Pages:
Author

Topic: Hashie.co - Cloud Mining from 0.0012 BTC / GH | NEW: AMHash | FREE 10 GH - page 8. (Read 160426 times)

legendary
Activity: 3654
Merit: 8909
https://bpip.org
So trade is a serial scammer?

Or an easy target to frame. I'm not defending him, just not sure if I can see a conclusive proof that the person using that e-mail address actually had control of said e-mail address and was the same person as TF. Does the Chromium bug report page validate poster's e-mail address?
hero member
Activity: 868
Merit: 1000
*update looks like hashie had control of email since it was started https://code.google.com/p/chromium/issues/detail?id=429395 Security: Window.opener bypasses same origin policy    
   1 person starred this issue and may be notified of changes.    Back to list
Status:     WontFix
Owner:    ----
Closed:     Nov 2
Type-Bug-Security


Add a comment below
     
Reported by [email protected], Oct 31, 2014

VULNERABILITY DETAILS
Opened windows (through normal hrefs with target="_blank") can modify window.opener.location and replace the parent webpage with something else, even on a different origin (bypassing same origin policy).

While this doesn't allow script execution, it does allow phishing attacks that silently replace the parent tab (which a user already mentally trusts).

window.opener.location should not be modifiable if on a different origin.

VERSION
Chrome Version: 37.0.2062.94 + stable
Operating System: Ubuntu

REPRODUCTION CASE

https://hashie.co/chrome/demo.html

That could have been someone completely different just using that as their username there. It's not though. It is TradeFortress as the same user made an earlier post here:

Quote
Oct 16, 2013
#2 [email protected]

I am also experiencing this bug on my website, https://coinchat.org .

So, there's now a definite link between TradeFortress and hashie. Interesting.


So trade is a serial scammer?
sr. member
Activity: 518
Merit: 250
has anyone been able to withdraw from magic miners btw ? Smiley i mean frostcoins should mean we are early investors in magic mining era, we deserve some respect at least!  Cool why even bother with this otherwise... oh,well, still a long way for me with my frostcoins to a paid magic miner...  Grin
legendary
Activity: 826
Merit: 1004
*update looks like hashie had control of email since it was started https://code.google.com/p/chromium/issues/detail?id=429395 Security: Window.opener bypasses same origin policy    
   1 person starred this issue and may be notified of changes.    Back to list
Status:     WontFix
Owner:    ----
Closed:     Nov 2
Type-Bug-Security


Add a comment below
     
Reported by [email protected], Oct 31, 2014

VULNERABILITY DETAILS
Opened windows (through normal hrefs with target="_blank") can modify window.opener.location and replace the parent webpage with something else, even on a different origin (bypassing same origin policy).

While this doesn't allow script execution, it does allow phishing attacks that silently replace the parent tab (which a user already mentally trusts).

window.opener.location should not be modifiable if on a different origin.

VERSION
Chrome Version: 37.0.2062.94 + stable
Operating System: Ubuntu

REPRODUCTION CASE

https://hashie.co/chrome/demo.html

That could have been someone completely different just using that as their username there. It's not though. It is TradeFortress as the same user made an earlier post here:

Quote
Oct 16, 2013
#2 [email protected]

I am also experiencing this bug on my website, https://coinchat.org .

So, there's now a definite link between TradeFortress and hashie. Interesting.
hero member
Activity: 526
Merit: 500
Its all about the Gold
19 womerah st
turramurra,new south wales,australia 2074

inputsio starts august 15th 2013
CoinLenders - bitcoin bank script / functional demo
Domain Name: coinlenders.com Creation Date: 03/23/2013 12:39:00 AM
CoinChat - chat network integrated with Bitcoin   
   Contact me via email! [email protected] | GPG KeyID 63DD3F13

now can add hashie and none are still active as far as i know.
newbie
Activity: 54
Merit: 0

WOW how long did it take you to write this up lol i almost finish a cigarate reading this lol, in anycase i see what is being said and should always be vigilant. If i ever have more than 1 bitcoin i will make sure i buy a cheap computer get bitcoin wallet and send my stuff there and never keep computer plugged in to internet or even powered up. Will be fun each time i need to get to wallet with having to wait for updates but my 1 bitcoin will be safe  Wink

About 5 minutes with copy paste, most of it was public I'm just trying to put things in context. Was kind of in a hurry so I didn't post sources. I didn't find much about the email just the domain was registered to  yan wang and now shows mark russells. https://bitcointalksearch.org/topic/do-we-have-a-potential-fraudster-among-us-211169 doesn't really prove much. Tradefortress still hasn't responded to asking if his email was compromised. who ever updated the site was probably meaning mark russell as that had to deal with btc atms. Not that that is who it is, but is probably just targeting different people in the community. Honestly the biggest weakness to bitcoin is the centralization of something that's very nature goes against it. In other words thing like mining and the markets should have their own protocol. the miner itself should somehow send you payments. maybe something like using bittorrent or bittorernt sync. you could do something like bittorent sync and create keys that tie to miners so you could rent them out.. etc different keys are used for length of time. there is just to much faith and room for market manipulations if btc is just stored on websites. I suppose for the time being something like an escrow or something similar to btcbuckets. in that if you are to buy a contract dude doesn't get all the money up front but is slowly trickled during length of contract. Something must be done to prevent ponzi scam and to stop things like cex suspending operations. makes it so people are stuck in limbo state not doing shit very little options but to either sell, wait or try to redeem for physical hardware.

Why are you having a conversation with yourself, malaimult. Yes, I checked, you've sorted you're quoting out with all three alts. Good job!

So, darkangel/darkgamer/malaimult, could you explain your connection to the cloudminr.io ponzi? If you say you have none, then could you explain why you still carry their sig when the sig campaign ended ages ago? Surely you realise that you and picolo are going be the ones people go after when the shit hits the fan.

I'm rarely on here, pretty much only come to the forum when crap like mt.gox/ hashie happens. despite having my name begin with dark, I don't think we really have that much in common. I don't even have a sig. The only thing I can say about cloudminr is that it's close to how pbmining operated. you can't predict the market (you can however look at trends. with hacks, scams and bad publicity lowering the price or crashing the market in the case of mtgox. while good publicity sites accepting bitcoin and the like cause the price to rise.) and offering a contract for greater than 1 year will most likely create problems. you have no guarantee the site will be around 5 months later.  hashie attempted to make it look legit with the market. in a way even though hashie was a scam, you still had more control than you do with contracts as you could trade until the market was removed. Honestly you would have better luck with https://www.miningrigrentals.com/

*update looks like hashie had control of email since it was started https://code.google.com/p/chromium/issues/detail?id=429395 Security: Window.opener bypasses same origin policy    
   1 person starred this issue and may be notified of changes.    Back to list
Status:     WontFix
Owner:    ----
Closed:     Nov 2
Type-Bug-Security


Add a comment below
     
Reported by [email protected], Oct 31, 2014

VULNERABILITY DETAILS
Opened windows (through normal hrefs with target="_blank") can modify window.opener.location and replace the parent webpage with something else, even on a different origin (bypassing same origin policy).

While this doesn't allow script execution, it does allow phishing attacks that silently replace the parent tab (which a user already mentally trusts).

window.opener.location should not be modifiable if on a different origin.

VERSION
Chrome Version: 37.0.2062.94 + stable
Operating System: Ubuntu

REPRODUCTION CASE

https://hashie.co/chrome/demo.html

Oct 31, 2014
#1 [email protected]

Thanks for the report, but the repro doesn't seem to be working on Chrome 38 on Linux. Could you try reproducing with a more recent version?

Oct 31, 2014
#2 [email protected]

Unfortunately the latest version of Chromium in my PPA is 37.

I've been able to reproduce this on Chrome 38.0.2125.114 for Android.

Oct 31, 2014
#3 [email protected]

To clarify, the actual POC is in the link on the page. The https://hashie.co/chrome/demo.html page will be replaced with example.org by pix4bit.com

Nov 1, 2014
#4 [email protected]

The demo page doesn't work for me on M37 on Mac either. When I switch back to example.com tab I see a very brief flash of https://hashie.co/chrome/demo.html but otherwise the actual example.com page is displayed in page contents. I haven't tested on Android yet though.

Nov 2, 2014
#5 [email protected]

The user decides to trust a particular tab by inspecting the URL and determining the origin.  In all cases here both tabs area always showing the correct origin for the content being shown.

On android, when entering any data into a form, the origin is always shown, even if it's previously been elided by scrolling down.  The user can then make a trust decision based on this visible origin.

Given this, I don't see any risk to users more than the users just clicking on a link and visiting a new page, so I am closing with WontFix.
legendary
Activity: 826
Merit: 1004

WOW how long did it take you to write this up lol i almost finish a cigarate reading this lol, in anycase i see what is being said and should always be vigilant. If i ever have more than 1 bitcoin i will make sure i buy a cheap computer get bitcoin wallet and send my stuff there and never keep computer plugged in to internet or even powered up. Will be fun each time i need to get to wallet with having to wait for updates but my 1 bitcoin will be safe  Wink

About 5 minutes with copy paste, most of it was public I'm just trying to put things in context. Was kind of in a hurry so I didn't post sources. I didn't find much about the email just the domain was registered to  yan wang and now shows mark russells. https://bitcointalksearch.org/topic/do-we-have-a-potential-fraudster-among-us-211169 doesn't really prove much. Tradefortress still hasn't responded to asking if his email was compromised. who ever updated the site was probably meaning mark russell as that had to deal with btc atms. Not that that is who it is, but is probably just targeting different people in the community. Honestly the biggest weakness to bitcoin is the centralization of something that's very nature goes against it. In other words thing like mining and the markets should have their own protocol. the miner itself should somehow send you payments. maybe something like using bittorrent or bittorernt sync. you could do something like bittorent sync and create keys that tie to miners so you could rent them out.. etc different keys are used for length of time. there is just to much faith and room for market manipulations if btc is just stored on websites. I suppose for the time being something like an escrow or something similar to btcbuckets. in that if you are to buy a contract dude doesn't get all the money up front but is slowly trickled during length of contract. Something must be done to prevent ponzi scam and to stop things like cex suspending operations. makes it so people are stuck in limbo state not doing shit very little options but to either sell, wait or try to redeem for physical hardware.

Why are you having a conversation with yourself, malaimult. Yes, I checked, you've sorted you're quoting out with all three alts. Good job!

So, darkangel/darkgamer/malaimult, could you explain your connection to the cloudminr.io ponzi? If you say you have none, then could you explain why you still carry their sig when the sig campaign ended ages ago? Surely you realise that you and picolo are going be the ones people go after when the shit hits the fan.
legendary
Activity: 2100
Merit: 1012
Europecoin Financecloud API

WOW how long did it take you to write this up lol i almost finish a cigarate reading this lol, in anycase i see what is being said and should always be vigilant. If i ever have more than 1 bitcoin i will make sure i buy a cheap computer get bitcoin wallet and send my stuff there and never keep computer plugged in to internet or even powered up. Will be fun each time i need to get to wallet with having to wait for updates but my 1 bitcoin will be safe  Wink

About 5 minutes with copy paste, most of it was public I'm just trying to put things in context. Was kind of in a hurry so I didn't post sources. I didn't find much about the email just the domain was registered to  yan wang and now shows mark russells. https://bitcointalksearch.org/topic/do-we-have-a-potential-fraudster-among-us-211169 doesn't really prove much. Tradefortress still hasn't responded to asking if his email was compromised. who ever updated the site was probably meaning mark russell as that had to deal with btc atms. Not that that is who it is, but is probably just targeting different people in the community. Honestly the biggest weakness to bitcoin is the centralization of something that's very nature goes against it. In other words thing like mining and the markets should have their own protocol. the miner itself should somehow send you payments. maybe something like using bittorrent or bittorernt sync. you could do something like bittorent sync and create keys that tie to miners so you could rent them out.. etc different keys are used for length of time. there is just to much faith and room for market manipulations if btc is just stored on websites. I suppose for the time being something like an escrow or something similar to btcbuckets. in that if you are to buy a contract dude doesn't get all the money up front but is slowly trickled during length of contract. Something must be done to prevent ponzi scam and to stop things like cex suspending operations. makes it so people are stuck in limbo state not doing shit very little options but to either sell, wait or try to redeem for physical hardware.

WOW you just invented a gamechanger, to sad my programming skills are used to long ago to build that, but anybody who would be able to build that concept will be a rich man (and really earned it in a fair way).
newbie
Activity: 54
Merit: 0

WOW how long did it take you to write this up lol i almost finish a cigarate reading this lol, in anycase i see what is being said and should always be vigilant. If i ever have more than 1 bitcoin i will make sure i buy a cheap computer get bitcoin wallet and send my stuff there and never keep computer plugged in to internet or even powered up. Will be fun each time i need to get to wallet with having to wait for updates but my 1 bitcoin will be safe  Wink

About 5 minutes with copy paste, most of it was public I'm just trying to put things in context. Was kind of in a hurry so I didn't post sources. I didn't find much about the email just the domain was registered to  yan wang and now shows mark russells. https://bitcointalksearch.org/topic/do-we-have-a-potential-fraudster-among-us-211169 doesn't really prove much. Tradefortress still hasn't responded to asking if his email was compromised. who ever updated the site was probably meaning mark russell as that had to deal with btc atms. Not that that is who it is, but is probably just targeting different people in the community. Honestly the biggest weakness to bitcoin is the centralization of something that's very nature goes against it. In other words thing like mining and the markets should have their own protocol. the miner itself should somehow send you payments. maybe something like using bittorrent or bittorernt sync. you could do something like bittorent sync and create keys that tie to miners so you could rent them out.. etc different keys are used for length of time. there is just to much faith and room for market manipulations if btc is just stored on websites. I suppose for the time being something like an escrow or something similar to btcbuckets. in that if you are to buy a contract dude doesn't get all the money up front but is slowly trickled during length of contract. Something must be done to prevent ponzi scam and to stop things like cex suspending operations. makes it so people are stuck in limbo state not doing shit very little options but to either sell, wait or try to redeem for physical hardware.
sr. member
Activity: 424
Merit: 250


Yes works within 48 for me but I requested it even before it was offical announced as working.

btw there is a amhash thread were you can find this answer.

Regards
Stefan


Could you feed me with the link, please?
hero member
Activity: 792
Merit: 501
To all having hashes with Amhash

Has anyone had successful withdraw from Am?

I am waiting now over 96h from request and no payment has been made....

Could someone from AM pm me/get in touch as tickets are left  not responded too

Yes works within 48 for me but I requested it even before it was offical announced as working.

btw there is a amhash thread were you can find this answer.

Regards
Stefan
sr. member
Activity: 424
Merit: 250
To all having hashes with Amhash

Has anyone had successful withdraw from Am?

I am waiting now over 96h from request and no payment has been made....

Could someone from AM pm me/get in touch as tickets are left  not responded too
legendary
Activity: 1059
Merit: 1020
nana, so the next scam is ready, DIVIDE your frostcoin (by zero ? ),   all the way down to half of nothing

hashie faggie, you know how much you owe me, you know where to send it, its not my job to come looking for it, you know the deal
I try with 0.066 Frostcoins.
I look if they pay off my split Frostcoins me.
hero member
Activity: 672
Merit: 500
ADAMANT — the most secure and anonymous messenger
hashie is using the same email that seems to have been compromised last year. glados.cc and using the admin account that once belonged or may still belong to TradeFortress.

There's no evidence whatsoever to suggest that. Hashie simply posted Tradefortress' email address as their contact details.

If anyone wants to contact darkgamer, send him an email at [email protected]. Oh my god! Darkgamer = hashie = TradeFortress!

Come on man, think about these things for at least 1 second.



Here’s your digital-currency lesson of the day, courtesy of a guy who calls himself TradeFortress: “I don’t recommend storing any bitcoins accessible on computers connected to the internet.”

That may sound like a paradox. Bitcoin is the world’s most popular digital currency, and it’s controlled by a vast collection of computers spread across the internet. But TradeFortress knows what he’s talking about. He’s the founder of inputs.io, a company that used to store bitcoins in digital wallets for people across the globe. The site was just hacked, with the bandits making off with more than a million dollars’ worth of bitcoins.

Yes, bitcoins are digital. And, yes, bitcoin transactions necessarily happen on the internet. But you can store bitcoins offline, and that’s what the most careful of investors will do. A collection of bitcoins is essentially a private cryptograph key you can use to send money to someone else, and though you can store that key in an online digital wallet, you can also store it on an offline computer — and even on a physical item here in the real world, writing it on a piece of paper or engraving it on a ring. That’s why your money can’t be hacked.

Until last week, inputs.io seemed like a nifty service for Bitcoin users. The company not only offered bitcoin wallets, it mixed the wallets up in order to anonymize the coins they stored, sped up bitcoin payments, and even spared them from the tiny transaction fees that are typically charged on the bitcoin network.

But there was a catch. You had to trust the company — and its internet-connected computers — with your bitcoins. In retrospect, that was a bad idea. And now, Inputs.io customers are learning just how bad of an idea it was.

The site was compromised on Oct 23, and again on Oct. 26, and hackers made off with 4,100 bitcoins ($1.2 million) stolen in two separate attacks. The company waited until this week to notify customers of the incident, which only affects certain users. A small number of Bitcoins belonging to TradeFortress’s other business, CoinLenders, were also taken, TradeFortress said in an email interview (He didn’t provide his real name).

Inputs.io doesn’t have the funds to pay back everything that was stolen, but TradeFortress says he’s going to issue partial refunds. “I’m repaying with all of my personal Bitcoins, as well as remaining cold storage coins on Inputs, which adds up to 1540 BTC,” he told WIRED.

TradeFortress says that this was a social engineering attack, meaning that the attacker masqueraded as someone he wasn’t in order to get access to the site’s systems on cloud-hosting provider Linode. “The attack was done through compromising a chain of email accounts which eventually allowed the attacker to reset the password for the the Linode server,” he said.

The hacker’s first step was recovering an email address for an account that TradeFortress set up six years ago.

The “attacker rented an Australian server to proxy as close to my geographical location so it won’t raise alarms with email recoveries,” TradeFortress said in a forum post.

“I know this doesn’t mean much, but I’m sorry, and saying that I’m very sad that this happened is an understatement,” TradeFortress wrote on the inputs.io website.

Like I said earlier, it wouldn't be hard to go around attacking websites once you learn enough about who runs them. I'm pretty sure that with all the above info it's not hard to think that maybe the email account got pwned.  I guess we won't know if it's hashie unless we email them. I'm just saying that it's someone that knows a bit about the bitcoin operations and it would be nice to have clarification from TraderFortress to find out if he still owns the email. I'm also saying that if a server was once compromised it would be good to take control of it during a scam like hashie as it wouldn't be hard to impersonate the site owner. in this way, you could offer a scam called hashie and run off with money. then, go right back and offer a new scam using the credentials of someone else.

WOW how long did it take you to write this up lol i almost finish a cigarate reading this lol, in anycase i see what is being said and should always be vigilant. If i ever have more than 1 bitcoin i will make sure i buy a cheap computer get bitcoin wallet and send my stuff there and never keep computer plugged in to internet or even powered up. Will be fun each time i need to get to wallet with having to wait for updates but my 1 bitcoin will be safe  Wink
member
Activity: 112
Merit: 10
nana, so the next scam is ready, DIVIDE your frostcoin (by zero ? ),   all the way down to half of nothing

hashie faggie, you know how much you owe me, you know where to send it, its not my job to come looking for it, you know the deal

Division by zero is undefined.

wich in terms of my refund, is zero
hero member
Activity: 504
Merit: 500
sucker got hacked and screwed --Toad
nana, so the next scam is ready, DIVIDE your frostcoin (by zero ? ),   all the way down to half of nothing

hashie faggie, you know how much you owe me, you know where to send it, its not my job to come looking for it, you know the deal

Division by zero is undefined.
member
Activity: 112
Merit: 10
nana, so the next scam is ready, DIVIDE your frostcoin (by zero ? ),   all the way down to half of nothing

hashie faggie, you know how much you owe me, you know where to send it, its not my job to come looking for it, you know the deal
hero member
Activity: 504
Merit: 500
sucker got hacked and screwed --Toad
Elsa is probably laughing away at our misfortune  Roll Eyes
newbie
Activity: 54
Merit: 0
Maybe, but they also wanted everyone to let it go and they carried on now for about 3 weeks I don't really think they will let it go. This is their xbox live entertainment.

 Huh I don't even know what your trying to say. You lost me a couple of conversations a go. Just seemed like a wall of gibberish.  Undecided

why post an email that was involved in a hack, even it's not TradeFortress it is someone that knows the community well and could be the same person that took down inputs.io as a way to gloat on here about previous achievements.
Pages:
Jump to: