Bitcoin Forum
January 17, 2026, 10:02:10 AM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 [589] 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 ... 2548 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761756 times)
Damelon
Legendary
*
Offline Offline

Activity: 1092
Merit: 1010



View Profile
January 01, 2014, 03:35:36 PM
 #11761

Well. Thought for sure it couldn't happen to me. but just had all of NXT stolen out of my account. yey..

Complete NIGHTMARE!   Sad Angry Sad

It's a nightmare I have often.  

I am terrified of keystroke loggers.  The more widespread NXT becomes, the more keystroke loggers are going to be deployed to steal it.  That's a fact.

I am only running my main NXT account on an old XP laptop that I sanitized by doing a zero bit overwrite of the hard drive and reinstalling the OS from a Dell reinstall disk followed by the minimal add-ons like Java etc brought over on a CD drive of via online downloads.   This laptop is used for NXT and that's it.  I have a hidden and uncommented local handwritten copy of my random password generated offline on the laptop using Awesome Password Generator 1.4 from Google (you know, the guys that are secretly partnered with the NSA) and another handwritten copy in my bank vault safe deposit box.  

I still worry.

I understand that the user space is unimaginably huge at something like (I think I remember seeing) 10^70 - but still.  One lucky hit by somebody else miskeying their own password under the current scheme, and it's all over for you.  That's a fact, mitigated only by just how much luck the thief would need to have.  I've got a degree in math and I understand probability and it still doesn't do much to calm the reptilian fear in my brain.

Is there a separate white paper PDF someplace that goes over in detail from scratch / first principles the entire NXT security scheme and just the security scheme?  If not, there needs to be.  We are going to have to point specifically to that information over and over and over as more and more people come to risk larger and larger sums that the security scheme is adequate - particularly when single colored coins are made that could be worth millions of regular NXT.

So, bottom line, I think we need a security whitepaper PDF and a link to it.

It's weird how even potential wealth can fry the brain Smiley
I have the same issue.

Member of the Nxt Foundation | Donations: NXT-D6K7-MLY6-98FM-FLL5T
Join Nxt Slack! https://nxtchat.herokuapp.com/
Founder of Blockchain Workspace | Personal Site & Blog
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 03:40:50 PM
 #11762

Oops, wrong key on edit.
laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 03:42:27 PM
 #11763

I see a lot of use for one special NXT donation fund in the future - Paranoia Therapy Fund. I am serious.
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1010

Newbie


View Profile
January 01, 2014, 03:44:57 PM
 #11764

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 03:49:33 PM
 #11765

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

For the record, I hereby vote for implementing an optional 2 factor authorization scheme via cellphone SMS as soon as possible.  All in favor, say aye?
BitcoinForumator
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000


View Profile
January 01, 2014, 03:50:45 PM
 #11766

What's going on with the Blockchain Explorer? It's been down longer than 24h
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 03:52:57 PM
 #11767

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

For the record, I hereby vote for implementing an optional 2 factor authorization scheme via cellphone SMS as soon as possible.  All in favor, say aye?

to tie the phone number to the account would be risky.....but you could easily create X amount of anonymous e-mail addresses.


Anon136
Legendary
*
Offline Offline

Activity: 1722
Merit: 1217



View Profile
January 01, 2014, 03:53:22 PM
 #11768

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

For the record, I hereby vote for implementing an optional 2 factor authorization scheme via cellphone SMS as soon as possible.  All in favor, say aye?

that doesn't make any sense. there is no "nxt company" to receive the text message.

Rep Thread: https://asktom.cf/index.php?topic=381041
If one can not confer upon another a right which he does not himself first possess, by what means does the state derive the right to engage in behaviors from which the public is prohibited?
Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1010

Newbie


View Profile
January 01, 2014, 03:53:56 PM
 #11769

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

For the record, I hereby vote for implementing an optional 2 factor authorization scheme via cellphone SMS as soon as possible.  All in favor, say aye?

to tie the phone number to the account would be risky.....but you could easily create X amount of anonymous e-mail addresses.



Guys? R u kidding???
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 03:54:26 PM
 #11770


that doesn't make any sense. there is no "nxt company" to receive the text message.

it could be a value added service provided by SERVICE PROVIDERS

Come-from-Beyond
Legendary
*
Offline Offline

Activity: 2142
Merit: 1010

Newbie


View Profile
January 01, 2014, 03:56:21 PM
 #11771

it could be a value added service provided by SERVICE PROVIDERS

Only if it's multisig and u trust this service provider.
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 01, 2014, 03:59:24 PM
 #11772

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

For the record, I hereby vote for implementing an optional 2 factor authorization scheme via cellphone SMS as soon as possible.  All in favor, say aye?

to tie the phone number to the account would be risky.....but you could easily create X amount of anonymous e-mail addresses.



Guys? R u kidding???

OK, using cellphone is not immediately feasible except as an add-on service later.  But I really do believe that some kind of hooks for a 2 factor authorization should be built into the code for transfers above a certain amount.  It would be slow because you would have to wait for the blockchain to generate the authorization code and get it back to you some minutes after you requested it, but I guarantee you that many users would pay extra fees for this to disallow transfers over a certain threshold without a blockchain generated authorization code.  I would pay for it right now.  

As programmers and math geeks, this seems unnecessary.  For public acceptance by high value users, it is mandatory or close to it.  
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 03:59:45 PM
 #11773

it could be a value added service provided by SERVICE PROVIDERS

Only if it's multisig and u trust this service provider.

optional service....people trusted banks in Cyprus.

landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 04:02:24 PM
 #11774

But I really do believe that some kind of hooks for a 2 factor authorization should be built into the code for transfers above a certain amount.  
  

This makes sense

Edit: A thief could always transfer smaller amounts under the threshold....

laowai80
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 01, 2014, 04:02:27 PM
 #11775

NXT is like a gun.
Once you squeeze the trigger, you can't stop the bullet.
Safety lock is your pass phrase.
People are asking for additional safety measures so that they or someone else can't squeeze that trigger or that the gun asks them 'are you sure you want to squeeze it?'
ImmortAlex
Hero Member
*****
Offline Offline

Activity: 784
Merit: 501


View Profile
January 01, 2014, 04:03:08 PM
 #11776

I vote for automatic transfer of 100,000 NXT from account, who ask for 2FA in decentralized network Cheesy
And another 100,000 NXT for user/password scheme request.
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 01, 2014, 04:04:54 PM
 #11777

NXT is like a gun.
Once you squeeze the trigger, you can't stop the bullet.
Safety lock is your pass phrase.
People are asking for additional safety measures so that they or someone else can't squeeze that trigger or that the gun asks them 'are you sure you want to squeeze it?'


Edit:
its simple for us...but for the general public its gonna be too much....pls bank pins are 4 digits....they are not gonna be used to 30+ char.


I know it is a must....but we have to try to see things from the perspective of the everyday person...who we want to adopt this technology.




chanc3r
Sr. Member
****
Offline Offline

Activity: 952
Merit: 253



View Profile
January 01, 2014, 04:05:10 PM
 #11778

Just a password to send....The function can be optional.

Nxt is decentralized, u can ask the password million times but it won't make ur account more secure if u use a weak master password.

Passwords are often stolen by observation, looking over someones shoulder etc. if you are in a shop you don't want to be entering a 30 character complex password on a smartphone its completely impractical so I suspect the smart phone clients will need to do something and keep next logged in with the passphrase.

I suspect when in wider adoption to prevent fraud by people accessing these devices NXT should ask for a level of authentication, people will expect this and however wonderful NXT is, the common man/woman/child will expect you to make the account safe and practical for them to use.

The first password opens the account - anyone can guess it / type it etc which is the driver of the discussion.
The second password would personalise the account to the person who selected the key the first time and then set a second key.

with other currencies you have the password/random characters that created the wallet and the option of a second password to encrypt the client - would be cooler with NXT if you could put that second password in the protocol.

SMS 2 factor authentication works for centralised organisations not decentralised systems, same problems as email - 3rd parties are also involved or would have to be, it would cost and someone would have to pay - there are lots of models but maintaining the stance that the only protection NXT provides is via a 50/60/70{- where do we stop} character password will become a barrier to adoption.

Damelon
Legendary
*
Offline Offline

Activity: 1092
Merit: 1010



View Profile
January 01, 2014, 04:05:43 PM
 #11779

NXT is like a gun.
Once you squeeze the trigger, you can't stop the bullet.
Safety lock is your pass phrase.
People are asking for additional safety measures so that they or someone else can't squeeze that trigger or that the gun asks them 'are you sure you want to squeeze it?'

This may all be so, but there is a need for the safety to be better.
Mainstream users will NEVER enter NXT in any way if safety is an issue.
Most people just want peace of mind and the knowledge that their money is safe and guaranteed.
For now, in this phase, it's maybe not an issue, but it should definitely be on the cards if NXT has plans to be anything other than a service that is used by the few.

Member of the Nxt Foundation | Donations: NXT-D6K7-MLY6-98FM-FLL5T
Join Nxt Slack! https://nxtchat.herokuapp.com/
Founder of Blockchain Workspace | Personal Site & Blog
sparta_cuss
Sr. Member
****
Offline Offline

Activity: 386
Merit: 250


View Profile
January 01, 2014, 04:05:58 PM
 #11780

Hey, looks like I just got robbed, too.
Someone please check this account: 12152013998194592943
They now have 147k+ from me.
Had a 40 char random password, capital, lower, numbers, symbols.
WTF?

"We must be willing to let go of the life we have planned, so as to have the life that is waiting for us." - E.M. Forster
NXT: NXT-Z24T-YU6D-688W-EARDT
BTC: 19ULeXarogu2rT4dhJN9vhztaorqDC3U7s
Pages: « 1 ... 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 [589] 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 ... 2548 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!