Pages:
Author

Topic: Reused R values again - page 18. (Read 121336 times)

full member
Activity: 187
Merit: 100
December 09, 2014, 10:52:58 PM
#88
Johoe is gentlemen.
newbie
Activity: 4
Merit: 0
December 09, 2014, 10:00:03 PM
#87
Mr. Johoe, hats off to you sir.
legendary
Activity: 1372
Merit: 1000
--------------->¿?
December 09, 2014, 09:43:50 PM
#86
I'm impressed.  Shocked
legendary
Activity: 1260
Merit: 1116
December 09, 2014, 09:20:40 PM
#85
Johoe is now a crypto superhero. I must to bump
newbie
Activity: 44
Merit: 0
December 09, 2014, 09:12:03 PM
#84
It is *so* relieving to see some decency around here after many months of disgraceful attitude.

Thank you, johoe, for being generally awesome.
sr. member
Activity: 336
Merit: 250
Twitter: @Steven_McKie
December 09, 2014, 09:08:58 PM
#83
I hope to expect an announcement that they're hiring this guy as a security consultant.
legendary
Activity: 1148
Merit: 1001
December 09, 2014, 09:08:43 PM
#82
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.

That's very ethical of you. I hope they gave you a substantial reward.

I posted on reddit that BC.i should hire him and pay him well just to keep his eyes on the Blockchain and look for issues.  He already earned a year's worth of wages I would say.

But perhaps he has no need. Wink  

Nice job johoe!   Smiley
X7
legendary
Activity: 1162
Merit: 1009
Let he who is without sin cast the first stone
December 09, 2014, 09:05:11 PM
#81
You sir... are a fucking champion *tips hat*
sr. member
Activity: 404
Merit: 250
December 09, 2014, 09:04:08 PM
#80
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.

Quote
From: Ben Reeves <[email protected]>
If you could return the funds to address 15tXHJCjehqCEL6zRCkGwvuDY6YzZV5sKP that would be fantastic.



The return address is SINGLE SIG??!?   C'mon guys.

I absolutely love Blockchain -- but there is not a great excuse to not use multi signin this of all transactions.

administrator
Activity: 5222
Merit: 13032
December 09, 2014, 08:14:15 PM
#79
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.

That's very ethical of you. I hope they gave you a substantial reward.
full member
Activity: 217
Merit: 259
December 09, 2014, 07:57:10 PM
#78
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.

Quote
From: Ben Reeves <[email protected]>
If you could return the funds to address 15tXHJCjehqCEL6zRCkGwvuDY6YzZV5sKP that would be fantastic.

I should also add if that using our admin tools, if users supply us with the correct wallet information, we are able to accurately determine which refund claims are valid and which are not. So far we have processed over 30 refund requests and will be processing more over the rest of this week.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

15tXHJCjehqCEL6zRCkGwvuDY6YzZV5sKP
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iQEcBAEBAgAGBQJUh5AdAAoJEP3NqDUC96SQqH0H/3pTTawCXZWfWAwIoVQPkSYa
DgpioEvHLDHXegfAfXyo8X9vc50kEseQVeZ5FAvoeC3Hy76gNIgEDllP5o6FUXL2
HsEj7qcafY5AxlxMgRRG9p1OcbeJS6mlbZrjB78BD+zrtzZaLFoSAf4+lw3YZHg5
xvA0WyNoHE1Hzg8+pdPbg1PPN6dHT38+PCyqFgYIjkjq07UbxxtyyWs8KIQqSuTe
4XIh0gjd73Wqtxm4CAHtnwy0PA5Pi/lE7v0d6qqF2l86SlxDkT6067asMw9Te0JJ
WgnFM8fePrM8HU980n0xvamae7J71zlFMN2/RYfj2t/pTIEWz25ZI2iVS0MGg14=
=9MGK
-----END PGP SIGNATURE——

PGP key is available from https://blockchain.info/security.txt



https://blockchain.info/tx/ea8fa447d59000843910932a42bf7a28915772d97a006e97714d026b78885754
legendary
Activity: 1988
Merit: 1077
Honey badger just does not care
December 09, 2014, 07:46:33 PM
#77

Is it the unconditional use of Math.random() after the use of the Crypto API (if available), that lead to the bug? Or is there some other problem, I don't see?
Why isn't there a fixing commit, yet?

zootreeves added a note an hour ago:
Quote
For those interested. The bug was caused by missing line 29 and not initialising rng_pptr to 0. This commit was force pushed over.
hero member
Activity: 1582
Merit: 759
December 09, 2014, 03:59:07 PM
#76
I just want to say that I contacted the blockchain.info support, but I haven't heard back from them, yet.

To avoid double reimbursement, I want coordinate this with the blockchain.info people.  They should, hopefully, be able to check whether claims are valid or not.  If you lost funds due to this bug, contact the blockchain support, not me.  I cannot answer all PMs regarding this problem.


In my support ticket with them, I mentioned you. Hopefully this may elevate /escalate the priority.
sr. member
Activity: 350
Merit: 251
Dolphie Selfie
December 09, 2014, 02:10:21 PM
#75

Is it the unconditional use of Math.random() after the use of the Crypto API (if available), that lead to the bug? Or is there some other problem, I don't see?
Why isn't there a fixing commit, yet?
hero member
Activity: 935
Merit: 1002
December 09, 2014, 08:00:59 AM
#73
Most of the coins were saved (216BTC) the remeaning ones went to this address https://blockchain.info/address/1xyWYGDStMKVmNH4hivbfhJZa5xWFVWfd
legendary
Activity: 4270
Merit: 1313
December 09, 2014, 06:13:08 AM
#72
I just want to say that I contacted the blockchain.info support, but I haven't heard back from them, yet.

To avoid double reimbursement, I want coordinate this with the blockchain.info people.  They should, hopefully, be able to check whether claims are valid or not.  If you lost funds due to this bug, contact the blockchain support, not me.  I cannot answer all PMs regarding this problem.


Just remember, no good deed goes unpunished. Perhaps this should be in a new thread too.
full member
Activity: 217
Merit: 259
December 09, 2014, 05:56:09 AM
#71
I just want to say that I contacted the blockchain.info support, but I haven't heard back from them, yet.

To avoid double reimbursement, I want coordinate this with the blockchain.info people.  They should, hopefully, be able to check whether claims are valid or not.  If you lost funds due to this bug, contact the blockchain support, not me.  I cannot answer all PMs regarding this problem.
hero member
Activity: 910
Merit: 1003
December 09, 2014, 03:07:50 AM
#70
I suppose that they generated one number with the new code, and it looked random allright.  Tongue
newbie
Activity: 1
Merit: 0
December 09, 2014, 02:42:17 AM
#69
Pages:
Jump to: