Pages:
Author

Topic: This message was too old and has been purged - page 2. (Read 5009 times)

hero member
Activity: 574
Merit: 500
But I would prove it to you anyway. Just sign some text and post it along with a signature. Maybe the significance will become clear then.

Ok, I'm mathematically minded - what do you want me to do exactly - please post clear reproducible instructions and I'll give it a go...

Just sign a message with a btc address, and post message + signature + public key (the "address") - just as Automatic did.

sig : Hzkosd/No+cUbW8WvUdJvgCIV0F4xkPVKk2anyMp7NPedJkcmg/VD8BrAgGGuaP52tlsCv/csnAcpmTNDc3YH6A=

message : This is my Transaction Malleability Reloaded message

address : 1JuRLLT7YrtPKWooSPsuqgFU2EHSCN6Hdq

Any joy?
hero member
Activity: 535
Merit: 500
yup, hes a bitch
hero member
Activity: 644
Merit: 500
You got a negative trust rating because you've hyped bogus and deceptive security claims multiple times and tried to charge people for exploit tools that didn't. But hey, you could still collect on that 50 BTC bounty I offered you for your last set of claims, and I'll even remove the negative trust to boot.

He also claims to have found a flaw in Nxt and wanted money before he writes the code to exploit it.

https://bitcointalksearch.org/topic/m.5663483
member
Activity: 81
Merit: 10
Hi Serpens! I will be doing a demonstration soon, the problem is that we have 3 am at night over here and I am a bit tired.
But what I can say at least is, that such unprofessional people should never ever be part of a development team involved in a multi-billion-dollar-project.
This guy sounds like "if you say anything bad about bitcoin, i will give you a bad rating, mimimimi". I am sorry, but this is unprofessional.

I am really thinking about offering a donation of 50 BTC to the bitcoin foundation if they kick this guy out.

You shouldn't make your ulterior intentions so clear. Either man-up and prove the point in your OP or quit this holy crusade of yours.
sr. member
Activity: 434
Merit: 250
Malleability With security it is best move to solve problems.
legendary
Activity: 1148
Merit: 1018
This guy sounds like "if you say anything bad about bitcoin, i will give you a bad rating, mimimimi". I am sorry, but this is unprofessional.

The fact is that you tried to sell a useless program that simply did not work, while promoting it with fake arguments that could be explained only by a) a total lack of understanding of basic cryptography, or b) malice.

Now please prove you can generate multiple valid signatures for the messages + public keys posted above.
staff
Activity: 4284
Merit: 8808
Eight hours after the original post and not a single thing of substance has been said, just more FUD and whining like the prior incidents with this poster. Soon I suppose we'll see requests for payment.

Since he's asking for signmessages in particular, let me guess that if we get anything at all it'll be repetitions of the same signature and different messages with different public keys, which is exactly how it's supposed to work (every validly encoded signature is valid, which is why bitcoind's veryify message functionality forces you to provide the expected address.)

E.g.

verifymessage '1NskFs6D7NYP9rpnaAVAdz7NhLLNkSjf1J 'Gyk26Le4ER0EUvZiFGUCXhJKWVEoTtQNU449puYZPaiUmYyrcozt2LuAMgLvnEgpoF6cw8ob9Mj/CjP9ATydO1k=' '1'

verifymessage '17aiPTrsQtAHpRFvzxGoYiZ1m63ujDX43K' 'Gyk26Le4ER0EUvZiFGUCXhJKWVEoTtQNU449puYZPaiUmYyrcozt2LuAMgLvnEgpoF6cw8ob9Mj/CjP9ATydO1k=' '2'

verifymessage '1AY1MXXY6aPHW1Raj9QVjJprMo8BewMdB9' 'Gyk26Le4ER0EUvZiFGUCXhJKWVEoTtQNU449puYZPaiUmYyrcozt2LuAMgLvnEgpoF6cw8ob9Mj/CjP9ATydO1k=' '3'
Which is just a property of public key recovery and isn't interesting or related to Bitcoin transactions. Every possible signature,message pair is valid for some public-key.
legendary
Activity: 2632
Merit: 1023
Hi Serpens! I will be doing a demonstration soon, the problem is that we have 3 am at night over here and I am a bit tired.
But what I can say at least is, that such unprofessional people should never ever be part of a development team involved in a multi-billion-dollar-project.
This guy sounds like "if you say anything bad about bitcoin, i will give you a bad rating, mimimimi". I am sorry, but this is unprofessional.

I am really thinking about offering a donation of 50 BTC to the bitcoin foundation if they kick this guy out.

Dear EK, given the walls of text you are makeing , and the magnitude of your claim, you would be up 3.AM no worries setting out a brief proof....

You have had signed messages or so forth as you requested and only walls of text follow.

Do you see how this make you harder to believe?

I/m not ruling anything out, it just he story does not square at this time
legendary
Activity: 1260
Merit: 1168
This message was too old and has been purged
legendary
Activity: 2940
Merit: 1131
I think you all should calm down. You all made mistakes by offending the other users.

So Evil-Knievel, please just prove the things you are saying.
Next time you maybe should start with the evidences =/
legendary
Activity: 1260
Merit: 1168
This message was too old and has been purged
staff
Activity: 4284
Merit: 8808
You got a negative trust rating because you've hyped bogus and deceptive security claims multiple times and tried to charge people for exploit tools that didn't. But hey, you could still collect on that 50 BTC bounty I offered you for your last set of claims, and I'll even remove the negative trust to boot.
hero member
Activity: 535
Merit: 500
WHAT KIND OF COMMUNITY IS THIS???

I have just gotten a negaitve trust rating from gmaxwell, just because I wanted to discuss some potential security issues with you guys? What kind of cumminity is this, please? Do you get a negative rating if you talk about your concerns? Is it better to shut up completely, even if sometimes a false alarm might be sent off?

How can this be? Don't you guys think this is unfair?

are you a bitch? because you act like a bitch.
hero member
Activity: 546
Merit: 500
I'm sure it'll be retracted pretty quickly if you do something with the signed messages above, as you requested Smiley
legendary
Activity: 1260
Merit: 1168
This message was too old and has been purged
donator
Activity: 477
Merit: 250
Okay, it's highly unlikely that sha256 becomes broken near-term. But let's wait if he found a workaround on that signing procedure. In this case he would deserve some serious worship for publishing it here. Let us pray, let the unicorns fly!
hero member
Activity: 574
Merit: 500
So what's up? Do we have devcon 1 or is this just an alarm drill?

It is possible I think but would take some kind of genius inspiration to break the encryption algorithm. I remember there was some Chinese girl who did (then didn't yeah right) break the sha256 algorithm... still waiting for his asics to crunch the numbers...

This means if his Asperger turns out misunderstood genius, sha256 is basically broken? Is there a way we can "easily" follow/confirm his claim?

Well if he posts a message that I can verify as signed my me - then yeah shit hits the fan. Probability is low though but you can't rule out a mule (isaac asimov Smiley )

[edit] and then we would need to know how he did it... yeah

[edit2] even if he did manage to post a message that I could verify as signed by me - it's more likely to be a a 'feature' in bitcoin qt 0.8.6 rather than a crack for sha256...
donator
Activity: 477
Merit: 250
So what's up? Do we have devcon 1 or is this just an alarm drill?

It is possible I think but would take some kind of genius inspiration to break the encryption algorithm. I remember there was some Chinese girl who did (then didn't yeah right) break the sha256 algorithm... still waiting for his asics to crunch the numbers...

This means if his Asperger turns out misunderstood genius, sha256 is basically broken? Is there a way we can "easily" follow/confirm his claim?
hero member
Activity: 574
Merit: 500
So what's up? Do we have devcon 1 or is this just an alarm drill?

It is possible I think but would take some kind of genius inspiration to break the encryption algorithm. I remember there was some Chinese girl who did (then didn't yeah right) break the sha256 algorithm... still waiting for his asics to crunch the numbers...
donator
Activity: 477
Merit: 250
So what's up? Do we have devcon 1 or is this just an alarm drill?

Hello Everyone!

It was hard to miss the recent implications of the transaction malleability issue, in which context for example nearly all MtGox funds were lost. Now the simple idea was to take the negative value of a part of the signature which also resultet in a valid signature (at least in the bitcoin implementation which falsely accepts this non-standard type of signatures).

I have probably found a way to resign "already signed" messages with perfectly correct signatures. Filtering for these typical "transaction malleability signatures" will therefore be not enough. Now the problem might be huge and not just solved by filtering out these "changed and non-standard signatures".

If you like we can discuss these issues here.
Pages:
Jump to: