It was the Bitcointalk forum that inspired us to create Bitcointalksearch.org - Bitcointalk is an excellent site that should be the default page for anybody dealing in cryptocurrency, since it is a virtual gold-mine of data. However, our experience and user feedback led us create our site; Bitcointalk's search is slow, and difficult to get the results you need, because you need to log in first to find anything useful - furthermore, there are rate limiters for their search functionality.
The aim of our project is to create a faster website that yields more results and faster without having to create an account and eliminate the need to log in - your personal data, therefore, will never be in jeopardy since we are not asking for any of your data and you don't need to provide them to use our site with all of its capabilities.
We created this website with the sole purpose of users being able to search quickly and efficiently in the field of cryptocurrency so they will have access to the latest and most accurate information and thereby assisting the crypto-community at large.
RealSolid: https://bitcointalk.org/index.php?topic=270155.0 <-- can i get a ACK/NACK on this? ie that you store the users PW in plain (or decryptable only by X ppl) passwords are stored encrypted yeah they are the only identifyable information atm, i may change it in the future and have other info i force people to enter name of first pet, etc as suggestion, hash the passwords... in 1970-1980 hashing started, now we have 2013! no theres no added security to my system in salting them i like your idea about the selfbuild engine + DB alot, as its secure. but this is horrible i dont talk abuot salting, i talk about hashing! or hashing that may change as i adapt future requirements of course not hashing is a huge security risk, mtgox had to learn it the hard way haha thinking its a security risk shows your ignorance on mcxnow security hmm, "they are the only identifyable information atm" <-- so you identify users per password and not per user id? no but if they want a reset its the only info they have put in there so i either offer no resets or add more info they can store to prove they are account holders so if someone forgot his password (and really forgot), hes totally fucked or you just give it to them? the exchanges that do password email resets are way more insecure i agree that password email resets are extreme insecure same with automated password recovery the mcxnow database is undumpable from the internet and you should be using a unique password at the site anyhow, this is what i tell everyone if you K1773R use a unique password at mcxnow there is no difference whether i hash+salt+shit on your password so im not sure what *your* personal issue is with the way i handle passwords, even if you think its insecure, when you should be following good security protocol as a security expert :P if someone successfully takes over your engine, he gets access to the user DB as its needed to identify persons right? so why not just dumping this, all thats needed is to break the encryption (password? privkey? combination?) and you have the password of every person @ mcxnow or did i miss something? i protect the people who are insecure people by nature by not allowing auto password resets and requiring they remember part of their password the only person who can "take over the engine" is someone who works at the datacenter of the exchange server not internet hackers and ive added protection against local admin hacking by encrypting everything the exchange uses nothing is fullproof of course, but worrying about your unique password being in the wild is nothing compared to losing all your funds right? how comes? if your engine needs informations to identifiy users (ie, username + password), as soon you got the engine, you also got the encrypted password, all you need then is to encrypt it and as soon as you got the engine youve got all the funds too if youre an elite hacker who can decrypt and reverse engineer a x64 binary yes, i liked your setup alot as its the only exchange i saw knowing something about security, this is just the little ugly thing that poped up, so im wondering ;) so if a compromised amazon elite hacker data center admin finds out about the mcxnow exchange server we could be in trouble so what do you propose to do instead of what i do to verify lost passwords? just lock people out of accounts if they forget? nope, its a tough question to be honest i think only morons/haters care about this because as a specific user if you use unique password at mcxnow you are no more or less compromised if the database gets breached i have no idea so far how an average person could be able to get his account back due to missing knowledge so why should *YOU* care about these people? well, i dont care about anyone usual ;) so if we are in trouble (stolen funds), would you pay it back out of ur pocket? people recommend salting and hashing passwords because sql and other database technologies are often compromised, mine cant be from the internet if yes, well then i dont care anymore worrying about rogue elite datacenter admin hacker taking your password is the least of your worries, the funds are more important :P and unlike pretty much all other exchanges except perhaps mtgox ive put a lot of thought into protecting against those so you would pay back the stolen funds? i dont have enough money to do that if theres a 50/50 split on funds in hot/cold for instance, i guess id just pay back the percentage in cold to everyone ok to me thats pretty much game over material though so i never want it to happen at all hence the paranoia and security