Bitcoin Forum
April 23, 2024, 07:48:59 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 [17] 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 »
  Print  
Author Topic: GLBSE 2.0 open for testing  (Read 51712 times)
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
March 31, 2012, 10:20:23 PM
 #321



Thanks! Hopefully no one sold because of it..  Actually that brings up a feature request..  Need a "shareholder of record date" function in GLBSE.  This is common practice in the "real" exchanges.

teek


Could you explain this a little more please.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
1713901739
Hero Member
*
Offline Offline

Posts: 1713901739

View Profile Personal Message (Offline)

Ignore
1713901739
Reply with quote  #2

1713901739
Report to moderator
1713901739
Hero Member
*
Offline Offline

Posts: 1713901739

View Profile Personal Message (Offline)

Ignore
1713901739
Reply with quote  #2

1713901739
Report to moderator
The forum was founded in 2009 by Satoshi and Sirius. It replaced a SourceForge forum.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713901739
Hero Member
*
Offline Offline

Posts: 1713901739

View Profile Personal Message (Offline)

Ignore
1713901739
Reply with quote  #2

1713901739
Report to moderator
mila
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
March 31, 2012, 10:43:19 PM
 #322



Thanks! Hopefully no one sold because of it..  Actually that brings up a feature request..  Need a "shareholder of record date" function in GLBSE.  This is common practice in the "real" exchanges.

teek


Could you explain this a little more please.

I'm not his spokesperson and reserve the right to be wrong but what I understood is a feature request that would enable to pay dividends to the list of shareholders "as of the date = date entered in the dividend payment form"

so if I pay dividends each Sunday 6 a.m. GMT but I slept a bit longer and missed my committed time, somebody may have sold the shares at 9 a.m. and me a few hours later (lunch time) wants to set things right and would like to pay to shareholders from 6 a.m. moment.

@teek is that right ^^ ?

your ad here:
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
March 31, 2012, 10:51:09 PM
 #323



Thanks! Hopefully no one sold because of it..  Actually that brings up a feature request..  Need a "shareholder of record date" function in GLBSE.  This is common practice in the "real" exchanges.

teek


Could you explain this a little more please.

I'm not his spokesperson and reserve the right to be wrong but what I understood is a feature request that would enable to pay dividends to the list of shareholders "as of the date = date entered in the dividend payment form"

so if I pay dividends each Sunday 6 a.m. GMT but I slept a bit longer and missed my committed time, somebody may have sold the shares at 9 a.m. and me a few hours later (lunch time) wants to set things right and would like to pay to shareholders from 6 a.m. moment.

@teek is that right ^^ ?

Whoa, if this is correct then it's doable, but fairly difficult. Will take some time but I can add it to the list.

Nefario.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
teek
Hero Member
*****
Offline Offline

Activity: 667
Merit: 500



View Profile
March 31, 2012, 11:31:01 PM
 #324



Thanks! Hopefully no one sold because of it..  Actually that brings up a feature request..  Need a "shareholder of record date" function in GLBSE.  This is common practice in the "real" exchanges.

teek


Could you explain this a little more please.

I'm not his spokesperson and reserve the right to be wrong but what I understood is a feature request that would enable to pay dividends to the list of shareholders "as of the date = date entered in the dividend payment form"

so if I pay dividends each Sunday 6 a.m. GMT but I slept a bit longer and missed my committed time, somebody may have sold the shares at 9 a.m. and me a few hours later (lunch time) wants to set things right and would like to pay to shareholders from 6 a.m. moment.

@teek is that right ^^ ?


Yep something like that.  Can be used for all kinds of things.. right now the record date ends up being exactly when the transaction happens as mila pointed out..  That works ok for now too, but say a company is paying out Q2 earnings in August or something like that, they want to pay the holders of record 06/30 etc..  many other reasons..  Record dates will be handy and probably necessary for certain issues, especially when the exchange grows..
shad
Full Member
***
Offline Offline

Activity: 148
Merit: 100


View Profile
April 01, 2012, 03:38:35 AM
 #325

so i changed my account to 2.0
and now i forgot my password  Shocked

i miss the send me my passwort button  Embarrassed

15dUzJEUkxgjrtcvDSdsEDkXu7E7RCbNN3
mila
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
April 01, 2012, 04:06:53 AM
 #326

so i changed my account to 2.0
and now i forgot my password  Shocked

i miss the send me my passwort button  Embarrassed

tl;dr; send Nefario your claim code to verify yourself ; )

OP: well, this is one of the things that are important but not yet there (not urgent)
nefario fixed critical things first, then urgent & important
and things around resetting forgotten passwords via email are simply not yet in the top X todo things.

you won't miss any dividends and your account will wait for you ...
just send him a PM or email (email might be actually better, you know, kind of proof it's you)
disclaimer: i know sender can be spoofed but it's still better than a PM to nefario "hi, I forgot my password, please reply to my pm here with a new password for account registered with email doctor.nefario@gmail.xxx or email it to my backup email rookie.hax0r@tormail.net"

let it be a reminder for you to take better care of your passwords and just bear with nefario to get back to you.

@all how could be password reset protected from potential abuse (brute force guessing registered emails and demanding password resend?). I mean, ok, password reset would be automated, email sent to the claimed address would be addressed to the email address registered with an account but I'm shivering with worries how easy it could be fetched and abused.

In my perfect dream world I would have a public key associated with my account and all emails from glbse would arrive encrypted so that the next poor guy w/o password would have to be in possession of the private key as well ... and that's another thing that can be forgotten or lost.

as it is now, you'll be probably asked details about your account (which shares did you own, can you remember approx what your btc balance was and stuff like that, to support your claim).

your ad here:
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 03:03:39 AM
 #327

so i changed my account to 2.0
and now i forgot my password  Shocked

i miss the send me my passwort button  Embarrassed

We now have an account recovery option, beside the login form.

Keep in mind now that this means that if your email account is compromised, then so will your GLBSE account, and we will bear no responsibility for this.

Nefario.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
April 02, 2012, 05:03:00 AM
 #328

Keep in mind now that this means that if your email account is compromised, then so will your GLBSE account, and we will bear no responsibility for this.

Is a two-factor authentication method on the roadmap?

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
April 02, 2012, 12:39:44 PM
 #329

Keep in mind now that this means that if your email account is compromised, then so will your GLBSE account, and we will bear no responsibility for this.

Is a two-factor authentication method on the roadmap?
+1, I hope so. Yubikeys have a nice and fairly easy to use system going on. Or you can do other options like matrix cards.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 02:57:10 PM
 #330

I've added captcha's to the login process.

Regarding two factor auth, this is tricky.

Actually it IS something I'd like to implement, however in it's current state it's quite pricey.

I think the only method I can think of would be to have an android app that sends a hash of the users phone number and pin to the server for a verification code or something like that. I need to look into it.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
antirack
Hero Member
*****
Offline Offline

Activity: 489
Merit: 500

Immersionist


View Profile
April 02, 2012, 03:02:18 PM
 #331

Not sure if this is still current, but look at this:

http://net.tutsplus.com/tutorials/php/integrating-two-factor-authentication-with-codeigniter/

Lucky for you, Duo Security offers a free two-factor service ideal for anybody looking to protect their website.

Not only is Duo free, but it’s full of features. They let you authenticate in a variety of ways, including:

    Phonecall authentication
    SMS-based tokens
    Mobile app token generator
    Push-based authentication
    Hardware tokens available for purchase
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
April 02, 2012, 03:13:10 PM
 #332

Yubikeys are not cheap for the end user, but they are free for you to implement. You can either use their free cloud based system, or issue your own keys tied to your own auth server. http://www.yubico.com/developers-intro

Google Authenticator is free on both ends. http://code.google.com/p/google-authenticator/

Other methods of OTP authentication are available, at varying difficulties of implementation.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 03:21:01 PM
 #333

I'll look into adding one of these systems quite soon, keep in mind that GLBSE has never had any breakins so far (fingers crossed).

antirack, already had a look at DuoSecurity, the free system is limited to 10 users, then $3 a month per user

I might end up making my own as I've been looking to get started building for android for some time, and finally here would be a good reason.

Nefario.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
REF
Hero Member
*****
Offline Offline

Activity: 529
Merit: 500


View Profile
April 02, 2012, 10:07:55 PM
 #334

the vote buttons should go away after you vote on a motion. Right now I have a motion from tygrr-bank and every time I click on it I see buttons to vote yes and no when I click on them Im sent back to my portfolio page. Only the option you picked show stay and it should let you know you voted and not let you click anything.
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 10:09:10 PM
 #335

the vote buttons should go away after you vote on a motion. Right now I have a motion from tygrr-bank and every time I click on it I see buttons to vote yes and no when I click on them Im sent back to my portfolio page. Only the option you picked show stay and it should let you know you voted and not let you click anything.

You are allowed change your vote as much as you like right up until the vote closes. This is why it shows.


PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
April 02, 2012, 11:24:05 PM
 #336

Yubikeys are not cheap for the end user, but they are free for you to implement.

And if GLBSE were to implement it, someone with an existing Mt. Gox yubikey could use it as well, right?

That approach makes sense if two-factor is an option for the accountholder.   If I'm holding $20 USD worth of stocks I shouldn't be forced to buy a $30 dongle, but if I'm holding a significant amount I have the option to protect my account by requiring two factor auth.

I might end up making my own

Making your own mobile-based OTP token system?   Please tell me that wasn't what you meant to write.  Also please read on NIH:
 - http://en.wikipedia.org/wiki/Not_invented_here

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


paraipan
In memoriam
Legendary
*
Offline Offline

Activity: 924
Merit: 1004


Firstbits: 1pirata


View Profile WWW
April 02, 2012, 11:32:25 PM
 #337

......

I might end up making my own

Making your own mobile-based OTP token system?   Please tell me that wasn't what you meant to write.  Also please read on NIH:
 - http://en.wikipedia.org/wiki/Not_invented_here


anyone using google authencator to do that 2 step auth ?

BTCitcoin: An Idea Worth Saving - Q&A with bitcoins on rugatu.com - Check my rep
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 11:36:07 PM
 #338

Yubikeys are not cheap for the end user, but they are free for you to implement.

And if GLBSE were to implement it, someone with an existing Mt. Gox yubikey could use it as well, right?

That approach makes sense if two-factor is an option for the accountholder.   If I'm holding $20 USD worth of stocks I shouldn't be forced to buy a $30 dongle, but if I'm holding a significant amount I have the option to protect my account by requiring two factor auth.

I might end up making my own

Making your own mobile-based OTP token system?   Please tell me that wasn't what you meant to write.  Also please read on NIH:
 - http://en.wikipedia.org/wiki/Not_invented_here


Lol, said that because I didn't know what was available out there.

No I'm integrating Google Auth right now, it's exactly what I was looking for.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
April 02, 2012, 11:36:59 PM
 #339

Yubikeys are not cheap for the end user, but they are free for you to implement.
And if GLBSE were to implement it, someone with an existing Mt. Gox yubikey could use it as well, right?
No, because Mtgox uses their own authentication server and custom programmed Yubikeys. It theoretically would be possible to liaise with Mtgox and use their auth server, but I doubt that they would allow it. Making it optional would of course be the best way to go.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
Nefario (OP)
Hero Member
*****
Offline Offline

Activity: 602
Merit: 512


GLBSE Support support@glbse.com


View Profile WWW
April 02, 2012, 11:56:28 PM
 #340

Yubikeys are not cheap for the end user, but they are free for you to implement.
And if GLBSE were to implement it, someone with an existing Mt. Gox yubikey could use it as well, right?
No, because Mtgox uses their own authentication server and custom programmed Yubikeys. It theoretically would be possible to liaise with Mtgox and use their auth server, but I doubt that they would allow it. Making it optional would of course be the best way to go.

No Yubikey, I refuse to buy one just to even get started developing, and then make people buy one, there is absolutely no point when a free option is available.

I've already got google auth 1/2 working, a few more hours and it will be done.

PGP key id at pgp.mit.edu 0xA68F4B7C

To get help and support for GLBSE please email support@glbse.com
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 [17] 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!