you never did give me an image or a good enough explanation
It's kind of hard to paint a picture, this is more like looking for signs of arson after a huge fire has been set. The scam sites he ran have different names but all say sydney australia. The common theme is that all the sites use the same email, they all run fine for a while then payments stop. hashie said something like I'll give you a hint and posted a picture of team fortress, then dropped the email that leads to trade fortress. hashie and $username seem to have the same typing pattern when posting. for example
Inputs had been penetration tested regularly, and on security-critical projects I regularly spend upwards of $5000 on a thorough pentest by professional security forums firms.
made a typo.
This is the sticking point with me. TF was smart enough to know that you can't fully secure anything, and even if you make it so hard it isn't worth it, there's always social engineering. Leaving that much sitting around was foolish, and I don't think he's a fool. Maybe I'm giving him too much credit, I don't know.
Yeah, I don't have any explanation other than (i) lazyness (the system wasn't set up to make sending to cold storage easy, and it had to be performed manually), (ii) wanting to keep sufficient amounts on the server so nobody worries/panics, and (iii) about 1500 BTC was deposited within 48 hrs of the hack.
The later systems I've built do make sending to cold storage easier, but for the most recent site it was still an manual process. I intend on doing automatic cold storage transfers (hourly cronjob) for my future projects.
Good luck with your studies!
When you come back, please try to be more level headed instead of throwing little tantrums.
All the best.
hashie vs TF
How could I have missed this thread? Thanks so much Quickseller (and everyone else of course). I will do whatever I can and if you guys ever need anything, just send me a PM.
Enjoy your mod coins
no matter what username you use, certain typing traits will still show.
the admin email is also tied with a website called die2nite. he post something on google about it here
https://groups.google.com/forum/#!msg/mt_die2night/zwnstqaV7L0/1yzH4QcxCVIJ and he posted on the die2nite website here
http://www.die2nite.com/tid/forum#!view/4|thread/1329041
My email ends with "glados.cc" and twinoid suggests me to change it to "glados.cl".
.cc is a valid domain name and I think it's more commonly used compared to .cl.
although he probably isn't still active in it
What things look like is that tf registers sites using fake names, then tries to change it later on. example, hashie is registered to queen elsa now. the Best explanation would be from tf as i'm pretty sure others have done research from his various scams and could elaborate more while we wait for tf to come back from vacation.