Bitcoin Forum
November 02, 2024, 08:44:30 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 »  All
  Print  
Author Topic: [ANN] Coinapult - send Bitcoin over email or SMS in seconds  (Read 10294 times)
bearbones (OP)
Sr. Member
****
Offline Offline

Activity: 316
Merit: 250



View Profile WWW
April 13, 2012, 05:04:16 AM
 #21

Just sent a couple of catapults flying.. thanks for the site.

A quick question, if a recipient does click on the URL and log into Coinapult to see the funds but does NOT take their Bitcoins do I still get the option to recover the coins in 30 days?

Edit: PM sent Smiley

Bitdime sent.

So long as there are no withdrawals from the payload, it will be refunded.

Example:
slothbag sends grandma 1btc
grandma opens email and follows link, but doesn't understand how to recover the bitcoin
...30 days...
slothbag receives an email with recovery link for 1btc

Example 2:
slothbag sends grandma 1btc
grandma tips the paper boy 0.1btc from her coinapult stash
...30 days...
nothing happens. Grandma has a balance of 0.9btc

Feed Ze Birds Pay and get paid for tweets
Coinapult Send Bitcoins easily over email or text message
Foxpup
Legendary
*
Offline Offline

Activity: 4531
Merit: 3183


Vile Vixen and Miss Bitcointalk 2021-2023


View Profile
April 13, 2012, 05:27:40 AM
 #22

I just tried deliberately claiming coins with an invalid bitcoin address, and got this unhelpful error message:
Quote
This transaction is still unconfirmed. Please wait 10 or 15 minutes and try again.
Target (email address): ________
Secret Location: ________
To recover your bitcoins, simply enter your email address and top secret key.
Which implies the system successfully broadcast the bogus transaction! Shocked Fortunately, the coins didn't just disappear, and I was able to later claim the coins with a valid address, but there should really be server-side validation of bitcoin addresses, allowing the site to display a more, well, helpful error message, explaining that the bitcoin address the user entered was invalid and that they may have mistyped it, and ask them to re-enter it.

Will pretend to do unspeakable things (while actually eating a taco) for bitcoins: 1K6d1EviQKX3SVKjPYmJGyWBb1avbmCFM4
I am not on the scammers' paradise known as Telegram! Do not believe anyone claiming to be me off-forum without a signed message from the above address! Accept no excuses and make no exceptions!
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 13, 2012, 05:32:19 AM
 #23

PM sent! Lemme test the 'catapulting' too.  Grin  Is there any fees associated with this service so far atm?
bearbones (OP)
Sr. Member
****
Offline Offline

Activity: 316
Merit: 250



View Profile WWW
April 13, 2012, 05:44:18 AM
 #24

I just tried deliberately claiming coins with an invalid bitcoin address, and got this unhelpful error message:
Quote
This transaction is still unconfirmed. Please wait 10 or 15 minutes and try again.
Target (email address): ________
Secret Location: ________
To recover your bitcoins, simply enter your email address and top secret key.
Which implies the system successfully broadcast the bogus transaction! Shocked Fortunately, the coins didn't just disappear, and I was able to later claim the coins with a valid address, but there should really be server-side validation of bitcoin addresses, allowing the site to display a more, well, helpful error message, explaining that the bitcoin address the user entered was invalid and that they may have mistyped it, and ask them to re-enter it.

Hmmm, good point. I'll add a more useful error message for this case. As you noted, the transaction was refused; it just gave the wrong reason.

Feed Ze Birds Pay and get paid for tweets
Coinapult Send Bitcoins easily over email or text message
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 13, 2012, 05:48:01 AM
 #25

Got the catapult, thanks! Transaction was initiated immediately after pressing send, no delays.
bearbones (OP)
Sr. Member
****
Offline Offline

Activity: 316
Merit: 250



View Profile WWW
April 13, 2012, 05:52:00 AM
 #26

Got the catapult, thanks! Transaction was initiated immediately after pressing send, no delays.

NP, and fyi, there are no fees for using the coinapult site. For applications wishing to use the API, we charge 1% to help cover the cost of operations.

I have 0.4btc left to give away to the next 4 PMs. Smiley

Feed Ze Birds Pay and get paid for tweets
Coinapult Send Bitcoins easily over email or text message
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
April 13, 2012, 07:17:45 AM
Last edit: April 13, 2012, 03:34:30 PM by Stephen Gornick
 #27

Pretty decent ... a few usability issues, and a concern regarding security.

1.) When sending I see the "Load Bitcoins Here" dialog,  
The message states "Once the Bitcoins are received, the Catapult will launch." and I see a link to Close.
As a first-time user, I wasn't sure what "Catapult will launch" means.   If I were thinking this were like a game, I might be watching the graphic of the catapult waiting for it to sling the scoop of gold (bitcoins?).  
Of course, what it really means to say is that Once the Bitcoins are received the Catapult will send a message to: "recipientname@recipientdomain.com".
That's what is meant by "catapult will launch".  
So perhaps if there were some way to let the user know that after the coins are sent what to do next.  (i.e., Click Close after you've sent the bitcoins).

2.) The message ended up getting flagged as spam by Google's Postini.
X-pstn-levels:     (S: 0.01365/97.07104 CV:99.9000 FC:95.5390 LC:95.5390 R:95.9108 P:95.9108 M:97.0282 C:98.6951 )
You might want to look into DKIM (and /  or SPF) to help lessen the chances that the message goes into the spam box.
Would there maybe after a few days a message to the "from:" e-mail address notifying that the funds hadn't been retrieved and offer the abiliity to get them back?

3.) When trying to retrieve the bitcoins, the first time I only had two confirmations I believe.  When I went to spend it it had said
"This transaction is still unconfirmed. Please wait 10 or 15 minutes and try again.".    

Firstly, what is the number of confirmations the site requires?   It appeared that after three I could then "retrieve the payload".

At the time the page is being rendered, wouldn't the state of being confirmed be known and thus it could tell me before I even enter the Send To address that I just need to hold on for a bit?

Additionally after that error message, I got another "Retrieve Payload" page, except this one asked for "Target (email address)" and also "Secret Location".  If I'm redeeming funds, I wouldn't be sending it to an email address.  Additionally, the e-mail sent to me to claim the funds never describes what 'Secret Location" is.  Of course, that's what is in the URL, but that isn't described in English in the message.

5.) When I entered the Send To address it had a trailing space in what I had copied and pasted and as a result there was an error message. The form validation could  do a trim() to help eliminate this from resulting in an error.

6.) On a later attempt, after there were three confirmations I then went to retrieve the payload.  It was a trivially small amount, like under 0.003 BTC.  When I hit the Send button the response said "Insufficient Funds."  I entered the exact amount that I had sent earliery.  I tried a second time same thing.  I then tried with 0.00001 BTC and it went through fine.  I tried another time, less than the full balance, and it too went through.  The third time I spend the remaining amout and it too went through.   So the entire amount couldn't be sent but breaking it up and sending portions, even though they added up to the same as the original number, were able to go through.

I presumed that the message was saying that as recipient I was trying to spend more than I had available.  Perhaps instead the "Insufficient Funds" message refers to the service's wallet itself not being able to send because it has insufficient funds?

7.) Consistency.  Am I retrieveing bitcoins or recovering bitcoins?   Both terms are used.

8.) Security.  SMTP messages are transferred clear text.  That means that if your service starts becoming popular that there is then an economic incentive for a sysadmin at the ISP or at the e-mail hosting service or somewhere between Coinapult and the recipient to heist the coins.  By simply adding a filter, every message that comes from Coinapult gets special attention by the scammer who redeems the coins, never with even a slight chance of getting caught.

E-mail is just not a secure method for transmitting essentially what is a negotiable bearer instrument  (the URL to claim the money).  This would be the same risk that exists when sending Mt. Gox Redeemable Voucher codes thorough e-mail, which is not recommended either.

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


davout
Legendary
*
Offline Offline

Activity: 1372
Merit: 1008


1davout


View Profile WWW
April 13, 2012, 07:44:01 AM
 #28

Just for the record : Paytunia.com has this exact feature, upon reception users may create a Paytunia account, or provide an arbitrary address to claim their funds. If the funds aren't claimed they get automatically refunded to the sender.

Also you should remove the 's' from 'fantastiques' Wink I do really like your design!

Foxpup
Legendary
*
Offline Offline

Activity: 4531
Merit: 3183


Vile Vixen and Miss Bitcointalk 2021-2023


View Profile
April 13, 2012, 07:57:23 AM
 #29

A few usability pointers regarding the email messages (keeping in mind that they will be read by people who may not have heard of Bitcoin before):

Your from field should read: "Coinapult" <emailaddress>
It is very important that you format your from field like this.

Your subject line should read something like: $sender has sent you some bitcoins!
Since the whole point of Coinapult is to send bitcoins to people who don't know what Bitcoin is, and by extension would have no idea what Coinapult is, saying "You've been hit with the Coinapult" does not convey any useful information, and would most likely be interpreted as spam due to the weirdness of it.

The body of the email should:
* Start out by saying $sender has sent you $amount bitcoins using Coinapult.
* Then explain what bitcoins are, in the simplest terms possible (but no simpler).
* Explain that if they don't already have a bitcoin wallet, they'll need to either download a bitcoin client or sign up for an online wallet service; and provide instructions for doing so.
* Then provide the link to claim the bitcoins.
* Provide an assurance that no fee is required to receive the bitcoins and that no personal information will be requested at any time. (Otherwise most people will see it as yet another "Get free money now! After paying a large transaction fee upfront" scam)
* Inform them that if the bitcoins are not claimed within 30 days they will be refunded to the sender.
* Then finally put the sender's message.

8.) Security.  SMTP messages are transferred clear text.  That means that if your service starts becoming popular that there is then an economic incentive for a sysadmin at the ISP or at the e-mail hosting service or somewhere between Coinapult and the recipient to heist the coins.  By simply adding a filter, every message that comes from Coinapult gets special attention by the scammer who redeems the coins, never with even a slight chance of getting caught.

E-mail is just not a secure method for transmitting essentially what is a negotiable bearer instrument  (the URL to claim the money).  This would be the same risk that exists when sending Mt. Gox Redeemable Voucher codes thorough e-mail, which is not recommended either.
Yes, this is an issue (and an extremely serious one), but judging by the number of companies (including banks Shocked) that send passwords and other sensitive data in plaintext email, and the fact that almost nobody uses or has even heard about PGP, I'm forced to conclude that nobody actually cares about security in the slightest, even if their money is at stake. The only difference here is that bitcoins are anonymous, so now people can steal your money with virtually no chance of being caught. I don't know what to suggest either (apart from lamenting the typical person's apathetic attitude towards email security).

Will pretend to do unspeakable things (while actually eating a taco) for bitcoins: 1K6d1EviQKX3SVKjPYmJGyWBb1avbmCFM4
I am not on the scammers' paradise known as Telegram! Do not believe anyone claiming to be me off-forum without a signed message from the above address! Accept no excuses and make no exceptions!
mem
Hero Member
*****
Offline Offline

Activity: 644
Merit: 501


Herp Derp PTY LTD


View Profile
April 13, 2012, 12:01:11 PM
 #30

a confirmation email sent to the from address would also be a nice feature

ShadowOfHarbringer
Legendary
*
Offline Offline

Activity: 1470
Merit: 1006


Bringing Legendary Har® to you since 1952


View Profile
April 13, 2012, 12:05:02 PM
 #31

Q: Do you support sending PGP/GPG - encrypted emails ?

davout
Legendary
*
Offline Offline

Activity: 1372
Merit: 1008


1davout


View Profile WWW
April 13, 2012, 12:33:57 PM
 #32

Not to hijhack this thread but...

a confirmation email sent to the from address would also be a nice feature
We have on Paytunia Wink

Foxpup
Legendary
*
Offline Offline

Activity: 4531
Merit: 3183


Vile Vixen and Miss Bitcointalk 2021-2023


View Profile
April 13, 2012, 01:53:05 PM
 #33

a confirmation email sent to the from address would also be a nice feature

For what purpose? As far as I can tell, the only reason the from address is needed at all is so that the person receiving the email has a chance of recognising the sender and not deleting the email on sight (after all, the email does look suspiciously like some sort of weird scam).

Will pretend to do unspeakable things (while actually eating a taco) for bitcoins: 1K6d1EviQKX3SVKjPYmJGyWBb1avbmCFM4
I am not on the scammers' paradise known as Telegram! Do not believe anyone claiming to be me off-forum without a signed message from the above address! Accept no excuses and make no exceptions!
PrintCoins
Hero Member
*****
Offline Offline

Activity: 533
Merit: 501


View Profile
April 13, 2012, 02:12:39 PM
 #34

Sorry to be a downer, but it is pretty easy to send someone bitcoins in email.

Go to https://www.bitaddress.org/
and generate an address. Fund it with whatever you want, and send the private key to the recipient.

If a year rolls by and the person never uses the bitcoin, they can be "reclaimed" by just importing the PK into your wallet.

Be sure to tell them that you will do that otherwise you might get an angry email.

evoorhees
Legendary
*
Offline Offline

Activity: 1008
Merit: 1023


Democracy is the original 51% attack


View Profile
April 13, 2012, 03:14:12 PM
 #35

Sorry to be a downer, but it is pretty easy to send someone bitcoins in email.

Go to https://www.bitaddress.org/
and generate an address. Fund it with whatever you want, and send the private key to the recipient.

If a year rolls by and the person never uses the bitcoin, they can be "reclaimed" by just importing the PK into your wallet.

Be sure to tell them that you will do that otherwise you might get an angry email.

To someone who is new to Bitcoin, the above may as well be latin.

One could always email a wallet file to someone, but Coinapult is a service for normal people Wink
bearbones (OP)
Sr. Member
****
Offline Offline

Activity: 316
Merit: 250



View Profile WWW
April 13, 2012, 03:24:10 PM
 #36

Thanks for all of the feedback! There is far to much to respond to individually here, but I'll address some of the more salient points and consider the rest carefully.

Regarding consistency of wording on the site and in emails, it certainly isn't perfect. We may lighten up on the catapult terminology to avoid confusion. There were a lot of other good suggestions we'll take into account.

On confirmations, the transaction server waits until there are enough funds in the account with 2 confirmations to allow sending. It may not be the exact funds you sent. It may be part of the buffer we keep in there to avoid delays. It may be older funds that have simply been sitting. In this way, there is a 1:1 relationship between incoming and outgoing funds, but access is maximized. This also makes Coinapult a very basic mixer.

On email security, this is an issue. Email is almost always insecure. I can allow PGP mail, with modest effort, but only a small percentage of people would be able to use it. I'm open to suggestions on how to improve the email security, but the goal of Coinapult is usability. As has been noted, those who are ultra security conscious, or have need to move large amounts of funds, have other means of doing so. bitaddress.org and an encrypted email is one reasonable solution. Try getting grandma to open it, though. Smiley Last, on this subject, DKIM is a great idea.


Feed Ze Birds Pay and get paid for tweets
Coinapult Send Bitcoins easily over email or text message
bracek
Hero Member
*****
Offline Offline

Activity: 530
Merit: 500


View Profile
April 13, 2012, 04:06:13 PM
 #37

nice service Smiley

i received some and sent it back

Funds sent. Transaction ID:
4d437d4661598db0de15d946f1f295a7ce360e2be0c5fc89cff6324589a1c327

it was so easy

note :
on arrival it came into my gmail spam folder
ShadowOfHarbringer
Legendary
*
Offline Offline

Activity: 1470
Merit: 1006


Bringing Legendary Har® to you since 1952


View Profile
April 13, 2012, 04:20:56 PM
 #38

note :
on arrival it came into my gmail spam folder

Lately almost everything lands in gmail spam folder.
Their spam filters became crazy.

PS.
@Coinapult author
So what about PGP support ? Is it planned at least ?

OgNasty
Donator
Legendary
*
Offline Offline

Activity: 4914
Merit: 4827


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
April 13, 2012, 04:52:08 PM
 #39

This sounds like a great service.  I hope it helps get some new people involved in Bitcoin.  Good work!

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
bearbones (OP)
Sr. Member
****
Offline Offline

Activity: 316
Merit: 250



View Profile WWW
April 13, 2012, 04:59:02 PM
 #40

note :
on arrival it came into my gmail spam folder

Lately almost everything lands in gmail spam folder.
Their spam filters became crazy.

PS.
@Coinapult author
So what about PGP support ? Is it planned at least ?

Honestly, I hadn't considered PGP support, because so few people use it. Now that you mention it, though, it might not be too hard to implement. Say:

1. received email address
2. checked for public key associated with it
3. if found, sign the message before sending

I'll look into it a bit more. Right now, though, I don't see any downside to such an arrangement.

Feed Ze Birds Pay and get paid for tweets
Coinapult Send Bitcoins easily over email or text message
Pages: « 1 [2] 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!