Pages:
Author

Topic: My doubt about signing bitcoin sign message. (Read 2953 times)

legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 30, 2015, 09:31:49 AM
#53
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

You should not use the secret question since the encryption of the answer is not that strong. The forum will warn you about that too.

Yes, you can create a strong password. But that is not the only way to hack an account. I think not a few accounts get hacked because the email address attached gets hacked. At least it sounds to me after reading not a few stories about hacked accounts whose password were reset by email.

Buddy ,  my email account cannot be hacked in anyway. Bcoz,  2nd factor  authentication is activated on it. If I gave you my email account login details too , you need my mobile phone and mobile number to use the verification code to get my account access.

That is actually a good email provider then. Though you should not feel too safe with 2FA. It might be hard to hack it but with a poor implementation it might be possible for a hacker to circumvent your account. Hacking doesn't always mean knowing the password. It might mean not needing such things too.

At the end... i don't see a reason why NOT adding another layer of security. It surely can't hurt when you are cautious and back up your private keys.

Buddy, whenever someone will tries to sign in to my gmail account. I will receive the verification call everytime on my Mobile number which is owned by me only. If the hacker don't have my mobile phone, how he will get the verification code and will enter to my account ? its not possible.

The notification email is a good thing that adds additional security.

Regarding the 2FA. You feel safe because no one can get the codes. But what i wanted to tell you is that hackers might not need the code. Only a part of hacks happen because the details are known to be able to login. Many hacks happen because of serverissues, errors in code and so on. Then it might not matter if the hacker does not have the code. He does not need it to check out your emails. Maybe he got a direct database access or something. Then you trusting on 2FA would be a hollow trust.

It might be unlikely that this happens with gmail but still. Things like that happen all the time. You should not feel too safe only because your 2FA.

I think i will leave it now at this. Smiley
legendary
Activity: 1106
Merit: 1000
September 30, 2015, 05:04:54 AM
#52
For stake your addres here, you can find a thread on meta section.
don't provide your private key, just your old wallet which you can sign message with.

Hacker nowadays is became more smart.

I cannot sign my old btc address which I lost recently.

No need old btc address, you just need an address which you used now, and for the future if your account got bad thing. you just sign message which have been stake.
legendary
Activity: 1722
Merit: 1014
September 29, 2015, 11:44:42 AM
#51
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

You should not use the secret question since the encryption of the answer is not that strong. The forum will warn you about that too.

Yes, you can create a strong password. But that is not the only way to hack an account. I think not a few accounts get hacked because the email address attached gets hacked. At least it sounds to me after reading not a few stories about hacked accounts whose password were reset by email.

Buddy ,  my email account cannot be hacked in anyway. Bcoz,  2nd factor  authentication is activated on it. If I gave you my email account login details too , you need my mobile phone and mobile number to use the verification code to get my account access.

That is actually a good email provider then. Though you should not feel too safe with 2FA. It might be hard to hack it but with a poor implementation it might be possible for a hacker to circumvent your account. Hacking doesn't always mean knowing the password. It might mean not needing such things too.

At the end... i don't see a reason why NOT adding another layer of security. It surely can't hurt when you are cautious and back up your private keys.

Buddy, whenever someone will tries to sign in to my gmail account. I will receive the verification call everytime on my Mobile number which is owned by me only. If the hacker don't have my mobile phone, how he will get the verification code and will enter to my account ? its not possible.
legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 29, 2015, 11:39:49 AM
#50
For stake your addres here, you can find a thread on meta section.
don't provide your private key, just your old wallet which you can sign message with.

Hacker nowadays is became more smart.

I cannot sign my old btc address which I lost recently.

Did you post that old address? If not then it doesn't matter. A posted bitcoin address only would help you when it was posted some months ago in an unedited post. The older the better since it raises the chance that the account was not hacked because the real owner would have found out about that most probably in the meanwhile.
legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 29, 2015, 11:38:01 AM
#49
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

You should not use the secret question since the encryption of the answer is not that strong. The forum will warn you about that too.

Yes, you can create a strong password. But that is not the only way to hack an account. I think not a few accounts get hacked because the email address attached gets hacked. At least it sounds to me after reading not a few stories about hacked accounts whose password were reset by email.

Buddy ,  my email account cannot be hacked in anyway. Bcoz,  2nd factor  authentication is activated on it. If I gave you my email account login details too , you need my mobile phone and mobile number to use the verification code to get my account access.

That is actually a good email provider then. Though you should not feel too safe with 2FA. It might be hard to hack it but with a poor implementation it might be possible for a hacker to circumvent your account. Hacking doesn't always mean knowing the password. It might mean not needing such things too.

At the end... i don't see a reason why NOT adding another layer of security. It surely can't hurt when you are cautious and back up your private keys.
legendary
Activity: 1722
Merit: 1014
September 29, 2015, 09:12:19 AM
#48
For stake your addres here, you can find a thread on meta section.
don't provide your private key, just your old wallet which you can sign message with.

Hacker nowadays is became more smart.

I cannot sign my old btc address which I lost recently.
legendary
Activity: 1106
Merit: 1000
September 29, 2015, 08:38:15 AM
#47
For stake your addres here, you can find a thread on meta section.
don't provide your private key, just your old wallet which you can sign message with.

Hacker nowadays is became more smart.
full member
Activity: 196
Merit: 100
September 28, 2015, 09:40:01 PM
#46
Simple
Export the address with its private key from your wallet(the one you forget password)
Import the private key in new wallet
That's it
legendary
Activity: 1722
Merit: 1014
September 28, 2015, 09:34:03 PM
#45
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

You should not use the secret question since the encryption of the answer is not that strong. The forum will warn you about that too.

Yes, you can create a strong password. But that is not the only way to hack an account. I think not a few accounts get hacked because the email address attached gets hacked. At least it sounds to me after reading not a few stories about hacked accounts whose password were reset by email.

Buddy ,  my email account cannot be hacked in anyway. Bcoz,  2nd factor  authentication is activated on it. If I gave you my email account login details too , you need my mobile phone and mobile number to use the verification code to get my account access.
legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 28, 2015, 06:24:22 PM
#44
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

This is good thing to set up the password strongly and use different pass for every site.

But i think stake your address is good backup to your account, if someday you haven't being active om this forum, and bad thing happen to your account. because you can easily sign message with your account.

May i know, what is the procedure of staking my old address. Do i have to just submit the old address or i have to provide the private key along with it too which i don't have it now .?

No, never ever post your private key. If you do then everyone can control your address that private key belongs to.

You can use this thread to stake your address. Simply post a bitcoin address that you control, that you won't lose and backed up and from which you can get the private key: https://bitcointalk.org/index.php?topic=996318.new#new

About how signing a message works. Here is a good explaination: https://bitcointalksearch.org/topic/how-to-sign-a-message-990345
legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 28, 2015, 06:20:42 PM
#43
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

You should not use the secret question since the encryption of the answer is not that strong. The forum will warn you about that too.

Yes, you can create a strong password. But that is not the only way to hack an account. I think not a few accounts get hacked because the email address attached gets hacked. At least it sounds to me after reading not a few stories about hacked accounts whose password were reset by email.
legendary
Activity: 1722
Merit: 1014
September 28, 2015, 09:34:11 AM
#42
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

This is good thing to set up the password strongly and use different pass for every site.

But i think stake your address is good backup to your account, if someday you haven't being active om this forum, and bad thing happen to your account. because you can easily sign message with your account.

May i know, what is the procedure of staking my old address. Do i have to just submit the old address or i have to provide the private key along with it too which i don't have it now .?
legendary
Activity: 1106
Merit: 1000
September 28, 2015, 09:03:15 AM
#41
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.

This is good thing to set up the password strongly and use different pass for every site.

But i think stake your address is good backup to your account, if someday you haven't being active om this forum, and bad thing happen to your account. because you can easily sign message with your account.
legendary
Activity: 2954
Merit: 4158
September 28, 2015, 08:22:01 AM
#40
stake your address at tomatocage's thread if you plan to use your new bitcoin address
but I guess someone is funding your loan by now from your other thread

is it really compulsory to stake my old btc message though ? Plz explain me .
Do you mean by signing a message with your old address and the message containing the new address? It would help to prove that the account is not compromised if so. If not, you can just stake an address there as it is easier to find your address there.
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.
Changing secret questions and answers with strong passwords would help against bruteforce attacks which the forum have measures to prevent this from happening. Use a different password for different websites, hence you don't need to worry so much if other sites got compromised and hackers cannot access all your accounts. Also, do not download and run any foreign and suspicious programs.
legendary
Activity: 1722
Merit: 1014
September 28, 2015, 08:05:10 AM
#39
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.

1st thing , I am not gonna sell my one and only one account which helps me to earn my pocket money.  I am dreaming to be a legendary member on bitcointalk forum. And as you said about the security issue of my account , I will set the secret question and answers with a strong password for my account safety.
legendary
Activity: 2674
Merit: 1082
Legendary Escrow Service - Tip Jar in Profile
September 28, 2015, 07:30:45 AM
#38
If you ever get your account hacked or if you want to sell it then you need to prove that you are the real owner of that account and you are no hacker. Otherwise it would be hard to reclaim your account.

If you sign a message you post publicly then make sure that you include event details. Not that someone takes your general signature and makes trouble.
legendary
Activity: 1106
Merit: 1000
September 27, 2015, 03:44:24 AM
#37
stake your address at tomatocage's thread if you plan to use your new bitcoin address
but I guess someone is funding your loan by now from your other thread

is it really compulsory to stake my old btc message though ? Plz explain me .

Although is not compulsory, but it's really help you in the future, stake your address there is prove if you're the owner. and if your account got hacked, you just sign message with address which you have already stake on that thread.
copper member
Activity: 924
Merit: 1007
hee-ho.
September 26, 2015, 02:03:28 PM
#36
stake your address at tomatocage's thread if you plan to use your new bitcoin address
but I guess someone is funding your loan by now from your other thread

is it really compulsory to stake my old btc message though ? Plz explain me .

no it's not. actually you are not required (it's recommended, but not required) to do it at all because you already posted your addresses and proved that you own the old one.
legendary
Activity: 1722
Merit: 1014
September 26, 2015, 12:07:24 AM
#35
stake your address at tomatocage's thread if you plan to use your new bitcoin address
but I guess someone is funding your loan by now from your other thread

is it really compulsory to stake my old btc message though ? Plz explain me .
legendary
Activity: 1722
Merit: 1014
September 04, 2015, 01:33:37 PM
#34
You are the only person that has access to that address. You can change it and delete the private key when you wish but you need to create a signature first. Something like. "Iam XXX, i will delete my bitcoin address now and delete this address. I will post a new address now. It is XXXXX."

If you have this then nobody can blame you when you can't sign further messages because the signature is valid and shows that you owned that signature at one point. It should not be possible to fake this.

Did i miss something?

Everything is cleared now. QS suggested me to post a new address from where I can sign a message.

I think that might not be enough. At least if you want to sell the account or proov ownership in the short term.

What a hacker would do when he hacks an account with the intention to sell it or give it out as collateral would be to delete all addresses you posted and post a new address he controls. If he can't delete an address then he might hope for luck.

If you can't sign a message for the old address then, at least up to some months, your account will look risky for potential buyers. I think it will always be good to be safe. Though i wonder why you would delete a private key at all. Safe the private key or/and import it into your new wallet and you are fine.

I even thought about an attack vector from someone selling an account where he posted a bitcoin address in. Before he sells he posts a new address and deletes the old one. Then he sells the account with a fresh account and writes a signature for the new address. Then he waits until the new owner levelled the account up until it is hero or so. Then claims a stolen account and shows the old address in internet cache. He would get the account probably. Though he has to tell why he was not online for one year of course.

Theoretical attack vector i guess. Tongue

But anway... think about if that would be a problem for you.

I have read everything you wrote above. Actually , I was totally new and a noob when I entered In the bitcoin world. I have opened that btc wallet account to start claiming some satoshis from faucets.  I haven't take the mnemonics phrases seriously  and didn't saved it. I can remember my main password always that time. But from the day of attaching that btc address to android wallet. I was only doing transactions using my phone only with the help of PIN. so, there was no need of main password .

Before some days , accidentally my phone get restored and everything finished. 


Your last query answer is I am not going to sell my account in any how.  Bcoz , I always like to be engaged on bitcointalk.org forum and forum members only.
Pages:
Jump to: