Author

Topic: NXT :: descendant of Bitcoin - Updated Information - page 420. (Read 2761637 times)

hero member
Activity: 574
Merit: 500
Final draft. What do you guys think? I'm pretty sure this is what the bars are going to look like.




Looking good, what format is that in?

I always liked "Sic Parvis Magna" - Greatness from small beginnings.

It isn't arrogant and will get better over time as Nxt's greatness improves Cheesy
sr. member
Activity: 308
Merit: 250
Anon136, that is too cool!


Wesleyh, yes that is the manual Passphrase entry I was looking for .

Any way it can show the user the bits of entropy and a Very Strong, Strong, Weak, Very Weak rating after the Passphrase is typed in but before the user creates the account with that Passphrase?


Hmm, dunno, it doesn't allow you to create a password without upper case and lowercase, at least 1 number and at least 1 special character and 35 character length. Isn't that good enough?
hero member
Activity: 644
Merit: 500
On "What happens to the static key if you lose your Yubikey?"  You are only storing one part of your NXT Passphrase in the pseudo 2 factor authentication use case described.  If lost, it cannot be used to gain access to your Nxt account without ALSO knowing the first part of the Nxt Passphrase (which user would memorize)

So you have to type the part that you memorized every time and rest is filled by Yubikey?

I realize that Lastpass signs and encrypts locally before transmitting encrypted data.  STILL, some security paranoid users may not feel comfortable with any option but LOCAL backup of private keys.

To each their own. I like having encrypted version backed up online, as I know I can access it even if everything in my house is stolen.

As long as the master password is strong, I am not bothered with online back ups. I like it even better.
hero member
Activity: 574
Merit: 500
Is the Testnet down?

I am using Wesley's client in Firefox in Windoze.

I see the funds I have and I have created an asset that shows up on the dashboard.

But when I click on the asset exchange and it says "Please select an asset on the left sidebar" nothing appears. The Asset exchange title still appears to be loading (going ... ... ... ... etc) but no change. I see the asset I issued in "My assets" too.

Any help?

Thanks
hero member
Activity: 490
Merit: 504
Final draft. What do you guys think?
that "chao" is a nonsense, at least in latin it must be "chaos"
legendary
Activity: 1181
Merit: 1018
Final draft. What do you guys think? I'm pretty sure this is what the bars are going to look like.
 

+1
member
Activity: 84
Merit: 10
Anon136, that is too cool!


Wesleyh, yes that is the manual Passphrase entry I was looking for .

Any way it can show the user the bits of entropy and a Very Strong, Strong, Weak, Very Weak rating after the Passphrase is typed in but before the user creates the account with that Passphrase?
legendary
Activity: 1722
Merit: 1217
Final draft. What do you guys think? I'm pretty sure this is what the bars are going to look like.



member
Activity: 84
Merit: 10
On "What happens to the static key if you lose your Yubikey?"  You are only storing one part of your NXT Passphrase in the pseudo 2 factor authentication use case described.  If lost, it cannot be used to gain access to your Nxt account without ALSO knowing the first part of the Nxt Passphrase (which user would memorize)

On "How are you going to get your money out of Nxt account in event of lost Yubikey?  Option 1) Make a backup Yubikey and store it in a safe deposit box or other secure location for the contingency of losing your main Yubikey.  Option 2) Create a local Keepass database with your Yubikey static key backed up inside the encrypted LOCAL Keepass database.

No, Nxt Passphrase backup is not on Yubikey server.  The only involvement of the Yubikey server in the use case I described is to register the Yubikeys and potentially Revoke them if they are lost.

I realize that Lastpass signs and encrypts locally before transmitting encrypted data.  STILL, some security paranoid users may not feel comfortable with any option but LOCAL backup of private keys.


Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?

No, I meant what happens to the static password if you lose your Yubikey? How are you going to get your money out of Nxt account? That static key must be saved somewhere (as a back up). Wiping key doesn't help you to login to Nxt. So there must be a backup somewhere. Where is that backup? On Yubikey server?

As for Lastpass, encryption is done locally on the computer. Only encrypted blob is sent to Lastpass server.
legendary
Activity: 1778
Merit: 1043
#Free market
Let me introduce our new weapon for promotions and conferences. Shiny piece of 3D printed metal.


                                  Nxt CPU
                   Cryptocurrency Processing Unit


I have tried to connect an old days of the computers with bright future of the Nxt cryptocurrency. I hope you will like it!

For now I'm starting with the limited silver edition of the Nxt CPU. Total 7 pieces will be made.

I will sell six silver Nxt CPU in an auction only for NXT.
I hope Nxt will succeed and this limited silver edition will be part of beginning and the great future.
You will be able to buy real pieces in more than ten different materials (silver, steel, plastic).

3D printed brass prototype; 3.872cm long:



+1
sr. member
Activity: 364
Merit: 250
☕ NXT-4BTE-8Y4K-CDS2-6TB82
full member
Activity: 180
Merit: 100
Let me introduce our new weapon for promotions and conferences. Shiny piece of 3D printed metal.


                                  Nxt CPU
                   Cryptocurrency Processing Unit


I have tried to connect an old days of the computers with bright future of the Nxt cryptocurrency. I hope you will like it!

For now I'm starting with the limited silver edition of the Nxt CPU. Total 7 pieces will be made.

I will sell six silver Nxt CPU in an auction only for NXT.
I hope Nxt will succeed and this will be part of beginning and the great future.
You will be able to buy real pieces in more than ten different materials (steel, plastic).

3D printed brass prototype; 3.506cm long:



sr. member
Activity: 308
Merit: 250
Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?

There is an option to not use the auto-generated pass phrase, is this not what you want?

hero member
Activity: 644
Merit: 500
Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?

I agree the Yubikey standard looks like an interesting option. 

(emphasis mine)

I am still not sure Yubikey does anything. It's main purpose (as I understand it) is for 2 factor authentication (dynamic part of password that changes).

By the way, does anyone know how you restore your  Yubikey if you lose it?


 

sr. member
Activity: 490
Merit: 250
I don't really come from outer space.
Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?

I agree the Yubikey standard looks like an interesting option. 

However, on the topic of Lastpass, from https://lastpass.com/how-it-works/
Quote
All sensitive data is encrypted and decrypted locally before syncing with LastPass. Your key never leaves your device, and is never shared with LastPass. Your data stays accessible only to you.

(emphasis mine)
hero member
Activity: 644
Merit: 500
Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?

No, I meant what happens to the static password if you lose your Yubikey? How are you going to get your money out of Nxt account? That static key must be saved somewhere (as a back up). Wiping key doesn't help you to login to Nxt. So there must be a backup somewhere. Where is that backup? On Yubikey server?

As for Lastpass, encryption is done locally on the computer. Only encrypted blob is sent to Lastpass server.
legendary
Activity: 2142
Merit: 1010
Newbie
CfB:  how does payout during leased forging work?  will the account owner (that all effectiveBalance values are leased out to) have to do manual reconciliation or does NXT just figure it out?

Fees go to the leasee (pool) and added to the balance of the account the power was leased to.
full member
Activity: 238
Merit: 100
CfB:  how does payout during leased forging work?  will the account owner (that all effectiveBalance values are leased out to) have to do manual reconciliation or does NXT just figure it out?
member
Activity: 84
Merit: 10
Yubikey offers a Key Registration service that allows multiple keys to be remotely wiped at https://admin.yubico.com/yubirevoke/login.php

A Yubikey costs $30 and is worth far more than that to protect valuable digital assets.

Lastpass uses a third party server verification and for the most security paranoid this is not acceptable.

Wesleyh, can you code your login so that users can enter their OWN STRONG password so that the described Yubikey pseudo 2 factor authentication method can be used?
hero member
Activity: 644
Merit: 500
To quote Eadeqa, "Huh? I never mentioned yubikey. I think that's for 2-factor authentication. It won't even work with Nxt as Nxt is local login to NRS. "

Yubikey has a second slot for a user programmed static password.  The second slot is not involved with 2-factor authentication by server.


What happens to static password if you lose Yubikey? Yubikey costs money. Given small Nxt community you probably will be the only one who will  use it.

There is much easier (and free) solution to make  it easier. Use Lastpass browser plugin

https://lastpass.com/

Then you don't have to type anything as Lastpass will autofill the password. Plus you can use Yubikey (as it was intended for 2 factor authentication) with Lastpass.




Jump to: