Bitcoin Forum
May 10, 2024, 06:21:44 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Re: [WARNING] Bitcoinica Claims Process is insecure  (Read 1357 times)
Nyaaan (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile WWW
May 20, 2012, 07:50:42 AM
 #1

It has been compromised in the past, so it likely will again in the future. You should simply just not use StartCom, especially after you've been hacked yourself. StartCom should have been completely blacklisted in browsers.

Comodo, USER-TRUST, and even Verisign have also been compromised in the past, and there's no chance that they'll be removed from browsers because they're so popular. Lots of governments also have their own probably-insecure CAs which are accepted by all browsers. The CA system is a lost cause.

Tell me what isn't a lost cause then. Please.
The forum was founded in 2009 by Satoshi and Sirius. It replaced a SourceForge forum.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12982


View Profile
May 20, 2012, 08:41:42 AM
 #2

Tell me what isn't a lost cause then. Please.

I use the Certificate Patrol and Perspectives Firefox extensions. I've also disabled most of the CAs in Firefox, though Firefox's handling of invalid certificates is pretty bad, so I don't recommend doing this unless you're paranoid.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
check_status
Full Member
***
Offline Offline

Activity: 196
Merit: 100


Web Dev, Db Admin, Computer Technician


View Profile
May 20, 2012, 09:51:00 AM
Last edit: May 20, 2012, 10:06:05 AM by check_status
 #3

Quote from: Theymos
I use the Certificate Patrol and Perspectives Firefox extensions. I've also disabled most of the CAs in Firefox, though Firefox's handling of invalid certificates is pretty bad, so I don't recommend doing this unless you're paranoid.
(If this is OffTopic, let me know. Smiley )
The only problem with Perspectives is they only authenticate the first connection, other stuff on the website, pics, forms are still vulnerable. Have you thought about using Convergence instead? http://convergence.io/

For Bitcoin to be a true global currency the value of BTC needs always to rise.
If BTC became the global currency & money supply = 100 Trillion then ⊅1.00 BTC = $4,761,904.76.
P2Pool Server List | How To's and Guides Mega List |  1EndfedSryGUZK9sPrdvxHntYzv2EBexGA
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12982


View Profile
May 20, 2012, 04:39:55 PM
 #4

The only problem with Perspectives is they only authenticate the first connection, other stuff on the website, pics, forms are still vulnerable. Have you thought about using Convergence instead? http://convergence.io/

I've heard that Convergence is no longer being actively developed.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
check_status
Full Member
***
Offline Offline

Activity: 196
Merit: 100


Web Dev, Db Admin, Computer Technician


View Profile
May 20, 2012, 10:23:40 PM
 #5

Well Convergence is accepting Contributions via Bitcoin and via Bit-Pay.
There were active donations sent April through May of 2012.
15TUpE7Qtehxzrx2gMdE6jbHdQa42Edk4G




For Bitcoin to be a true global currency the value of BTC needs always to rise.
If BTC became the global currency & money supply = 100 Trillion then ⊅1.00 BTC = $4,761,904.76.
P2Pool Server List | How To's and Guides Mega List |  1EndfedSryGUZK9sPrdvxHntYzv2EBexGA
zer0
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250



View Profile
May 21, 2012, 04:31:29 PM
 #6

I'm pretty sure it's still being actively maintained, can always ask moxie or 0day charlie of thoughtcrime labs on twitter if they're still involved, they always reply

check_status
Full Member
***
Offline Offline

Activity: 196
Merit: 100


Web Dev, Db Admin, Computer Technician


View Profile
May 22, 2012, 08:26:16 AM
 #7

Me: I heard the Convergence project is no longer being developed, Is this true?
Moxie Marlinspike: Convergence is still being developed, although the core
feature set is pretty stable now.
Me: Should anyone run a notary?
Moxie Marlinspike: Anyone can run a notary, and anyone is free to use that notary if they trust the organization.
Me: Who would be your ideal candidate for running a notary?
Moxie Marlinspike: Ideally, organizations that can dedicate the resources to running HA notaries are preferred.

For Bitcoin to be a true global currency the value of BTC needs always to rise.
If BTC became the global currency & money supply = 100 Trillion then ⊅1.00 BTC = $4,761,904.76.
P2Pool Server List | How To's and Guides Mega List |  1EndfedSryGUZK9sPrdvxHntYzv2EBexGA
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!