • You may need to add a night mode.
                                      Website Readability review:



                                      Mixing Process & Speed

                                      The mixing process is simple and clear, but there are many details that must be included:


                                      • JavaScript: I prevented giving Java permissions, but the site did not work for me. It is better to think carefully about building the site without JavaScript.
                                      • Captcha: It doesn't work well with Tor, it's best to remove it.
                                      • Letter of Guarantee: I am supposed to get it before I deposit as proof that the address shown belongs to you.
                                      • The mixing process takes a long time, at least an hour.
                                      • The positive aspects are smoothness and simplicity



                                      Mixing Process & Speed review:



                                      F.A.Q & Support

                                      I like the support page, it's perfect but there are some notes:

                                      • It is good for the user to get the money back if he sends amounts less than 0.001 BTC, but it is better for the warning to be clear and to consider that money as a donation to the site with the possibility of refunding if the user contacts the support team. (Such option will add a lot of tasks to the support team.)
                                      • It is better to make the lower limits in dollars or altcoins if you want to mix altcoins.



                                      F.A.Q & Support review:


                                      Recommendations:

                                      • Remove Captcha and JavaScript dependency
                                      • Reduce animation.
                                      • Add night mode.
                                      • Add a Letter of Guarantee as proof because the deposit address belongs to you.


                                      Final review:




                                      Will add more.

                                      .BEST..CHANGE.███████████████
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ██
                                      ███████████████
                                      ..BUY/ SELL CRYPTO..
                                      bitbollo
                                      Legendary
                                      *
                                      Offline Offline

                                      Activity: 3248
                                      Merit: 3489


                                      Nec Recisa Recedit


                                      View Profile
                                      April 02, 2022, 02:47:26 PM
                                      Last edit: April 02, 2022, 06:29:09 PM by bitbollo
                                       #43

                                      Premium review and suggestion spreadsheet#06





                                      0.
                                      Premise: I am not a user who habitually uses TOR and crypto mixer.
                                      My review and suggestions are those of a "novice" user (more or less Grin) who uses such kind of service.
                                      Some observations may also be elementary, but they help to develop IMHO a service that is as inclusive as possible also for who is not a regular visitor to certain services.

                                      1.
                                      To access the site I used TOR and the Classic url: https://[banned mixer]/
                                      Once inside I switched to the onion address
                                      http://[banned mixer]/
                                      I also did the test to log in directly from the onion link and the connection is practically immediate.

                                      2.
                                      I like the simplicity of the homepage which clearly highlights the "start mixing" button, the main features of the site, and information on the uniJoin site. The idea of leaving the site details - type of technology used etc etc - in the second part of the home page is excellent.

                                      3.
                                      This option ”Recurring Client"... Is it information that is stored on your servers? Does it provide "special advantages" such as lower payment of fees? There are not information added on the website. Since it's the first item that a user will find, it would be really helpful find more information to clarify this area and how it works.
                                      Please note, the button (?) Nearby "transfer delay" does not work (does not allow access to any information).

                                      4.
                                      "Guarantee letter"
                                      Quote
                                      The terms specify: I confirm that I need to download the letter of guarantee after transferring coins to the generated address of Unijoin.
                                      But it is actually generated AFTER the two confirmations!
                                      In the past with other mixers I have noticed that it is generated / downloaded automatically once the sending and receiving addresses are confirmed. Moreover it is never explicitly mentioned in your terms and conditions ... This passage to a novice can create many problems and doubts (where is my letter?)(let's imagine making a big mixing)
                                      Regarding this point, mine pure curiosity, but how do you really manage to guarantee "up to 250 btc mix"?
                                      (Is there any evidence of funds? Other ploys?)

                                      5.
                                      Question: Hypothetically, if two payments are sent to the same address, is the second one irremediably lost? Is there no way to recover these lost bitcoins?

                                      Why not also add “estimated time to complete mixing” along with awaiting confirmations?

                                      edit: I have noticed a difference between amount on site and amount received (probably due tx fees).
                                      I think this should be added specified clearly before mixing (likewise cost of service and cost (estimate) of transaction)

                                      6.
                                      In general the process went quite "smooth" but isn't the faster that I have used. the doubt that remains is about the "letter of guarantee" which is not generated immediately after sending coins but after two confirmations.

                                      ███████████████████████████
                                      ███████▄████████████▄██████
                                      ████████▄████████▄████████
                                      ███▀█████▀▄███▄▀█████▀███
                                      █████▀█▀▄██▀▀▀██▄▀█▀█████
                                      ███████▄███████████▄███████
                                      ███████████████████████████
                                      ███████▀███████████▀███████
                                      ████▄██▄▀██▄▄▄██▀▄██▄████
                                      ████▄████▄▀███▀▄████▄████
                                      ██▄███▀▀█▀██████▀█▀███▄███
                                      ██▀█▀████████████████▀█▀███
                                      ███████████████████████████
                                      .
                                      .Duelbits.
                                      ..........UNLEASH..........
                                      THE ULTIMATE
                                      GAMING EXPERIENCE
                                      DUELBITS
                                      FANTASY
                                      SPORTS
                                      ████▄▄█████▄▄
                                      ░▄████
                                      ███████████▄
                                      ▐███
                                      ███████████████▄
                                      ███
                                      ████████████████
                                      ███
                                      ████████████████▌
                                      ███
                                      ██████████████████
                                      ████████████████▀▀▀
                                      ███████████████▌
                                      ███████████████▌
                                      ████████████████
                                      ████████████████
                                      ████████████████
                                      ████▀▀███████▀▀
                                      .
                                      ▬▬
                                      VS
                                      ▬▬
                                      ████▄▄▄█████▄▄▄
                                      ░▄████████████████▄
                                      ▐██████████████████▄
                                      ████████████████████
                                      ████████████████████▌
                                      █████████████████████
                                      ███████████████████
                                      ███████████████▌
                                      ███████████████▌
                                      ████████████████
                                      ████████████████
                                      ████████████████
                                      ████▀▀███████▀▀
                                      /// PLAY FOR  FREE  ///
                                      WIN FOR REAL
                                      ..PLAY NOW..
                                      NeuroticFish
                                      Legendary
                                      *
                                      Offline Offline

                                      Activity: 3668
                                      Merit: 6382


                                      Looking for campaign manager? Contact icopress!


                                      View Profile
                                      April 03, 2022, 08:14:16 AM
                                      Merited by hugeblack (7)
                                       #44

                                      Code:
                                      Premium review and suggestion spreadsheet#11

                                      1. I’ve started with the link from this very page. First note: it’s a clear net link and when doing proper mixing one may look only for TOR address of the page. I’ve found the TOR address at the bottom of the clearnet page, but it tells "Office Tor Mirror". I think that’s a typo and some may think it’s an office/contact page, you may want to rephrase that and also put it on the ANN pages and closer to the top of the web page. Ah, and a copy button may be more appropriate than connect, since another browser would be used (at least in my case).

                                      So the TOR page does exist, you need only small cosmetic changes imho.

                                      2. Since I don’t want to make mistakes, I did a quick look into the FAQ. I’ve found a little funny the part about hardware wallets. Not incorrect though, since those problems are real. I find it funny because you may scare off HW users. I don't know, maybe a rephrase could be needed, or maybe it's just me, especially as it's not a problem only for HW, one can have cold storage and use Electrum with online servers.
                                      Nothing big though.

                                      3. The question mark near Transfer Delay has only the tooltip “transfer delay” and nothing happens when I link it (both on Firefox clear net and on TOR browser).

                                      4. I’ve noticed noticed the different amounts and delay/receive times if more final recipients are chosen – nice touch. For my small amount I’ve used only one recipient though.

                                      5. At actual mixing, from start, you provide OrderStatus link, UniCode (the name may be misleading when one asks for support, since Unicode usually means something else), order Id, yet I was expecting the Letter of Guarantee. At a second look into FAQ I understood that probably the Letter is generated only after the 2 confirmations (it may be good that you write about confirmations in the FAQ, for clarity) and I’ve also found that the session link is enough for getting to that page (I recommend to add explanatory [?]) to Order Link and UniCode. I find Order Id a bit redundant (as it’s in the order link).

                                      After getting reassured I’ll recover easily the session, I’ve closed the browser completely and didn’t pay attention to the confirmations since I’ve sent with pretty low fee; I returned later to the session.

                                      6. After 2 confirmations I was able to download the letter of guarantee. Then I’ve also seen how much I should expect to receive back. Here some cosmetic changes would be in order:
                                      * show from start, on the main page how much one should expect the fees to be (although it’s already in FAQ, I know)
                                      * after the 2 confirmations, after the amount to be received is shown, it won’t hurt to add info about the fee (the amount and the %) so those not reading the FAQ don’t get surprised. I’ve calculated my fee to be: 1.69%

                                      7. I’ve set a couple of hours of delay and around the expected time I’ve got the incoming transaction, which had a quite big tx fee and got confirmed very fast. Here I’ve done the math again and that fee was subtracted from the amount "they’ve promised" when the funds I’ve sent got confirmed. Which is normal, since (for my small amount) that tx fee was even bigger than their 1.69%. Whether that bit of information needs or not to be written down, I don’t know; maybe.

                                      8. Internals. Since it boasts CoinJoin basically even in its name, I’ve been somewhat afraid that the funds will be combined with other funds, but the link between source and destination will not be broken. But I’ve checked the deposit address and at the moment the coins were sent to me (mixing is over), those initial funds are still at the initial deposit address. Nice! (actually - even after the second mix the initial inputs were not touched!).

                                      9. Forgetting. At the moment the (mixed) tx is sent to me, the page shows "This status page and all your personal data are now deleted and will not be available anymore." If I restart the browser and try to open by the order link it’s no longer reachable: link not valid (and a proper explanation why). Good.

                                      10. TOR again. I’ve made a second mixing using the TOR browser. Everything went good, including recovery from the Letter of Guarantee, but I’ve also found two bugs:
                                      * here the Order Status Link is also a clear net link
                                      * I’ve set mixing time almost 25h and not long after confirmations, the page has shown 00h 37m 25s. It’s a display bug, since after the 37m have passed it has shown correctly 23h59m59s and at the expected time the new tx was sent to me.


                                      Conclusions:

                                      While I find the UI is fancier than necessary, there are still some cosmetic things that could be improved and made more informative. There are minor bugs, but the only one that actually somewhat scared me (because of my schedule/plans) was the delay time display problem.

                                      But overall the mixing simply works as expected: the money is delivered to the expected address and at the expected time and the link with the initial input(s) is broken.

                                      .
                                      .HUGE.
                                      ▄██████████▄▄
                                      ▄█████████████████▄
                                      ▄█████████████████████▄
                                      ▄███████████████████████▄
                                      ▄█████████████████████████▄
                                      ███████▌██▌▐██▐██▐████▄███
                                      ████▐██▐████▌██▌██▌██▌██
                                      █████▀███▀███▀▐██▐██▐█████

                                      ▀█████████████████████████▀

                                      ▀███████████████████████▀

                                      ▀█████████████████████▀

                                      ▀█████████████████▀

                                      ▀██████████▀▀
                                      █▀▀▀▀











                                      █▄▄▄▄
                                      ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                      .
                                      CASINSPORTSBOOK
                                      ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                      ▀▀▀▀█











                                      ▄▄▄▄█
                                      LoyceV
                                      Legendary
                                      *
                                      Online Online

                                      Activity: 3304
                                      Merit: 16620


                                      Thick-Skinned Gang Leader and Golden Feather 2021


                                      View Profile WWW
                                      April 03, 2022, 11:36:11 AM
                                      Last edit: April 03, 2022, 03:11:35 PM by LoyceV
                                       #45

                                      Quote from: the Terms
                                      I confirm that I need to download the letter of guarantee after transferring coins to the generated address of Unijoin.
                                      There it is again: what's the point of a letter of guarantee after depositing, if I don't get it before sending funds?
                                      ➡️ We have checked this matter again, and we will amend it. Letter of Guarantee will be made available for download before the transaction must be made.
                                      Thanks for changing this. Note that the text at Step 2 still needs to be updated:
                                      Image loading...
                                      I assume this should be "after" > "before".

                                      To be continued, but not before my main concern (in red) is clarified.
                                      Now I can continue my review:

                                      I'm not a native English speaker, but I'd say the word "Recurring" shouldn't be here:
                                      Image loading...

                                      When setting multiple output addresses, the amounts can be adjusted with a slider:
                                      Image loading...
                                      I understand that a slider with percentages makes it look more random and is probably best for privacy, but I can imagine users would want to receive an exact amount on some of the addresses.

                                      The captcha works quite okay on Tor.

                                      The Letter of Guarantee has a weird format:
                                      Code:
                                      letter_of_guarantee_xxxxxxxxxx_.json: ASCII text, with very long lines, with CRLF, LF line terminators
                                      That makes it look weird in both xed and vi:
                                      Image loading...
                                      (yellow is meant to censor some data)
                                      I've tried to verify the LoG, and I've used Kleopatra for this before, but I have no idea how to verify this one. Also: I can't find your public key anywhere on the website. Without that, this public key can be specifically created for only my transaction, which would still mean I can't use it to prove anything.

                                      Since I couldn't verify the LoG, this was a good chance to test the /en/contact/pzRrS4OtM5gzEvi]Support Chat.
                                      Me:
                                      Quote
                                      How can I verify the Letter of Guarantee?
                                      After 46 seconds, I received an automated response:
                                      Quote
                                      Hello Yovonnda, Thank you for your contact request. A member of the support team will deal with your request as soon as possible. You should receive an answer within the next 24 hours. Thank you for using our service.
                                      That's disappointing. If it's automated, can't it be instant instead of making me wait for 46 seconds?
                                      After about an hour I got this response:
                                      Quote
                                      Hi there! You can upload it here when creating a support ticket. Or you can verify it in the restore session page. Here is the link: https://[banned mixer]/en/restore.
                                      Me:
                                      Quote
                                      Are you saying there is no way to verify its authenticity locally?
                                      If so, its just a Letter without Guarantee.



                                      Why don't you sign the Letter of Guarantee from a Bitcoin address? That makes it much easier to verify the message, and the address used for signing can be posted on your website and here for verification.
                                      Example:
                                      -----BEGIN BITCOIN SIGNED MESSAGE-----
                                      This is LoyceVs PM publisher staking address 1QEHZg9KVa1Am9iCdSJ7NktqSs1t569vYi on February 15, 2022 for https://bitcointalk.org/index.php?topic=996318
                                      -----BEGIN SIGNATURE-----
                                      1QEHZg9KVa1Am9iCdSJ7NktqSs1t569vYi
                                      IJa2+WnJOxKamvXzoiV7DHOSlGNT+ZHHFxsY2pKG0gQwTIHxmh9/ljbCJthRR+vic8Qv7C7ERl1c89bIW9SZB+Y=
                                      -----END BITCOIN SIGNED MESSAGE-----
                                      This is human readable and can easily be verified by a variety of Bitcoin wallets. All you'd have to do is publish the signing address so anyone can verify it's authenticity.



                                      I'm posting part 2 of my (still incomplete) review so I don't lose it. I'll continue after I've been able to verify the LoG.

                                      NeuroticFish
                                      Legendary
                                      *
                                      Offline Offline

                                      Activity: 3668
                                      Merit: 6382


                                      Looking for campaign manager? Contact icopress!


                                      View Profile
                                      April 03, 2022, 12:42:06 PM
                                      Merited by LoyceV (1)
                                       #46

                                      The Letter of Guarantee has a weird format:
                                      Code:
                                      letter_of_guarantee_xxxxxxxxxx_.json: ASCII text, with very long lines, with CRLF, LF line terminators
                                      That makes it look weird in both xed and vi:

                                      Can you try to rename it to .txt? It's basically a text file with multiple sections, public key, signature format (?), signature and an actual json only at the end.
                                      Maybe it helps; I've opened with notepad++ under Windows and looked pretty good/understandable (not that I've checked anything else than recovering the session, which can be done with the link too).

                                      .
                                      .HUGE.
                                      ▄██████████▄▄
                                      ▄█████████████████▄
                                      ▄█████████████████████▄
                                      ▄███████████████████████▄
                                      ▄█████████████████████████▄
                                      ███████▌██▌▐██▐██▐████▄███
                                      ████▐██▐████▌██▌██▌██▌██
                                      █████▀███▀███▀▐██▐██▐█████

                                      ▀█████████████████████████▀

                                      ▀███████████████████████▀

                                      ▀█████████████████████▀

                                      ▀█████████████████▀

                                      ▀██████████▀▀
                                      █▀▀▀▀











                                      █▄▄▄▄
                                      ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                      .
                                      CASINSPORTSBOOK
                                      ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                      ▀▀▀▀█











                                      ▄▄▄▄█
                                      LoyceV
                                      Legendary
                                      *
                                      Online Online

                                      Activity: 3304
                                      Merit: 16620


                                      Thick-Skinned Gang Leader and Golden Feather 2021


                                      View Profile WWW
                                      April 03, 2022, 12:59:50 PM
                                      Last edit: April 04, 2022, 07:39:34 AM by LoyceV
                                       #47

                                      Can you try to rename it to .txt? It's basically a text file with multiple sections, public key, signature format (?), signature and an actual json only at the end.
                                      Sometimes the solution is so easy Smiley Thanks, I never expected those 2 programs to adjust the view based on the file extension.
                                      This shows another inconsistency though: the PUBLIC KEY part uses normal looking line breaks, the SIGNATURE uses Windows line breaks (EOL). This is highlighted in vi by adding ^M at the end of the lines.

                                      Quote
                                      Maybe it helps; I've opened with notepad++ under Windows and looked pretty good/understandable (not that I've checked anything else than recovering the session, which can be done with the link too).
                                      Any idea how to verify the LoG? Depositing without verifying is what makes many people send their funds to a phishing site, and that's all the more reason why verifying the LoG should be as easy as possible.

                                      since the LoG contains the public key too (which my guess would be that it would be used to verify the signature), it probably can be spoofed fully by a phishing site.
                                      I addressed that already:
                                      I can't find your public key anywhere on the website. Without that, this public key can be specifically created for only my transaction, which would still mean I can't use it to prove anything.

                                      I'm starting to wonder if it's really not possible to verify the LoG (which also makes me wonder why I'm the only one not completing the review without checking this!):
                                      After about an hour I got this response:
                                      Quote
                                      Hi there! You can upload it here when creating a support ticket. Or you can verify it in the restore session page. Here is the link: https://[banned mixer]/en/restore.
                                      Me:
                                      Quote
                                      Are you saying there is no way to verify its authenticity locally?
                                      If so, its just a Letter without Guarantee.
                                      For the record: without a LoG that can be verified independently, it's impossible to provide evidence if you claim you got scammed.

                                      NeuroticFish
                                      Legendary
                                      *
                                      Offline Offline

                                      Activity: 3668
                                      Merit: 6382


                                      Looking for campaign manager? Contact icopress!


                                      View Profile
                                      April 03, 2022, 01:12:32 PM
                                       #48

                                      Any idea how to verify the LoG? Depositing without verifying is what makes many people send their funds to a phishing site, and that's all the more reason why verifying the LoG should be as easy as possible.

                                      Sorry, nope. However, since the LoG contains the public key too (which my guess would be that it would be used to verify the signature), it probably can be spoofed fully by a phishing site.
                                      One proper way could be to publish on the website, but also on Bitcointalk and other reputable areas (eg github) the asc file with the key to verify the signatures.

                                      .
                                      .HUGE.
                                      ▄██████████▄▄
                                      ▄█████████████████▄
                                      ▄█████████████████████▄
                                      ▄███████████████████████▄
                                      ▄█████████████████████████▄
                                      ███████▌██▌▐██▐██▐████▄███
                                      ████▐██▐████▌██▌██▌██▌██
                                      █████▀███▀███▀▐██▐██▐█████

                                      ▀█████████████████████████▀

                                      ▀███████████████████████▀

                                      ▀█████████████████████▀

                                      ▀█████████████████▀

                                      ▀██████████▀▀
                                      █▀▀▀▀











                                      █▄▄▄▄
                                      ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                      .
                                      CASINSPORTSBOOK
                                      ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                      ▀▀▀▀█











                                      ▄▄▄▄█
                                      LoyceV
                                      Legendary
                                      *
                                      Online Online

                                      Activity: 3304
                                      Merit: 16620


                                      Thick-Skinned Gang Leader and Golden Feather 2021


                                      View Profile WWW
                                      April 04, 2022, 07:38:32 AM
                                       #49

                                      I'll continue my review here:
                                      Me:
                                      Quote
                                      Are you saying there is no way to verify its authenticity locally?
                                      If so, its just a Letter without Guarantee.
                                      About 5 hours later I got this response from Support Chat:
                                      Quote
                                      You can also verify it locally, you can use the public key and the signature format to generate the signature.

                                      -----BEGIN PUBLIC KEY----- MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxDT7TzmPR+7UdV76iSCr IrdN8DXE4aSMjzgb1Tl66w7p6HOUXGhS4knzAPUklEMqJMDeB0XOhNlsYxLqfzY2 NzFkx6iuYaCgDV9CW/Ilx1Bxp7KY0SWNkJTRU/SQhwTyKoFc0/k+u95+Qt9YxpqX om9Ab9s5EkBRHzz9G5Tzcm1MYVWlk2fBe5g5pF65agCZpbd7tYFRpYdYiyLSFTP/ baF6GljcOfaO7Zq/IdyoXH+2vISMFTspaGAyqmEM2dgTpOfsljQ9s2bOcfLoIN1u CH8iOLfgdCbCOzJ6GWEv8gyBURHFg7YydQ2iOYHbVFhqbtOcqWiY5fx+cph7DmGV PD5Rv72Epue+90cJ7RbODBMMlrJ4XAnb/rUxw9q5ZeMCfROOn8462hoggLjEZJ4S WgvZBepax3/OFJL3BZftf5JCU2YrS55YGY26aRdZyIfa4ZE1WT0hbdCCgKq+EYUW 3uTRi7coAcHmhmtYaxmXIWn//tkNbvwoVkm4lQgs1NBhi7oVbqyHGOFwbCUgdKac hRZ6gczHYPTIUdTctAwBuDfgHX7MBXTOxmjpGDHG20x1/cuUgUYvk3OpO+g+uvvK PKysw589rqYOxq2hs2Q80D1Kd9VzayGU5+ZBcM35fby6bQmhUgvVAa6fIm9a3NK2 SiazvF6yc59qdzdBnBkWUVkCAwEAAQ== -----END PUBLIC KEY-----

                                      Here is our public key so you can double check it in the letter of guarantee

                                      The signature was created through RSA and can be verified through the public key mentioned above and the signature format.

                                      If you dont have a specific tool to verify the signature locally you can use for example this website.

                                      https://8gwifi.org/rsasignverifyfunctions.jsp

                                      Enter the Public Key from your letter of guarantee, the clear text is the signature format, enter the signature itself and select SHA256withRSA as the Signature Algorithm.

                                      We will also add the public key into our website shortly so people can compare and proof the authenticity of the public itself.
                                      First: the public key above is the same as I received. I'll keep this post as the first public mention of UniJoin's public key.

                                      Using a third-party website to verify a signed message is terrible for privacy, but the site might work offline. I haven't been able to test that, because I haven't been able to verify the LoG. All I get is:
                                      Quote
                                      Signature Verification Failed

                                      I'll say again that verifying a signed message would have been so much easier if it's signed from a Bitcoin address.

                                      UniJoin
                                      Copper Member
                                      Full Member
                                      ***
                                      Offline Offline

                                      Activity: 173
                                      Merit: 286


                                      Your Bitcoin Mixer


                                      View Profile
                                      April 04, 2022, 01:00:49 PM
                                       #50

                                                                  Hello hugeblack, thank you for your detailed review!

                                                                Quote
                                                                The site design is simple, Fonts are easy to read, Home page is a bit more detailed, Content could be understood on mobile devices (3440 x 1440 screens,) but there are a lot of animations and things that must be removed, the most important of which are:

                                                                • Intro video: It doesn't talk about how to mix using [banned mixer], use the site etc, it's a general intro video.
                                                                • About Us: It can be made in a separate page or in the Contact Us page.
                                                                • Regain Your Privacy: I don't think anyone will read it.
                                                                • Why People Choose Us: Again, too many words on the homepage without focusing on the nature of the service.
                                                                • UniJoin Blog Articles: It is better to remove them.
                                                                • Use UniJoin To Anonymize: It is better to remove them.
                                                                • If it's a bitcoin mixer, why you have "Coins We Mix."

                                                                As you mentioned, it is a general promo video that we have on our website. In future, we will also add short explanation video of how to use UniJoin and how the CoinJoin technology in general work.

                                                                For now, it is only a Bitcoin mixer. We are working to add more currencies to our mixer, which will include Ethereum and others.
                                                                Thank you for your general feedback about the contents in the homepage.

                                                                Quote
                                                                • Fonts are easy to read
                                                                • Site contains a lot of unnecessary pages
                                                                • The site is perfect for fonts in Japanese, but the Russian language needs to be modified.
                                                                • You may need to add a night mode.

                                                                We are glad to hear that you like the design of our website. Russian will need modification, as you mentioned.

                                                                The mixing process is simple and clear, but there are many details that must be included:


                                                                Quote
                                                                • JavaScript: I prevented giving Java permissions, but the site did not work for me. It is better to think carefully about building the site without JavaScript.
                                                                • Captcha: It doesn't work well with Tor, it's best to remove it.
                                                                • Letter of Guarantee: I am supposed to get it before I deposit as proof that the address shown belongs to you.
                                                                • The mixing process takes a long time, at least an hour.
                                                                • The positive aspects are smoothness and simplicity

                                                                We are already thinking about building a site without JavaScript for users that value their privacy very much and deactivate it. We will let our community know about future updates about this.
                                                                Letter of guarantee is now provided before the transfer happens. Also the public key will be published on our website soon for verification.
                                                                For the mixing time: We will soon add a feature in where people can instantly mix their coins and instantly receive clean coins back

                                                                Quote
                                                                I like the support page, it's perfect but there are some notes:

                                                                • It is good for the user to get the money back if he sends amounts less than 0.001 BTC, but it is better for the warning to be clear and to consider that money as a donation to the site with the possibility of refunding if the user contacts the support team. (Such option will add a lot of tasks to the support team.)
                                                                • It is better to make the lower limits in dollars or altcoins if you want to mix altcoins.

                                                                We will consider this, thanks for your feedback!



                                                                Quote
                                                                Will add more.

                                                                Thank you, we are looking forward to more feedback from you! All in all, you helped us to find things that we can improve. We will work on further updates!

                                                                UniJoin
                                                                Copper Member
                                                                Full Member
                                                                ***
                                                                Offline Offline

                                                                Activity: 173
                                                                Merit: 286


                                                                Your Bitcoin Mixer


                                                                View Profile
                                                                April 04, 2022, 01:56:03 PM
                                                                 #51

                                                                Hi NeuroticFish, thank your for participating in the Premium Bounty Campaign! Your feedback is much appreciated!

                                                                Quote
                                                                0.
                                                                Premise: I am not a user who habitually uses TOR and crypto mixer.
                                                                My review and suggestions are those of a "novice" user (more or less Grin) who uses such kind of service.
                                                                Some observations may also be elementary, but they help to develop IMHO a service that is as inclusive as possible also for who is not a regular visitor to certain services.

                                                                Your feedback will be very important for us, because we also address users who do not know that Bitcoin is not really anonymous. So the feedback of a "novice" will help us to see the point of view of such people we want to address as well!

                                                                Quote
                                                                1.
                                                                To access the site I used TOR and the Classic url: https://[banned mixer]/
                                                                Once inside I switched to the onion address
                                                                http://[banned mixer]/
                                                                I also did the test to log in directly from the onion link and the connection is practically immediate.

                                                                2.
                                                                I like the simplicity of the homepage which clearly highlights the "start mixing" button, the main features of the site, and information on the uniJoin site. The idea of leaving the site details - type of technology used etc etc - in the second part of the home page is excellent.

                                                                We are very glad to hear that you had a good experience here!

                                                                Quote
                                                                3.
                                                                This option ”Recurring Client"... Is it information that is stored on your servers? Does it provide "special advantages" such as lower payment of fees? There are not information added on the website. Since it's the first item that a user will find, it would be really helpful find more information to clarify this area and how it works.
                                                                Please note, the button (?) Nearby "transfer delay" does not work (does not allow access to any information).

                                                                All customers receive a unique code that they can use for further shuffling orders with UniJoin. This code ensures that coins sent to us for shuffling will not be sent to the user again that they once owned. And the question marks (?) are working now.

                                                                Quote
                                                                4.
                                                                "Guarantee letter"
                                                                Quote
                                                                The terms specify: I confirm that I need to download the letter of guarantee after transferring coins to the generated address of Unijoin.
                                                                But it is actually generated AFTER the two confirmations!
                                                                In the past with other mixers I have noticed that it is generated / downloaded automatically once the sending and receiving addresses are confirmed. Moreover it is never explicitly mentioned in your terms and conditions ... This passage to a novice can create many problems and doubts (where is my letter?)(let's imagine making a big mixing)
                                                                Regarding this point, mine pure curiosity, but how do you really manage to guarantee "up to 250 btc mix"?
                                                                (Is there any evidence of funds? Other ploys?)

                                                                The Letter of Guarantee is now generated before the transfer of funds. We followed the feedback of the Bitcointalk community and found it important too, so people can verify the address before sending the funds. Regarding the huge mixing amounts, we can mix such amounts, however these will take longer than usual (up to 72 hours).

                                                                Quote
                                                                5.
                                                                Question: Hypothetically, if two payments are sent to the same address, is the second one irremediably lost? Is there no way to recover these lost bitcoins?

                                                                The second payment is of course not lost. It is just that the system doesn't automatically recognize the second payment. Users will need to contact us along with the Letter of Guarantee in this case.

                                                                Quote
                                                                Why not also add “estimated time to complete mixing” along with awaiting confirmations?

                                                                The mixing time is given only after the two confirmations, because we cannot predict how long it will take for the transaction to have 2 confirmations.

                                                                Quote
                                                                edit: I have noticed a difference between amount on site and amount received (probably due tx fees).
                                                                I think this should be added specified clearly before mixing (likewise cost of service and cost (estimate) of transaction)

                                                                That's right, the tx fees are paid by the user himself. We have added this in the Terms of Condition, FAQs and in the pricing page.

                                                                Quote
                                                                6.
                                                                In general the process went quite "smooth" but isn't the faster that I have used. the doubt that remains is about the "letter of guarantee" which is not generated immediately after sending coins but after two confirmations.

                                                                Thanks for the feedback. We will of course work on further updates to make the whole process smoother, safer and simpler, but if you have any other suggestions, we would still be happy to hear them!

                                                                NeuroticFish
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 3668
                                                                Merit: 6382


                                                                Looking for campaign manager? Contact icopress!


                                                                View Profile
                                                                April 04, 2022, 02:51:15 PM
                                                                 #52


                                                                I messaged you, but I guess that I was too late: you thanked me, but you replied to bitbollo post, not to mine.

                                                                .
                                                                .HUGE.
                                                                ▄██████████▄▄
                                                                ▄█████████████████▄
                                                                ▄█████████████████████▄
                                                                ▄███████████████████████▄
                                                                ▄█████████████████████████▄
                                                                ███████▌██▌▐██▐██▐████▄███
                                                                ████▐██▐████▌██▌██▌██▌██
                                                                █████▀███▀███▀▐██▐██▐█████

                                                                ▀█████████████████████████▀

                                                                ▀███████████████████████▀

                                                                ▀█████████████████████▀

                                                                ▀█████████████████▀

                                                                ▀██████████▀▀
                                                                █▀▀▀▀











                                                                █▄▄▄▄
                                                                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                                                .
                                                                CASINSPORTSBOOK
                                                                ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                                                ▀▀▀▀█











                                                                ▄▄▄▄█
                                                                GazetaBitcoin
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 1694
                                                                Merit: 6586


                                                                Fully-fledged Merit Cycler|Spambuster'23|Pie Baker


                                                                View Profile
                                                                April 04, 2022, 06:35:23 PM
                                                                 #53

                                                                Premium review and suggestion spreadsheet#10

                                                                1. The first impression the website offered me was that it looks too crowded. Chosen colors are relaxing the eyes, but the homepage, to say the least, is overcrowded.

                                                                2. On the homepage there is a banner showing various companies (Yahoo!, Yahoo! Finance, Yahoo! Money, Cryptonews etc.) but the banner has no explanation to state why those companies are listed there. Perhaps they are partners on UniJoin, but, even so, there should be an indication for that (something like "Official Partners"). Moreover, when clicking on Yahoo! name, the displayed page is not Yahoo!'s homepage, but Yahoo! News homepage. Maybe this name should be replaced with Yahoo! News.

                                                                3. If the above mentioned banner is a list of official partners, then maybe it can be mentioned at the bottom of the page, for making homepage look less crowded.

                                                                4. When switching the website localization to Chinese, from the button placed on the top-right of homepage, China's flag is not displayed. Besides, the "N" from "CN" is also not entirely displayed.

                                                                5. Another element of overcrowding the website is the presence of "Start Mixing" / "Mix Now" buttons, which appear everywhere. On home page these buttons appear in four places: on top-right corner of homepage, under the "Make your Crypto Finances Untraceable" title (both being on the upper area of homepage), under "Use UniJoin To Anonymize Your Cryptos" title and under "Your Anonymity Is Our Priority" title (both being on the lower area of homepage). Besides, when accessing any area of the website by clicking its various buttons, on each section there is again a "Start Mixing" or "Mix Now" button. Example: click on the buttons from the top of homepage - Why UniJoin, Referral, Pricing, FAQ, Blog, Contact Us. On each of these pages there is a "Start Mixing" / "Mix Now" button. It seems somehow pushy for the user, like the website cares only for mixing coins and thus it tries to determine the user to click on mixing buttons on absolutely any area of the website. Perhaps it would be a better idea to have the button displayed only once or twice on homepage and to be removed from the other website sections, thus having a section of the website dedicated to mixing the coins. As comparison, image an email provider homepage where you would see in 4 places on the homepage the fields for entering user / password. Furthermore, there is an inconsistency regarding the name of these buttons, as in one place the name is "Start Mixing" and in another place the name is "Mix Now". Perhaps, for consistency matters, all these buttons could have a unique name.

                                                                6. When the user starts the mixing process, on the page named "One Last Step Before Mixing Your Coins!" is a field named "Order Status Link". The URL written there appears truncated. Perhaps the respective field can be enlarged a bit, thus the entire URL is visible?

                                                                7. Still on the "One Last Step Before Mixing Your Coins!" page, there is a warning, saying "If no funds are received within the remaining time, this link will be deleted [...]". However, there is no time counter displayed there.

                                                                8. Transfer-wise, the system is working on its basic parameters, meaning that I successfully received my mixed funds with the default delay time. However, I would suggest to have this test performed on various settings of delayed time, in order to be sure that it works properly on any amount of time set as delay.

                                                                9. Other than these, I tested the website menu functionality and all buttons are working.

                                                                10. Localization-wise, I would advise to UniJoin to try to recruit natives from all the languages in which the website is localized, in order to perform a full proofreading check and spot all translation problems. Seriousness in writing, having no typos, having all the text localized not by translating the words, but also idiomatic, may be crucial in giving a first good impression to website visitors. Otherwise, if many grammar / typos are encountered on various localizations, users may think that the website admins are illiterate and they may lose their enthusiasm in using the services. So far I searched the text only on English localization and it looks fine, but I can not say anything about any other language supported by the website, as I don't speak the respective languages.

                                                                I will end here this feedback, but I will come back in case I will find any other bug on the website or in case I'll have more suggestions.

                                                                Congratulations, UniJoin!

                                                                █▀▀▀











                                                                █▄▄▄
                                                                ▀▀▀▀▀▀▀▀▀▀▀
                                                                e
                                                                ▄▄▄▄▄▄▄▄▄▄▄
                                                                █████████████
                                                                ████████████▄███
                                                                ██▐███████▄█████▀
                                                                █████████▄████▀
                                                                ███▐████▄███▀
                                                                ████▐██████▀
                                                                █████▀█████
                                                                ███████████▄
                                                                ████████████▄
                                                                ██▄█████▀█████▄
                                                                ▄█████████▀█████▀
                                                                ███████████▀██▀
                                                                ████▀█████████
                                                                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                                                c.h.
                                                                ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                                                ▀▀▀█











                                                                ▄▄▄█
                                                                ▄██████▄▄▄
                                                                █████████████▄▄
                                                                ███████████████
                                                                ███████████████
                                                                ███████████████
                                                                ███████████████
                                                                ███░░█████████
                                                                ███▌▐█████████
                                                                █████████████
                                                                ███████████▀
                                                                ██████████▀
                                                                ████████▀
                                                                ▀██▀▀
                                                                UniJoin
                                                                Copper Member
                                                                Full Member
                                                                ***
                                                                Offline Offline

                                                                Activity: 173
                                                                Merit: 286


                                                                Your Bitcoin Mixer


                                                                View Profile
                                                                April 07, 2022, 12:09:21 PM
                                                                 #54

                                                                Hi NeuroticFish, you are right, apologies for that! Thank you for your feedback!


                                                                I messaged you, but I guess that I was too late: you thanked me, but you replied to bitbollo post, not to mine.

                                                                Quote
                                                                1. I’ve started with the link from this very page. First note: it’s a clear net link and when doing proper mixing one may look only for TOR address of the page. I’ve found the TOR address at the bottom of the clearnet page, but it tells "Office Tor Mirror". I think that’s a typo and some may think it’s an office/contact page, you may want to rephrase that and also put it on the ANN pages and closer to the top of the web page. Ah, and a copy button may be more appropriate than connect, since another browser would be used (at least in my case).

                                                                You are right, this is a typo and will be amended, very soon. It should say "Official Tor Mirror". Regarding the Button we will consider this too.

                                                                Quote
                                                                2. Since I don’t want to make mistakes, I did a quick look into the FAQ. I’ve found a little funny the part about hardware wallets. Not incorrect though, since those problems are real. I find it funny because you may scare off HW users. I don't know, maybe a rephrase could be needed, or maybe it's just me, especially as it's not a problem only for HW, one can have cold storage and use Electrum with online servers.
                                                                Nothing big though.

                                                                Yes, it might scare hardware wallets off, but as you mentioned, it's not incorrect. But we will consider amending this FAQ and make it more clear.

                                                                Quote
                                                                3. The question mark near Transfer Delay has only the tooltip “transfer delay” and nothing happens when I link it (both on Firefox clear net and on TOR browser).

                                                                Question marks are working now.

                                                                Quote
                                                                4. I’ve noticed noticed the different amounts and delay/receive times if more final recipients are chosen – nice touch. For my small amount I’ve used only one recipient though.

                                                                Thanks for the kind feedback!

                                                                Quote
                                                                5. At actual mixing, from start, you provide OrderStatus link, UniCode (the name may be misleading when one asks for support, since Unicode usually means something else), order Id, yet I was expecting the Letter of Guarantee. At a second look into FAQ I understood that probably the Letter is generated only after the 2 confirmations (it may be good that you write about confirmations in the FAQ, for clarity) and I’ve also found that the session link is enough for getting to that page (I recommend to add explanatory [?]) to Order Link and UniCode. I find Order Id a bit redundant (as it’s in the order link).

                                                                We already considered changing the name of the UniCode, and make it more clear, what this code is about. Regarding the FAQ in the letter of guarantee, this needs to be changed of course, because now, we are providing the letter of guarantee already before funds are sent. And you are right, order ID is in the order link so it might be unnecessary.

                                                                Quote
                                                                6. After 2 confirmations I was able to download the letter of guarantee. Then I’ve also seen how much I should expect to receive back. Here some cosmetic changes would be in order:
                                                                * show from start, on the main page how much one should expect the fees to be (although it’s already in FAQ, I know)
                                                                * after the 2 confirmations, after the amount to be received is shown, it won’t hurt to add info about the fee (the amount and the %) so those not reading the FAQ don’t get surprised. I’ve calculated my fee to be: 1.69%

                                                                Also regarding this, we already considered to add the fee in the first page when creating the order. We will also add the real total fee percentage to the orders

                                                                Quote
                                                                7. I’ve set a couple of hours of delay and around the expected time I’ve got the incoming transaction, which had a quite big tx fee and got confirmed very fast. Here I’ve done the math again and that fee was subtracted from the amount "they’ve promised" when the funds I’ve sent got confirmed. Which is normal, since (for my small amount) that tx fee was even bigger than their 1.69%. Whether that bit of information needs or not to be written down, I don’t know; maybe.

                                                                8. Internals. Since it boasts CoinJoin basically even in its name, I’ve been somewhat afraid that the funds will be combined with other funds, but the link between source and destination will not be broken. But I’ve checked the deposit address and at the moment the coins were sent to me (mixing is over), those initial funds are still at the initial deposit address. Nice! (actually - even after the second mix the initial inputs were not touched!).

                                                                We take good care of the quality of mixing and make sure that it's mixed properly!

                                                                Quote
                                                                10. TOR again. I’ve made a second mixing using the TOR browser. Everything went good, including recovery from the Letter of Guarantee, but I’ve also found two bugs:
                                                                * here the Order Status Link is also a clear net link
                                                                * I’ve set mixing time almost 25h and not long after confirmations, the page has shown 00h 37m 25s. It’s a display bug, since after the 37m have passed it has shown correctly 23h59m59s and at the expected time the new tx was sent to me.

                                                                Yes, we received the feedback about the clearnet link in the Tor browser already in previous comments, nevertheless, thanks for the feedback again! And regarding the timing, it shouldn't be the case of course. We will check that!

                                                                Thank you very much for your overall feedback! It helped us to find improvements. Hope we will here more feedback from you in the future!

                                                                MFahad
                                                                Hero Member
                                                                *****
                                                                Offline Offline

                                                                Activity: 2464
                                                                Merit: 644


                                                                Eloncoin.org - Mars, here we come!


                                                                View Profile WWW
                                                                April 07, 2022, 12:56:04 PM
                                                                 #55

                                                                BTC address (Segwit): bc1qzsjd8dmc6uqdjng5unhd07r80929ccxsa2jenh?time=1649335973&exp=86400
                                                                Merit earned in the last 120 days: 17









                                                                ▄▄████████▄▄
                                                                ▄▄████████████████▄▄
                                                                ▄██
                                                                ████████████████████▄
                                                                ▄███
                                                                ██████████████████████▄
                                                                ▄████
                                                                ███████████████████████▄
                                                                ███████████████████████▄
                                                                █████████████████▄███████
                                                                ████████████████▄███████▀
                                                                ██████████▄▄███▄██████▀
                                                                ████████▄████▄█████▀▀
                                                                ██████▄██████████▀
                                                                ███▄▄█████
                                                                ███████▄
                                                                ██▄██████████████
                                                                ░▄██████████████▀
                                                                ▄█████████████▀
                                                                ████████████
                                                                ███████████▀
                                                                ███████▀▀
                                                                .
                                                                ▄▄███████▄▄
                                                                ▄███████████████▄
                                                                ▄███████████████████▄
                                                                ▄██████████
                                                                ███████████
                                                                ▄███████████████████████▄
                                                                █████████████████████████
                                                                █████████████████████████
                                                                █████████████████████████
                                                                ▀█
                                                                ██████████████████████▀
                                                                ▀██
                                                                ███████████████████▀
                                                                ▀███████████████████▀
                                                                ▀█████████
                                                                ██████▀
                                                                ▀▀███████▀▀
                                                                .
                                                                 ElonCoin.org 
                                                                .
                                                                ████████▄▄███████▄▄
                                                                ███████▄████████████▌
                                                                ██████▐██▀███████▀▀██
                                                                ███████████████████▐█▌
                                                                ████▄▄▄▄▄▄▄▄▄▄██▄▄▄▄▄
                                                                ███▐███▀▄█▄█▀▀█▄█▄▀
                                                                ███████████████████
                                                                █████████████▄████
                                                                █████████▀░▄▄▄▄▄
                                                                ███████▄█▄░▀█▄▄░▀
                                                                ███▄██▄▀███▄█████▄▀
                                                                ▄██████▄▀███████▀
                                                                ████████▄▀████▀
                                                                █████▄▄
                                                                .
                                                                "I could either watch it
                                                                happen or be a part of it"
                                                                ▬▬▬▬▬
                                                                LoyceV
                                                                Legendary
                                                                *
                                                                Online Online

                                                                Activity: 3304
                                                                Merit: 16620


                                                                Thick-Skinned Gang Leader and Golden Feather 2021


                                                                View Profile WWW
                                                                April 07, 2022, 02:40:20 PM
                                                                 #56

                                                                Using a third-party website to verify a signed message is terrible for privacy, but the site might work offline. I haven't been able to test that, because I haven't been able to verify the LoG. All I get is:
                                                                Quote
                                                                Signature Verification Failed
                                                                I'll continue my review here. The delay is caused by me (Support Chat answered after 2 hours, I took 3 days to continue my testing):
                                                                Me:
                                                                Quote
                                                                Can you walk me through verifying the LoG on 8gwifi.org, or any external tool? I still can not figure it out.
                                                                Support Chat:
                                                                Quote
                                                                Of course! So first, visit the site https://8gwifi.org/rsasignverifyfunctions.jsp. After that, select Verify Signature option first.
                                                                Public Key: Enter the public key in the LoG including -----BEGIN PUBLIC KEY----- and -----END PUBLIC KEY-----
                                                                ClearText Message: Enter the content of SIGNATURE FORMAT in the letter of guarantee, but without memberCode and so on. Only the content that comes one line after with your real member code and so on.
                                                                Provide Signature Value: Enter the content of the signature in the Letter of Guarantee. Here without -----BEGIN SIGNATURE----- and -----END SIGNATURE-----
                                                                You will also need to choose SHA256withRSA in the RSA Signature Algorithms below
                                                                Then it will show that the signature verification is passed
                                                                This verified the signed message. It might be good to add verification instructions to the website.
                                                                But 8gwifi.org's verification didn't work offline, so chances are the 8gwifi.org server now knows the details of my transaction.
                                                                After I verified the LoG, I made a deposit. I used a short delay to speed things up.

                                                                When I checked my wallet after a while, it had 11 confirmations already. But the site (on Tor browser) still shows an animation and this:
                                                                Quote
                                                                Awaiting Confirmations
                                                                0.00xxxxxx BTC 0 / 2 Confirmations
                                                                If this can be fixed to auto-update, that would be great. I thought fees must have gone up, so I was still waiting until I checked my own wallet.
                                                                Reloading the page fixed it.

                                                                After reaching Step 5 ("Done!"), I can't check back the earlier steps anymore for the exact details, but at Step 4 it showed that I would receive a slightly larger amount than what I actually received. The difference wasn't much (maybe 1000 sats), but this should have been the exact amount. The total fee is now about 50% higher than what it showed earlier.

                                                                Suggestion: can you make the random fee provably fair? For instance, you can use the order ID and block hash of the incoming transaction as input to generate the random number. This might prevent complaints if someone is charged 3% on a large deposit. This can be prevented if both you and the user can't know fee before the deposit gets confirmed.

                                                                Coinjoin?
                                                                Now the thing it's all about: a coinjoin transaction! The transaction I received had 1 input and 2 outputs.
                                                                Let me quote from /en/why-unijoin]the website:
                                                                Quote
                                                                CoinJoin is a method where different people join together a single pool and together create a single transaction where each of them give coins as inputs and fresh & anonymous addresses as outputs.
                                                                This didn't happen. I expected my own deposit to join a pool of other transactions, and be included in the transaction that funds my withdrawal address.

                                                                I followed my withdrawal up the blockchain, until I got to March 29, 2022. This is the first transaction that looks like a coinjoin. But if I follow it a bit further, I get to many parent transactions that look the same, which makes me think the same funds are being used for several coinjoins in a row. This one is from February 10, 2022 for instance.

                                                                The entire concept of "UniCode" doesn't make sense when doing a real coinjoin:
                                                                Quote
                                                                With this UniCode we make sure that the same coins are not sent again to the same user in future mixing operations.
                                                                With coinjoin, I expect to receive part of my own coins back. What you're doing now is what most "classic" mixers do.

                                                                From /en/terms-and-conditions]Terms and Conditions:
                                                                Quote
                                                                The service is provided on a non-custodial basis.
                                                                ~
                                                                trustless CoinJoin
                                                                I'll get back to this later.
                                                                To conclude: it's not non-custodial, it's not trustless, and it's not coinjoin. I've said this before in a discussion with another mixer: you're in the business of trust. People need to be able to absolutely trust you're going to do what you say you're going to do. Now it looks like you're using buzzwords to inspire confidence. All in all this does the opposite: if you lie about things that I know for sure are incorrect, how can I trust you on other promises, such as not keeping any logs?



                                                                One more thing: Support Chat rejects many normal characters, I can't say "can't" and I can't use (brackets). If that can be fixed, that would be great! It's annoying having to remove common characters for every message I post.

                                                                This completes my review. Sorry for doing it in several parts, but it was necessary to verify things before I could continue with confidence.

                                                                DarkStar_
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 2758
                                                                Merit: 3282


                                                                View Profile WWW
                                                                April 09, 2022, 06:10:31 AM
                                                                Merited by LoyceV (6), NeuroticFish (3), khaled0111 (1)
                                                                 #57

                                                                Premium review and suggestion spreadsheet#14

                                                                First impressions: I don't like that the site loads external fonts from Google, as it means that Google will know when I visit your website. You should be able to move to hosting the fonts locally fairly easily, preventing this privacy leak. I also don't like that the site loads scripts from hCaptcha for the same reason, but it's marginally more acceptable as there is no very simple alternative - hopefully the javascript-free website fixes this.

                                                                I tried using a random string of characters for my UniCode, and was surprised to see that the UniCode that shows up at the mixing step was not what I entered. After some experimentation, it seems like the site will give you another random UniCode if the code you entered isn't 6 characters long. This is very very minor, but it would be better if the site gave you an error message instead of replacing your UniCode.



                                                                I'd like to echo LoyceV's suggestion to add verification instructions to the website, as I had no idea how to verify my letter of guarantee without seeing their post.

                                                                But 8gwifi.org's verification didn't work offline, so chances are the 8gwifi.org server now knows the details of my transaction.

                                                                I can confirm that the 8gwifi.org website makes requests to their server in order to verify messages. That site also seems to use Cloudflare, so even if the site owner doesn't log, there's a good chance that Cloudflare will have your mixing transaction info. I did a quick search to find other sites that verify SHA256withRSA messages in hopes of finding one that does it locally, but I surprisingly didn't find anything that just worked - it was a mix of language/library documentation, stackoverflow posts and GitHub scripts. I feel like it will be very difficult for any non-technical user to verify their letter of guarantee in a way that doesn't leak their info to a third party.

                                                                I would suggest swapping to using a Bitcoin signed message instead - users would likely be way more familiar with the format, and there are many ways of verifying a Bitcoin signed message, including verification websites that run fully client side. I'd also recommend adding a timestamp to the letter of guarantee, since deposit addresses expire after 24 hours. With the current setup, if an issue occurs, neither you or the user can prove with 100% certainty that they were correct as you can claim that the deposit was received past the 24 hour period, and they can claim that the deposit was received before.



                                                                After I mixed my coins and waited out the mixing process, I was redirected to the finish screen. I noticed that this screen showed the last UniCode I entered into the website (since I experimented with different UniCodes after sending my funds in a separate tab), rather than the actual UniCode of my mixing transaction. Not a huge issue but I think it is a bug nonetheless.

                                                                The transaction to my destination address was also a 1 input + 2 output transaction, meaning that it was also a fake "CoinJoin". I'm surprised more people didn't call them out on this, since it's advertised as one of their major selling points. Following the input chain, I also ended up with a transaction that looks like a CoinJoin after a few jumps, so I guess that might be what they actually mean by "using CoinJoin technology". The website definitely does not make that clear though, and seems to make an effort into misleading the user into thinking that their specific mixing transaction is CoinJoin. For example, they say this when referring specifically to "your" crypto funds:

                                                                Quote from: https://[banned mixer
                                                                /en/why-unijoin]We make this possible by ensuring that the output amounts are exactly the same.

                                                                This is just objectively false. However, the website seems to make a decent attempt at never explicitly stating that your transaction will be CoinJoin - just that they are powered by CoinJoin technology so this might be an oversight or an interpretation issue. All other mentions of CoinJoin that I saw on the site never explicitly stated that your transaction would be CoinJoin, and it actually took a bit of effort and careful reading to find this specific instance.

                                                                I followed my withdrawal up the blockchain, until I got to March 29, 2022. This is the first transaction that looks like a coinjoin. But if I follow it a bit further, I get to many parent transactions that look the same, which makes me think the same funds are being used for several coinjoins in a row. This one is from February 10, 2022 for instance.

                                                                I think it's likely that these are real CoinJoins, rather than transactions back and forth from addresses all controlled by one person. Some of the inputs ended up being from renBTC and various exchanges, so the varied inputs make me suspect that these belong to different users. It's not uncommon for users to participate in multiple CoinJoins in a row to increase their anonymity.



                                                                Overall, I'm not a big fan of the mixer's current state. The letter of guarantee isn't worth very much, as users can't use it to prove that they were scammed without any doubt in a worst case scenario due to the lack of a timestamp. The website seems like it's designed to try to mislead users into thinking that their specific mixing transaction will be a CoinJoin, while (almost) never explicitly stating that it will be so they're technically not lying. As a normal mixer, it does seem to work. However, compared to other mixers, it's less safe, and attempts to mislead you.

                                                                taking a break - expect delayed responses
                                                                AB de Royse777 (OP)
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 2478
                                                                Merit: 3893


                                                                Hire Bitcointalk Camp. Manager @ r7promotions.com


                                                                View Profile WWW
                                                                April 11, 2022, 10:04:57 PM
                                                                 #58

                                                                bump!
                                                                Those who got paid, please leave your reviews whenever you get time.
                                                                Code:
                                                                shasan
                                                                khaled0111
                                                                Kavelj22
                                                                examplens
                                                                Little Mouse

                                                                We still have 11 spots left.

                                                                Cheers,

                                                                PS: I really would like to send some merits to some of the users who reviewed but damn I do not want others to ask questions :-P

                                                                ..Stake.com..   ▄████████████████████████████████████▄
                                                                   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
                                                                   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
                                                                   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
                                                                   ██ ██      ██ ██████  ██ ██      ██ ██    ██
                                                                   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
                                                                   ██ █████  ███ ████  ████ █████  ███ ████████
                                                                   ██ ████  ████ ██████████ ████  ████ ████▀
                                                                   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
                                                                   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
                                                                   ▀█████████▀ ▄████████████▄ ▀█████████▀
                                                                  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
                                                                 ██████████████████████████████████████████
                                                                ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
                                                                █  ▄▀▄             █▀▀█▀▄▄
                                                                █  █▀█             █  ▐  ▐▌
                                                                █       ▄██▄       █  ▌  █
                                                                █     ▄██████▄     █  ▌ ▐▌
                                                                █    ██████████    █ ▐  █
                                                                █   ▐██████████▌   █ ▐ ▐▌
                                                                █    ▀▀██████▀▀    █ ▌ █
                                                                █     ▄▄▄██▄▄▄     █ ▌▐▌
                                                                █                  █▐ █
                                                                █                  █▐▐▌
                                                                █                  █▐█
                                                                ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
                                                                ▄▄█████████▄▄
                                                                ▄██▀▀▀▀█████▀▀▀▀██▄
                                                                ▄█▀       ▐█▌       ▀█▄
                                                                ██         ▐█▌         ██
                                                                ████▄     ▄█████▄     ▄████
                                                                ████████▄███████████▄████████
                                                                ███▀    █████████████    ▀███
                                                                ██       ███████████       ██
                                                                ▀█▄       █████████       ▄█▀
                                                                ▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
                                                                ▀███████         ███████▀
                                                                ▀█████▄       ▄█████▀
                                                                ▀▀▀███▄▄▄███▀▀▀
                                                                ..PLAY NOW..
                                                                examplens
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 3276
                                                                Merit: 3170


                                                                Crypto Swap Exchange


                                                                View Profile WWW
                                                                April 11, 2022, 10:09:52 PM
                                                                 #59

                                                                bump!
                                                                Those who got paid, please leave your reviews whenever you get time.
                                                                Code:
                                                                shasan
                                                                khaled0111
                                                                Kavelj22
                                                                examplens
                                                                Little Mouse

                                                                We still have 11 spots left.

                                                                Cheers,

                                                                PS: I really would like to send some merits to some of the users who reviewed but damn I do not want others to ask questions :-P

                                                                For the last 7-8 days I have been out of my computer with a very poor roaming internet connection. it was very difficult to do anything more serious via mobile device.
                                                                now I am slowly returning to the activity, in the next two days I will finish the review.
                                                                sorry for the delay, this was really unplanned.

                                                                █▀▀▀











                                                                █▄▄▄
                                                                ▀▀▀▀▀▀▀▀▀▀▀
                                                                e
                                                                ▄▄▄▄▄▄▄▄▄▄▄
                                                                █████████████
                                                                ████████████▄███
                                                                ██▐███████▄█████▀
                                                                █████████▄████▀
                                                                ███▐████▄███▀
                                                                ████▐██████▀
                                                                █████▀█████
                                                                ███████████▄
                                                                ████████████▄
                                                                ██▄█████▀█████▄
                                                                ▄█████████▀█████▀
                                                                ███████████▀██▀
                                                                ████▀█████████
                                                                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
                                                                c.h.
                                                                ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                                                                ▀▀▀█











                                                                ▄▄▄█
                                                                ▄██████▄▄▄
                                                                █████████████▄▄
                                                                ███████████████
                                                                ███████████████
                                                                ███████████████
                                                                ███████████████
                                                                ███░░█████████
                                                                ███▌▐█████████
                                                                █████████████
                                                                ███████████▀
                                                                ██████████▀
                                                                ████████▀
                                                                ▀██▀▀
                                                                shasan
                                                                Copper Member
                                                                Legendary
                                                                *
                                                                Offline Offline

                                                                Activity: 2198
                                                                Merit: 1271

                                                                Need a Bounty Manager? t.me/shasan32


                                                                View Profile WWW
                                                                April 11, 2022, 10:16:02 PM
                                                                 #60

                                                                Those who got paid, please leave your reviews whenever you get time.
                                                                I have been informed via pm and I will complete my review this week, thank you.
                                                                Pages: « 1 2 [3] 4 5 6 7 »  All
                                                                  Print  
                                                                 
                                                                Jump to:  

                                                                Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!