Author

Topic: NXT :: descendant of Bitcoin - Updated Information - page 783. (Read 2761629 times)

hero member
Activity: 616
Merit: 500
Unregistered users = 3 votes per hour!

>>>>>>>>>>>>>>> PLEASE VOTE! <<<<<<<<<<<<<<<

Registered users = 6 votes per hour!


Please quote me, share on Twitter, Facebook, Reddit... thanks!


BUY VOTES FOR NXT!

1 VOTE = 0,00005 BTC
1 BTC = 20,000 VOTES FOR NXT

Website: https://www.mintpal.com/voting
How to? Send your BTC to 1KB2AWLpKByBifkyQLJERhZi4jVDGWMA4n

Each 0.00005000 BTC received will count for 1 vote. All payment votes will be publicly visible, as you can see by clicking here.



I put it on reddit. Can you please upvote it for visibility?
http://www.reddit.com/r/NXT/comments/1yafnz/lets_vote_nxt_into_an_upcoming_exchange_every/
I've posted this on Nextcoin.org too! Almost at the top of Mintpal!!  Grin
https://nextcoin.org/index.php/topic,4104.0.html


We're at the top  Grin
full member
Activity: 224
Merit: 100
Just a quick update for those not following the other thread: Nxtopia bounty has broken the 20,000 NXT mark after receiving our latest donation from msin.

--

Nxtopia -- MMORPG built on-top of the NXT network

current bounty: 20,500 NXT

5000 - jl777
1000 - swartzfeger (Transaction id: 12550164158045962834)
3000 - chanc3r (Transaction id: 5658009271669858297)
1000 - MyZhre (Transaction id: 8826881503135433086)
3000 - Damelon (Transaction id: 17094914052077797717)
1000 - DrearyUrbanite (Transaction id: 5539495976647418930)
1000 - brooklynbtc (Transaction id:   )
0500 - rdanneskjoldr (Transaction id: 91193539943795488)
5000 - msin (Transaction id:   )

This is an opportunity to support an online game that leverages many of Nxt's advanced features, one of the highlights being a user-driven crafting economy.

Donations can be sent to 13776816462073143763; please include tx id so I can include it when updating this post and making it easier for James to keep track of incoming transactions.

We're also considering implementing a kickstarter-style tier system for bounty donators. These would be cosmetic rewards that wouldn't be available after game launch. Something like:

10 NXT - badge
100 NXT - cap
1000 NXT - cape
10000 NXT - beta access (?)

Depending on how we handle character death/respawning, these items may be also confer a quicker resurrection.

How about an ingame auction house like WOW, but the ingame(atleaset in the auction house) currency is milli NXT or something?

I think you will get banned for that in many MMOS Cheesy...
real cash to items is banable in most of games expetialy in Blizzard games.

Yes, but now WE CAN do that. No one here to swing the banhammer Wink
Better anyway is using ebay and buy whole accounts.
There you have reputation for traders some kind of safety is there,anyway world of MMORPGs is full of scammers. Cheesy

Luckily, the game's asset trading is secured through the NXT Asset Exchange. In order to get scammed, the attacker would have to get past the NXT network.
legendary
Activity: 1205
Merit: 1000
Unregistered users = 3 votes per hour!

>>>>>>>>>>>>>>> PLEASE VOTE! <<<<<<<<<<<<<<<

Registered users = 6 votes per hour!


Please quote me, share on Twitter, Facebook, Reddit... thanks!


BUY VOTES FOR NXT!

1 VOTE = 0,00005 BTC
1 BTC = 20,000 VOTES FOR NXT

Website: https://www.mintpal.com/voting
How to? Send your BTC to 1KB2AWLpKByBifkyQLJERhZi4jVDGWMA4n

Each 0.00005000 BTC received will count for 1 vote. All payment votes will be publicly visible, as you can see by clicking here.



I put it on reddit. Can you please upvote it for visibility?
http://www.reddit.com/r/NXT/comments/1yafnz/lets_vote_nxt_into_an_upcoming_exchange_every/
I've posted this on Nextcoin.org too! Almost at the top of Mintpal!!  Grin
https://nextcoin.org/index.php/topic,4104.0.html
full member
Activity: 168
Merit: 100
Quote
Quote
   
Since you keep referring back to that stackexchange link, some quotes from the man himself:

Quote
As everything is done using javascript in the site is particularly vulnerable to browser exploits including malicious browser extensions. Modern web browsers are much more secure than the internet explorer 6 generation.

Quote
If our servers were compromised the attacker could theoretically alter the javascript files to intercept the users password next time they login. For this to be effective the attack would have to go unnoticed for an extended period of time.


Quote
   


10 Immutable Laws of Security.

Law #1: If a bad guy can persuade you to run his program on your computer, it's not solely your computer anymore.
Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore.
Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore.
Law #4: If you allow a bad guy to run active content in your website, it's not your website any more.
Law #5: Weak passwords trump strong security.
Law #6: A computer is only as secure as the administrator is trustworthy.
Law #7: Encrypted data is only as secure as its decryption key.
Law #8: An out-of-date antimalware scanner is only marginally better than no scanner at all.
Law #9: Absolute anonymity isn't practically achievable, online or offline.
Law #10: Technology is not a panacea.


What is Two-Channel Auto-Type Obfuscation?

The Auto-Type feature of KeePass is very powerful: it sends simulated keypresses to other applications. This works with all Windows applications and for the target applications it's not possible to distinguish between real keypresses and the ones simulated by Auto-Type. This at the same time is the main disadvantage of Auto-Type, because keyloggers can eavesdrop the simulated keys. That's where Two-Channel Auto-Type Obfuscation (TCATO) comes into play.

TCATO makes standard keyloggers useless. It uses the Windows clipboard to transfer parts of the auto-typed text into the target application. Keyloggers can see the Ctrl-V presses, but do not log the actual contents pasted from the clipboard.

Clipboard spies don't work either, because only parts of the sensitive information is transferred on this way.

Anyway, it's not perfectly secure (and unfortunately cannot be made by theory). None of the currently available keyloggers or clipboard spies can eavesdrop an obfuscated auto-type process, but it is theoretically possible to write a dedicated spy application that specializes on logging obfuscated auto-type.

Enter Master Key on Secure Desktop (Protection against Keyloggers)
Note: KeePass was one of the first (maybe even the first) password manager that allows entering the master key on a secure desktop!

KeePass 2.x has an option (in 'Tools' -> 'Options' -> tab 'Security') to show the master key dialog on a secure desktop (supported on Windows ≥ 2000), similar to Windows' User Account Control (UAC). Almost no keylogger works on a secure desktop.

The option is disabled by default for compatibility reasons.

KeePass 2.x Only
Note that auto-type can be secured against keyloggers, too, by using Two-Channel Auto-Type Obfuscation.

In an effort to help this brilliant idea is nxt summarize my experience with the problem of security and key management.

first thing I did is get off free keepass program after analyzing several programs , being an open source program and enjoy a high reputation as a program.

then after reading a lot about the key generation choose to use absurd and nonsensical phrases formed by not less than 50 characters memorize words and 2 phrases from roughly 50 characters for the master password kee pass .

Install the plugin otpkeyprov keepass password and activate two factors to open kee pass with google authenticator in my android phone.

the first 50 characters of a sentence and the second sentence of 48 characters to activate google autenthicator 48 characters and match the standard b32 . the advantage of two-factor master password is nobody can not make all phishing password .

Within keepass generate passwords you want including accounts of nxt ( nxt also advise to memorize words and not less than 50 characters consisting of nonsensical words )

Enable tools options " change master key in a secure desktop " every time you open your account using automatic writing nxt
Enable automatic writing on the flap of each password " Obfuscation 2 channel automatic writing"

I hope you can help with these tips. in any case you can write me for any questions in kee pass and handle the "plug in" otpkeyprov .

Finally the technique of two-factor authentication for  nxt client passwords would be a good option against phishing . I leave it open to discussion forum .
legendary
Activity: 1680
Merit: 1001
CEO Bitpanda.com
This is how I see it: I use blockchain.info and I love it. But I don't store all my bitcoins there. I like to spread the bitcoins in 3 or more different baskets, the more I trust a basket the more bitcoins I put there. My offline wallet has the most.

I think it's the same with NXT. For a newbie, that just wants to start using NXT, I think the online wallet is perfect. If you own several thousand or million NXT, I would not recommend putting all of it in the same place, be it the online wallet or a single NXT NRS wallet.

But you could put some in the online wallet in case you need to use them on the go, or at work, etc.. this is how I am going to use it myself.

What i am saying is: your project is very nice, but if you altered your project to a blockchain.info type thing it would be uber-awesome.

That a coldstorage solution is needed is not even debatable!

Okay. Let's pause this discussion for a while. I will think about the browser side encryption a bit more. In the end of the day, I want to make something that people will use.

Agreed, and i can tell you, if you are the creator of such a service, you will be a rich man in the future Wink
hero member
Activity: 750
Merit: 500
www.coinschedule.com
This is how I see it: I use blockchain.info and I love it. But I don't store all my bitcoins there. I like to spread the bitcoins in 3 or more different baskets, the more I trust a basket the more bitcoins I put there. My offline wallet has the most.

I think it's the same with NXT. For a newbie, that just wants to start using NXT, I think the online wallet is perfect. If you own several thousand or million NXT, I would not recommend putting all of it in the same place, be it the online wallet or a single NXT NRS wallet.

But you could put some in the online wallet in case you need to use them on the go, or at work, etc.. this is how I am going to use it myself.

What i am saying is: your project is very nice, but if you altered your project to a blockchain.info type thing it would be uber-awesome.

That a coldstorage solution is needed is not even debatable!

Okay. Let's pause this discussion for a while. I will think about the browser side encryption a bit more. In the end of the day, I want to make something that people will use.
newbie
Activity: 56
Merit: 0
This is how I see it: I use blockchain.info and I love it. But I don't store all my bitcoins there. I like to spread the bitcoins in 3 or more different baskets, the more I trust a basket the more bitcoins I put there. My offline wallet has the most.

I think it's the same with NXT. For a newbie, that just wants to start using NXT, I think the online wallet is perfect. If you own several thousand or million NXT, I would not recommend putting all of it in the same place, be it the online wallet or a single NXT NRS wallet.

But you could put some in the online wallet in case you need to use them on the go, or at work, etc.. this is how I am going to use it myself.

Excellent points.

I would like to mention that a  trustless newb-friendly online wallet is overkill.
hero member
Activity: 750
Merit: 500
www.coinschedule.com
Quote
Yes, what you don't understand is: All attacks on one Computer will lead to the loss of funds. With your thing and a blockchain type thing.

Agreed.

Quote
The big difference is, that your service has about 10 more points of attack.

I don't think so.

Quote
If the creator of blockchain goes rouge , we would know that within minutes (as many DO check the source with hashes). If you did that, we would only know AFTER you just transfered ALL balances you collected the passwords for.[/b]

Maybe.
legendary
Activity: 1680
Merit: 1001
CEO Bitpanda.com
This is how I see it: I use blockchain.info and I love it. But I don't store all my bitcoins there. I like to spread the bitcoins in 3 or more different baskets, the more I trust a basket the more bitcoins I put there. My offline wallet has the most.

I think it's the same with NXT. For a newbie, that just wants to start using NXT, I think the online wallet is perfect. If you own several thousand or million NXT, I would not recommend putting all of it in the same place, be it the online wallet or a single NXT NRS wallet.

But you could put some in the online wallet in case you need to use them on the go, or at work, etc.. this is how I am going to use it myself.

What i am saying is: your project is very nice, but if you altered your project to a blockchain.info type thing it would be uber-awesome.

That a coldstorage solution is needed is not even debatable!
legendary
Activity: 1680
Merit: 1001
CEO Bitpanda.com
It wouldn't be difficult at all to develop a blockchain.info version of nxt. The entire thing could be done with a few servers and PHP.

CFB has made it extraordinarily easy to use PHP commands with the API of NXT.

This basic format could be used for transactions, or anything really.
ArrayID->json_decode(file_get_contents(url));

ArrayID is the response in this case.

If I get some free time I can have something that works online, I have a meeting in a hour, if it goes well I should have the rest of the day off.

The problem is (as far as i understand) that local signing is not yet ready!
member
Activity: 96
Merit: 10
Maybe change it to a simpler version:

Quote
Unregistered users = 3 votes per hour!
Just click 3 times on the VOTE Button for NXT - that's it!

>>>>>>>>>>>>>>> PLEASE VOTE! <<<<<<<<<<<<<<<
Much color, so many less words, yammy nxt Shocked

We should be in 1st place in a little bit.

Nxt just hit first place with 35k votes! Nice job!

But for how long does Nxt have to stay on first place? Or will the poll end at a specific time?
legendary
Activity: 1680
Merit: 1001
CEO Bitpanda.com
Since you keep referring back to that stackexchange link, some quotes from the man himself:

Quote
As everything is done using javascript in the site is particularly vulnerable to browser exploits including malicious browser extensions. Modern web browsers are much more secure than the internet explorer 6 generation.

Yes, what you don't understand is: All attacks on one Computer will lead to the loss of funds. With your thing and a blockchain type thing. The big difference is, that your service has about 10 more points of attack. If the creator of blockchain goes rouge , we would know that within minutes (as many DO check the source with hashes). If you did that, we would only know AFTER you just transfered ALL balances you collected the passwords for.

Quote
If our servers were compromised the attacker could theoretically alter the javascript files to intercept the users password next time they login. For this to be effective the attack would have to go unnoticed for an extended period of time.

see above

hero member
Activity: 750
Merit: 500
www.coinschedule.com
This is how I see it: I use blockchain.info and I love it. But I don't store all my bitcoins there. I like to spread the bitcoins in 3 or more different baskets, the more I trust a basket the more bitcoins I put there. My offline wallet has the most.

I think it's the same with NXT. For a newbie, that just wants to start using NXT, I think the online wallet is perfect. If you own several thousand or million NXT, I would not recommend putting all of it in the same place, be it the online wallet or a single NXT NRS wallet.

But you could put some in the online wallet in case you need to use them on the go, or at work, etc.. this is how I am going to use it myself.
full member
Activity: 168
Merit: 100
Quote
   
Since you keep referring back to that stackexchange link, some quotes from the man himself:

Quote
As everything is done using javascript in the site is particularly vulnerable to browser exploits including malicious browser extensions. Modern web browsers are much more secure than the internet explorer 6 generation.

Quote
If our servers were compromised the attacker could theoretically alter the javascript files to intercept the users password next time they login. For this to be effective the attack would have to go unnoticed for an extended period of time.

10 Immutable Laws of Security.

Law #1: If a bad guy can persuade you to run his program on your computer, it's not solely your computer anymore.
Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore.
Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore.
Law #4: If you allow a bad guy to run active content in your website, it's not your website any more.
Law #5: Weak passwords trump strong security.
Law #6: A computer is only as secure as the administrator is trustworthy.
Law #7: Encrypted data is only as secure as its decryption key.
Law #8: An out-of-date antimalware scanner is only marginally better than no scanner at all.
Law #9: Absolute anonymity isn't practically achievable, online or offline.
Law #10: Technology is not a panacea.
sr. member
Activity: 364
Merit: 250
☕ NXT-4BTE-8Y4K-CDS2-6TB82
right, we do get that, but ideally, the goal is a trustless environment.

I agree. We finally agreed on that.

Browser/JS signing and sending/receiving data with public servers allows this, without forcing a local blockchain sync, so this is our end game goal
But it is NOT trustless in the pure sense of that word.
hero member
Activity: 750
Merit: 500
www.coinschedule.com
Since you keep referring back to that stackexchange link, some quotes from the man himself:

Quote
As everything is done using javascript in the site is particularly vulnerable to browser exploits including malicious browser extensions. Modern web browsers are much more secure than the internet explorer 6 generation.

Quote
If our servers were compromised the attacker could theoretically alter the javascript files to intercept the users password next time they login. For this to be effective the attack would have to go unnoticed for an extended period of time.
newbie
Activity: 56
Merit: 0
It wouldn't be difficult at all to develop a blockchain.info version of nxt. The entire thing could be done with a few servers and PHP.

CFB has made it extraordinarily easy to use PHP commands with the API of NXT.

This basic format could be used for transactions, or anything really.
ArrayID->json_decode(file_get_contents(url));

ArrayID is the response in this case.

If I get some free time I can have something that works online, I have a meeting in a hour, if it goes well I should have the rest of the day off.
full member
Activity: 184
Merit: 100
I have a site prepared for selling stickes, mugs, etc... and much more. Just wait few days for publishing Smiley
Great!
I seem to have missed the announcement. It's very hard to keep up with all the updates on the various sites...  Sad

Will you also create / sell clothing for promotional purposes?
no, we are waiting for pro company to create for us branding packages, so we will have new logos etc, so any items created with old logos are a waste of time and resources I think


new logo's?

was there agreement on spending big money on professional branding? not totally sure, if we need this.
I for one am producing a useful marketing item, which also uses some Nxt logo.
when it is ready I can send it worldwide. keep it decentralized.
sr. member
Activity: 364
Merit: 250
☕ NXT-4BTE-8Y4K-CDS2-6TB82
Where is the list of client side javascript libraries for signing? (a bounty was offered by cfb for this)

I found this link - https://bitcointalksearch.org/topic/m.4612928

So, you get the bounty. Wink
legendary
Activity: 1680
Merit: 1001
CEO Bitpanda.com
Quote
If one computer is hacked than ONE person loses money.

Same for mynxt.info

Quote
If your server is compromised, he gets access to every wallet that logs in....

No, not every wallet that logs in. But every wallet the sends money somewhere because that is the only time we decrypt the wallet.

Imagine if there is a malware that can steal blockchain wallets from Firefox or IE or Chrome right when these are decrypted?

Quote
If you decide to collect the passwords and go rouge ....

Same for blockchain.info. How do you know they don't store a copy of passwords?

PLEASE read the technical aspects of blockchain.info

http://bitcoin.stackexchange.com/questions/5249/how-secure-is-blockchain-info

Quote
Same for blockchain.info. How do you know they don't store a copy of passwords?
If you would read that info you knew that your question is BS
Jump to: