Bitcoin Forum
November 04, 2024, 05:37:45 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
Author Topic: Reused R values again  (Read 121270 times)
dserrano5
Legendary
*
Offline Offline

Activity: 1974
Merit: 1029



View Profile
December 03, 2014, 07:23:42 AM
 #21

You must be joking right? Considering his machine, the virus was probably written 15 years ago or longer.

You implying that it's impossible for it to have gotten a new virus in the last month?
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 03, 2014, 05:53:19 PM
 #22

I just noticed that amaclin tries to double spend the broken transaction in real-time:

https://blockchain.info/tx/df02f56b230c397cb67bb5334209f7e45d58f1f9d6eb1df1bc17e6ecb107e206

This is a double spend of the transaction that revealed the private keys.  In this case the double spend was not successful (despite the fact that he used twice the fee).

Since my lists are generated using only the transactions in the block chain, the list won't contain the addresses where the broken transactions were successfully double spent.



Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
newIndia
Legendary
*
Offline Offline

Activity: 2226
Merit: 1052


View Profile
December 06, 2014, 03:19:41 PM
 #23

You must be joking right? Considering his machine, the virus was probably written 15 years ago or longer.

You implying that it's impossible for it to have gotten a new virus in the last month?

A Pentium II machine, which is not connected online for long is supposed to be safe from new viruses. Is not it ?

altcoinex
Sr. Member
****
Offline Offline

Activity: 293
Merit: 251


Director - www.cubeform.io


View Profile WWW
December 06, 2014, 04:14:01 PM
 #24

You must be joking right? Considering his machine, the virus was probably written 15 years ago or longer.

You implying that it's impossible for it to have gotten a new virus in the last month?

A Pentium II machine, which is not connected online for long is supposed to be safe from new viruses. Is not it ?

Nothing is safe. You have to ASSUME compromise and act under that assumption. Nothing wrong with using this machine, but only after a full whipe and clean and you verify no root kits, and not running and old software or some decades old OS etc.. Beyond that, there is NO REASON to connect the system to the internet for ANY time as opposed to 'not long'. If your going the route of an isolated machine for generating keys, I would recommend a livecd version of a linux distro, with a python or shell based tool for address/key generation included on it. No exposure to the internet for the system....


                                     ╓╢╬╣╣╖
                                   ┌║██████║∩
                                   ]█████████
                                    ╜██████╝`
                                      ╙╜╜╜`
                                   ╓╥@@@@@@╥╓
         ╓╖@@╖,                 ,@║██████████╢@,                 ,╓@@╖╓
       ╓╢██████╢.              ╓╢███████████████╖               ║╢█████║╓
       ║█████████    ,,╓╓,,   ┌║█████████████████┐   ,,╓╓,,    ]█████████
       └╢██████║` ╓╢║██████╢║∩``╙╙╙╙╙╙╙╙╙╙╙╙╙╙╙╙╙`»╢╢██████╢║╖  ║███████╜
         "╜╜╜╜` ╖╢█████████╣╜                      └╢██████████@ `╜╜╜╜╜
               ║██████████╜                          ╙╢██████████
              ┌█████████╜                              ╙╢█████████
              └███████╨`                                 ╜████████
               ║████╨╜                                    `╢█████
                ╙╢╣╜                                        └╢█╜
                ,,                                            ,,
             ╓@║██┐                                          ┌██║@╓
            ╢██████                                          ]█████H
           ╢███████∩                                        ┌████████
  ╓@@@@╓   █████████                                        ║████████`  ╓@@@@╖
╓╢██████║. █████████∩                                      ┌█████████ ,║███████╖
██████████ └█████████                                      ██████████ ]█████████
`║██████╜`  └╢████████                                    ┌███████╣╜   ╙██████╨`
  `╙╜╜╙`      `╙╨╢████                                    █████╝╜`       `╙╜╜`
                      ]@╓                              ╓╖H
                      ███╢║@╓,                    ,╓@╢╢███`
                      ████████╢@╖╓.           ╓╖@║████████`
                      ]███████████╢║@╓,  ,╓@╢╢████████████
                       ╙╢█████████████╨` ╜██████████████╜
                         ╙╝╢███████║╜`    `╜║████████╝╜`
                     ,╓@@@╓  `²╙``             `╙²`  ╓@@@╖,
                    ║╢█████╢H                      ╓╢██████H
                    █████████                      █████████`
                    ╙╢██████╜                      ╙╢██████╜
                      └╨╩╝┘                          └╨╩╝╜
WINFLOW.
██
██
██
██
██
██
██
██
██
██
██
██
██
..
██
██
██
██
██
██
██
██
██
██
██
██
██
.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 07, 2014, 12:43:26 PM
 #25

Quote
Since this thread was bumped, I think I should update it.
There seems to be a new buggy program that reuses the same R value for all signatures in a transaction.  It started around September 2014.
[...]
Does anyone know what the buggy program is?
I know.
yakuza699
Hero Member
*****
Offline Offline

Activity: 935
Merit: 1002


View Profile
December 07, 2014, 12:54:20 PM
 #26

Quote
Since this thread was bumped, I think I should update it.
There seems to be a new buggy program that reuses the same R value for all signatures in a transaction.  It started around September 2014.
[...]
Does anyone know what the buggy program is?
I know.
Would you mind charing it?

▄▄▄▄▄▄▄▄
▄▄▄▄▄▄
▄▄▄▄
BTC BitDice.me 
.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 07, 2014, 02:51:43 PM
 #27

Quote
Would you mind charing it?
Do you mean "share info"? I do now want to do it right now.
Everything is visible enough in the blockchain. Just open your eyes and use your brain.
arnuschky
Hero Member
*****
Offline Offline

Activity: 518
Merit: 502


View Profile
December 07, 2014, 03:07:03 PM
 #28

You must be joking right? Considering his machine, the virus was probably written 15 years ago or longer.

You implying that it's impossible for it to have gotten a new virus in the last month?

A Pentium II machine, which is not connected online for long is supposed to be safe from new viruses. Is not it ?

Why take the risk if you can just start a bootable live cd of some linux distro?
arnuschky
Hero Member
*****
Offline Offline

Activity: 518
Merit: 502


View Profile
December 07, 2014, 03:08:42 PM
 #29

Quote
Would you mind charing it?
Do you mean "share info"? I do now want to do it right now.
Everything is visible enough in the blockchain. Just open your eyes and use your brain.

Well, either you keep that information because you have informed the developers of the buggy program that they have to fix it (which would be laudable) or you have other, possible sinister reasons to keep the program's name for yourself.

Which one is it?
cr1776
Legendary
*
Offline Offline

Activity: 4214
Merit: 1312


View Profile
December 07, 2014, 03:10:05 PM
 #30

Quote
Would you mind charing it?
Do you mean "share info"? I do now want to do it right now.
Everything is visible enough in the blockchain. Just open your eyes and use your brain.

Well, either you keep that information because you have informed the developers of the buggy program that they have to fix it (which would be laudable) or you have other, possible sinister reasons to keep the program's name for yourself.

Which one is it?

He sweeps those addresses for the coins.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 07, 2014, 03:19:40 PM
 #31

Quote
you have informed the developers of the buggy program that they have to fix it
I haven't said that I have developers contacts. How can I inform them?

Quote
He sweeps those addresses for the coins.
Are you ready to prove it?
cr1776
Legendary
*
Offline Offline

Activity: 4214
Merit: 1312


View Profile
December 07, 2014, 04:54:37 PM
 #32

Quote
you have informed the developers of the buggy program that they have to fix it
I haven't said that I have developers contacts. How can I inform them?

Quote
He sweeps those addresses for the coins.
Are you ready to prove it?

I was just reporting what you said here:



Quote
What wallet?  It is old given the bug you encountered.
Fix the issue and amaclin may return it. He is usually helpful - many people will just sweep it and do not help people who have an issue.

Do not import compromised private keys to your wallet
Do not give your private keys to anybody
Do not use untrusted services

How else can I help you?
I think this advises cost more than 0.02

PS. No. I do not return btc. I can give you knowledge and experience - they cost more.

See:
https://bitcointalk.org/index.php?topic=879419.20

And other threads where you say you scan for the addresses (like many other people do).



amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 07, 2014, 05:18:18 PM
 #33

These are only words. This is not a proof.
Let me say here that I am a president of United States.
Do you trust me and my words now?
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 08, 2014, 11:18:08 AM
 #34

Hello,

there were a large bunch of new broken addresses today (several 100s in one day).  I took the liberty of saving some funds before they got swiped by others.  If you can convince me that they belong to you (signing a message with the address is obviously not enough; the private key is already known),  I will send the funds back.

Look into the file http://johoe.mooo.com/bitcoin/broken.txt, to see whether your address was broken.







Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 08, 2014, 12:30:23 PM
 #35

Quote
I took the liberty of saving some funds before they got swiped by others.

Is it your address 1HuqM18GMVaLxTRGdmSgytzVYnhRzu7U68 ?
And is it your service: http://sharedcoin.com/Grin
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 08, 2014, 01:07:14 PM
 #36

Quote
I took the liberty of saving some funds before they got swiped by others.

Is it your address 1HuqM18GMVaLxTRGdmSgytzVYnhRzu7U68 ?
yes
Quote
And is it your service: http://sharedcoin.com/Grin
no.  Just plain old bitcoind using rawtransaction interface

I think this is not related to the other bug that started in September.  There are a lot of reused R-values sometimes not even in the same transaction.  The scale is also much bigger (500 addresses in one day, >200 BTC).  I still count almost 300 unspent outputs (but I'm too lazy to swipe them all).


Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
December 08, 2014, 01:19:58 PM
 #37

Quote
no.  Just plain old bitcoind using rawtransaction interface
I mean that this service belongs to bc.i
And you are also from bc.i (may be I am wrong of course)

Quote
I think this is not related to the other bug that started in September.

Man-in-the-middle on tor exit node?
or may be http://www.reddit.com/r/Bitcoin/comments/2oltp9/warning_blockchaininfos_javascript_verifier_is/
btcdrak
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000


View Profile
December 08, 2014, 04:57:19 PM
 #38

Quote
no.  Just plain old bitcoind using rawtransaction interface
I mean that this service belongs to bc.i
And you are also from bc.i (may be I am wrong of course)

Quote
I think this is not related to the other bug that started in September.

Man-in-the-middle on tor exit node?
or may be http://www.reddit.com/r/Bitcoin/comments/2oltp9/warning_blockchaininfos_javascript_verifier_is/

No, this: http://www.reddit.com/r/Bitcoin/comments/2onm5r/blockchaininfo_security_disclosure/
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 08, 2014, 05:38:41 PM
 #39


Thanks, for the link.  Although, if they already fixed this problem this morning, why are there still repeated R values generated? 
I still find reused R values in new transactions.   Is this just a browser cache issue or is the problem still not solved completely?

E.g.:

https://blockchain.info/tx/f10d5c469c634de25276aae9c4e14add80ad9c66000182fac1b30e72a99298fb

uses the same R values as:

https://blockchain.info/tx/cf0b65ec6a2f9b5e003358d7b9bb6e04b30138c4dba30724f600bf753bfc3f4a


Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
zymfk
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
December 08, 2014, 06:57:00 PM
 #40

Dude you took from my address, I was saving up for my family for christmas and you went and stolen it this morning..

Please have the heart to give it back, PMing you now
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!