Pages:
Author

Topic: Blockchain.info - Bitcoin Block explorer & Currency Statistics - page 60. (Read 482537 times)

hero member
Activity: 560
Merit: 500
I am the one who knocks
Can you confirm that the server will NOT send the encrypted blob until 2FA is successful (assuming it is on of course)??

Also for clarity can you state how 2 level encryption could have possibly helped this scenario?
I cannot see how that is possible.  Everything happens in the browser.  So, I imagine, the encrypted blob must be sent to the browser once it visits the URL.
Then what is the point of 2FA?  In that scenario how does it protect you?  You can't base the encryption off the 2FA value because it is ever changing.
donator
Activity: 668
Merit: 500
Can you confirm that the server will NOT send the encrypted blob until 2FA is successful (assuming it is on of course)??

Also for clarity can you state how 2 level encryption could have possibly helped this scenario?
I cannot see how that is possible.  Everything happens in the browser.  So, I imagine, the encrypted blob must be sent to the browser once it visits the URL.
donator
Activity: 668
Merit: 500
@piuk
Can you give your opinion on this?
https://bitcointalksearch.org/topic/m.1816127
Is it possible?

The site has not been compromised in any way. I think some users are possibly using the same usernames on bitcointalk as alias's to blockchain wallets in combination with weak passwords and using the same password on other bitcoin sites.

As always I recommend to never reuse the same password on any other websites and to use the chrome/firefox browser extension (not the verifier).

Thanks piuk.  How do you think thieves are getting wallet URLs?  My friend never logged on since it was setup 6 months ago, and didn't use an alias (and has never heard of bitcointalk...).  Yet she had 7 coins stolen last week.  Lots of similar reports going round.
hero member
Activity: 560
Merit: 500
I am the one who knocks
@piuk
Can you give your opinion on this?
https://bitcointalksearch.org/topic/m.1816127
Is it possible?

The site has not been compromised in any way. I think some users are possibly using the same usernames on bitcointalk as alias's to blockchain wallets in combination with weak passwords and using the same password on other bitcoin sites.

As always I recommend to never reuse the same password on any other websites and to use the chrome/firefox browser extension (not the verifier).

Can you confirm that the server will NOT send the encrypted blob until 2FA is successful (assuming it is on of course)??

Also for clarity can you state how 2 level encryption could have possibly helped this scenario?
legendary
Activity: 1666
Merit: 1000


The site has not been compromised in any way. I think some users are possibly using the same usernames on bitcointalk as alias's to blockchain wallets in combination with weak passwords and using the same password on other bitcoin sites.

As always I recommend to never reuse the same password on any other websites and to use the chrome/firefox browser extension (not the verifier).


In other news... the site has been down pretty much all day though, right? Any news?

read up about 5 posts  Roll Eyes
full member
Activity: 238
Merit: 100
RMBTB.com: The secure BTC:CNY exchange. 0% fee!


The site has not been compromised in any way. I think some users are possibly using the same usernames on bitcointalk as alias's to blockchain wallets in combination with weak passwords and using the same password on other bitcoin sites.

As always I recommend to never reuse the same password on any other websites and to use the chrome/firefox browser extension (not the verifier).


In other news... the site has been down pretty much all day though, right? Any news?
hero member
Activity: 767
Merit: 500
Piuk, can you comment on the Amazon S3 backup regime for deleted private keys - i.e. if I were to upload a private key and then later on delete it - are old copies of the encrypted wallet file still stored on S3 - and if so, for how long?

Regards,

Will
staff
Activity: 4256
Merit: 1208
I support freedom of choice
hero member
Activity: 910
Merit: 1005
@piuk
Can you give your opinion on this?
https://bitcointalksearch.org/topic/m.1816127
Is it possible?

The site has not been compromised in any way. I think some users are possibly using the same usernames on bitcointalk as alias's to blockchain wallets in combination with weak passwords and using the same password on other bitcoin sites.

As always I recommend to never reuse the same password on any other websites and to use the chrome/firefox browser extension (not the verifier).
vip
Activity: 1316
Merit: 1043
👻
Hopefully it comes up soon. I don't want to have to be bothered with downloading the blockchain on qt :/
hero member
Activity: 924
Merit: 502
https://twitter.com/blockchain

The DDOSer discovered our real server IP and was therefore able to attack us direct circumventing cloudflare (and the disposable nginx proxies blockchain switched to for a while). The Site is running privately but before it is made publicly accessible again some changes need to be made in order to ensure the same situation doesn't happen again. Approximate ETA 30 minutes - 1 hour.

http://i.imgur.com/R4i7ddC.png

Thanks for keeping the community informed - much appriciated.
staff
Activity: 4256
Merit: 1208
I support freedom of choice
@piuk
Can you give your opinion on this?
https://bitcointalksearch.org/topic/m.1816127
Is it possible?
legendary
Activity: 1666
Merit: 1000
Have to follow on twitter it seems  Smiley
hero member
Activity: 910
Merit: 1005
https://twitter.com/blockchain

The DDOSer discovered our real server IP and was therefore able to attack us direct circumventing cloudflare (and the disposable nginx proxies blockchain switched to for a while). The Site is running privately but before it is made publicly accessible again some changes need to be made in order to ensure the same situation doesn't happen again. Approximate ETA 30 minutes - 1 hour.

http://i.imgur.com/R4i7ddC.png
legendary
Activity: 1666
Merit: 1000
Still FUBAR this morning...
member
Activity: 112
Merit: 10
Any news on what's going on with the site?  Maintenance?  It's been down for awhile for me ...
full member
Activity: 154
Merit: 100
yes, blockchain does have the wrong price.

is the wallet itself working right now?  i was gonna use blockchain.info to email somebody a bitcoin but everything on the site seems screwed up and mad errors
The ticker price was off too, screwed up one of my orders...
member
Activity: 112
Merit: 10
The sending part works just fine, just be sure you're not using their exchange rate to calculate the amount you're sending.  (since it's still showing $91).
hero member
Activity: 615
Merit: 500
yes, blockchain does have the wrong price.

is the wallet itself working right now?  i was gonna use blockchain.info to email somebody a bitcoin but everything on the site seems screwed up and mad errors
member
Activity: 112
Merit: 10
New issue: the wallet thinks the current rate is $91 when in fact it is (right now anyway) $68.5 ... so all of the balances are screwed up. 

Is this happening with anyone else's blockchain.info wallet?
Pages:
Jump to: