Forgot your password?
typodupeerror

Comment: Re:How did people not notice this early? (Score 3, Informative) 101

by grnbrg (#47630721) Attached to: Network Hijacker Steals $83,000 In Bitcoin

I got hit April 25th with this. I noticed within an hour, and it took me about an hour to determine that my connection to the pool had been spoofed, and my miners redirected to the attackers pool. I had no idea at the time *how* it was done.

My mining software was a couple of months old at the time, and the latest version would ignore such redirect requests. I updated and continued on, having lost maybe 2 hours of mining.

The redirect comes from that fact that the "Stratum" protocol used by many minors to request work from the pools was originally designed as a wallet to blockchain server protocol. Under that use case, it makes sense that the server might suggest to a (wallet) client that they use another server.

Comment: Re:Except, of course, they have to prove you can (Score 1) 560

by grnbrg (#47334963) Attached to: Mass. Supreme Court Says Defendant Can Be Compelled To Decrypt Data

There is a hierarchy of trustworthiness with the judge at the top, and the dirty criminal at the bottom. Anything the police say will be believed over what you (the dirty criminal, otherwise why would you be arrested) say. Lawyers are above the police in that hierarchy.

Comment: Shamir's Secret Sharing and Encryption. (Score 2) 208

by grnbrg (#47274899) Attached to: Ask Slashdot: How To Bequeath Sensitive Information?

Pick a nice, long, secure passphrase. Use it to secure a GPG keypair. Back up this keypair in multiple locations, and with multiple people who know "This is the key that encrypts all of my digital stuff. My family will need it when I die.".

Use that keypair to encrypt all of your important passwords and data. Back up the encrypted files in multiple locations. Make sure your family knows where these locations are, and why thy and the files they contain are important.

Download a copy of http://passguardian.com/ . Load the saved copy (preferably in an offline PC) in a browser, and use it to convert your passphrase into several N of M parts. ie: Create 10 parts, and require at least 6 to reconstruct the passphrase.

Use something like http://goqr.me/ (or any other generator) to create QR codes for the 10 secret shares. Laser print the text share, QR code and some instructions onto a business card sized piece of paper, and have them laminated.

You now have 10 waterproof, hard to damage cards, any 6 of which will unlock your digital data. Distribute them to trusted parties and locations with instructions to use the shares once they hear and confirm your death. These parties don't have to be literate enough to merge and decrypt the data themselves, they just need to know that it is possible with their share. On your death, they will arrange to bring the shares and data together, and even if they have to hire a nerd to help them, they will unlock what they need.

Comment: Re:Ban them everywhere! (Score 1) 376

by grnbrg (#47207315) Attached to: Theater Chain Bans Google Glass

Alamo Drafthouse is banning them, and I doubt they care at all about the piracy thing - they ban talking and any sort of device use or distracting behavior flat out. People go there to watch the movie, if you want to play with your electronics instead, there are plenty of other places to go.

And from what I've read, if they catch you using your electronics, they'll help you get started finding those other places by escorting you to the parking lot. :)

Comment: Re:Maybe they should ask corded phone manufacturer (Score 4, Insightful) 399

by grnbrg (#46858843) Attached to: Japanese and Swiss Watchmakers Scoff At Smartwatches

Corded phones didn't cost $350 - $500 either.

$350-$500 puts you into the range of cheap trash and knock-off timepieces. Try adding a zero. Or two.

I'm a geek, and I've got a Pebble that I wear fairly regularly. But the watch I wear when I want to dress up a bit (or when I get tired of the cheesy plastic smart watch) is a Tag Heurer with an automatic movement. The Pebble is neat, and has IMHO the right balance of features and price. But it has no soul.

Comment: PassGuardian, with N of M secret reconstruction. (Score 2) 381

by grnbrg (#45897771) Attached to: Ask Slashdot: How To Protect Your Passwords From Amnesia?

http://passguardian.com/

This uses Shamir's Secret Sharing algorithm to take your password, and split it into a configurable number of pieces, and requires a subset of those shares to reconstruct the original. Take your master password, split it into 10 shares, and require 5 shares to reconstruct. Then distribute the 10 shares to secure locations and trusted people.

Example:

Password: 12345
Share 1: 801650d0edcbd0c3c949f
Share 2: 802c91a40a532182e3570
Share 3: 803ad177a79bc1420a1de

Any 2 shares can reconstruct the password.

And the site runs entirely in Javascript. You can save it to a USB stick and run it from an offline PC, so you don't have to worry about your password being stolen.

Comment: Re:Reminds me of other inflated markets (Score 1) 371

by grnbrg (#45542271) Attached to: Bitcoin Tops $1,000 For the First Time

Who needs luck?

Over the last couple of years, I've put a two to three thousand dollars into Bitcoin... I've made some bad decisions, and currently have "only" 20 BTC or so.

If the whole thing implodes, and those coins become worthless... I've had a hell of a ride, and think the couple of grand was well spent for the entertainment. On the other hand, if it takes off and Bitcoin turns out to be the next big thing like Ebay or Facebook, I can retire early.

Comment: Re:When will people accept it's not a real currenc (Score 1) 157

by grnbrg (#45482217) Attached to: Cyprus University Accepts Bitcoin For Tuition Fee Payments

Please can we see an end to the "it's not a real currency" posts. It's money and you can buy stuff with it. The end.

Heh. You waited too long for the punchline... Just about everyone started foaming before they got to the end.

Not everyone missed the bus, though. :golf clap:

Comment: Re:Good Luck (Score 1) 157

by grnbrg (#45482193) Attached to: Cyprus University Accepts Bitcoin For Tuition Fee Payments

What amazes me is that even after the recent stolen Bitcoin news, the prices have actually gone up. I'm still predicting that there will be a really major theft or attack against Bitcoin that will absolutely devastate it.

To date, there have been no successful attacks against the underlying Bitcoin protocol. There have been one or two serious client issues -- for example there was an incident a year ago where the latest version of the Bitcoin network software started creating blocks that older versions rejected. It was fixed in time, but if it hadn't there wouldn't have been hugely serious effects. All the miners would have been forced to upgrade. There was also an issue due to a buggy crypto implementation on Android that made some Bitcoin wallets vulnerable to theft.

It will be something stupid involving trust where nobody thought that another party would do something, but they will do it, and it will be devastating. Then everybody will cry and moan saying "Why didn't we protect against that?". Of course, I could be wrong, but I have no skin in this game so either way I'm not losing or gaining whether I'm right or wrong.

Again, there have been many problems with exchanges, service providers and outright fraud that have been related to Bitcoin, but these have all been problems with entities having poor security, and not being careful with how they integrate Bitcoin with their systems, not problems with Bitcoin itself. Those events would not have changed at all, if you had replaced Bitcoin with fiat in their operations.

If Bitcoin fails, it will be because it is regulated out of existence (which will be hard -- it is more likely to just be driven underground) or because it is deliberately attacked by a player with huge amounts of money to do so. Such an attack would likely be a government or group of "big money" interests willing to spend hundreds of millions of dollars in hardware to attack the block chain through mining.

APL hackers do it in the quad.

Working...