Author

Topic: [XMR] Monero - A secure, private, untraceable cryptocurrency - page 542. (Read 4671924 times)

donator
Activity: 1274
Merit: 1060
GetMonero.org / MyMonero.com
Our aim is to replace lots of components (eg. the web server used for JSON RPC API access) with standard, well-known, secure libraries.

Why?

Because epee is *not* known-good, *not* well-reviewed, *not* used anywhere except Monero. It is much higher risk to keep epee around, or to roll our own stuff, than to replace it with stuff that is widely reviewed.

Rolling your own can be better if you are talking about complexity getting dragged in with the standard component.  If you need something simple, it is often possible to achieve exceptional levels of confidence in the correctness if the component when you control it.  You can use declarative systems which are provable, and compile into c++, for example.  The upstream being uncontrolled adds a maintenance issue, but it is a much lower-order factor.

What is the preferred venue for such threads?

We're talking about components that require some complexity and extensibility. We're currently so heavily reliant on the Boost libraries that we literally can't get more complex by using other components.

We're also not talking about components used by one project - issues in something like Boost or 0MQ or netcpplib would affect thousands and tens-of-thousands of projects, and so they handle their efforts with care. We take similar precautions by statically compiling these in, and not updating to potentially broken versions until they're reasonable to consider safe.

There's no fixed venue, if you have a concern about a choice that the dev community has made then open a GitHub issue. That said, the contributors (ie. those that have actually submitted pull requests) are generally in the best position to know the code, so if you want your opinion to matter and not be discarded then you need to start pushing code;)

Attending the dev meetings every second week would also go a long way towards that. Opinions on design decisions from non-contributors are not discarded, but they typically won't be considered as strongly precisely to prevent interference by the sort of third-parties you'd be worried about. It's much easier for someone to make a lot of noise about a decision than to push code, which leads to loud-voices-from-non-contributors simply not being enough to affect design and architectural decisions.
donator
Activity: 1274
Merit: 1060
GetMonero.org / MyMonero.com
See SafeCurves for details: https://safecurves.cr.yp.to

The bottom of this web page says it's funded by the "NWO" Cheesy

DUN DUN DUN DUN:)
legendary
Activity: 1722
Merit: 1217
See SafeCurves for details: https://safecurves.cr.yp.to

The bottom of this web page says it's funded by the "NWO" Cheesy
legendary
Activity: 1596
Merit: 1030
Sine secretum non libertas
I suggest that we all refrain from prompting anyone to act in a prima facie unlawful manner.  If one errs in such a way, it is reasonable to delete comments to correct the record, or to amend the comments with a clarification.
legendary
Activity: 1596
Merit: 1030
Sine secretum non libertas
Our aim is to replace lots of components (eg. the web server used for JSON RPC API access) with standard, well-known, secure libraries.

Why?

Because epee is *not* known-good, *not* well-reviewed, *not* used anywhere except Monero. It is much higher risk to keep epee around, or to roll our own stuff, than to replace it with stuff that is widely reviewed.

Rolling your own can be better if you are talking about complexity getting dragged in with the standard component.  If you need something simple, it is often possible to achieve exceptional levels of confidence in the correctness if the component when you control it.  You can use declarative systems which are provable, and compile into c++, for example.  The upstream being uncontrolled adds a maintenance issue, but it is a much lower-order factor.

What is the preferred venue for such threads?
sr. member
Activity: 478
Merit: 252
XMR instead of ETH become No.1 in Poloniex. Shocked

Bullish is still the main Monero trading trend now. Monero will be the No.1 for a long time. It's hard for Etherium to recover now.
sr. member
Activity: 290
Merit: 250
and it would suck tax wise if I am not able to proof the date I got the coins.

maybe it would be good. you could say you got them for a higher price than you did and protect yourself from a portion of the extortion.
It's tax free if I hodl the coins for 1 year, no need to tell a wrong price.
newbie
Activity: 31
Merit: 0
XMR instead of ETH become No.1 in Poloniex. Shocked
newbie
Activity: 28
Merit: 0
correctly... two things see same,.. It was confusing for me even at the beginning
legendary
Activity: 3164
Merit: 1118
...

You mean to say when I use the light wallet I would also have to open simplewallet.exe in the console at the same time? I do not get it. I thought you only open the light wallet and do everything from there.

Lightwallet uses simplewallet behind the scenes, but you shouldn't have to do anything special to get it to save. After it completes the sync it will issue a save command every few minutes, or there is a button to save it on the wallet tab. Initially it says "Not saved Sad" in red, but should change to something green when it successfully stores the wallet.
donator
Activity: 1274
Merit: 1060
GetMonero.org / MyMonero.com
bad Tor exit nodes

Huh How could a bad tor exit node learn your private key? mymonero.com is https encrypted.

No DANE support in browsers, and no wide DNSSEC support, means that downgrade attacks are trivial. Even then, you should only ever use Tor exit nodes if you happen to have the TLS fingerprints saved somewhere to verify your connection. MyMonero has HSTS on, but even if we were in the HSTS preload list it's a half-baked solution and is just a band aid till the next POODLE comes along.
donator
Activity: 1274
Merit: 1060
GetMonero.org / MyMonero.com
Perhaps implementing 2 factor would mitigate some of this.  Is the code on github?

Not entirely feasible - everything is client-side, MyMonero never knows your spend key. Ostensibly the spend key could be encrypted with some 2FA, but I'd be very wary about the ability to recover the actual key in the event of a 2FA failure or lost device or some such. It also doesn't solve the problem of an MITM attack.
legendary
Activity: 3164
Merit: 1506
Why does the light wallet not save the state after it has fully synced? After syncing I close the light client and the opened it again and it was syncing again starting from 0.

can u provide more info? light client? version number? os?

I used version 0.2 that I have downloaded here https://getmonero.org/getting-started/choose

I am using Windows 7 64bit. Do you have any idea what is going wrong with it?

You have to exit simplewallet gracefully by typing
Code:
exit
as command. If you don't do this the "state" will not be saved into the wallet cache.

You mean to say when I use the light wallet I would also have to open simplewallet.exe in the console at the same time? I do not get it. I thought you only open the light wallet and do everything from there.
member
Activity: 85
Merit: 10
   
Payment_ID can be entered after the address separated by a space, format: Address Payment_ID

https://i.imgur.com/pDikYEN.png
legendary
Activity: 1722
Merit: 1217
Hello, can someone tell me, as I make a withdrawal XMR in Bter exchange. Paste the address Monero first, spacing, and paste the address Monero Payment ID

You probably don't need a payment id if you are sending to yourself.
sr. member
Activity: 504
Merit: 250
askNFTY Team Account
Hello, can someone tell me, as I make a withdrawal XMR in Bter exchange. Paste the address Monero first, spacing, and paste the address Monero Payment ID
 (47sghzufGhJJDQEbScMCwVBimTuq6L5JiRixD8VeGbpjCTA12noXmi4ZyBZLc99e66NtnKff34fHsGR oyZk3ES1s1V4QVcB c149b93acd8adb62ebbdb203c357cc73ea9db94e81cdf3c7ed955a725b579789)

and I'm still waiting, and nothing comes. sorry no speack english.


https://p12.zdusercontent.com/attachment/494969/cFYu2Q3tqh40FQ6IaEGQ4wMuU?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..PbnJEbHP1hjT_M4CQb3hRg.ZSTfmQrnhgbrKWkfHFdCvFl4ZDmNWyNv_EE4gfYPPRJ8pEgOizFmAR2bK9wvcATVklMD6IIEvGESd8I5dTL8zLGZFBQD_0GPdP14oaQN4TuxBrKYy5w1ogCaBxXE0b-P7X6jYZjpiP-SWE1FufjOneIU6HSO7-yuVprNfSy-Yz4wyEuSwbnG8ftFaq1-EIlz0kZkAzRtBcww-bWFqt0u8VFVyyE1LFIwIrtdlnyCy5APRt9Oz-2OquI_R9UiMx88JzUbqaNgdkoD1asBJ7mt-2-NGdmwmAzvAXw9Cw62kb8.rfSEiwD05Rn074NmJvci3w



https://p12.zdusercontent.com/attachment/494969/4C6ePMZLkiycThczxNCV0jZCS?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..yXT26WgyX3L3Tnkv3B_s7g.4Hqk1gRX7fLPdMow0WpWran4I_1hkpu45nt45X7UApvtrHt1TnM_wvq1lP7pdxM73iMPSGoQgALXN6Lawwtri3dZyZ-SQV4aqfzx1ggS5HhcmoWMCTQuDnY94EtsTPlRO3JQkLRrdCJ1LJSZF5gWcHSw7Lz2jzz6e1CzoiV1XxOQIP2LALnXXM83IjyY8ma5Keafy7CwGvPYjIW_03H7k13-uerP65tstiyXjHzxu8PufxvGQ07ka7OD2uvlBQNm03hXnIivKV5qUlXPcMCRoGwJ5ML75DFR5O1aLiYLhic.bhXRFkySJryv-_v3mis_fQ



