Pages:
Author

Topic: eMunie - page 2. (Read 6641 times)

member
Activity: 112
Merit: 10
Independent Analyst
July 25, 2013, 04:29:23 PM
Mac addresses.... come on.  This is a laughable security feature.  You realize the entire first half is the manufacture.  There goes 1/2 of your entire security.

So by brute forcing last half just on major manufacture's mac's .... you will find chances are quite a few users mac's.

And how is it costly at all?  Timely... maybe depending on how many you can do until security cuts it off.  

Sigh, I don't know where your understanding level is at, read the article, MAC addresses are never going to be used for "Security" and stop making false security claim when you don't even understand a bit how it works.

PS. so as I understand your time isn't worth anything. Ok that's understandble, but my time is worth money, that's why something that takes me time costs me money.

If you make something just slightly hard to be gamed, but not impossible to be gamed, then the fewer people who do game it will just profit much more. I'd thank you for helping me profit, if there were a chance in hell I was going to use eMunie.

Same thing, you don't even understand that it is used to determine supply/demand, nothing to do with your proiftability!

And as long as 99% of the people using eMunie don't know how to spoof Mac Addresses, your own tiny network counts towards nothing and it's not even tired to profitability, not sure how you can even profit by successfully spoofing mac addresses, as far I'm concerned.

Go ahead and cheat, but unless you manage to convince everyone else to do the same (which is not possible) your action literally has zero effect on manipulating the network.

I shall emphasize again:
Quote
We don't need to prevent nerds like you from cheating to have a reliable demand/supply system, we just need to stop the regular Joe from doing so.

As far as security concerned, none of my above 8 ideas suggested are in any way related to security!
And I never talked about security in this thread because I never claimed to understand how it works, so dump assumptions regarding security based on my posts can be totally ignored Wink.
legendary
Activity: 1610
Merit: 1000
Crackpot Idealist
July 25, 2013, 04:15:02 PM
apt-get install macchanger -y

ifconfig eth1 down
macchanger -r eth1
ifconfig eth1 up

rinse repeat
legendary
Activity: 1456
Merit: 1000
July 25, 2013, 08:38:47 AM
Mac addresses.... come on.  This is a laughable security feature.  You realize the entire first half is the manufacture.  There goes 1/2 of your entire security.

So by brute forcing last half just on major manufacture's mac's .... you will find chances are quite a few users mac's.

And how is it costly at all?  Timely... maybe depending on how many you can do until security cuts it off. 
member
Activity: 84
Merit: 10
July 25, 2013, 08:25:34 AM
I am not butthurt, and especially not about your logo as your poor formatting would seem to imply. I called out bitcoin's bullshit within a week of learning of it, and my account was squelched, that is why this one is named Etlase2. I have also not resorted to personal attacks--referring to the fact that you lack significant knowledge in the area of distributed networking is not a personal attack, it is the obvious truth. Whenever I bring this up, you ignore it because you know it is true. Have I called out the emunie devs for being full of shit? Absolutely, as is my right to post on the internet until the local powers that be decide I need to be silenced. I'm not giving emunie any leeway because of promises and wishes, facts need to be provided, plain and simple. When that starts happening, I will shut up about the lack of facts and spend a little time on pointing out flaws if I can find any. To interpret this as being butthurt is your prerogative, but all it does is reek of fanboyism and continuing the lie-filled PR box surrounding cryptocurrencies that started with the huge pyramid scheme known as bitcoin.

Agree, my formatting was pure, in the rush to push post button. What I meant to imply is that you are butthurt because Dan took your ideas and implemented them while you are still musing over your white paper, which Dan still seems to lack to date. I did not imply that you were resorting to personal attacks, it were the other people, I know you just want your factual questions answered, which none of us who have posted inthis thread has been able to answer so far.

And just to clarify, my ideas regarding filtering MAC Addresses are not silly, I was well aware of the fact that it can be gamed, but your too technical mind never seemed to understand the real purpose of doing so - it was to make gaming the system costly and troublesome, not impossible.

People only want to break rules when there is an economic advantage for them to do so. Take that economic advantage away and they wouldn't even bother doing it.

lolol, you're going to check MAC addresses to tell people apart?

If you make something just slightly hard to be gamed, but not impossible to be gamed, then the fewer people who do game it will just profit much more. I'd thank you for helping me profit, if there were a chance in hell I was going to use eMunie.
hero member
Activity: 630
Merit: 500
Bitgoblin
July 25, 2013, 02:19:25 AM
That sounds like a self-fulfilling prophecy, if you make it closed source at first because you don't think it will be popular anyway at first. Not getting popular ever is also a possibility.
Exactly, that's what I tried to explain several times, but he's just a troll and didn't care about that.
He came here, we helped him, he scorned us.
Now he can just fuck off, as far as I'm concerned.
member
Activity: 84
Merit: 10
July 25, 2013, 02:00:00 AM
I'm no C++ coder but  I know people in fairly advanced areas of network security , MAC is completely flawed as per Etlase explains .  Its just a supposed  " Hard code identifier "  that runs on a certain protocol but it is easily faked .

hero member
Activity: 798
Merit: 1000
July 25, 2013, 12:57:47 AM
You may be a good technical know how person, but honestly, I don't think you understand economics. Dan, however, understands both sides and that I know for a fact.

Economics is irrelevant. As I have said, the monetary scheme is tertiary to the security of the protocol. Maybe Dan understands "both", maybe he doesn't, but he has been unwilling or unable to provide a defense for the obvious vulnerabilities in his so-written design. I think the reality is that Dan knows how to program, but he does not know how to truly design a defensible system of this nature. Or perhaps he does, but he has made a very big mistake in attempting to work on the code without fully fleshing out the design. That is going to cost him a lot of time in rewriting the protocol over and over.

Quote
So you think you understand and know everything? How come Decrits is still in paper?

This is of course irrelevant to the topic at hand, but the answer is quite simply because I did take the other route in design, one where I would be confident in the proposed design before attempting to program it. I also spent a significant amount of time researching cryptography, network protocols (and the attacks that can be made on them), economics and monetary systems, and more. Dan hasn't mentioned even a whit about the cryptography or the network protocol used in emunie. This is scary and should be ringing alarm bells.
hero member
Activity: 798
Merit: 1000
July 25, 2013, 12:49:20 AM
I said MAC addresses are not transmitted, not can not. As in, it is not part of the TCP/IP protocol, as in, anyone with the slightest bit of networking background should realize that any "MAC address" received by a peer can not be verified as valid in any way, shape, or form other than it is a 6-byte string. Ergo, it is a completely meaningless metric. "Here are 1 billion 6-byte strings, award me lots of emunie pls"--"prove it"--"here are 1 billion 6-byte strings"...

I picked up on MAC addresses again and again because it is an easy one to poke holes in and show that you are not qualified to be making suggestions of this nature.

I shall go line by line quickly if you want:

1) Total balance of hatchers. -- Relies on a small, unpredictable subset of people who can collude, likely not even on purpose, to create more money for themselves. The basis of new money creation is one where hatchers are paid significantly more of the new money than the rest of the network as a reward for service. How hatchers come to be and how they acquire transactions and how they prove work are all completely unanswered questions, so there is little to do but grossly speculate on how those systems can be abused to put nefarious people in control of the hatchers and collude on purpose.
2-5) Are all essentially based on the "emugraph" concept which is likely unscalable to any reasonable degree (how much information must be kept, how often must this information be accessed, how is a consensus on what this information is reached, etc.) -- and again there is no information at all as to how it works so specific attacks can't be easily surmised at this point. But as I have already stated to your head which seems to be firmly planted in the sand--this will be easily manipulated in an open source protocol. If emunie is to remain closed source, it would be significantly more difficult to game (but far from impossible), but also completely untrustworthy.
6) Is irrelevant
7-8) Both rely on clients reporting honest information in a distributed network. It is a complete failure of design that ignores any notion of a sybil attack. It also somehow presumes that this information can be transmitted and agreed upon by a multitude of nodes who have no way of proving whatsoever that the information is reliable. It is ridiculously easy to game. No cost other than the small amount of time required to reverse engineer a very small part of the network protocol in the case of closed source, or compile in a few extra lines in open source.
member
Activity: 112
Merit: 10
Independent Analyst
July 25, 2013, 12:37:01 AM
If you don't understand that--whatever. If Dan doesn't understand that, emunie has serious problems ahead of it.

So you think you understand and know everything? How come Decrits is still in paper?

You may be a good technical know how person, but honestly, I don't think you understand economics. Dan, however, understands both sides and that I know for a fact.
member
Activity: 112
Merit: 10
Independent Analyst
July 25, 2013, 12:23:53 AM
What stops the client from retrieving MAC address from the device running it and distributing it to the network?

:sigh: Open source software, for one. For two, it would be fairly trivial to detect and intercept a packet prior to it leaving the computer and replace the MAC address with anything, without having access to the source code. For three, whatever mechanism that is used for compiling a list of MAC addresses could be also easily intercepted and have added any number of addresses of a malicious node's choosing. A way around this would be to have some way to hide a private and common signing key in each client (assuming closed source, of course), but that would be fairly easily for any ASM hacker to break, too. If there were some way to obfuscate the signing key in memory from the computer itself (bitcoin could sure benefit from this knowledge because as of yet there is no such thing), even then there are side-channel attacks on ECDSA when one is in control of the hardware and it could eventually be broken, assuming anyone gave a shit to put the effort into it--which I think would be excessively unlikely as few if any would be using this software.

There we go, in the earlier reply you said MAC addresses cannot be transmitted over WAN, and now you are just giving me a bunch of options on how that info can actually be retrieved!

And didn't I tell you in the first place that the MAC Adress thing in place wasn't designed to stop people from cheating? but just to make their life harder bit by bit? Beside, the things you mentioned only nerds like you can do, most people like me have never even heard of it. Which is all we ever need, as long the the majority of eMunie holders don't cheat, the minority who do will have little to zero impact on demand/supply model, which the whole MAC addresses filtering was designed for.

I don't know why you even decided to pick up on MAC addresses again and again, sigh... as I'm sure in my original list of ideas, there were at least 8 of them.
hero member
Activity: 798
Merit: 1000
July 24, 2013, 11:45:14 PM
What stops the client from retrieving MAC address from the device running it and distributing it to the network?

:sigh: Open source software, for one. For two, it would be fairly trivial to detect and intercept a packet prior to it leaving the computer and replace the MAC address with anything, without having access to the source code. For three, whatever mechanism that is used for compiling a list of MAC addresses could be also easily intercepted and have added any number of addresses of a malicious node's choosing. A way around this would be to have some way to hide a private and common signing key in each client (assuming closed source, of course), but that would be fairly easily for any ASM hacker to break, too. If there were some way to obfuscate the signing key in memory from the computer itself (bitcoin could sure benefit from this knowledge because as of yet there is no such thing), even then there are side-channel attacks on ECDSA when one is in control of the hardware and it could eventually be broken, assuming anyone gave a shit to put the effort into it--which I think would be excessively unlikely as few if any would be using this software.
member
Activity: 112
Merit: 10
Independent Analyst
July 24, 2013, 11:34:00 PM
MAC addresses are not transmitted over a WAN.

What stops the client from retrieving MAC address from the device running it and distributing it to the network?
hero member
Activity: 798
Merit: 1000
July 24, 2013, 11:09:13 PM
What I meant to imply is that you are butthurt because Dan took your ideas and implemented them while you are still musing over your white paper, which Dan still seems to lack to date.

I am not musing over a whitepaper having never had an intention to write one. I have been musing over how to make sure everything can work rather than diving into coding something with various and numerous flaws. From this, I have a fairly unique perspective on how to design a cryptocurrency that is not reliant on proof-of-work for its security, nor centralization. The emunie devs could benefit greatly from this, but would apparently rather protect the first-run flawed design and flawed philosophy of programming first and bugfixing second. This *is not* the correct way to do it. There are far too many things that can go wrong. And Dan did not take my ideas, at least not by any stretch that I can figure.

Quote
And just to clarify, my ideas regarding filtering MAC Addresses are not silly, I was well aware of the fact that it can be gamed, but your too technical mind never seemed to understand the real purpose of doing so - it was to make gaming the system costly and troublesome, not impossible.

MAC addresses are not transmitted over a WAN. MAC addresses are used to identify hardware over a local network, or hardware to an ISP to verify that you're a customer. They cannot be used to keep track of people connected to a distributed network. And they are easily spoofed. And there is no way to come to a distributed consensus as to what MAC addresses or IP addresses are connected to the network. It is a completely flawed premise. If you don't understand that--whatever. If Dan doesn't understand that, emunie has serious problems ahead of it.
member
Activity: 98
Merit: 10
July 24, 2013, 10:57:33 PM
The "typical" QT? emunie is not a bitcoin clone, buddy.

I'm not your buddy, guy!

member
Activity: 112
Merit: 10
Independent Analyst
July 24, 2013, 10:37:05 PM
I am not butthurt, and especially not about your logo as your poor formatting would seem to imply. I called out bitcoin's bullshit within a week of learning of it, and my account was squelched, that is why this one is named Etlase2. I have also not resorted to personal attacks--referring to the fact that you lack significant knowledge in the area of distributed networking is not a personal attack, it is the obvious truth. Whenever I bring this up, you ignore it because you know it is true. Have I called out the emunie devs for being full of shit? Absolutely, as is my right to post on the internet until the local powers that be decide I need to be silenced. I'm not giving emunie any leeway because of promises and wishes, facts need to be provided, plain and simple. When that starts happening, I will shut up about the lack of facts and spend a little time on pointing out flaws if I can find any. To interpret this as being butthurt is your prerogative, but all it does is reek of fanboyism and continuing the lie-filled PR box surrounding cryptocurrencies that started with the huge pyramid scheme known as bitcoin.

Agree, my formatting was pure, in the rush to push post button. What I meant to imply is that you are butthurt because Dan took your ideas and implemented them while you are still musing over your white paper, which Dan still seems to lack to date. I did not imply that you were resorting to personal attacks, it were the other people, I know you just want your factual questions answered, which none of us who have posted inthis thread has been able to answer so far.

And just to clarify, my ideas regarding filtering MAC Addresses are not silly, I was well aware of the fact that it can be gamed, but your too technical mind never seemed to understand the real purpose of doing so - it was to make gaming the system costly and troublesome, not impossible.

People only want to break rules when there is an economic advantage for them to do so. Take that economic advantage away and they wouldn't even bother doing it.
hero member
Activity: 798
Merit: 1000
July 24, 2013, 09:21:57 PM
The "typical" QT? emunie is not a bitcoin clone, buddy.
member
Activity: 98
Merit: 10
July 24, 2013, 09:10:23 PM
What does being closed source have anything to do with updates?

Not agreeing with them at all, but closed source allows them to protect IP for as long as possible and prevent competitors from copying code.

I read in the forums another reason for it being closed-source was that it would allow them to push out updates, hard forks / forks, without the need to update clients and whatnot. The coin is not using the normal QT but rather a Java application so the update system will be different I would assume.

Feel free to correct me if I am wrong.

The beta is in java but the final client will be in c++

Yes but will still within a Java application and not using the typical QT.
hero member
Activity: 616
Merit: 500
July 24, 2013, 08:43:33 PM
What does being closed source have anything to do with updates?

Not agreeing with them at all, but closed source allows them to protect IP for as long as possible and prevent competitors from copying code.

I read in the forums another reason for it being closed-source was that it would allow them to push out updates, hard forks / forks, without the need to update clients and whatnot. The coin is not using the normal QT but rather a Java application so the update system will be different I would assume.

Feel free to correct me if I am wrong.

The beta is in java but the final client will be in c++
hero member
Activity: 798
Merit: 1000
July 24, 2013, 08:38:05 PM
I am not butthurt, and especially not about your logo as your poor formatting would seem to imply. I called out bitcoin's bullshit within a week of learning of it, and my account was squelched, that is why this one is named Etlase2. I have also not resorted to personal attacks--referring to the fact that you lack significant knowledge in the area of distributed networking is not a personal attack, it is the obvious truth. Whenever I bring this up, you ignore it because you know it is true. Have I called out the emunie devs for being full of shit? Absolutely, as is my right to post on the internet until the local powers that be decide I need to be silenced. I'm not giving emunie any leeway because of promises and wishes, facts need to be provided, plain and simple. When that starts happening, I will shut up about the lack of facts and spend a little time on pointing out flaws if I can find any. To interpret this as being butthurt is your prerogative, but all it does is reek of fanboyism and continuing the lie-filled PR box surrounding cryptocurrencies that started with the huge pyramid scheme known as bitcoin.
member
Activity: 112
Merit: 10
Independent Analyst
July 24, 2013, 08:25:08 PM
I don't pretend to predict whether your coin will be a success or a failure. I hope it personally makes you a lot of wealth. But you are fighting against the side of freedom and that's not a fight I would want to take up. I can understand how you might be kind of butthurt about the response here to a project you have every right to be proud of, but you ought not be surprised that people who are fervent about transparency wouldn't support a closed-source money.

First, it's not a "coin". Second, it's not mine, I only did graphic stuffs. And I don't intend to fight against anything you've mentioned. This is community project, has never been and will never be mine. Don't understand where did you get hat info from.

Dan, the founder, hasn't posted a thing in this thread.

lol, and no way can I be butthurt, the only person who may be is Etlase2. As a professional designer, I know better than any trolls in this btt forum when something is mimic, similar or just copy-cat. And my logo design clearly falls into none. Besides using the same letter e, there is literally zero similarity with IE logo. If they are similar, then Facebook must have been successful at accusing Twitter of copying their logo icon by simply reverting the "f" letter to "t"!!!

Upset trolls will always do what they can, and that means clinging to personal attacks. Sorry to disappoint, but so far I'm not hurt even slightly ROFL  Roll Eyes
Pages:
Jump to: