Pages:
Author

Topic: NXT account hacked. All assets gone. (Read 2559 times)

hero member
Activity: 750
Merit: 500
www.coinschedule.com
September 03, 2014, 05:46:20 AM
#45
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

Hi guys!

Be careful, it is one NXT drawbacks. I have recently posted an article about this coin, you can find it here http://www.cryptobang.com/2014/09/01/check-out-interesting-facts-about-nxt/

i am going to create many articles which will give info about different cryptocurrencies.

Is you no some facts - please you the form on my site "Drop facts"

Or maybe you are interested in a concrete coin - you can order the investigation Smiley

That's a really lame and inaccurate article. You should learn more before posting anything like that.
newbie
Activity: 41
Merit: 0
September 02, 2014, 04:45:43 AM
#44
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

Hi guys!

Be careful, it is one NXT drawbacks. I have recently posted an article about this coin, you can find it here http://www.cryptobang.com/2014/09/01/check-out-interesting-facts-about-nxt/

i am going to create many articles which will give info about different cryptocurrencies.

Is you no some facts - please you the form on my site "Drop facts"

Or maybe you are interested in a concrete coin - you can order the investigation Smiley
full member
Activity: 131
Merit: 101
September 01, 2014, 05:21:41 AM
#43
Sorry for your loss. Yes you cannot stress enough how important a secure passphrase is. Many people become lazy at some point and sacrifice their security for comfort - big mistake, especially in the wild west of cryptos
hero member
Activity: 532
Merit: 500
September 01, 2014, 05:04:26 AM
#42
just ask for a rollback.

To day 0? I'm sure the big holders would love that one.  Wink
legendary
Activity: 2492
Merit: 1473
LEALANA Bitcoin Grim Reaper
September 01, 2014, 01:57:56 AM
#41
just ask for a rollback.

lol thanks for that!  Grin Grin Grin
sr. member
Activity: 336
Merit: 260
September 01, 2014, 12:19:27 AM
#40
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

12 random words generated by the client are secure.

It's when a user rejects that random pass and invents their own weak password that most of the hacks take place.

If you can't invent your own secure password, just use what the client software tells you to use and you'll be safe.
hero member
Activity: 912
Merit: 1021
If you don’t believe, why are you here?
August 31, 2014, 11:05:10 PM
#39
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.
legendary
Activity: 1588
Merit: 1000
August 31, 2014, 10:23:24 PM
#38
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

I doubt that you hear about even 10% of crypto hacks...
In fact, virtually all security deficiencies are automatically blamed on "password hacks".

Would you put $1,000,000 on the NXT platform?

OP, don't feel bad...
For every post I read where the user maybe was careless...
I read another one where victim was an amateur cryptologist, jumped through 100 hoops, and still got ripped off.

Decentralized crypto security = Free Lunch.
newbie
Activity: 55
Merit: 0
August 31, 2014, 09:34:46 PM
#37
oh, maybe you are water army   Grin Grin Grin
member
Activity: 74
Merit: 10
August 31, 2014, 07:24:46 PM
#36


The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!
 

Would the hacker's transaction have confirmed faster because he paid the 51,000 NXT fee, or would it have confirmed just as fast if he had paid a 1 NXT fee?
full member
Activity: 140
Merit: 100
August 31, 2014, 07:10:42 PM
#35
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!

BTW: the random 12 word passphrase that current NXT clients have should be secure enough. We've never heard of a randomly generated passphrase being compromised, only bad user-chosen passwords. 

Thax for all your advices , didn't know about the fess , I think I will create another account just because that password in English is really hard to rememeber for me .
hero member
Activity: 854
Merit: 1001
August 31, 2014, 05:08:43 PM
#34
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!

BTW: the random 12 word passphrase that current NXT clients have should be secure enough. We've never heard of a randomly generated passphrase being compromised, only bad user-chosen passwords. 
sr. member
Activity: 368
Merit: 250
August 31, 2014, 04:01:17 PM
#33
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

Dude, do it right now.  Don't be like me!  Wink
full member
Activity: 140
Merit: 100
August 31, 2014, 03:58:33 PM
#32
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .
hero member
Activity: 532
Merit: 500
August 31, 2014, 03:57:24 PM
#31
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

Account Control is coming up soon as a NXT feature....it'll allow you to cold-wallet and lockdown your account.
But the point is: the user is responsible for his own security.
NXT is safe, provided you use a decent password and the normal security precautions such as anti-malware scanners and not clicking on every link you see.

Ultimately it's the user's responsibility, yes, but even allowing weak passwords to begin with seems counter-intuitive if hackers are allowed unlimited password attempts.
hero member
Activity: 854
Merit: 1001
August 31, 2014, 03:51:41 PM
#30
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

Account Control is coming up soon as a NXT feature....it'll allow you to cold-wallet and lockdown your account.
But the point is: the user is responsible for his own security.
NXT is safe, provided you use a decent password and the normal security precautions such as anti-malware scanners and not clicking on every link you see.
hero member
Activity: 854
Merit: 1001
August 31, 2014, 03:46:20 PM
#29
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear Smiley Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.

and even more importantly as BitcoinExpress just said.. DO NOT RE-USE YOUR PASSWORDS !

EVER !!!!!!!!!!!!!!!!!!!!!!! period !!!!!!!!!!!!!!!

you can have 9327587298467508926409750602916843509287640956 of random characters
but when you re-use it.. your fucked !

Its a strange moment....total agreement with Spoetnik!
This was the cause of the BTER hack: if you re-use a password, and it gets compromised somewhere.....the rest of your shit is immediately compromised.

@Yuzu: good luck, mate. I'll see if I can find some orphans to pass a 1000 NXT on to...... Wink
legendary
Activity: 1050
Merit: 1000
August 31, 2014, 03:42:28 PM
#28
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  Undecided

Very sad to hear. I hope that the thief gets his comeuppance soon.

I had one simple account created initially which had a few hundred NXT, but its all gone long back. I haven't looked into NXT since.
hero member
Activity: 532
Merit: 500
August 31, 2014, 03:37:10 PM
#27
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
August 31, 2014, 03:31:59 PM
#26
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear Smiley Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.

and even more importantly as BitcoinExpress just said.. DO NOT RE-USE YOUR PASSWORDS !

EVER !!!!!!!!!!!!!!!!!!!!!!! period !!!!!!!!!!!!!!!

you can have 9327587298467508926409750602916843509287640956 of random characters
but when you re-use it.. your fucked !
Pages:
Jump to: