scriptSig

Joined Sep 04, 2018

Profile not set

Mute
1PDBscfDpVrfZShDANtG9uaRumsBFnMDbK
Actions 423
Following 6
Followers 16
Topics following 5
Muted 6
Is Muted By 1

replied 2167d
TrashPosterInTheDark
This is a shit post: 💩
anarchovegan
2167d
voted December 1st 2167d
BitcoinHoarder
created poll 2167d
Mega blast stress test attempt of 5,000,000+ transactions November 15th or December 1st?
November 15th 6 votes · 125,344 satoshis
December 1st 34 votes · 164,638 satoshis
Never, tests are stupid. HODL! 0 votes · 0 satoshis

Results

replied 2167d
Yours.org isn't accepting anymore people and hasn't been for quite some time.
replied 2167d
Generate BIP39 mnemonic, use that as seed to derive m/44'/145'/x' where x' is the service. Forget the root master and use the Memo pass to encrypt the XPRV of this account.
replied 2167d
As blake said this has been brought up and is fairly standard practice. We are changing our stance on this though and will be removing plaintext passwords from local storage soon. Ty.
anarchovegan
replied 2168d
replied 2168d
I expressed my concerns with this months ago to @jason when I first started on the app but was told it's standard practice. I'm with you. Session tokens, no plaintext.
replied 2168d
Malware can search for it because the data has the same rights as you. Instead of stealing, it'll just post spam from your account. At least that's how I'd exploit it.
replied 2168d
BIP39 mnemonic should be provided to the user and forgotten. The Memo password should encrypt the XPRV for this specific account and should be unlocked on each session.
2168d · memo
Security risk: my Memo pass is stored in plain text in the browser. Please ENCRYPT local storage and hold the plain text only in SESSION storage (and provide public mode where there's no plaintext).
replied 2168d
anarchovegan
It lives forever on the blockchain. EIGHT.
replied 2168d
That code URI is incorrect. It's not prefixed with bitcoincash. Should be "bitcoincash:qzlycgpk2kym38d9pt6gwz2wvd7p405t5y996s96vx"
replied 2168d
12UrgWaQFhE7XBB9
That sounds like the wording from a bad banner ad from 1999. The kind that wiggled on the screen. Did you create a P2SH for that puzzle?
replied 2168d
anarchovegan
SEVEN!
replied 2169d
It's like the original Bitcoin client that chose random keys. Lose the wallet.dat, lose the coins.
replied 2169d
anarchovegan
Now you have six.
2169d · memo
Memo needs an edit feature or at least I need one badly. Could it work by "overriding" the existing memo, sending a new memo with the existing posts ID and the site displays the most recent?
replied 2169d
Wish there was a diff Memo code. You'd just post the diff of the text, that way changes can be tracked.
2169d
Mega Millions is nearly $1 bill cash. Anyone interested in doing a pool (BCH equiv of $2)? I'll buy the tickets in a state with no income tax and post pics of the tickets.
replied 2170d
In that case, your only option is to share the extended key as you did (which is not ideal). But going forward, you might want to find a secure way to share it 👍
replied 2170d
(cont) But I'm not sure if you're gaining anything since you'd still be sending it to a single address (the bot) in the end anyway, which could be used to steal the funds.
replied 2170d
(cont) People would donate funds to that P2SH address. When you want to spend, all cosigners will sign the transaction consolidating the donations and send to the bot's wallet. (cont)
replied 2170d
You'd set up the multisig wallet in Electron by sharing the extended public key with the other cosigners, then create a P2SH address. This is the donation address for the bot. (cont)
followed 2170d