[A little update on the above: The scam was not pulled off thru the Asset Exchange. It was a pretty simple forum account hack followed by some sneaky social engineering: the forum account belonging to JustaBit was used to post a request for an immediate investment opportunity and asked people to simply send BTC to the posters BTC address. Not a very innovative scam, no actual hacking skills needed apart from obtaining the forum password, and there was no compromise of the NXT AE technology or any part of the NXT network. So NFD is also safe, in case you were worrying.
Yes, that is why I was worrying. Since NFD's Asset Exchange is a clone of Nxt's, any attack vector in the former is an attack vector in the latter. To be frank, I wasn't worried about any purported hardcode flaw: I was worried about social-engineering attacks by slick con artists issuing fake assets on the AE. (I still am.) That's what I thought had took place when I posted that original warning. Even though that was not the case specifically this time, it was close enough to my "worry spot" to prompt me to warn the NFD community to look out for themselves if they see a new asset listed on NFD's AE.
[And no, I'm not referring to EvilCoin.
]
The lesson is: no matter how much you may think you can trust a forum post, do more investigation before handing over funds or insist on reputable escrow.
Yeah...that can't be drummed in enough. Thankfully, we're not at the point where we would have to advise, "don't trust anyone you don't know personally."
On NFD...good job, guys. Really.
I'm running an NFD forging node 24/7 since the launch, and I might set it up as a public node if I'm feeling really generous.
Has NFD had any changes made from the NXT network architecture, apart from port assignments?
Thanks a lot! As of now, there aren't any changes worth mentioning - but we're working on it.
Actually, we're in a bit of a dilemma as to what development path we want to follow:
1) coevolution - we adapt Nxt's advances and offer our advances (once we have them) to the Nxt community for adaptation into Nxt itself?
2) divergence - we go our own way and the Nxt devs go theirs?
There's a fair bit of sympathy in the dev team for (1) because every one of them has some Nxt experience.
But #2 is standard in the clonecoin track...