Bitcoin Forum
June 16, 2025, 01:37:32 AM *
News: Latest Bitcoin Core release: 29.0 [Torrent]
 
   Home   Help Search Login Register More  

Warning: Moderators do not remove likely scams. You must use your own brain: caveat emptor. Watch out for Ponzi schemes. Do not invest more than you can afford to lose.

Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 ... 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 [856] 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 ... 1348 »
  Print  
Author Topic: ASICMINER: Entering the Future of ASIC Mining by Inventing It  (Read 3918196 times)
Herp
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
February 14, 2014, 05:26:18 PM
 #17101


2. Pending withdrawal of your Bitcoins; time lock?


How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. It can be unlocked, but upon doing so an email is sent notifying me that it's been unlocked and it takes a further 7 days or so before a new address can be entered?

Yep, this would be a great feature.


███████████████████████████████████████
███████████████████████████████████████
█████████████████████████████
██████████████████████████
████████████████████████
███████████████████████
█████████████████▐████
███████████████████████
████████████████████████
██████████████████████████
█████████████████████████████
███████████████████████████████████████
███████████████████████████████████████
DECENT
FOUNDATION



██
██
██
██
██
██
██
██
██

██
██
██


[D]ecentralized application
[E]liminated third parties
[C]ontent distribution



██
██
██
██
██
██
██
██
██

██
██
██


[E]ncrypted & secure
[N]o borders
[T]imeless reputation



██
██
██
██
██
██
██
██
██

██
██
██



██
██
██
██
██
██
██
██
██

██
██
██

Fabrizio89
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1000


View Profile
February 14, 2014, 05:34:17 PM
 #17102


How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. [...]

+1
elasticband
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


Nighty Night Don't Let The Trolls Bite Nom Nom Nom


View Profile
February 14, 2014, 06:07:46 PM
 #17103


2. Pending withdrawal of your Bitcoins; time lock?


How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. It can be unlocked, but upon doing so an email is sent notifying me that it's been unlocked and it takes a further 7 days or so before a new address can be entered?

Yep, this would be a great feature.

Does not stop a hacker selling your shares for dirt cheap to himself.
silverfuture
Legendary
*
Offline Offline

Activity: 947
Merit: 1008


central banking = outdated protocol


View Profile
February 14, 2014, 06:10:44 PM
 #17104


2. Pending withdrawal of your Bitcoins; time lock?


How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. It can be unlocked, but upon doing so an email is sent notifying me that it's been unlocked and it takes a further 7 days or so before a new address can be entered?

Yep, this would be a great feature.

Does not stop a hacker selling your shares for dirt cheap to himself.

...or transferring them to another account for free.

-----------------------------------------------------------------------------------------------------------------------
NastyFans - The Fan Club for Bitcoin Enthusiasts | MININGCOINS | POOL | ESCROW
-----------------------------------------------------------------------------------------------------------------------
twentyseventy
Legendary
*
Offline Offline

Activity: 1386
Merit: 1000


View Profile
February 14, 2014, 06:34:41 PM
 #17105

Here at Havelock we take security issues very seriously.

We have never had any issues with users that enabled 2FA on their account. We have contacted the person that has made the claim that is account has been compromised and are looking to resolve the matter has soon as possible.

Trying to balance ease of use and security is never easy, especially in the Bitcoin realm. We can always add additional security features but those will always slow down the user experience.

So we turn to you, our valued customers, what features would like us to add to our platform?

1. Confirmation email before any action is taken; some but not all actions.

2. Pending withdrawal of your Bitcoins; time lock?

3. Lock account by IP address?

We always value your opinions and we strive to serve the Bitcoin community to the best of our ability.

Also we can assure everyone that it was not an "inside rogue employee"

Thank you,

Support Team
Havelock Investments
PIN for orders or withdrawals, perhaps, or lock the BTC withrawal address for x days.

Instant BTC withdrawals to any old BTC address is a problem.

I like that idea - PIN for withdrawals, BTC withdrawal address can only be changed after 7-day waiting period. You could even make the second part optional.
havelock
Sr. Member
****
Offline Offline

Activity: 328
Merit: 250



View Profile WWW
February 14, 2014, 06:48:12 PM
 #17106

Thank you for all of your quick replies,

We will start to work on the following security implementations:

1. The option to Lock your account to a specific IP

2. Required 2FA for withdrawal / optional for order execution

3. Once 2FA is enabled, you will be required to enter your 2FA to view the private key or to disable 2FA on your account.


Once again thank you for all of your support,

Havelock Investments


electerium
Full Member
***
Offline Offline

Activity: 179
Merit: 100


View Profile
February 14, 2014, 07:06:41 PM
 #17107

2fa on withdraw is a decent roadblock to mitm attacks that can circumvent the initial 2fa sign in. Additionally I think the 2fa email is also a decent idea but less robust for obvious reasons
shawshankinmate37927
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1000


Bitcoin: The People's Bailout


View Profile
February 14, 2014, 08:22:09 PM
 #17108

2fa on withdraw is a decent roadblock to mitm attacks that can circumvent the initial 2fa sign in. Additionally I think the 2fa email is also a decent idea but less robust for obvious reasons

I like 2FA via e-mail because my e-mail account is set up with 2FA via a text message to my cell phone.  With 2FA via e-mail, a hacker would have to hack my e-mail account in order to access my Havelock account.  In order to hack my e-mail account, he would also have to hack my cell phone.

"It is well enough that people of the nation do not understand our banking and monetary system, for if they did, I believe there would be a revolution before tomorrow morning."   - Henry Ford
runam0k
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001


Touchdown


View Profile
February 14, 2014, 08:31:35 PM
 #17109

Thank you for all of your quick replies,

We will start to work on the following security implementations:

1. The option to Lock your account to a specific IP

2. Required 2FA for withdrawal / optional for order execution

3. Once 2FA is enabled, you will be required to enter your 2FA to view the private key or to disable 2FA on your account.


Once again thank you for all of your support,

Havelock Investments


No locking the BTC withdraw address (which seemed to be the most popular suggestion here)?
lunarboy
Hero Member
*****
Offline Offline

Activity: 544
Merit: 500



View Profile
February 14, 2014, 08:38:33 PM
 #17110

Here at Havelock we take security issues very seriously.

We have never had any issues with users that enabled 2FA on their account. We have contacted the person that has made the claim that is account has been compromised and are looking to resolve the matter has soon as possible.

Trying to balance ease of use and security is never easy, especially in the Bitcoin realm. We can always add additional security features but those will always slow down the user experience.

So we turn to you, our valued customers, what features would like us to add to our platform?

1. Confirmation email before any action is taken; some but not all actions.

2. Pending withdrawal of your Bitcoins; time lock?

3. Lock account by IP address?

We always value your opinions and we strive to serve the Bitcoin community to the best of our ability.

Also we can assure everyone that it was not an "inside rogue employee"

Thank you,

Support Team
Havelock Investments

This is the Asciminer thread so we should probably move this discussion over to havelock exchange, although if you remember Havelock suggestions have been made in the past, had these been implemented this sort of thing could not so easily happen
https://bitcointalk.org/index.php?topic=135035.msg3661143#msg3661143

withdrawals should be locked to a specific BTC address and multisig should be signed for share transfer. This would at least stop funds leaving the accounts. YOU WERE WARNED.
minerpumpkin
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


A pumpkin mines 27 hours a night


View Profile
February 14, 2014, 10:59:12 PM
 #17111

Some sort of address locking seems to be the sweet spot.
The other proposals are nice to have, but a compromised mail account won't help against mail confirmations and may not help against 2FA. Keep your 2FA separate (phone and unrelated email address)!

I should have gotten into Bitcoin back in 1992...
noah1987
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 15, 2014, 02:59:03 AM
Last edit: February 15, 2014, 06:09:36 AM by noah1987
 #17112

A miner which use asicminer gen3 chip now on pre-sale, the poster is very famous in Chinese Bitcoin circle. This is the translation of the weibo post:

Miner presale Details:
Miner price :11000 RMB/T (1813 USD/T), full payment in advance.
Power consumption: 600W/T.
If a single miner's speed doesn't meet the design requirements, or beyond the design requirements, in accordance 11000RMB / T price, refund for any overpayment or a supplemental payment for any deficiency.
If you order more than 10T , it is 10000RMB/T.
April 20 is the deadline, if not shipped on time, we'll give you a full refund!
Tel: 13581816335 Zhao Dong's QQ group: 326548639

In the weibo below, one people replys:
So cheap, is it Asicminer's chip?
Zhao replys:"Yes"
Then he ask again:
Asicminer's gen3 haven't tapeout yet, can it mass production in April?
Zhao replys:"Almost"

Sorry for my poor English translation, the original weibo can be found here:
http://weibo.com/1658066713/AwIw85hLy

I have snapshoted the weibo and the chat.
BuildTheFuture
Full Member
***
Offline Offline

Activity: 195
Merit: 100


View Profile
February 15, 2014, 04:36:54 AM
 #17113

Interesting, anyone know if this first batch of Gen 3 hardware will be sold in the US as well? Or only to the Chinese?
bitcoin.newsfeed
Sr. Member
****
Offline Offline

Activity: 378
Merit: 250


View Profile
February 15, 2014, 06:39:35 AM
 #17114


2. Pending withdrawal of your Bitcoins; time lock?


How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. It can be unlocked, but upon doing so an email is sent notifying me that it's been unlocked and it takes a further 7 days or so before a new address can be entered?

^^ THIS. + yubikey

... Question Everything, Believe Nothing ...
ning
Full Member
***
Offline Offline

Activity: 173
Merit: 100



View Profile
February 15, 2014, 06:43:53 AM
 #17115

If we take a look at the numbers, we can see that:

The power consumption of the new chips (3rd gen) is 0.2~0.35 J/GHash [1];
and the power consumption of the chips about to be sold is 600 W/THash = 0.6 J/GHash [2].

The numbers are different, so are the chips, seemingly.


[1] https://bitcointalk.org/index.php?topic=438359.msg4816701#msg4816701
[2] https://bitcointalk.org/index.php?topic=99497.msg5153058#msg5153058
romerun
Legendary
*
Offline Offline

Activity: 1078
Merit: 1002


Bitcoin is new, makes sense to hodl.


View Profile
February 15, 2014, 07:11:12 AM
 #17116

sounds like another pump attempt from chinese again
Lohoris
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500


Bitgoblin


View Profile
February 15, 2014, 08:35:37 AM
 #17117

How about allowing us to specify a withdrawal address that is then locked; coins can only be sent to this address. It can be unlocked, but upon doing so an email is sent notifying me that it's been unlocked and it takes a further 7 days or so before a new address can be entered?
It won't help if your email is compromised, since you might also easily miss the confirmation email (the attacker would delete it).

1LohorisJie8bGGG7X4dCS9MAVsTEbzrhu
DefaultTrust is very BAD.
Lohoris
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500


Bitgoblin


View Profile
February 15, 2014, 08:37:21 AM
 #17118

Here at Havelock we take security issues very seriously.

We have never had any issues with users that enabled 2FA on their account. We have contacted the person that has made the claim that is account has been compromised and are looking to resolve the matter has soon as possible.

Trying to balance ease of use and security is never easy, especially in the Bitcoin realm. We can always add additional security features but those will always slow down the user experience.

So we turn to you, our valued customers, what features would like us to add to our platform?

1. Confirmation email before any action is taken; some but not all actions.

2. Pending withdrawal of your Bitcoins; time lock?

3. Lock account by IP address?

We always value your opinions and we strive to serve the Bitcoin community to the best of our ability.

Also we can assure everyone that it was not an "inside rogue employee"

Thank you,

Support Team
Havelock Investments

Since apparently the email is the weak link, how about adding an optional extra layer via SMS?

1LohorisJie8bGGG7X4dCS9MAVsTEbzrhu
DefaultTrust is very BAD.
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
February 15, 2014, 02:59:26 PM
 #17119

That's pretty scary. Not sure what other attack vectors there might be except for some Havelock employee gone rogue or a security breach at their servers. Maybe your email account is compromised and they used it for some social engineering shenanigans (which would also be hard with you noticing).

Why would a rogue havelock employee sell his shares instead of just the bitcoins from one of the guys with a buy order?

Anyways I would try to contact havelock and see if they can dig up any further info. If it is a security breach on their end then that would be very serious.

Not sure about how 2fa can be breached along with your password. My guess would be an infected pc (keylogger or something).

I don't believe it was an employee. I have no reason to believe Havelock did this internally. But also, I don't believe it was a keylogger. All my other accounts are intact (banks, paypal etc) and not even been touched.

Would have been nice if havelock responded to my support email though !
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
February 15, 2014, 03:00:48 PM
 #17120

Here at Havelock we take security issues very seriously.

We have never had any issues with users that enabled 2FA on their account. We have contacted the person that has made the claim that is account has been compromised and are looking to resolve the matter has soon as possible.

Trying to balance ease of use and security is never easy, especially in the Bitcoin realm. We can always add additional security features but those will always slow down the user experience.

So we turn to you, our valued customers, what features would like us to add to our platform?

1. Confirmation email before any action is taken; some but not all actions.

2. Pending withdrawal of your Bitcoins; time lock?

3. Lock account by IP address?

We always value your opinions and we strive to serve the Bitcoin community to the best of our ability.

Also we can assure everyone that it was not an "inside rogue employee"

Thank you,

Support Team
Havelock Investments

Yes to every one of those. (Instant bitcoin withdrawals worries me a bit)

Also maybe requiring a pin before placing orders/doing anything like btct.co would be nice.

The sad thing was someone took 80BTC or whatever ...... and there was no delay. He was just allowed to keep withdrawing. He must have withdrawn about 20 times in an hour.
Pages: « 1 ... 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 [856] 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 ... 1348 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!