ID 152886
Address/TxID  

47sghzufGhJJDQEbScMCwVBimTuq6L5JiRixD8VeGbpjCTA12noXmi4ZyBZLc99e66NtnKff34fHsGR oyZk3ES1s1V4QVcB

c149b93acd8adb62ebbdb203c357cc73ea9db94e81cdf3c7ed955a725b579789

e857ddcc83bc18cfe5841b4d2a72cdf722138bef4bd014070ae53fa1c5d870e1

Amount 0.5   

Date    Operation 2016-08-27 18:29:43

It may take up to one day to see the coins transfer successfully. How long have you been waiting?. Wait atleast 24 hours. I once got it after 8 hours.
member
Activity: 85
Merit: 10
Hello, can someone tell me, as I make a withdrawal XMR in Bter exchange. Paste the address Monero first, spacing, and paste the address Monero Payment ID
 (47sghzufGhJJDQEbScMCwVBimTuq6L5JiRixD8VeGbpjCTA12noXmi4ZyBZLc99e66NtnKff34fHsGR oyZk3ES1s1V4QVcB c149b93acd8adb62ebbdb203c357cc73ea9db94e81cdf3c7ed955a725b579789)

and I'm still waiting, and nothing comes. sorry no speack english.


https://p12.zdusercontent.com/attachment/494969/cFYu2Q3tqh40FQ6IaEGQ4wMuU?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..PbnJEbHP1hjT_M4CQb3hRg.ZSTfmQrnhgbrKWkfHFdCvFl4ZDmNWyNv_EE4gfYPPRJ8pEgOizFmAR2bK9wvcATVklMD6IIEvGESd8I5dTL8zLGZFBQD_0GPdP14oaQN4TuxBrKYy5w1ogCaBxXE0b-P7X6jYZjpiP-SWE1FufjOneIU6HSO7-yuVprNfSy-Yz4wyEuSwbnG8ftFaq1-EIlz0kZkAzRtBcww-bWFqt0u8VFVyyE1LFIwIrtdlnyCy5APRt9Oz-2OquI_R9UiMx88JzUbqaNgdkoD1asBJ7mt-2-NGdmwmAzvAXw9Cw62kb8.rfSEiwD05Rn074NmJvci3w



https://p12.zdusercontent.com/attachment/494969/4C6ePMZLkiycThczxNCV0jZCS?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..yXT26WgyX3L3Tnkv3B_s7g.4Hqk1gRX7fLPdMow0WpWran4I_1hkpu45nt45X7UApvtrHt1TnM_wvq1lP7pdxM73iMPSGoQgALXN6Lawwtri3dZyZ-SQV4aqfzx1ggS5HhcmoWMCTQuDnY94EtsTPlRO3JQkLRrdCJ1LJSZF5gWcHSw7Lz2jzz6e1CzoiV1XxOQIP2LALnXXM83IjyY8ma5Keafy7CwGvPYjIW_03H7k13-uerP65tstiyXjHzxu8PufxvGQ07ka7OD2uvlBQNm03hXnIivKV5qUlXPcMCRoGwJ5ML75DFR5O1aLiYLhic.bhXRFkySJryv-_v3mis_fQ



ID 152886
Address/TxID 

47sghzufGhJJDQEbScMCwVBimTuq6L5JiRixD8VeGbpjCTA12noXmi4ZyBZLc99e66NtnKff34fHsGR oyZk3ES1s1V4QVcB

c149b93acd8adb62ebbdb203c357cc73ea9db94e81cdf3c7ed955a725b579789

e857ddcc83bc18cfe5841b4d2a72cdf722138bef4bd014070ae53fa1c5d870e1

Amount 0.5   

Date    Operation 2016-08-27 18:29:43
legendary
Activity: 1722
Merit: 1217
bad Tor exit nodes

Huh How could a bad tor exit node learn your private key? mymonero.com is https encrypted.
legendary
Activity: 1722
Merit: 1217
and it would suck tax wise if I am not able to proof the date I got the coins.

maybe it would be good. you could say you got them for a higher price than you did and protect yourself from a portion of the extortion.
legendary
Activity: 3766
Merit: 5146
Note the unconventional cAPITALIZATION!
https://mymonero.com/  ever compromised?
I deposited  more than 10K xmr on mymonero last year, I forgot the last time I logged-in my wallet, it's been a long time.
but today,  I logged-in and found all xmr was stolen on yesterday,
I have no idea how the hacker steal my xmr...
Any advice for me?



Please lay out screenshots, for without them, little hard to believe.

vphen is in contact with me, can confirm that it appears his Monero was swiped. This is nb?ot the first time this has happened, previous instances have resulted from bad Tor exit nodes, rootkits, private keys stored in Word documents, and other malware that targets Monero. Suffice it to say, if the DNMs are waking up to Monero's usefulness now, malware authors have been aware of it for a while (see: the botnets that have been mining Monero for a couple of years already).

PLEASE treat MyMonero as you would a normal wallet. If you would only carry $150 comfortably in cash in your actual wallet, then you should only keep like 40 XMR in your MyMonero wallet. For cold storage, use MoneroAddress or simplewallet offline on an air-gapped computer, and follow the instructions that have been detailed before.
Perhaps implementing 2 factor would mitigate some of this.  Is the code on github?
Jump to: