Pages:
Author

Topic: Blockchain.info - Bitcoin Block explorer & Currency Statistics - page 53. (Read 482537 times)

legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
What happened to the formfield at blockchain.info? I told others they can put their address or transaktion id in there to check transaktion but now i dont see this field anymore.
Is there a reason for this?
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
I think, judging from what i was told, that the message can only be made from someone who has access to the sending address.

A note can be added by the person who submits a transaction to blockchain.info which hasn't been seen on the network previously. Signature verification using a signed message is better because a) you are trusting that blockchain.info is not lying to you b) a transaction could be intercepted very quickly from its true originator before it reaches our node and manually submitted to us including a note.

But it does serve a reasonable proof if you are ok with the above.

Hm... then i will demand a real proof. If there are possibilities to interfere its not good.

Thanks for clearing this up...
hero member
Activity: 910
Merit: 1005
I think, judging from what i was told, that the message can only be made from someone who has access to the sending address.

A note can be added by the person who submits a transaction to blockchain.info which hasn't been seen on the network previously. Signature verification using a signed message is better because a) you are trusting that blockchain.info is not lying to you b) a transaction could be intercepted very quickly from its true originator before it reaches our node and manually submitted to us including a note.

But it does serve a reasonable proof if you are ok with the above.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
Which client signed the tx? I found something like this in log:

Those non-standard signatures should have been fixed a while back. I don't think it is the web interface producing those, possibly another client using /pushtx or an old iphone app. I've added IsCanonicalSignature() checks to the javascript signer and /pushtx which will be deployed in the next update all the signatures I tested produced with the web interface and android app passed but will have to wait and see if anyone starts complaining, regardless those transactions should not be broadcast anymore since the majority of nodes will rejected them.

Are you the owner of blockchain.info? If so can you say word about the description of transactions that can be done. I think, judging from what i was told, that the message can only be made from someone who has access to the sending address. So it delivers the same security like signing a message to an address. Because you have to have access to that address to be able to send money and to be able to sing messages/make a notice on a transaction. Thats right?
hero member
Activity: 910
Merit: 1005
Which client signed the tx? I found something like this in log:

Those non-standard signatures should have been fixed a while back. I don't think it is the web interface producing those, possibly another client using /pushtx or an old iphone app. I've added IsCanonicalSignature() checks to the javascript signer and /pushtx which will be deployed in the next update all the signatures I tested produced with the web interface and android app passed but will have to wait and see if anyone starts complaining, regardless those transactions should not be broadcast anymore since the majority of nodes will rejected them.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ask her to sign a message with the priv key

She wrote her username into the transaction, so that i could see it in blockchain.info. As long as she have no donor it should be proof that its her address, so this forumuser paid this. At least i understand it now this way that only the real sender can put in a message. So it should be a proof as good as signing a message. Correct me if im wrong...

Just ask her to sign a message using the key. It's common practice. Why rely on something you don't know much about if you have something secure?

So you say it is unsecure? I asked in this thread and i was told its not possible to put your username to another users transaction. At least as long as you dont have access to his wallet. But if its this far a signed message cant help too anymore. So for now it looks like a proof to me. If you see a risk please explain where it lies.
donator
Activity: 2772
Merit: 1019
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ask her to sign a message with the priv key

She wrote her username into the transaction, so that i could see it in blockchain.info. As long as she have no donor it should be proof that its her address, so this forumuser paid this. At least i understand it now this way that only the real sender can put in a message. So it should be a proof as good as signing a message. Correct me if im wrong...

Just ask her to sign a message using the key. It's common practice. Why rely on something you don't know much about if you have something secure?
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ask her to sign a message with the priv key

She wrote her username into the transaction, so that i could see it in blockchain.info. As long as she have no donor it should be proof that its her address, so this forumuser paid this. At least i understand it now this way that only the real sender can put in a message. So it should be a proof as good as signing a message. Correct me if im wrong...
b!z
legendary
Activity: 1582
Merit: 1010
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ask her to sign a message with the priv key
full member
Activity: 140
Merit: 100
Which client signed the tx? I found something like this in log:

ERROR: Non-canonical signature: S value negative
ERROR: CScriptCheck() : d1b6f78247cfb448a7e9b00964d801fc02abb5f2c80423053634e01be26d6125 VerifySignature failed
ERROR: CTxMemPool::accept() : ConnectInputs failed d1b6f78247cfb448a7e9b00964d801fc02abb5f2c80423053634e01be26d6125

check it out:
http://blockchain.info/tx/d1b6f78247cfb448a7e9b00964d801fc02abb5f2c80423053634e01be26d6125?show_adv=true

sometimes other wrong type of signature appeared, all comes from blockchain.info

Edit: Add another one:
ERROR: Non-canonical signature: R value negative
ERROR: CScriptCheck() : e65f7625cc2f2f280e5af5b6c320c9e8a978000a70d61e399210890e435177c4 VerifySignature failed
ERROR: CTxMemPool::accept() : ConnectInputs failed e65f7625cc2f2f280e5af5b6c320c9e8a978000a70d61e399210890e435177c4

http://blockchain.info/tx/e65f7625cc2f2f280e5af5b6c320c9e8a978000a70d61e399210890e435177c4?show_adv=true

and a5ab5a894ac936771f716357c92660acedc5c35b915b9b5e599380c0a1252800 ...
hero member
Activity: 910
Merit: 1005
The Chrome App needs translations.

Please add them  Wink

Added in the latest version (Needs to be set in Account Settings).
donator
Activity: 2772
Merit: 1019
No! people should read and pay only from addresses they control  Roll Eyes

Yes, and the world should be a better place Smiley
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
- snip -
In the future, to avoid this confusion, you should really give each sender a different bitcoin address to send their bitcoins to you.  That way you know immediately who sent the bitcoins since you know who you gave the address to.

Its the address for a groupbuy. So it wouldnt work out to create unique addresses for each payment.

I disagree.



Till now its 69 orders. So creating a new address for everyone and then having to collect all bitcoins again to order sounds like a bit of work for me.
Edit: And not to forget the mails asking for an address, creating this, sending back and so on. It looks easier to me to receive the payment, get the claim and a signature i can check here for example: http://brainwallet.org/?vrMsg=sf#verify
rme
hero member
Activity: 756
Merit: 504
The Chrome App needs translations.

Please add them  Wink
legendary
Activity: 3472
Merit: 4794
- snip -
In the future, to avoid this confusion, you should really give each sender a different bitcoin address to send their bitcoins to you.  That way you know immediately who sent the bitcoins since you know who you gave the address to.

Its the address for a groupbuy. So it wouldnt work out to create unique addresses for each payment.

I disagree.

hero member
Activity: 910
Merit: 1005
Are you going to add the P2P Fallback mode also on the Chrome app?

I suspect it could be done with a native client plugin but if it needs to be dependant on a native plugin then it might as well just be a standalone desktop lite client. May be some time in the future but for the moment my priority is to revise the iphone app and then get multisig working and/or support for a hardware wallet.

If some key is a "compressed" one, and you pass that "04..." string to someone else,
who then creates a multisig-address based on the "04..." key you gave him, then you
will NOT be able to sign it later!

I think this is just a limitation of Bitcoin-Qt though? if the client tests both the compressed and compressed version of the key signing should be possible. The correct pub key will now been shown now.

Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

Usernames were spidered from signatures on this forum and since you can put anything in your own signature it isn't good verification. Notes also be added when a transaction is submitted to blockchain.info which is slightly better proof because because the person that submitted it is likely to be the signer, however it still not 100% verification. You can sign and verify a message in the web interface.

------

Changes:

- The mnemonic phrase now encodes both the wallet identifier and password and can be used to restore a wallet at https://blockchain.info/wallet/recover-wallet

- Blockchain.info will not be enforcing the new 54uBTC minimum output size. However the transaction creation routine has been altered to avoid creating any change outputs less than 0.01 BTC, using more outputs if necessary. This will avoid none standard transactions being created accidentally as defined by the new Bitcoin-Qt rule. The apps will also need adjusting.

- mBTC display can be enabled in account settings

- You can no longer add an alias without first verifying an email address.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ah, I misunderstood what you were asking.  I wouldn't call it "equivalent of verifying an address with a signature", but it is might be sufficient for the purposes you are trying to use it.

Are you willing to post (or PM) the transactionID here, or would you prefer to keep that information private?  In the future, to avoid this confusion, you should really give each sender a different bitcoin address to send their bitcoins to you.  That way you know immediately who sent the bitcoins since you know who you gave the address to.

Its the address for a groupbuy. So it wouldnt work out to create unique addresses for each payment. Thats why i let them verify the sending address.
But this special payment is coming from the username that its signed with because no other person could fake this.

No! people should read and pay only from addresses they control  Roll Eyes

I think its possible to sign a message with a blockchain.info wallet. The buyer thought that the message she sent with the transaction was the verification i think. But when its a similar proof... Smiley
yxt
legendary
Activity: 3528
Merit: 1116
No! people should read and pay only from addresses they control  Roll Eyes
legendary
Activity: 3472
Merit: 4794
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?

Ah, I misunderstood what you were asking.  I wouldn't call it "equivalent of verifying an address with a signature", but it is might be sufficient for the purposes you are trying to use it.

Are you willing to post (or PM) the transactionID here, or would you prefer to keep that information private?  In the future, to avoid this confusion, you should really give each sender a different bitcoin address to send their bitcoins to you.  That way you know immediately who sent the bitcoins since you know who you gave the address to.
legendary
Activity: 2674
Merit: 1083
Legendary Escrow Service - Tip Jar in Profile
Only a question about the messages that sometimes are above a transaction. public note. When such transaction shows the username of a user here in the forum then thats a proof when this forum user claims the btc are coming from him. I mean that can only be edited or set by the real owner of the sending address right? Its an equivalent of verifying an address with a signature?

I don't think this is true.

I got a payment and need to confirm that the user in forum that claims that its her payment is the real person. She added her username in the transaction. So now im wondering if that is proof enough. Can only the owner of the address set this note?
Pages:
Jump to: