Pages:
Author

Topic: [ANN] MangoCoinz Official ANN Thread - Mine cryptocurrencies on you smart phone - page 65. (Read 164585 times)

sr. member
Activity: 245
Merit: 250
CTO at MangoCoinz
Hey everybody,

We've just published MangoCoinz v0.5.2 and it will be available to update in a few hours.
This is a security update, and updating from v0.5.1 will not result in coin loss.

A short time after the update is available, it will be the only version able to interact with the system.

Best regards, Srele from MangoCoinz.
hero member
Activity: 671
Merit: 501
Blockchain and stuff
hey guys, I have an older Nexus 7, and when I try and sign up on the app, it keeps crashing.  Is this due to it not being a phone?  The OS is older too, I haven't updated it in about a year.  Unfortunately, my primary phone is a 4S.

JJ

Hey JJ12880,

Sorry, but the app wasn't made to run on tablets, that's why it crashes.
The iPhone version of the app will be coming soon, so you will be able to mine on your iPhone.

Best regards, Srele from MangoCoinz.

Ok, no worries!  Thanks for the info!

Im excited to try it out.  Best of luck to you and your team!

JJ12880
legendary
Activity: 1162
Merit: 1000
sr. member
Activity: 245
Merit: 250
CTO at MangoCoinz
Where are you from DEVs?

I think they are from Serbia, have you seen their video regarding mangocoinz ?  The guy gets up after sleeping, says I want to mine mangocoinz and runs with 2 phones in his hand lol

Yep, we're from Serbia.

Best regards, Srele from MangoCoinz.
legendary
Activity: 1554
Merit: 1001
Where are you from DEVs?

I think they are from Serbia, have you seen their video regarding mangocoinz ?  The guy gets up after sleeping, says I want to mine mangocoinz and runs with 2 phones in his hand lol
full member
Activity: 165
Merit: 100
Where are you from DEVs?
sr. member
Activity: 245
Merit: 250
CTO at MangoCoinz
newbie
Activity: 4
Merit: 0
Since everyone is talking about source and security lately, let me share my opinions. I'm an Android app and system developer and just recently started looking into cryptocurrencies.

So here are my findings about this coin:
- Reverse-engineering the apk was trivial, devs didn't even use ProGuard to make it harder to read. This is not a problem actually, because even if the app is obfuscated, it's not much harder to understand.
- The coin is centralized and all data is probably stored in a database without a blockchain and proof-of-anything. This system can be hacked, devs can do bad things (though they seem to be honest).
- Even if you don't have the source, there are a lot of ways to cheat the system on Android.
- Coding a desktop implementation based on the reverse-engineered apk is trivial, one can sync without using an Android device at all. Add proxies and bots to this and you can easily "mine" hundreds of coins per day. You can also signout anyone just by knowing the username. It might be possible to sync an arbitary amount of coins to any username too, this depends on how much checking is implemented. I guess it could work since if one used random device data, the system would think the user started using another device (too).
- The app uploads the following information about a device: device model and name, IMEI number and if the device is rooted. All of them can be faked on a rooted device. I understand that IMEI is used for checking multi-account usage on one device, but not in plaintext, it should be hashed and only that value sent to the server. What if the server is hacked, IMEI numbers are stolen and sold on the black market? I personally wouldn't be happy.
- Up until v0.5.0b, only salted password hashes were sent to the server, providing a secure authentication. The salt was generated by the device randomly upon signup. Since v0.5.1 update, passwords are sent directly to the server without hashing. This causes a security risk as devs can now save passwords in plaintext, which is problematic if you use the same password elsewhere, let's say for your e-mail account, not to mention they know your e-mail address too.
- Probably this was introduced to ease server load as there's no need for another API call to get the salt.
- Fortunately, communication between the device and the server is done through the secure HTTPS protocol. However, the server uses a self-signed certificate (trusted certificates are not free) and the app is coded not to reject unauthorized certificates for this very reason. This makes it possible to successfully execute a man-in-the-middle attack and steal passwords which aren't sent hashed anymore. This kind of attack is very common on public Wi-Fi access points, such as a coffee shop, airport, etc.

By all this said, please do not think I'm against this coin or anything. People just have to know the truth. Even if it might have sounded harsh at places, I appreciate developers' work, because this really is a unique idea. Unfortunately without a real blockchain and proof-of-anything system there's no way to properly secure the system. You can make it harder to cheat, but not impossible.
hero member
Activity: 1036
Merit: 504
Becoming legend, but I took merit to the knee :(
Might be time you guys go open-source and let people help with bugs more. I mean it is an Android app so the source is available if you want it, no sense in keeping it closed any longer.
Bump.

Crypto is only strong if you can prove it openly. If there's a bug/flaw and you keep it closed you're risking the whole project.
Make it open and let the community help improve it. Like I said before, it's an Android app, the source is readily available anyways so might as well invite the community.

if you had the source you could fake the accelerometer requirements.

cheaty haxors Cheesy

So much this, one can simply modify the code and make it simpler for him to "mine" coins. Then again, whats with the posts recently trying to downplay the dev? I'm pretty sure the devs are coming up with bugs fixes and better application and features, take the upcoming iphone app for instance
legendary
Activity: 1204
Merit: 1000
to your stations, man the pineapples!!!
Might be time you guys go open-source and let people help with bugs more. I mean it is an Android app so the source is available if you want it, no sense in keeping it closed any longer.
Bump.

Crypto is only strong if you can prove it openly. If there's a bug/flaw and you keep it closed you're risking the whole project.
Make it open and let the community help improve it. Like I said before, it's an Android app, the source is readily available anyways so might as well invite the community.

if you had the source you could fake the accelerometer requirements.

cheaty haxors Cheesy
full member
Activity: 165
Merit: 100
1) I need to know what the official time of APP to understand what is the beginning and the end of the 24-hour cycle.

2) Why the app needs to determine the phone number and codes of the device?

This is extremely risky Huh
legendary
Activity: 1672
Merit: 1010
Might be time you guys go open-source and let people help with bugs more. I mean it is an Android app so the source is available if you want it, no sense in keeping it closed any longer.
Bump.

Crypto is only strong if you can prove it openly. If there's a bug/flaw and you keep it closed you're risking the whole project.
Make it open and let the community help improve it. Like I said before, it's an Android app, the source is readily available anyways so might as well invite the community.

while some might help improve, more likely we see all the scamcoin makers clone it and start pumping daily new *Coinz in altcoin seciton.  this would be enough to kill real development here imho.  The devs from what i see are making something original and is entirely their own work and not another crapcoin cloned from bitcoin/peercoin like the hundreds others here. 
too many scammers waiting to make a quick profit from easily available source, and are able to quickly shill their scamcoins and ipos with sockpuppets, and then the arrangements they have with exchanges to get their coins listed/ipo means the real hard working and honest devs and users stand to lose out, while the scammers would continue to profit with something they have contributed nothing to.
 
I think there maybe a place something like this to be opensourced and decntralized later on, but not while the project is still finding its feet, its doesnt need its hard work complicated and quickly devalued. 
sr. member
Activity: 312
Merit: 250
Graphic Designer & Programmer
Might be time you guys go open-source and let people help with bugs more. I mean it is an Android app so the source is available if you want it, no sense in keeping it closed any longer.
Bump.

Crypto is only strong if you can prove it openly. If there's a bug/flaw and you keep it closed you're risking the whole project.
Make it open and let the community help improve it. Like I said before, it's an Android app, the source is readily available anyways so might as well invite the community.
newbie
Activity: 19
Merit: 0
Tried signing up 2 New ppl different devices each time got a message saying that there is only allowed one user per device? This seems to be a bugg

¨

You can use only one account per device. It is not a bug.

im willing to bet these users had the app installed on their device and registered with a different username hence that error message and they just dont want to admit it
the information used for registration uses a value unique to each device and there is no possibility in a different device having the same information as another
infact most governments have bans placed on import/export of devices containing the same aforementioned duplicate information used for device identification

do you mean device's IMEI number?
exactly, glad someone does their research Cheesy
member
Activity: 84
Merit: 10
Tried signing up 2 New ppl different devices each time got a message saying that there is only allowed one user per device? This seems to be a bugg

¨

You can use only one account per device. It is not a bug.

im willing to bet these users had the app installed on their device and registered with a different username hence that error message and they just dont want to admit it
the information used for registration uses a value unique to each device and there is no possibility in a different device having the same information as another
infact most governments have bans placed on import/export of devices containing the same aforementioned duplicate information used for device identification

do you mean device's IMEI number?
newbie
Activity: 19
Merit: 0
Tried signing up 2 New ppl different devices each time got a message saying that there is only allowed one user per device? This seems to be a bugg

¨

You can use only one account per device. It is not a bug.

im willing to bet these users had the app installed on their device and registered with a different username hence that error message and they just dont want to admit it
the information used for registration uses a value unique to each device and there is no possibility in a different device having the same information as another
infact most governments have bans placed on import/export of devices containing the same aforementioned duplicate information used for device identification
sr. member
Activity: 245
Merit: 250
CTO at MangoCoinz
Tried signing up 2 New ppl different devices each time got a message saying that there is only allowed one user per device? This seems to be a bugg


Hey j22904,

Could you please send us the models of the phones that you are trying to signup to [email protected], and we will see how we can help you.

Best regards, Srele from MangoCoinz.
legendary
Activity: 1148
Merit: 1000
A Wound in Eternity
I just got the transfer, it was quite quick, and I like the idea that you use a nickname instead of a string of numbers  Smiley
legendary
Activity: 1148
Merit: 1000
A Wound in Eternity
I just sent 993 or so Mangocoinz to EBK1000 which is my nickname. How long does it take for it to show up on the blockchain
Pages:
Jump to: