Author

Topic: NXT :: descendant of Bitcoin - Updated Information - page 423. (Read 2761638 times)

sr. member
Activity: 308
Merit: 250
I bring forward a motion for Jean-Luc to modify the NRS client to check string length of the passphrase and reject it if less than 15 characters AND it has zero transactions. (dont want to lock out any people that do have NXT with a 15 char password)

Here's my new logic for my client http://nxtra.org/nxt-client (to be available later today, not yet uploaded)

Thoughts?


Thoughts: Implement this ASAP, and sort out the wallet.dat discussion later.

Do not get sidetracked into that discussion and then wait Smiley

It may not be *perfect* but it's WAY better than what we have.



I agree, keep main track as is while we discuss the nxtwallet.dat default method.

I'm keeping on track, wallet.dat is for later.

Problem with wallet.dat is security restrictions. For example, you will not be able to use a "wallet.dat" if you want to access an online web client (which some nodes may want to make available). (If you think of wallet.dat as a separate file). However it would be possible to save it in a websql/indexeddb database instead. Only the URL that makes the database can read it, so it should be safe.

For my downloadable client, the restriction should not apply and any file should be able to be used as a wallet.dat
full member
Activity: 238
Merit: 100
I bring forward a motion for Jean-Luc to modify the NRS client to check string length of the passphrase and reject it if less than 15 characters AND it has zero transactions. (dont want to lock out any people that do have NXT with a 15 char password)

Here's my new logic for my client http://nxtra.org/nxt-client (to be available later today, not yet uploaded)

Thoughts?


Thoughts: Implement this ASAP, and sort out the wallet.dat discussion later.

Do not get sidetracked into that discussion and then wait Smiley

It may not be *perfect* but it's WAY better than what we have.



+1
legendary
Activity: 1162
Merit: 1005
Hi Wesleyh

While you are alive and online, please answer me, I'm repeating.

Testing AE. Using NxtWallet. Have question as simple Joe:

Did I miss somewhere, but how to know at which price I bought asset or when and for what price I sold an asset? I don't see anything in transactions and my assets.

Could somebody point me if it is?
hero member
Activity: 910
Merit: 1000
I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.

But its really less confusing for newbie than Brainwallet / current wesley implementation

No.

you cant just come in here and say no and leave it at that.  read my argument and refute it.  that is if you want reasonable discourse, otherwise you get ignored.  seriously tell us why "no".

People lose their coins because of a weak password they can only blame themselved. If they lose their coins because they did not understand what a wallet.dat is,where it is why and how to take a backup, they will sure blame the software for being so difficult.

Wallet.dat should be an advanced feature.

optical, bidji29. i think you are (we all are) biased because we know this shit for a long time. what the fuck is a wallet file. but a password, hell, everybody knows that.
hero member
Activity: 910
Merit: 1000
I bring forward a motion for Jean-Luc to modify the NRS client to check string length of the passphrase and reject it if less than 15 characters AND it has zero transactions. (dont want to lock out any people that do have NXT with a 15 char password)

Here's my new logic for my client http://nxtra.org/nxt-client (to be available later today, not yet uploaded)

Thoughts?


Thoughts: Implement this ASAP, and sort out the wallet.dat discussion later.

Do not get sidetracked into that discussion and then wait Smiley

It may not be *perfect* but it's WAY better than what we have.



+1
legendary
Activity: 2142
Merit: 1010
Newbie
Any suggestions about Parallel Chains? If not then I'll stick to BCNext's draft.

Suggestion:
- SCIP mechanism to count blocks in order to have snapshot every 1440 blocks


Question:
Will snapshots integrated for free?

For fee.
hero member
Activity: 616
Merit: 500
People lose their coins because of a weak password they can only blame themselved. If they lose their coins because they did not understand what a wallet.dat is,where it is why and how to take a backup, they will sure blame the software for being so difficult.

Wallet.dat should be an advanced feature.
full member
Activity: 238
Merit: 100
I bring forward a motion for Jean-Luc to modify the NRS client to check string length of the passphrase and reject it if less than 15 characters AND it has zero transactions. (dont want to lock out any people that do have NXT with a 15 char password)

Here's my new logic for my client http://nxtra.org/nxt-client (to be available later today, not yet uploaded)

Thoughts?


Thoughts: Implement this ASAP, and sort out the wallet.dat discussion later.

Do not get sidetracked into that discussion and then wait Smiley

It may not be *perfect* but it's WAY better than what we have.



I agree, keep main track as is while we discuss the nxtwallet.dat default method.
full member
Activity: 238
Merit: 100
I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.

But its really less confusing for newbie than Brainwallet / current wesley implementation

No.

you cant just come in here and say no and leave it at that.  read my argument and refute it.  that is if you want reasonable discourse, otherwise you get ignored.  seriously tell us why "no".
hero member
Activity: 644
Merit: 500
This good enough for a start page? Shown ONLY ONCE to the user, afterwards it's back to the secret phrase input box being shown by default.



I think that's perfect.

Lets integrate this with next NRS release as default client.
legendary
Activity: 1092
Merit: 1010
I bring forward a motion for Jean-Luc to modify the NRS client to check string length of the passphrase and reject it if less than 15 characters AND it has zero transactions. (dont want to lock out any people that do have NXT with a 15 char password)

Here's my new logic for my client http://nxtra.org/nxt-client (to be available later today, not yet uploaded)

Thoughts?


Thoughts: Implement this ASAP, and sort out the wallet.dat discussion later.

Do not get sidetracked into that discussion and then wait Smiley

It may not be *perfect* but it's WAY better than what we have.

full member
Activity: 238
Merit: 100

you 2 bring basically the same argument.  We are in a state a flux right now - the current NRS client has no restrictions, and we have some new clients coming out.  I say the new clients should implement the restrictions I listed NOW.  Then if the case you bring where the user creates an low-entropy passphrase  then sends funds to it somehow, they are using NRS *ANYWAYS*; it doesnt matter that the new clients have restrictions.

Eventually the new clients will go widestream and security will improve.

Guys, KISS (not literally).

And don't force people. Make a big hint and if they still want to choose a short passphrase, then let it be.

I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.

you 2 do realize, that right now with no nxtwallet.dat file, AND a "big hint" the we currently have in all NRS clients that there are still people (yes morons, but what can we do) that are losing their NXT?"

how is a .dat file confusing?

the brainwallet function needs to be non-default;  I consider it an advanced feature.  No one can sanely argue this fact, given the big hints we give out but with idiots still ignoring the warnings.
hero member
Activity: 644
Merit: 500
I have a question about this.

If the password cracker knows what dictionary you are using, couldn't they just make a database of these words and cycle through every possible combination of said words instead of cycling through letter by letter?  

Yes, and now calculate the combinations and come back with the number Wink

I have not the math skills to do even this.

1600 * 10 = 16,000  

It's 12 words (not 10), so it's 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626 * 1626

sr. member
Activity: 308
Merit: 250
This good enough for a start page? Shown ONLY ONCE to the user (until the user has logged in), afterwards it's back to the secret phrase input box being shown by default.

hero member
Activity: 910
Merit: 1000
I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.

But its really less confusing for newbie than Brainwallet / current wesley implementation

No.
sr. member
Activity: 392
Merit: 250
I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.

But its really less confusing for newbie than Brainwallet / current wesley implementation
hero member
Activity: 644
Merit: 500
I have a question about this.

If the password cracker knows what dictionary you are using, couldn't they just make a database of these words and cycle through every possible combination of said words instead of cycling through letter by letter?  

Yes, and now calculate the combinations and come back with the number Wink

Since it's open source, everyone knows the dictionary

https://raw.github.com/spesmilo/electrum/master/lib/mnemonic.py

The security shouldn't be based on "secrecy" . It's secure as 12 words from 1626 word choices is equal to 2^128 possible combination.
sr. member
Activity: 364
Merit: 250
☕ NXT-4BTE-8Y4K-CDS2-6TB82
Any suggestions about Parallel Chains? If not then I'll stick to BCNext's draft.

Suggestion:
- SCIP mechanism to count blocks in order to have snapshot every 1440 blocks


Question:
Will snapshots integrated for free?
hero member
Activity: 910
Merit: 1000
I have a question about this.

If the password cracker knows what dictionary you are using, couldn't they just make a database of these words and cycle through every possible combination of said words instead of cycling through letter by letter?  

Yes, and now calculate the combinations and come back with the number Wink

I have not the math skills to do even this.

1600 * 10 = 160,000  
ok, I'm lost.

I was just wondering if the security level is the same if you change the brute force method in this way or if it decreases at all.

We make it simple. Imagine each word is a character, as you suggested. But now, for every of the 12 characters we type, we can choose out of 1626 characters.

First character (word): 1626 possibilities
Second character (word): 1626 possibilities
....

Now calculate. You can do it. Math is cool.
hero member
Activity: 616
Merit: 500
I vote for no wallet.dat as the default option. It's one of the things most confusing to bitcoin newbies.
Jump to: