Nxtblg
Legendary
Offline
Activity: 924
Merit: 1000
|
|
September 23, 2014, 04:01:26 PM |
|
i have less than 30 alphabet password and never got hacked, No number,dot,comma or anything. Dont blame coin for your own mistakes, if someone can hack in to your computer and copy wallet.dat file without the encryption will you still blame BTC for that?
Same here: only 24 chars in my case, until the Nxt client added a force to put in 36 or more, after which I shifted to a 48-char passphrase that was two 24-chars concatenated together. I've never been robbed, once. Chalk it up to "randomly-generated." Of course, I also use the PerfectGuard anti-keylogger suite...
|
|
|
|
spacehopper
Member
Offline
Activity: 121
Merit: 10
|
|
September 23, 2014, 04:31:19 PM |
|
Configure Keepass to generate a random 100 character password of upper and lower case letters, digits, and special characters.
|
|
|
|
Zer0Sum
Legendary
Offline
Activity: 1588
Merit: 1000
|
|
September 23, 2014, 07:22:27 PM |
|
hi devphp the pass phrase is like this tim cum sim prawn gin yuk bim rarl per tip pop from
It is NO more complicated or NO MORE simplified. If you want to call me a liar by not posting MY pass phrase to cover up security issues with nxt then carry on please.
If I was going to lie about it I would include numbers and characters to make myself look bullet proof to any hacks. The fact is I was hacked and no body has said there is a problem with the pass phrase. Which means nxt in my opinion is not secure enough if the strength of my pass phrase is ok.
I'm totally with you on this. Here you have these pro-devs and uber-geeks... SCOLDING you that to use NXT you must become an amateur cryptologist... And use THIRD PARTY software to secure your account... Plus a long list of other things you should do probably involving a clean Linux install or whatever... And it never ends there... because there IS NO ENDPOINT TO CRYPTO SECURITY. Let's see... You have a wallet written by anon devs... In fact, there are multiple 3rd party wallets and "official" sites for NXT... Controlled by about 10 people who control NXT... And you log into their web site with your "secret" password... what can possibly go wrong? In a world of biometrics, ubiquitous security fobs, smart cards, etc, etc... These rocket scientists have decided that you will be protected ONLY by a password... Which is 3,000 year old technology used by the Romans. Normal adult people would rather just use a bank, Visa, and Paypal... Than live a SHADY life constantly worried about being hacked or scammed.
|
|
|
|
Yuzu
|
|
September 23, 2014, 07:41:58 PM |
|
I'm really sorry your account got hacked. It happened to me last month. It was my own fault; my password was too weak. I felt really terrible. It's a crappy thing to have happen. I will never use words as a password again. I now have 50 random characters.
|
|
|
|
fivebells
|
|
September 23, 2014, 09:26:48 PM |
|
Assuming it's a vulnerability in NXT seems like leap at this point. It seems equally likely from here, for instance, that some national intelligence service is surveilling you, and one of its agents decided to take personal advantage of knowing your NXT account's password. After all, so far you're the only person to claim this, and the amount they could steal was relatively small and a matter of public record. If they can do that, why would they pick on small fry?
|
|
|
|
Mrrr
|
|
September 23, 2014, 10:54:11 PM |
|
I'm really sorry your account got hacked. It happened to me last month. It was my own fault; my password was too weak. I felt really terrible. It's a crappy thing to have happen. I will never use words as a password again. I now have 50 random characters.
This is BS if I may. A sufficiently long set of random words is safer than random characters. Random characters are a pain in the ass to copy/type from paper, are prone to ctrl+c mistakes and look terrible. Obviously "in the beginning the lord created the heaven and the earth" isn't a good password. "nail presence nature closet flame deal movement sanity chill yourself shimmer" is however. If you're smart and rely on a series of words as a seed you should of course always realize that the human brain is especially terrible at creating randomness. So, when in need of a good and usable password. Have a computer generate a random string of 12 words for you. In OP's case. I'm curious as to which extent this was a random password.
|
burp...
|
|
|
Mrrr
|
|
September 23, 2014, 11:08:28 PM |
|
I'm really sorry your account got hacked. It happened to me last month. It was my own fault; my password was too weak. I felt really terrible. It's a crappy thing to have happen. I will never use words as a password again. I now have 50 random characters.
This is BS if I may. A sufficiently long set of random words is safer than random characters. Random characters are a pain in the ass to copy/type from paper, are prone to ctrl+c mistakes and look terrible. Obviously "in the beginning the lord created the heaven and the earth" isn't a good password. "nail presence nature closet flame deal movement sanity chill yourself shimmer" is however. If you're smart and rely on a series of words as a seed you should of course always realize that the human brain is especially terrible at creating randomness. So, when in need of a good and usable password. Have a computer generate a random string of 12 words for you. In OP's case. I'm curious as to which extent this was a random password. Again it seems you don't bruteforce anything to know that different characters and symbols will make everyone take more effort to crack your password. And once they are about to do it, you are supposed to change your password every year or half a year.Depends how many times you use it, and which location. To me it seems that length is more important than the amount of different characters so to say. If random, obviously. If OP's password was indeed random I don't see how a password that long could possibly be brute forced. So, OP got hacked, OP's password wasn't random or NXT has a vulnerability. I opt for 1 or 2.
|
burp...
|
|
|
Yuzu
|
|
September 23, 2014, 11:16:10 PM |
|
I'm really sorry your account got hacked. It happened to me last month. It was my own fault; my password was too weak. I felt really terrible. It's a crappy thing to have happen. I will never use words as a password again. I now have 50 random characters.
This is BS if I may. A sufficiently long set of random words is safer than random characters. Random characters are a pain in the ass to copy/type from paper, are prone to ctrl+c mistakes and look terrible. Obviously "in the beginning the lord created the heaven and the earth" isn't a good password. "nail presence nature closet flame deal movement sanity chill yourself shimmer" is however. If you're smart and rely on a series of words as a seed you should of course always realize that the human brain is especially terrible at creating randomness. So, when in need of a good and usable password. Have a computer generate a random string of 12 words for you. In OP's case. I'm curious as to which extent this was a random password. You can say it's BS all you want. I'm relating from experience. I know that my password now is stronger than it was. I don't have the wherewithal to calculate the strength of passwords, so I'm going with what I've got.
|
|
|
|
|
Viper1
|
|
September 24, 2014, 12:03:50 AM |
|
Sort of sad that one has to generate some crazy password in order to secure an account. Every time someones NXT gets stolen, it's always the same thing. Oh your password wasn't good enough. Can someone point out some other coins that have this issue? Cause it seems to me NXT gets a lot of stolen NXT reports and would point to a fundamental problem with NXT. Just sayin.
|
BTC: 1F8yJqgjeFyX1SX6KJmqYtHiHXJA89ENNT LTC: LYAEPQeDDM7Y4jbUH2AwhBmkzThAGecNBV DOGE: DSUsCCdt98PcNgUkFHLDFdQXmPrQBEqXu9
|
|
|
EvilDave
|
|
September 24, 2014, 12:34:06 AM |
|
Sort of sad that one has to generate some crazy password in order to secure an account. Every time someones NXT gets stolen, it's always the same thing. Oh your password wasn't good enough. Can someone point out some other coins that have this issue? Cause it seems to me NXT gets a lot of stolen NXT reports and would point to a fundamental problem with NXT. Just sayin.
Because NXT is a brain wallet, your password is your account. No need for a local wallet.dat that can get lost/stolen (and there's lots of malware that looks for wallet.dat these days), if your house burns down, taking your PC with it, no worries. No need for backups.....I like the brainwallet, I've had no problems so far with it and I've been using NXT very actively, on multiple accounts, over the last 10 months. Every guide to NXT, and the client itself, gives information about password security, the client itself provides a (so far) unbreakable password generator, but still some people use a stupid password like a phrase from the Bible or the Russian constitution. This is what is happening: http://en.wikipedia.org/wiki/Rainbow_tableBtw,a rainbow table is also what the bad guys will use to open your wallet.dat if they can steal it, so pay attention to NXT level of password security on ALL crypto. Securing a BTC wallet with a quote from your favourite song will not keep out the bad guys for more than a few minutes at most, if they can access/copy it. Anyway, there is a problem, and we need to try to solve it. I've posted much of the info that I have on the thefts on nxtforum.org: https://nxtforum.org/general-discussion/help!-my-nxt-account-stolen-account-for-nxt-wczn-dgql-xm69-62l3n/msg106530/#msg106530 (copy and paste, the stupid ! breaks the URL) I'm offering a 5000 NXT bounty for help with recovery of the stolen funds, so if you want to help......feel free to join in.
|
|
|
|
bitfreak!
Legendary
Offline
Activity: 1536
Merit: 1000
electronic [r]evolution
|
|
September 24, 2014, 01:21:17 AM Last edit: September 24, 2014, 01:32:28 AM by bitfreak! |
|
To me it seems that length is more important than the amount of different characters so to say. If random, obviously. If OP's password was indeed random I don't see how a password that long could possibly be brute forced. I'm not a supporter of NXT, but that is a common misconception. The OP used what appears to be a list of lowercase English words. It's quite easy to build a brute forcer which cracks those types of pass phrases. You have to think about each word as if it was a single letter in an alphabet, because that's how the cracker would work, it would shift through words instead of letters. Now when you think about it that way it's easy to see why the OP's password was weak. EDIT: well actually no, it would be hard to crack, but I think it would be possible.
|
XCN: CYsvPpb2YuyAib5ay9GJXU8j3nwohbttTz | BTC: 18MWPVJA9mFLPFT3zht5twuNQmZBDzHoWF Cryptonite - 1st mini-blockchain altcoin | BitShop - digital shop script Web Developer - PHP, SQL, JS, AJAX, JSON, XML, RSS, HTML, CSS
|
|
|
devphp
|
|
September 24, 2014, 06:27:34 AM Last edit: September 24, 2014, 06:45:22 AM by devphp |
|
You have to think about each word as if it was a single letter in an alphabet, because that's how the cracker would work, it would shift through words instead of letters.
Except if you use words there are thousands in the 'alphabet' (=dictionary) to choose from not just 26 letters, and thousands of different 'letters' ensure 128+ bit entropy, which is impossible to crack.
|
|
|
|
ShroomsKit_Disgrace
Legendary
Offline
Activity: 952
Merit: 1000
Yeah! I hate ShroomsKit!
|
|
September 24, 2014, 07:31:52 AM |
|
I also heard that Mark Karpeles was hacked and lost 800,000BTC coz NXT is not safe enough. We must blame NXT folks!!! Edit: I was being sarcastic
|
|
|
|
devphp
|
|
September 24, 2014, 07:34:09 AM |
|
I also heard that Mark Karpeles was hacked and lost 800,000BTC coz NXT is not safe enough. We must blame NXT folks!!! Edit: I was being sarcastic Whatever happens, blame Canada NXT.
|
|
|
|
gravitate (OP)
Legendary
Offline
Activity: 1372
Merit: 1000
|
|
September 24, 2014, 08:35:21 AM |
|
Hi the pass phrase I always use which are different every time is a mixture between Chinese pinyin and simple English words. So I guess you can really say they are random yes.
|
To peel or not to peel.
|
|
|
Nullu
|
|
September 24, 2014, 08:57:17 AM |
|
Threads like this annoy me.
Mainly because, it's always NXT that's blamed, and not the user for not taking adequate security measures. In cases such as these, it's never proven to be an NXT security flaw. It could just as easily have been a trojan on your PC, a keylogger, or a man-in-the-middle attack, if YOU got hacked, then there's nothing wrong with NXT. Your system was compromised.
That's like blaming the bank because someone stole your credit card.
Security could be much better with NXT, and that is where the criticism should be aimed here, but I seriously doubt someone managed to "hack" into your NXT account unless they compromised you or your password. Otherwise, people would be losing NXT left, right and centre.
Perspective, please.
|
BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
|
|
|
gravitate (OP)
Legendary
Offline
Activity: 1372
Merit: 1000
|
|
September 24, 2014, 12:17:57 PM |
|
Nullu no one is blaming anyone really it is merely a warning to people wanting to invest in Nxt. If they see it as a trust worthy coin then they must use a 3rd party random character generating app. Simple as that and if they dont they could well lose all their coin.
|
To peel or not to peel.
|
|
|
youyou_
|
|
September 24, 2014, 12:29:36 PM |
|
Nullu no one is blaming anyone really it is merely a warning to people wanting to invest in Nxt. If they see it as a trust worthy coin then they must use a 3rd party random character generating app. Simple as that and if they dont they could well lose all their coin.
what is your OS ?
|
|
|
|
gravitate (OP)
Legendary
Offline
Activity: 1372
Merit: 1000
|
|
September 24, 2014, 02:02:06 PM |
|
Mavericks on a mac air
|
To peel or not to peel.
|
|
|
|