Author

Topic: KanoPool kano.is lowest 0.9% fee 🐈 since 2014 - Worldwide - 2432 blocks - page 2033. (Read 5352429 times)

legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
No compromise - but the 2FA is there so that people can better avoid it before it happens if they want Smiley

The extra single click is gonna stay since I want to force people to use https for the login (as I mentioned)

I thought of one more idea yesterday ... that I just added Smiley
To have the small login username+password at the top as well - hopefully that will work properly.
As for it remembering user+pass, I guess the problem there is that I moved it from one page to another so it may require clearing that in some browsers
Edit: in Safari on an iDevice: Settings App->Safari->Passwords&AutoFill->Saved Passwords
Then click 'Edit' in the top right, then select the one(s) you want to delete, then tap on 'Delete'

Payout 369390 sent
96f3f493718013c9d4633e3dbe2c618d7a1a0305c36af043dc7403c0b569db70
and confirmed
full member
Activity: 157
Merit: 100
I have been sitting in the shadows for awhile.
But I have to say the new sign in is  PAIN !
Did you do this because of a data compromise ?
From what I understand No one ever has a balance here.

Thanks for running a great pool Kano, you are about to have a 1 year anniversary ....congrats and best of luck !
legendary
Activity: 966
Merit: 1003
Block!!! Like 4 hours ago!! Cheesy
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Payout 369248 sent
93a028efea45f6e43e4ba082bb361cc242db131c0ef08b4d5066806027b57f09
and confirmed
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Well TheOneJester has a Google Play app
https://bitcointalksearch.org/topic/m.11687928

No idea if anyone else has done an AppStore app.
hero member
Activity: 575
Merit: 500
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
Same reason why a bank logs you out.

Right, but a bank is transactional.
PostgreSQL is transactional also Smiley
Not sure what the point is though.

Quote
I think what he is saying is stay logged in to read stats and data and require login again if changing anything.
Session life time is fixed at where I consider it optimal and as the system wide php setting.
If you want to stay logged in then use firefox with a reload every 5 minutes (like I do) or some other such option.
Or use the API which has no session life time.

Yes that is what i meant. There's no need for session expiring security on my private computer, imo. The information i'm interested to read is already public and kinda public. (Hashrate/Worker)
Then if you need to change settings, you already need to re input your password so *shrug*.

I might go the API route. The auto refresh doesn't work in every for situation for me. Maybe it could even be turned into a simple rain meter widget. That would be dandy. Smiley

I don't mind this on the computer, but on my phone it's a PITA to keep logging in to check on my workers and hash. It was perfect before as my Mac would remember credentials in safari and all that is synched with my phone so I would just auto fill on phone. Now I have to type it in each time on my phone.
legendary
Activity: 1302
Merit: 1068
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
Same reason why a bank logs you out.

Right, but a bank is transactional.
PostgreSQL is transactional also Smiley
Not sure what the point is though.

Quote
I think what he is saying is stay logged in to read stats and data and require login again if changing anything.
Session life time is fixed at where I consider it optimal and as the system wide php setting.
If you want to stay logged in then use firefox with a reload every 5 minutes (like I do) or some other such option.
Or use the API which has no session life time.

Yes that is what i meant. There's no need for session expiring security on my private computer, imo. The information i'm interested to read is already public and kinda public. (Hashrate/Worker)
Then if you need to change settings, you already need to re input your password so *shrug*.

I might go the API route. The auto refresh doesn't work in every for situation for me. Maybe it could even be turned into a simple rain meter widget. That would be dandy. Smiley
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
Same reason why a bank logs you out.

Right, but a bank is transactional.
PostgreSQL is transactional also Smiley
Not sure what the point is though.

Quote
I think what he is saying is stay logged in to read stats and data and require login again if changing anything.
Session life time is fixed at where I consider it optimal and as the system wide php setting.
If you want to stay logged in then use firefox with a reload every 5 minutes (like I do) or some other such option.
Or use the API which has no session life time.
hero member
Activity: 575
Merit: 500
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
Same reason why a bank logs you out.

Right, but a bank is transactional. I think what he is saying is stay logged in to read stats and data and require login again if changing anything.
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
Same reason why a bank logs you out.
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
...
PS. What about forwarding HTTP to HTTPS for the landing page? Then you could use the original login/pass that was at the top right, just a suggestion.
I don't want to forward it, since without forwarding, it allows anyone to access the index page and blocks page and also without having to issue a redirect.
It also means API access is however you choose, i.e. any web accessible program can access the API http or https

The way it is now, it forces a switch to https before you can type your password, thus you stay at https after that, but otherwise leaves it alone.
The forced switch going to the login page solves the problem for people logging in accidentally on http, but only when you click on it, so that was also another reason why I've changed it to that way.
legendary
Activity: 1302
Merit: 1068
Right now its adding several clicks to the usual several click to login then check your worker status. Its a lot of clicks unless you have a dedicated page on at all time auto refreshing so your session doesn't time out. Why not let read-only data always on?

I don't see a reason for always having to relog.
hero member
Activity: 575
Merit: 500
ckdb fixed - restarted and block now showing up properly.

Of course as per usual with a ckdb restart, no mining was affected at all.

As for the login page, can you clear all the remembered form data for the web site and see if that helps?
I do have it showing up on one of my browsers (I have 2fa on all the time now)

As for 2fa itself, if you don't enable 2fa, login is still just username+password as before.
You don't have to enable 2fa if you don't want to.
If you enable 2fa (later when it's ready - or if you want to try it now) then the 2fa value will also be required everywhere you enter your password.

Looks like Chrome saved password works, but does not work in Safari. It did work prior to the 2Fa changes. Possible that the 3 entry box on the new page is messing it up. Would it be possible to have a register, login and login 2FA link? If the standard login is back on its own, that may work as it did before.

Another option is to put the login back where it was on the upper right of page, then just provide a 2FA login link that takes you to the new login page.

Thanks,


So that did not work, I see the stored user/pass in my keychain but each time I land on the login page, safari suggests a password after I enter username. I think its not detecting the page as the one I have already stored a user/pass for. Although the keychain shows kano.is https and saved user/pass

PS. What about forwarding HTTP to HTTPS for the landing page? Then you could use the original login/pass that was at the top right, just a suggestion.
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
...
Looks like Chrome saved password works, but does not work in Safari. It did work prior to the 2Fa changes. Possible that the 3 entry box on the new page is messing it up. Would it be possible to have a register, login and login 2FA link? If the standard login is back on its own, that may work as it did before.

Another option is to put the login back where it was on the upper right of page, then just provide a 2FA login link that takes you to the new login page.

Thanks,
Try again now - made a minor change of not having a blank the username/password fields
(... meh safari ... )

The problem with the old login was that people would use it even on http
The Login/Register link goes to https.
So yeah I don't want to put the login back on the main page.
hero member
Activity: 575
Merit: 500
ckdb fixed - restarted and block now showing up properly.

Of course as per usual with a ckdb restart, no mining was affected at all.

As for the login page, can you clear all the remembered form data for the web site and see if that helps?
I do have it showing up on one of my browsers (I have 2fa on all the time now)

As for 2fa itself, if you don't enable 2fa, login is still just username+password as before.
You don't have to enable 2fa if you don't want to.
If you enable 2fa (later when it's ready - or if you want to try it now) then the 2fa value will also be required everywhere you enter your password.

Looks like Chrome saved password works, but does not work in Safari. It did work prior to the 2Fa changes. Possible that the 3 entry box on the new page is messing it up. Would it be possible to have a register, login and login 2FA link? If the standard login is back on its own, that may work as it did before.

Another option is to put the login back where it was on the upper right of page, then just provide a 2FA login link that takes you to the new login page.

Thanks,
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
ckdb fixed - restarted and block now showing up properly.

Of course as per usual with a ckdb restart, no mining was affected at all.

As for the login page, can you clear all the remembered form data for the web site and see if that helps?
I do have it showing up on one of my browsers (I have 2fa on all the time now)

As for 2fa itself, if you don't enable 2fa, login is still just username+password as before.
You don't have to enable 2fa if you don't want to.
If you enable 2fa (later when it's ready - or if you want to try it now) then the 2fa value will also be required everywhere you enter your password.
hero member
Activity: 575
Merit: 500
I use the google 2fa for lots of websites I am a big fan although maybe I should not be ?

I don't understand how compatibility with a sha256 algorithm is relevant to 2fa
OTP uses a hash function to generate the code.

"google 2fa" isn't "google", it's simply just the 2 IETF RFCs
 https://tools.ietf.org/html/rfc6238
 https://tools.ietf.org/html/rfc4226

I use sha2-256 since it's reasonably secure ... that's what we use in bitcoin mining Smiley

It would appear that the "Google Authenticator" app doesn't understand the code that says to use sha2-256 so it only uses sha1 - which of course wont give the correct 6 digit hash number.
The RFC specs say it should allow it but it doesn't work.

The 2 Apps I've listed work fine when told to use SHA2-256
You can run both apps on one phone/tablet if you need to.
However, you will find that the App I'm suggesting you use should work with gmail login also.

Kano, Since the update to the page with 2Fa, the login and register have been combined, but my browser will no longer profile the login user & pass. I now have to type in the credentials each time where before the update I was able to have browser profile the upper right green login box that existed. Also, not profiling on my mobile phone, both of these were very useful as I check on miner status many times a day. Anything that can be done about that? Maybe extend the mission cookie to 24 hrs? don't mind logging in once a day but the current timeout must be around 15 or 30 min.

Also, I am guessing that 2Fa will be optional and for things like changing payout address and not each time you login? again, just guessing.
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Heh another bug to add to the list for the new code ...

We just got a block, but I'm working on ckdb to fix it so it shows up:
https://blockchain.info/block/00000000000000000eb1bbe04a9d8751989f18e22dba3a329dea40f112f7d145

Of course it's there and succeeded, just gotta fix it in ckdb now ...
legendary
Activity: 4634
Merit: 1851
Linux since 1997 RedHat 4
Kano,
Have you looked into Steve Gibson's SQRL authentication?

https://www.grc.com/sqrl/sqrl.htm
It's 1FA, not 2FA, so doesn't really fit in with the change I've added.

Sure it can replace normal 1FA login (user+password), but it still has the security risk of any other 1FA of having only one place that needs to be compromised.

Payout 369010 sent
3ea3989d34fea95ede3d6dfeba1912eff8639711a898b81b0c443d0efab01771
and confirmed
legendary
Activity: 3586
Merit: 1099
Think for yourself
Kano,
Have you looked into Steve Gibson's SQRL authentication?

https://www.grc.com/sqrl/sqrl.htm
Jump to: