Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - DoctorClu

Pages: 1 ... 135 136 [137] 138 139 ... 149
2041
Bug Reports / Re: any captcha is valid?
« on: November 09, 2013, 07:18:35 am »
WTF so all of our accounts can easily be brute forced right now. every vender could easily be robed

This would only be possible if there are not any other rate limiting factors that protect the login system. Lets hope that's not the case :)

I PM'd the relevant threads regarding this issue to DPR.

Artist

And it would be only possible if you didn't activate PGP verification.
And it would be only possible if there were any btc on the accounts which are not until now.
And "easily" bruteforced is another point to argue about ;)

There have already been numerous noted problems with the PGP verification. Additionally, I would not put too much faith in it after seeing this issue concerning the CAPTCHAS.

I did not say anything about your second point, that was the user I quoted. However, whether or not there are coins in the account has nothing to with the possibility of accounts being brute forced. If you are talking about them being robbed in that instance, cracked passwords could be stored until market operations commence etc.

Your third point looks like it is attempting to say something clever but it is not really saying anything at all. Assuming the PGP verification works and there are no other rate limiting factors, it would be childsplay ("easy") to write a script to bruteforce the login. Whether or not it would be worthwhile or easy due to password complexity of the users here is another story.

Artist

EDIT: Spelling, spacing, signature,

Unless there is not a pretty standard anti-brute forcing measure in place where the login is disabled for X amount of time after X amount of failures, that third point is completely valid. I haven't tested it myself.

2042
Bug Reports / Re: whenever I open a silkroad new page it becomes black
« on: November 09, 2013, 07:14:50 am »
It may be a bug on touchscreens. I will test it on my surface and see if I experience the same thing. Either way, it will be a setting you can modify once the market is %100 live.

2043
Bug Reports / Re: whenever I open a silkroad new page it becomes black
« on: November 09, 2013, 07:05:23 am »
Why am I the bloody helpdesk tonight? Its a feature. Not a bug. It will happen if your session hits timeout.

2044
Bug Reports / Re: any captcha is valid?
« on: November 09, 2013, 07:01:08 am »
Considering there is no money in the road right now, there is nothing to rob except your identity as a vendor. I've posted this in the bug reports so hopefully is gets addressed sooner than later. Afterwards, it is probably advisable to change your password if you are concerned.

2045
Bug Reports / Re: whenever I open a silkroad new page it becomes black
« on: November 09, 2013, 06:57:50 am »
You said tablet so I am guessing its a touchscreen. Instead of refreshing the page, next time it fades out,  just try tapping the screen. It is a feature within the marketplace. It is the only place it will happen. For now you cant disable it, but DPR has stated that once everything is enabled, it will be a setting you can modify.

2046
Bug Reports / Re: whenever I open a silkroad new page it becomes black
« on: November 09, 2013, 06:44:38 am »
I'm using firefox for tablet, and it is strange because it only happens with the silkroad pages, all other sites are ok!

I open a new SR tab and suddenly it starts to become increasily black and then it gets all black in like 5 seconds

That is the timeout functionality. It will fade to a dark grey after you have been inactive for a short period of time.

2047
Bug Reports / Captcha not functioning at all
« on: November 09, 2013, 06:38:27 am »
Logins are being accepted using any random characters entered into the Captcha box. It doesn't seem to matter what is entered so this function is simply broken.

2048
Bug Reports / Re: any captcha is valid?
« on: November 09, 2013, 06:35:40 am »
I'm seeing the same behavior.  I will make a post in bug reports if there isnt one already.

2049
Bug Reports / Re: whenever I open a silkroad new page it becomes black
« on: November 09, 2013, 06:33:09 am »
I have not seen anything akin to this in the bug reports forum. Can you provide repro steps and/or screenshots? This may have to do with how your browser is configured.

2050
Silk Road Discussion / Re: Invite-system endangers anonymity
« on: November 09, 2013, 06:27:42 am »
I think a valid solution would be a combination of the two. Keep registration closed to invite only. As shown by the numerous keys posted in this thread alone and the ones being put on Twitter, this should allow for an exponential growth of the userbase. Also keep the delay between new account registration and the ability to generate keys.

In addition to this, bring back the 50 post quarantine from the old forum. This will stem the tide of trolls and spamming attempts while at the same time generating an atmosphere in the other forums that encourages posts of real value. I think that a daily/hourly post limit should also be implemented here to stop new users from simply spamming the quarantine forum with one-word posts so they can make it to 50 as fast as they can type.

Remove the functionality that allows for users to see who invited them. There is no purpose in this visibility and only serves to pose a potential security threat. DPR should be the only one able to view this information and a data retention policy should be put in place. The records should be purged either after X amount of days have passed or once the new user has reached 50 posts and is capable of generating keys themselves.

2051
Silk Road Discussion / Re: Domestic search/Filter by location
« on: November 09, 2013, 05:45:09 am »
This has already been discussed and confirmed in the Feature Requests forum:

http://silkroad5v7dywlc.onion/index.php?topic=2307.0

2052
Silk Road Discussion / Re: Invite-system endangers anonymity
« on: November 09, 2013, 05:42:51 am »
See?

(Rolls Eyes)

I am sure that was your invite chemmy :D.

How we move forward is still open for debate, but this culture of criticizing the system no matter what the state has to end, we need to actually hear some plans being put forth which are not the typical followings (ie close registration, open registration) since we have tried that and have come under even more criticism than the current state.

I understand that you and the moderators are a little stressed out and have a lot on your plates. I appreciate your response. I feel the need to defend myself though. This was my very first created topic ever and also my first criticism. I don't want to be part of your mentioned culture, so I will see your post as a thought-provoking impulse. Maybe we can make use of this thread and actually come up with something feasible.

Agreed +1. While security of the forum should not trump security of the market, I think other solutions can easily be thought up by the userbase as suggestions for improvement as opposed to lumping them all together as a culture of criticism. This is not our intent. Pointing out what we see as a potential security flaw should be encouraged DPR.

Staind - Sorry if I hijacked your thread in any way. It was not my intent.

2053
เลียของฉันกระเจี๊ยว

That's racist.

2054
Quote from: DeeMsTer
Quote from: ChemCat
What?

???

Raining SnowBalls  :-\

Oh Jeepers!!  I don't even have a Coat Out  ???

Dont take the piss outta the rain dance! You will regret making fun out of the rain dance! Rainmack or no rainmack!

เงียบท่านเองกรุณา บางครั้งความเงียบเป็นเครื่องมือการศึกษา :)

Amen.

2055
Cant the mods just ban this blithering idiot?

Pages: 1 ... 135 136 [137] 138 139 ... 149