Author

Topic: dead (Read 1331 times)

member
Activity: 112
Merit: 10
July 11, 2015, 05:46:09 AM
#26
Update Jan 25, 2016:

keysCrow has been rewritten and is now live. An announcement will be coming.

bump

After much trial, error, sweat, tears and smoke, I'm happy to announce Multisig support for Keyscrow.

We're really glad the community pointed us in the right direction with multisig, as it's even easier and more secure than our previous launch.

Clearnet:
   http://keyscrow.com/
Deepweb:
   http://crow6lupekunor5l.onion/


As always, feedback is always welcome, but first I need a nap.
sr. member
Activity: 392
Merit: 250
June 29, 2015, 05:21:22 AM
#25
Then please define what do you mean by "offline"?

Maybe I'm using improper wording, what I mean is just generating keypairs without using the wallet.
Like this:
http://bitcoin.stackexchange.com/questions/7491/how-to-generate-keypair-completely-offline

No matter the choice of word you use to qualify what you have to offer it would still met with stiff resistance because you are a newbie and your account is very new, I would have suggested that you build your account to at least Member level here and gain some trust before you can introduce something like this rather asking us to discover bugs in your project for bounty.
member
Activity: 112
Merit: 10
June 28, 2015, 09:12:23 PM
#24
I dont think you correctly understand how multisig works or how you would go about setting it up.

He was right. And with a bit more explanation and research, it's clear to me now that
the method that I built this service is pretty well obsolete when you include multisig.

I had the idea to encrypt BTC private keys with public PGP keys, and provide the simplest escrow possible. In my opionion, this method is
still safe, but not knowing about multisig and running with an idea kinda bit me in the arse here. This is why research is important.

I still believe in the right to a free and safe option for escrow, and would still like to see this vision a reality.
In the meantime, it's been suggested to look into partnering with a third-party trust; I'll look into that.

There would be no harm in offering both 1-of-1 alongside 2-of-3, for those who truly can't wrap their head around multisig, or laymen.

That's all for now, thanks to everyone for their input and direction.
legendary
Activity: 1630
Merit: 1000
June 28, 2015, 08:38:46 AM
#23
I dont think you correctly understand how multisig works or how you would go about setting it up. I would be glad to help you if you want the help. feel free to pm me.
member
Activity: 112
Merit: 10
June 28, 2015, 08:22:52 AM
#22
this is not really a good way to escrow

I'd like to know why you think this?
In my view, vendor initiated, end-to-end escrow, where the recipient simply imports an address, delivered to their inbox secured by PGP encryption, apart from a lack of multisig I'm not sure how this service is lacking.
hero member
Activity: 560
Merit: 509
I prefer Zakir over Muhammed when mentioning me!
June 28, 2015, 08:04:35 AM
#21
Then please define what do you mean by "offline"?

Maybe I'm using improper wording, what I mean is just generating keypairs without using the wallet.
Like this:
http://bitcoin.stackexchange.com/questions/7491/how-to-generate-keypair-completely-offline

The offline in that question make sense but not in yours. In yours, keys are not generated offline. Can you tell how the private keys are generated? Anyway, this is not really a good way to escrow but good luck!
member
Activity: 112
Merit: 10
June 28, 2015, 07:56:39 AM
#20
Then please define what do you mean by "offline"?

Maybe I'm using improper wording, what I mean is just generating keypairs without using the wallet.
Like this:
http://bitcoin.stackexchange.com/questions/7491/how-to-generate-keypair-completely-offline
hero member
Activity: 560
Merit: 509
I prefer Zakir over Muhammed when mentioning me!
June 28, 2015, 07:49:18 AM
#19
So if addresses are generated offline, are these addresses generated or send manually to email? If yes, wouldn't that be too time consuming?

The entire process is automated except for disputes, where I'd have to manually split whatever agreement the exchanging parties agree to.

Then please tell what you mean by "offline".
member
Activity: 112
Merit: 10
June 28, 2015, 07:48:05 AM
#18
So if addresses are generated offline, are these addresses generated or send manually to email? If yes, wouldn't that be too time consuming?

