Triffin
|
|
July 10, 2014, 10:21:44 PM |
|
It's all in here: https://nxtforum.org/general-discussion/general-security-and-klee-theft-situation/
Holy Crap on a Cracker !! I agree with the comments posted by "Uniqueorn" and "BitVenturerr" in the above referenced thread .. I'm not familiar with KeepPass but Coinbase uses the "SMS one time pass" feature prior to enabling a withdrawal from one's account .. Adds 20 seconds to a withdrawal .. Security features designed to foil 'access' to one's wallet are clearly not enough .. I vote for the "SMS one time pass" feature as an add on to the NXT client ASAP .. "klee" may have had sloppy security practices, but you have to admit that the addition of "SMS one time pass" would have prevented the coin heist .. You guys are the security experts here and maybe a more 'elegant' security solution can be developed at a later date .. Mass adoption of crypto ?? You've got to be kidding .. Fail safe wallet security should be priority # 1 Triff .. Do you store your coinbase password or anyother password somewhere in plain text .txt file?? Not even my tech-unsavy girlfriend does that. That heist is 100% on klee and not the software, so please don't try to blame that one the provided software... ==== No, I don't store any passwords on my PC that I'm aware of .. But, I'd assume ( correctly? ) that if I had a keylogger on my PC that I'd be in trouble .. I'm not stating that the NXT client is at fault here .. Just observing that once a wallet ( NXT's or any other coin's wallet ) has been accessed that the 'deed is done' Would "SMS one time pass" have foiled this heist ?? Yes or No ?? Triff ..
|
|
|
|
msin
Legendary
Offline
Activity: 1470
Merit: 1004
|
|
July 10, 2014, 10:23:28 PM |
|
How do you find out about assets on the exchange? Is there an official exchange list? Is there any oversight to what gets listed?
Brand new: http://www.secureae.com/Just click Login on the bottom left, it lists all the available assets. But most of them are announced on nxtformum.org. Wow, SecureAE is awesome, love the chart layout. Also, it's really easy to tell which Assets are scam by the trading chart alone, it's a flat line!
|
|
|
|
TwinWinNerD
Legendary
Offline
Activity: 1680
Merit: 1001
CEO Bitpanda.com
|
|
July 10, 2014, 10:23:36 PM |
|
It's all in here: https://nxtforum.org/general-discussion/general-security-and-klee-theft-situation/
Holy Crap on a Cracker !! I agree with the comments posted by "Uniqueorn" and "BitVenturerr" in the above referenced thread .. I'm not familiar with KeepPass but Coinbase uses the "SMS one time pass" feature prior to enabling a withdrawal from one's account .. Adds 20 seconds to a withdrawal .. Security features designed to foil 'access' to one's wallet are clearly not enough .. I vote for the "SMS one time pass" feature as an add on to the NXT client ASAP .. "klee" may have had sloppy security practices, but you have to admit that the addition of "SMS one time pass" would have prevented the coin heist .. You guys are the security experts here and maybe a more 'elegant' security solution can be developed at a later date .. Mass adoption of crypto ?? You've got to be kidding .. Fail safe wallet security should be priority # 1 Triff .. Do you store your coinbase password or anyother password somewhere in plain text .txt file?? Not even my tech-unsavy girlfriend does that. That heist is 100% on klee and not the software, so please don't try to blame that one the provided software... ==== No, I don't store any passwords on my PC that I'm aware of .. But, I'd assume ( correctly? ) that if I had a keylogger on my PC that I'd be in trouble .. I'm not stating that the NXT client is at fault here .. Just observing that once a wallet ( NXT's or any other coin's wallet ) has been accessed that the 'deed is done' Would "SMS one time pass" have foiled this heist ?? YES or NO ?? Triff .. Using proper software WOULD HAVE safed Klee. Keepass 2 has multiple ways of preventing keyloggers from spying
|
|
|
|
|
PilotofBTC
Legendary
Offline
Activity: 1736
Merit: 1001
|
|
July 10, 2014, 10:27:16 PM |
|
It's all in here: https://nxtforum.org/general-discussion/general-security-and-klee-theft-situation/
Holy Crap on a Cracker !! I agree with the comments posted by "Uniqueorn" and "BitVenturerr" in the above referenced thread .. I'm not familiar with KeepPass but Coinbase uses the "SMS one time pass" feature prior to enabling a withdrawal from one's account .. Adds 20 seconds to a withdrawal .. Security features designed to foil 'access' to one's wallet are clearly not enough .. I vote for the "SMS one time pass" feature as an add on to the NXT client ASAP .. "klee" may have had sloppy security practices, but you have to admit that the addition of "SMS one time pass" would have prevented the coin heist .. You guys are the security experts here and maybe a more 'elegant' security solution can be developed at a later date .. Mass adoption of crypto ?? You've got to be kidding .. Fail safe wallet security should be priority # 1 Triff .. Do you store your coinbase password or anyother password somewhere in plain text .txt file?? Not even my tech-unsavy girlfriend does that. That heist is 100% on klee and not the software, so please don't try to blame that one the provided software... ==== No, I don't store any passwords on my PC that I'm aware of .. But, I'd assume ( correctly? ) that if I had a keylogger on my PC that I'd be in trouble .. I'm not stating that the NXT client is at fault here .. Just observing that once a wallet ( NXT's or any other coin's wallet ) has been accessed that the 'deed is done' Would "SMS one time pass" have foiled this heist ?? Yes or No ?? Triff .. Yes. But there really is no way to enforce that in a client. You don't have access to the private keys for your Coinbase coin. It is a shared wallet. So, the auth and security is layered on top of the BTC wallet there. Anyone can create a client that doesn't send an SMS. Some type of 2FA or Multi-signature feature would have to be built into the core of NXT. If the auth or sig isn't valid it would be up to the network to reject the spend, not a single client.
|
|
|
|
_mr_e
Legendary
Offline
Activity: 817
Merit: 1000
|
|
July 10, 2014, 10:27:44 PM |
|
It's all in here: https://nxtforum.org/general-discussion/general-security-and-klee-theft-situation/
Holy Crap on a Cracker !! I agree with the comments posted by "Uniqueorn" and "BitVenturerr" in the above referenced thread .. I'm not familiar with KeepPass but Coinbase uses the "SMS one time pass" feature prior to enabling a withdrawal from one's account .. Adds 20 seconds to a withdrawal .. Security features designed to foil 'access' to one's wallet are clearly not enough .. I vote for the "SMS one time pass" feature as an add on to the NXT client ASAP .. "klee" may have had sloppy security practices, but you have to admit that the addition of "SMS one time pass" would have prevented the coin heist .. You guys are the security experts here and maybe a more 'elegant' security solution can be developed at a later date .. Mass adoption of crypto ?? You've got to be kidding .. Fail safe wallet security should be priority # 1 Triff .. Do you store your coinbase password or anyother password somewhere in plain text .txt file?? Not even my tech-unsavy girlfriend does that. That heist is 100% on klee and not the software, so please don't try to blame that one the provided software... ==== No, I don't store any passwords on my PC that I'm aware of .. But, I'd assume ( correctly? ) that if I had a keylogger on my PC that I'd be in trouble .. I'm not stating that the NXT client is at fault here .. Just observing that once a wallet ( NXT's or any other coin's wallet ) has been accessed that the 'deed is done' Would "SMS one time pass" have foiled this heist ?? Yes or No ?? Triff .. Multisig is what's required here. The fact that the much btc was available to steal with a single key on an online computer is completely inexcusable. As for the nxt... we need a greenaddress.it style wallet immediately. Or a 2 factor multisig app for your phone.
|
|
|
|
PilotofBTC
Legendary
Offline
Activity: 1736
Merit: 1001
|
|
July 10, 2014, 10:29:27 PM |
|
It's all in here: https://nxtforum.org/general-discussion/general-security-and-klee-theft-situation/
Holy Crap on a Cracker !! I agree with the comments posted by "Uniqueorn" and "BitVenturerr" in the above referenced thread .. I'm not familiar with KeepPass but Coinbase uses the "SMS one time pass" feature prior to enabling a withdrawal from one's account .. Adds 20 seconds to a withdrawal .. Security features designed to foil 'access' to one's wallet are clearly not enough .. I vote for the "SMS one time pass" feature as an add on to the NXT client ASAP .. "klee" may have had sloppy security practices, but you have to admit that the addition of "SMS one time pass" would have prevented the coin heist .. You guys are the security experts here and maybe a more 'elegant' security solution can be developed at a later date .. Mass adoption of crypto ?? You've got to be kidding .. Fail safe wallet security should be priority # 1 Triff .. Do you store your coinbase password or anyother password somewhere in plain text .txt file?? Not even my tech-unsavy girlfriend does that. That heist is 100% on klee and not the software, so please don't try to blame that one the provided software... ==== No, I don't store any passwords on my PC that I'm aware of .. But, I'd assume ( correctly? ) that if I had a keylogger on my PC that I'd be in trouble .. I'm not stating that the NXT client is at fault here .. Just observing that once a wallet ( NXT's or any other coin's wallet ) has been accessed that the 'deed is done' Would "SMS one time pass" have foiled this heist ?? YES or NO ?? Triff .. Using proper software WOULD HAVE safed Klee. Keepass 2 has multiple ways of preventing keyloggers from spying Yep, as does lastpass, as does 1password. But, we don't know if this was a keylogger or something else that got on his system and gained access to his text file. Was he really typing all his passwords in every day? I know I don't.
|
|
|
|
Daedelus
|
|
July 10, 2014, 10:35:07 PM |
|
I got to the fifth paragraph before closing the tab "...using technology built from the ground up to be more effective than bitcoin..." referring to Nxt and Blackcoin. Blackcoin is a clone of Novacoin which is a clone of Peercoin. They might have tweaked it but it can't be put in the same category as Nxt.
|
|
|
|
msin
Legendary
Offline
Activity: 1470
Merit: 1004
|
|
July 10, 2014, 10:42:28 PM |
|
Thanks Nexern, great work.
|
|
|
|
raleit2014
Member
Offline
Activity: 84
Merit: 10
Crypto is the Future!
|
|
July 10, 2014, 10:45:47 PM |
|
|
|
|
|
Magic8Ball
Legendary
Offline
Activity: 1050
Merit: 1000
|
|
July 10, 2014, 10:51:05 PM |
|
How much more NXT is left to cash out by the hacker? I heard that Bter froze his account, though I suspect he will have other accounts and other balances. One who takes the trouble of getting hold of all these will not be stupid enough to just dump them all at once through 1 account.
|
|
|
|
EvilDave
|
|
July 11, 2014, 12:06:21 AM |
|
How much more NXT is left to cash out by the hacker? I heard that Bter froze his account, though I suspect he will have other accounts and other balances. One who takes the trouble of getting hold of all these will not be stupid enough to just dump them all at once through 1 account.
take a look at this, BTERs trading for the last 24 hours: Looks like around 3 million got dumped.
|
|
|
|
|
DrearyUrbanite
|
|
July 11, 2014, 12:35:09 AM |
|
Thanks - send away. My address is in my sig
|
|
|
|
xBTC_Gateway
Newbie
Offline
Activity: 5
Merit: 0
|
|
July 11, 2014, 12:40:38 AM |
|
Thanks - send away. My address is in my sig I have sent the asset.
|
|
|
|
xBTC_Gateway
Newbie
Offline
Activity: 5
Merit: 0
|
|
July 11, 2014, 12:47:27 AM |
|
Thanks - send away. My address is in my sig is this not a bit pointless with multigateway coming out? Your business plan isn't very future proof lol A backup plan won't hurt Anything can happen in crypto world, so I think it is good to have alternatives.
|
|
|
|
cryptobanks
Newbie
Offline
Activity: 29
Merit: 0
|
|
July 11, 2014, 01:16:55 AM |
|
Use a safer OS such as Linux.
|
|
|
|
DrearyUrbanite
|
|
July 11, 2014, 01:20:14 AM |
|
Use a safer OS such as Linux.
OS X is Unix based and basically the same as Linux. Being secure is not really OS dependent.
|
|
|
|
lophie
|
|
July 11, 2014, 04:33:43 AM |
|
Use a safer OS such as Linux.
OS X is Unix based and basically the same as Linux. Being secure is not really OS dependent. Unless it comes bundled with the holes like Wondows . Ah the good old days of the windows sharing service overflow packet when I used to give my friends a bluescreen whenever they brag about their brand new windows 7.
|
Will take me a while to climb up again, But where is a will, there is a way...
|
|
|
From Above
|
|
July 11, 2014, 08:02:20 AM |
|
i cant believe some people are still using windows in the 21 century.
how can u seriously be that god damn stupid?
~CfA~
|
|
|
|
|