Bitcoin Forum
April 25, 2024, 07:02:29 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  

Warning: Moderators do not remove likely scams. You must use your own brain: caveat emptor. Watch out for Ponzi schemes. Do not invest more than you can afford to lose.

Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 ... 118 »
  Print  
Author Topic: [BitcoinMax.com] Closed  (Read 190155 times)
Epoch
Legendary
*
Offline Offline

Activity: 922
Merit: 1003



View Profile
June 06, 2012, 08:54:01 PM
 #81

Is anyone concerned, in terms of security, with the current website login of:

username: <forum name>
password: <deposit address>

Just thinking out loud, but taking an example, let's say we know someone sent 45 BTC on or before a specific date/time. We know who it was because they posted 'whoa, I just sent 45 BTC!' here in this forum (I notice there are several members who have posted their deposit amounts looking back at the post history).

The blockchain can be easily searched for all 45 BTC transactions prior to that date (for, say, the period 2 or 3 days prior). There may be several matching hits, but likely not a huge number.

We know the user's bitcoinmax.com name from the forum here. We could then try a login at bitcoinmax.com using that name and the various deposit addresses found from the blockchain matching 45 BTC. Eventually the login would be successful and the 'imposter' would have access to the account.

I may be missing something (and I hope I am), but I'm asking for someone to convince me that the <forum name>/<deposit address> system used by bitcoinmax.com is secure from a hack similar to what I've described above.
1714028549
Hero Member
*
Offline Offline

Posts: 1714028549

View Profile Personal Message (Offline)

Ignore
1714028549
Reply with quote  #2

1714028549
Report to moderator
1714028549
Hero Member
*
Offline Offline

Posts: 1714028549

View Profile Personal Message (Offline)

Ignore
1714028549
Reply with quote  #2

1714028549
Report to moderator
1714028549
Hero Member
*
Offline Offline

Posts: 1714028549

View Profile Personal Message (Offline)

Ignore
1714028549
Reply with quote  #2

1714028549
Report to moderator
The forum was founded in 2009 by Satoshi and Sirius. It replaced a SourceForge forum.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714028549
Hero Member
*
Offline Offline

Posts: 1714028549

View Profile Personal Message (Offline)

Ignore
1714028549
Reply with quote  #2

1714028549
Report to moderator
1714028549
Hero Member
*
Offline Offline

Posts: 1714028549

View Profile Personal Message (Offline)

Ignore
1714028549
Reply with quote  #2

1714028549
Report to moderator
tgmarks
Donator
Hero Member
*
Offline Offline

Activity: 490
Merit: 500


View Profile
June 06, 2012, 08:59:21 PM
 #82

Is anyone concerned, in terms of security, with the current website login of:

username: <forum name>
password: <deposit address>

Just thinking out loud, but taking an example, let's say we know someone sent 45 BTC on or before a specific date/time. We know who it was because they posted 'whoa, I just sent 45 BTC!' here in this forum (I notice there are several members who have posted their deposit amounts looking back at the post history).

The blockchain can be easily searched for all 45 BTC transactions prior to that date (for, say, the period 2 or 3 days prior). There may be several matching hits, but likely not a huge number.

We know the user's bitcoinmax.com name from the forum here. We could then try a login at bitcoinmax.com using that name, and the various deposit addresses found from the blockchain that matched 45 BTC. Eventually the login would be successful and the 'imposter' would have access to the account.

I may be missing something (and I hope I am), but I'm asking for someone to convince me that the <forum name>/<deposit address> system used by bitcoinmax.com is secure from a hack similar to what I've described above.

What is there to be concerned about?  So someone could possibly be able to see your deposit address, balance, and toggle whether to reinvest or not.  There is no access to your funds through the website.

BTC-engineer
Sr. Member
****
Offline Offline

Activity: 360
Merit: 250



View Profile
June 06, 2012, 09:01:02 PM
 #83

Is anyone concerned, in terms of security, with the current website login of:

username: <forum name>
password: <deposit address>

Just thinking out loud, but taking an example, let's say we know someone sent 45 BTC on or before a specific date/time. We know who it was since they posted 'whoa, I just sent 45 BTC!' here in this forum (I notice there are several members who have posted their deposit amounts looking back at the post history).

The blockchain can be easily searched for all 45 BTC transactions prior to that date (for, say, the period 2 or 3 days prior). There may be several hits, but likely not a huge number.

We know the user's bitcoinmax.com name from the forum here. We could then try a login at bitcoinmax.com using that name, and the various deposit addresses found from the blockchain that matched 45 BTC. Eventually the login would be successful and the 'imposter' would have access to the account.

I may be missing something (and I hope I am), but I'm asking for someone to convince me that the <forum name>/<deposit address> system used by bitcoinmax.com is secure from a hack similar to what I've described above.


I already worried about the same thing.
Because I'm not (yet) able to login I don't know if the user can change the password. If you would change the password before you do an transfer it should not be a problem.
Even if someone knows your account data I'm not sure what he really can do without seeing your bitcoins...

                             █         
                             ▀██       
                              ███▄     
                              █████     
                 ▄██████████   █████   
            ▄███████████████   █████▄   
         ▄██████████████████   ██████   
       █████████████████████  ███████   
     ██████████████████████   ████████ 
   ▄████████▀                █████████ 
  ██████    ▄██████         ██████████ 
 ███▀    ▄██████████      ███████████   
██       ████████████    ████████████   
          █████████████   ██████████   
            █████████████   ███████     
              █████████████▄    ██▀     
                 ██████████████         
                    ▀███████████████▄   
                          ▀███████████▀

FLUX 

  VALVE      UBISOFT     GAMING ECOSYSTEM      Origin      GAMELOFT 
                   WEBSITE WHITEPAPER MEDIUM TWITTER FACEBOOK TELEGRAM █       


  17 - 24 April
   Public Sale
Epoch
Legendary
*
Offline Offline

Activity: 922
Merit: 1003



View Profile
June 06, 2012, 09:02:24 PM
 #84

What is there to be concerned about?  So someone could possibly be able to see your deposit address, balance, and toggle whether to reinvest or not.  There is no access to your funds through the website.
I didn't know what is, and what is not, possible to do through the website. If you cannot withdraw (or set/change withdrawal address), then that eliminates one of my key concerns. Thanks.
BTC-engineer
Sr. Member
****
Offline Offline

Activity: 360
Merit: 250



View Profile
June 06, 2012, 09:57:15 PM
 #85

new investors that cannot log in yet, need to go back to the OP and read the FAQ.

creating a login is a manual process, and I'm not going to do that unless i see at least 10 coins come in. even then, i'll probably only be doing that once a day (setting up new logins).


Thank's for clarification. I've now first sent my coins and will check tomorrow again.

                             █         
                             ▀██       
                              ███▄     
                              █████     
                 ▄██████████   █████   
            ▄███████████████   █████▄   
         ▄██████████████████   ██████   
       █████████████████████  ███████   
     ██████████████████████   ████████ 
   ▄████████▀                █████████ 
  ██████    ▄██████         ██████████ 
 ███▀    ▄██████████      ███████████   
██       ████████████    ████████████   
          █████████████   ██████████   
            █████████████   ███████     
              █████████████▄    ██▀     
                 ██████████████         
                    ▀███████████████▄   
                          ▀███████████▀

FLUX 

  VALVE      UBISOFT     GAMING ECOSYSTEM      Origin      GAMELOFT 
                   WEBSITE WHITEPAPER MEDIUM TWITTER FACEBOOK TELEGRAM █       


  17 - 24 April
   Public Sale
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
June 06, 2012, 10:58:32 PM
 #86

Also people who post in a public forum of 'I just sent xxBTC' obviously are not too concerned with privacy.

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
bitdragon
Hero Member
*****
Offline Offline

Activity: 609
Merit: 501


peace


View Profile WWW
June 07, 2012, 07:26:24 AM
 #87

if anyone else notices deposits missing, please let me know.
thanks.

my additional funds have not shown up yet Smiley

payb.tc (OP)
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1000



View Profile
June 07, 2012, 07:36:47 AM
 #88

if anyone else notices deposits missing, please let me know.
thanks.

my additional funds have not shown up yet Smiley

okay then, i decided just for now to completely remove the code which tries to limit calls to blockchain.info, and your deposit showed up.

it'll now take slightly longer (~1 second) for everyone to log in, but it will force the check every time now.

i'll take a further look at the issue later, if i think it's calling blockchain.info too much.
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
June 07, 2012, 11:57:27 AM
 #89

What about a CHECK button that we can use to initiate the check?  That way it doesn't happen EVERYTIME but when we know we have sent money and want it to show we can hit that?

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
payb.tc (OP)
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1000



View Profile
June 07, 2012, 02:15:58 PM
 #90

latest investors (who have sent at least 10 btc) should be able to log in to bitcoinmax now.

...although some are missing the withdrawal address, but i'm going through and populating those at the moment.

oh, all these new accounts have been created with reinvest=YES, so if you want to change it, please do so in the login area.

BTC-engineer, your username for bitcoinmax has no dash in it.
xxaudioxx
Full Member
***
Offline Offline

Activity: 141
Merit: 111



View Profile
June 07, 2012, 02:40:56 PM
 #91

thanks payb.tc

+1 smracer, +2 MadSweeney, +1 bitdragon, +1 mimarob, +1 Valalvax, +2 dbox, +100 payb.tc, +1 TheBitMan, +2 gusti, +1 hashking, +1 Xunie, +2 wm-center, +1 Scott J

https://bitcointalk.org/index.php?topic=484.msg962923#msg962923
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1225


Away on an extended break


View Profile
June 07, 2012, 02:51:52 PM
 #92

thanks payb.tc

+1
ehmdjii
Sr. Member
****
Offline Offline

Activity: 351
Merit: 250


View Profile
June 07, 2012, 08:21:45 PM
 #93

how does one get an account?
is it referer based? if so, then i would be happy if i could get an invite!

BTC: 1LsD5HpnX1Kfyti7CnHiVB1rjUEXGqmR2H
LTC: LQbpdMZmYyJa9bJG6NweBNxkSTfgZorkrG
tgmarks
Donator
Hero Member
*
Offline Offline

Activity: 490
Merit: 500


View Profile
June 07, 2012, 08:30:33 PM
 #94

how does one get an account?
is it referer based? if so, then i would be happy if i could get an invite!
You should read the very first post in the thread.

fuxianhui888
Full Member
***
Offline Offline

Activity: 205
Merit: 100



View Profile
June 08, 2012, 06:43:11 AM
 #95

+2
payb.tc (OP)
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1000



View Profile
June 09, 2012, 01:57:34 PM
Last edit: June 09, 2012, 02:40:06 PM by payb.tc
 #96

over the past couple of hours, i've come up with an 'earnings report' page which is now in the login area of bitcoinmax.

i'm still doing some debugging on this page, but it should show you exactly how your payments are being calculated so you can verify the accuracy of your earnings each week.

thanks.


edit: i've now also extended this to include an estimate of your Next Payment at the top of every page.
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1225


Away on an extended break


View Profile
June 09, 2012, 03:15:08 PM
 #97

over the past couple of hours, i've come up with an 'earnings report' page which is now in the login area of bitcoinmax.

i'm still doing some debugging on this page, but it should show you exactly how your payments are being calculated so you can verify the accuracy of your earnings each week.

thanks.


edit: i've now also extended this to include an estimate of your Next Payment at the top of every page.

Thanks for this feature! Cheesy
By the way, you could add a clock to the page too so that we can know what timezone the server makes its calculations on.
payb.tc (OP)
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1000



View Profile
June 09, 2012, 03:37:44 PM
 #98

over the past couple of hours, i've come up with an 'earnings report' page which is now in the login area of bitcoinmax.

i'm still doing some debugging on this page, but it should show you exactly how your payments are being calculated so you can verify the accuracy of your earnings each week.

thanks.


edit: i've now also extended this to include an estimate of your Next Payment at the top of every page.

Thanks for this feature! Cheesy
By the way, you could add a clock to the page too so that we can know what timezone the server makes its calculations on.

everything is UTC.

my brain is UTC.

you should see my house too, some of the clocks are UTC.
DutchBrat
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
June 09, 2012, 04:31:14 PM
 #99

Looks great !

Thanks !!!
ErebusBat
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500

I am the one who knocks


View Profile
June 09, 2012, 05:05:56 PM
 #100

Can't wait until I have my BTC for my first deposit. 

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle

Signup for CEX.io BitFury exchange and get GHS Instantly!  Don't wait for shipping, mine NOW!
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 ... 118 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!