The entire process is automated except for disputes, where I'd have to manually split whatever agreement the exchanging parties agree to.

hero member
Activity: 560
Merit: 509
I prefer Zakir over Muhammed when mentioning me!
June 28, 2015, 07:14:11 AM
#17
So if addresses are generated offline, are these addresses generated or send manually to email? If yes, wouldn't that be too time consuming?
member
Activity: 112
Merit: 10
June 28, 2015, 06:26:40 AM
#16
I'm not sure how multisig will work with how I've implemented the technology available. I'm still trying to get a hold of the dev, but when I think about how multisig works and how Keyscrow works, it just doesn't fit.

Keyscrow generates BTC address keypairs offline, and encrypts the private WIF key on the spot with the vendor's PGP key. Finalizing sends the BTC Private key in WIF to the initiator's email address encrypted with with their provided PGP key.

The addresses we generate are offline, and there are no live wallets to move coins, so my thinking is with 2-of-3 how would I charge folks the support fee without being able to move the coins myself? The only time I get involved is to split disputes between seller and buyer, then take my cut. Maybe I'm misunderstanding how multisig works, but in needing 2 'auth' keys there's no way to take a cut after the keys are generated, which would require a live wallet to take a fee before creating multisig key right?

I really don't want to host a live wallet, for various reasons including funds security as well as my own peace of mind.

Maybe if I'm mistaken, someone will set me straight.

People don't trust here that easily though. Which is understandable due to all scamming that has been performed.

Yeah, people tend to get jaded easily after being ripped off. It only takes one person to give you a chance, trouble is finding that person eh? Thanks for the supporting encouragement my friend!
newbie
Activity: 50
Merit: 0
June 27, 2015, 03:17:22 PM
#15
Thank you for this... Looks promising.

I understand where you are coming from with the new forum things... I have been using Bitcoin since 2011 and never used this forum until recently,

People don't trust here that easily though. Which is understandable due to all scamming that has been performed.

As its a free service, You are not losing anything by leaving it open. Just leave it open to people who want to use it and sure enough after some time when people start to trust you more people will use it. You can't force trust on someone.

Partly why I have not joined any Bitcoin related projects, as I am new to the BitcoinTalk community, I doubt anyone trust me.

I do wish you the best of luck with your project however. Just give it time.
member
Activity: 112
Merit: 10
June 27, 2015, 02:29:44 PM
#14
Did you ever put bug bounty funds in escrow.   I will do some penetration testing on your site but have little incentive to do so without funds in escrow.

Sorry, I'm multi-tasking a lot today. I'm getting on this now using that dude's escrow above. brb

nvm that's a closed beta. I don't know how other escrows work, what would be proof to you guys. I'll look for another escrow site.

edit: i'm doing a bunch of reading, and all I see for escrow are limitations which don't allow an open escrow,
http://www.reddit.com/r/BitMarket/wiki/escrow
https://bitcoinhelp.net/know/more/best-escrow-services

I don't know how to prove my honesty here, I have much funds available, here's around 100$ in btc I brought in the other day,
https://blockchain.info/tx/92a60feb4ac00ff3163e61b2c5afb336c2e979403a8081b505e05123cc44eb06
here's a screenshot;
https://i.imgur.com/aTitHbg.png

If I ended up screwing someone from the beginning I can guarantee myself failure which clearly isn't what I desire. I don't know how else to prove this sirs. Any suggestions?
legendary
Activity: 2254
Merit: 1140
June 27, 2015, 01:45:52 PM
#13
Did you ever put bug bounty funds in escrow.   I will do some penetration testing on your site but have little incentive to do so without funds in escrow.
legendary
Activity: 1736
Merit: 1029
June 27, 2015, 11:44:56 AM
#12
The fact that you are not using multisig does not encourage trust in your site. You can simply walk away with every escrow deposit overnight. With multisig you can not do that.

I'm seeing what can be done about this right now. Thanks for the push, this will be no.1 on my to-do for this project.
Put simply: allow multi-sig escrow.  I'm not sure how you would be involved for that though.  Maybe just offer a non-profit free service Smiley
member
Activity: 112
Merit: 10
June 27, 2015, 11:26:35 AM
#11
The fact that you are not using multisig does not encourage trust in your site. You can simply walk away with every escrow deposit overnight. With multisig you can not do that.

I'm seeing what can be done about this right now. Thanks for the push, this will be no.1 on my to-do for this project.
legendary
Activity: 1630
Merit: 1000
June 27, 2015, 08:09:40 AM
#10
The fact that you are not using multisig does not encourage trust in your site. You can simply walk away with every escrow deposit overnight. With multisig you can not do that.
member
Activity: 112
Merit: 10
June 27, 2015, 03:20:05 AM
#9
There are lots of good escrows already, so why should we use yours?  I am not trolling, I am serious, what do you offer that can compete with other escrows?  And imo not charging anything is not exactly a good thing.  Being a escrow can be a pita, it takes work, so why would you do it for free?

Other than free, another good thing is not needing an account to use this. You only provide a PGP key and email address.

Also is the availability on Tor, it's running as a hidden service which I couldn't find others running this way.

Just multiple coin support, free of use, seller-initiated, what else is there to get out of escrow?

Quote from: melody82
Being a escrow can be a pita

haha what?

Quote from: melody82
why would you do it for free

Here's my thinking: The only time that I get involved will be for dispute handling. This is the only charge. Other than that, the server runs itself, there are plenty of free services available, why shouldn't escrow be? So I made a (mostly) automated solution.
sr. member
Activity: 378
Merit: 257
June 27, 2015, 03:09:31 AM
#8
There are lots of good escrows already, so why should we use yours?  I am not trolling, I am serious, what do you offer that can compete with other escrows?  And imo not charging anything is not exactly a good thing.  Being a escrow can be a pita, it takes work, so why would you do it for free?
member
Activity: 112
Merit: 10
June 27, 2015, 03:05:02 AM
#7
I understand your concern. If you have a chance, try out the testnet. If you like it, send me a pm and I'll do what can be done to gain at least one person's trust.

The incentive, I hoping, is the free escrow and multi-coin support.


legendary
Activity: 1288
Merit: 1043
:^)
June 27, 2015, 02:47:02 AM
#6
both the clearnet and TOR versions are loading for me now, but im still hesitant on giving your site a test, because you know, new account, new site, and the lack of trust. there is little incentive to use your service when there are plenty of reputable escrow services available on this forum.
member
Activity: 112
Merit: 10
June 27, 2015, 02:39:09 AM
#5
its not loading and i can guarantee that this isnt a problem on my end.

By the fork, you're right. Well now I feel dumb, I had my hosts file pointing locally.

I'm sorry, can you try again? It's working for me through a proxy browser now. Thanks for your patience.
legendary
Activity: 1288
Merit: 1043
:^)
June 27, 2015, 02:19:10 AM
#4
Quote
you are posting from a brand new account

I realize this is a new account, and knew this was going to be a problem. I never had the need to join a forum and actively participate in it, now that I have something to offer, this is how I'd like to become a part of this one. 

Quote
your site wont even load

It's loading fine on my end on both clearnet and tor hosts, can you try again?

Quote
id suggest escrowing the bug bounty funds

You mean escrow them in advanced? That's a good idea that I'll get started on.

its not loading and i can guarantee that this isnt a problem on my end.
member
Activity: 112
Merit: 10
June 27, 2015, 01:49:29 AM
#3
Quote
you are posting from a brand new account

I realize this is a new account, and knew this was going to be a problem. I never had the need to join a forum and actively participate in it, now that I have something to offer, this is how I'd like to become a part of this one. 

Quote
your site wont even load

It's loading fine on my end on both clearnet and tor hosts, can you try again?

Quote
id suggest escrowing the bug bounty funds

You mean escrow them in advanced? That's a good idea that I'll get started on.
legendary
Activity: 1288
Merit: 1043
:^)
June 27, 2015, 12:43:35 AM
#2
you are posting from a brand new account and your site wont even load, id suggest escrowing the bug bounty funds if you want any real attention for your site. seems suspicious than anything else.
member
Activity: 112
Merit: 10
June 26, 2015, 07:05:51 PM
#1
dead
Jump to: