Pages:
Author

Topic: [ANN] NEX :: Nxt Reimagined - Industrial Strength - Imagine Fairness! - page 18. (Read 102001 times)

legendary
Activity: 868
Merit: 1000
Cryptotalk.org - Get paid for every post!
Per BitcoinTalk guidelines,  you must visit the website to express interest:  http://www.nexcoin.net/

Earn a stake in NEX by leaving you email and by referring more friends!

legendary
Activity: 1181
Merit: 1002
If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.

LOL

Yeah i cant believe that FC actually believes it either

I really sorry that I was trolling this guy, he needs help of a professional psychologist. Let's leave him alone, it's not funny anymore...

I totally and truly agree, that's why I stopped a couple days ago as well.
FrictionlessCoin Carlos Perez without a doubt does have real mental issues.
Probably paired with a huge amount of real life problems he is hardly capable to deal with - and he most likely has kids.

Ignoring him is best thing to do and I really hope that someone is capable to help him in the real (not virtual) world. At the same time I hope that there are not too many suffering because of him and his actions.

All I can say is good luck Carlos.


member
Activity: 105
Merit: 10
free dinheiros, why not.
hero member
Activity: 532
Merit: 500
If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.

LOL

Yeah i cant believe that FC actually believes it either

That's like saying any password can be compromised.

Well obviously..
legendary
Activity: 2142
Merit: 1010
Newbie
If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.

LOL

Yeah i cant believe that FC actually believes it either

I really sorry that I was trolling this guy, he needs help of a professional psychologist. Let's leave him alone, it's not funny anymore...
sr. member
Activity: 420
Merit: 250
Kamehameha!!!
I was scamed by Neon's any chance of a free buy in?
full member
Activity: 238
Merit: 100
If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.

LOL

Yeah i cant believe that FC actually believes it either
full member
Activity: 322
Merit: 102
I think i already posted i'm interested but can't really remember.

But if i didn't, I'm interested! Smiley
hero member
Activity: 798
Merit: 500
If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.

LOL
hero member
Activity: 802
Merit: 501
hero member
Activity: 854
Merit: 1001
Interesting use of the word "demand"

Anyone apart from the FCs and freshly created, no activity accounts want to weigh in on the demand for nex?

Come on, lets see that demand, kids.
legendary
Activity: 868
Merit: 1000
Cryptotalk.org - Get paid for every post!
The genesis account passphrase was spectacularly weak, although long.

The opening line of 1984 ?
I'm surprised it wasn't cracked in December, TBH.

So, there's no real surprise here, DoctorEvil has simply highlighted a known issue. Password security needs to be ramped up, either by making users choose better passphrases or by beefing up password security in the client. or both...

Security is obviously not a top priority for Nxt.

Explains why there is a demand for NEX.
hero member
Activity: 854
Merit: 1001
Interested

How did u find this thread, possible sock puppet dude?
newbie
Activity: 2
Merit: 0
hero member
Activity: 854
Merit: 1001
The genesis account passphrase was spectacularly weak, although long.

The opening line of 1984 ?
I'm surprised it wasn't cracked in December, TBH.

So, there's no real surprise here, DoctorEvil has simply highlighted a known issue. Password security needs to be ramped up, either by making users choose better passphrases or by beefing up password security in the client. or both...

So stop waving your arms around and claiming that the sky is falling, FC.
legendary
Activity: 868
Merit: 1000
Cryptotalk.org - Get paid for every post!
Quote

Fun fact: the genesis account http://www.mynxt.info/blockexplorer/details.php?action=ac&ac=1739068987193023818 that credited all the original stakeholders used this passphrase:

Quote from: 1984 - George Orwell
It was a bright cold day in April, and the clocks were striking thirteen.

As I've pointed out in my first post https://nextcoin.org/index.php/topic,3608.msg34002.html

1.5% of NXT accounts are trivially crackable with a 15 line script and a widely-available passphrase list (the rockyou leak dataset).

I've let my script keep running on more lists since then and at current measure have recovered the passphrases of a little more than 3% of all accounts that have ever been used.  Since genesis ~8M NXT has been sent to these "weak" accounts.

As I pointed out in my original post, my motivation for doing this was to investigate the root cause of the rash of thefts that had been reported (since I suspected weak passphrases) as well as prod the devs to drop the brainwallet-based key management scheme as the default option.  I actually cracked the genesis account a few days ago but originally thought my code was just buggy when I saw it's balance was negative ... LOL.

As a side note, I should point out that widespread knowledge of the genesis account key isn't a security issue per se.  Although I'd advise devs to be defensive moving forward about the possibility of integer overflow/underflow whenever dealing with amounts/fees now that the whole world has access to an account with a negative balance.



Breaking news... Nxt genesis account compromised.  3% of all Nxt accounts already compromised. 

Breaking news...FCs spread their usual FUD.
And don't acknowledge the source:
https://nextcoin.org/index.php/topic,3752.0.html

In other words, don't worry too much.

I really don't thing you understand by the statement:

Quote
I've let my script keep running on more lists since then and at current measure have recovered the passphrases of a little more than 3% of all accounts that have ever been used.  Since genesis ~8M NXT has been sent to these "weak" accounts.

What he said was that after running his 15 line script since January 27th, he has discovered the secret phrase for 3% of all Nxt accounts.  He is saying that 8million NXT has been compromised by his simple 15 line script. 

He has of course said that he has not drained those accounts.   However, he did publish the code, so someone else could do so.   Furthermore,  a more sophisticated script running longer could compromise over time even more Nxt accounts.

If the genesis account can be compromised in such a short time, then almost every Nxt account can be compromised.
newbie
Activity: 1
Merit: 0
newbie
Activity: 4
Merit: 0
newbie
Activity: 5
Merit: 0
newbie
Activity: 4
Merit: 0
Pages:
Jump to: