Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Sunday November 26 2017, @01:43PM   Printer-friendly
from the gone! dept.

https://api.cointelegraph.com/amp/v1/news/bitcoin-account-holder-loses-100k-over-public-wireless-network

An unidentified 36-year-old man who owns a Bitcoin account has lost more than 100,000 euros ($117,000) worth of Bitcoins while he was logged in on a public wireless network in a restaurant in Vienna, Austria.

The Austrian police, however, claimed that they are still investigating whether the victim's account was already hacked before he opened his account on the unsecured network, CBS reports.

This latest case reflects the growing concern over the security of digital currencies like Bitcoin and Ethereum amidst their growing popularity as a mode of payment.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 5, Interesting) by martyb on Sunday November 26 2017, @03:53PM (15 children)

    by martyb (76) Subscriber Badge on Sunday November 26 2017, @03:53PM (#601750) Journal

    Invalid form key: ufdLithSAM

    SoylentNews is such a shitty codemonkey website.

    I noticed you posted as an Anonymous Coward... are you, by chance, connected through our onion address?

    I won't claim to fully understand the details, maybe one of the devs can elaborate.

    The code for SoylentNews is based on an open source version of the code that was used for Slashdot. It needed a great deal of cleaning up in order to be made to work. Given the technological expertise of the community, it would not take long for someone to discover they could spam a discussion by programmatically submitting a slew of comments. Imagine someone dropping a few hundred comments on a story. Very not good. The solution, as I understand it, was that each time you request a form to submit a comment, you are provided a form key which is based on a hash of your IP address. So far, so good.

    One of the improvements that was added to SN was support for a TOR connection.

    The way that works is you enter the TOR network through an entry node, and a route through other nodes is created until you exit through a different node... an exit node.

    We, obviously, have no control over the path your connection takes.

    So, if your route is dynamically changed between the time you requested a comment form, and the time you click on submit, then we detect that you are trying to submit a comment from a different IP address from the IP address you used to request the comment form. That is reported as an "invalid form key".

    It is a long-standing problem and if you have a solution for that, we would be much obliged.

    I apologize for the hastily-written reply as I need to get ready for work, but I hope this at least provides some explanation of the issue you are facing.

    --
    Wit is intellect, dancing.
    Starting Score:    1  point
    Moderation   +4  
       Interesting=3, Informative=1, Total=4
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   5  
  • (Score: 0, Disagree) by Anonymous Coward on Sunday November 26 2017, @04:14PM (8 children)

    by Anonymous Coward on Sunday November 26 2017, @04:14PM (#601755)

    Why couldn't a spammer just programmatically request a new form for each spam comment? How does a "form key" help?

    Clearly, tying an IP address to identity is a stupid idea; it is an example of a leaky abstraction. Tor proves this. Hell, NAT proves this.

    What's wrong with CAPTCHAs? Why not use HashCash in some way? It was invented to thwart spam!

    • (Score: 4, Insightful) by Anonymous Coward on Sunday November 26 2017, @04:31PM (1 child)

      by Anonymous Coward on Sunday November 26 2017, @04:31PM (#601759)

      > What's wrong with CAPTCHAs?

      Oh hell no. What's wrong is that, to stay ahead of bots, they are increasingly becoming unsolvable by humans. My success rate with Google's stupid CAPTCHAs is way, way below 50%. Probably worse than a decent bot.

      • (Score: -1, Flamebait) by Anonymous Coward on Monday November 27 2017, @06:00AM

        by Anonymous Coward on Monday November 27 2017, @06:00AM (#601959)

        SoylentNews, you're shit.

        I swear, you must all be old graybeards with no longer an iota of value.

        Invalid form key: dP1qzjV0KW

        Eat a gray, circumcised, American cock.

    • (Score: 3, Informative) by Runaway1956 on Sunday November 26 2017, @05:13PM (5 children)

      by Runaway1956 (2926) Subscriber Badge on Sunday November 26 2017, @05:13PM (#601767) Journal

      I am one of those who has ALWAYS had problems with Captcha puzzles. Color blind, half blind to boot, and those damned puzzles beat hell out of me. I've asked the wife to tell me what the text is, many, many times. If the wife isn't around, then I make a guess, two or three times, if I can't get it by then, I close the tab and move on.

      • (Score: -1, Troll) by Anonymous Coward on Sunday November 26 2017, @05:34PM (4 children)

        by Anonymous Coward on Sunday November 26 2017, @05:34PM (#601770)

        Maybe you should have done everyone a kindness and culled yourself voluntarily from the gene pool.

        • (Score: 2) by Runaway1956 on Sunday November 26 2017, @06:19PM (3 children)

          by Runaway1956 (2926) Subscriber Badge on Sunday November 26 2017, @06:19PM (#601781) Journal

          You're funny. One of my three sons has the same genes, affecting his eyes. Cull? You've obviously missed many facts about me, that are available here on Soylent. I served in my country's military. I've paid taxes all of my life, since age 15. I contribute to society. WTF would I cull my genes? Better to cull some far more famous genes. About half of the readers here would agree that Trump should have been culled. The other half would agree that Hillary AND Bill should have been culled, BEFORE Chelsea happened. Then, there are other lowlifes, such as Shkrelli. Tell me - which of those named has actually "contributed" to society? I can make a damned good argument that each and every one of them are parasites.

          Maybe you should have been culled?

          • (Score: -1, Flamebait) by Anonymous Coward on Sunday November 26 2017, @06:32PM (1 child)

            by Anonymous Coward on Sunday November 26 2017, @06:32PM (#601784)

            I never needed you to march around like a buffoon, or pretend to be fighting for my rights.

            Besides, you're poorly sighted; I'm guessing you were a paper pusher.

            • (Score: 2) by Runaway1956 on Sunday November 26 2017, @07:00PM

              by Runaway1956 (2926) Subscriber Badge on Sunday November 26 2017, @07:00PM (#601787) Journal

              I spent a couple years pushing paper - that's a fact. I carried an M-14 as well. What else did I do? I did maintenance on a ship. I cooked. I washed dishes. I manned a fire fighting station. On and on it goes - when you're a member of a crew, you do EVERYTHING. https://en.wikipedia.org/wiki/Surface_warfare_insignia#Enlisted_surface_warfare_specialist [wikipedia.org]

              March around like a buffoon? You're probably the same AC who believes that the Kurds will eventually be granted indepence, if they just sit back, and be patient. Whether or not you are the same AC, you're equally naive and foolish.

          • (Score: 1, Insightful) by Anonymous Coward on Monday November 27 2017, @01:32AM

            by Anonymous Coward on Monday November 27 2017, @01:32AM (#601905)

            half [...] agree that Trump should have been culled. The other half would agree that Hillary AND Bill should have been culled

            I assure you that the 2 halves have a lot of cross-over in their membership.

            -- OriginalOwner_ [soylentnews.org]
            (Nader/Stein voter)

  • (Score: 0) by Anonymous Coward on Sunday November 26 2017, @08:48PM (5 children)

    by Anonymous Coward on Sunday November 26 2017, @08:48PM (#601818)

    So if this error happens with a static IP then what? Probably someone MITMing the connection??

    • (Score: 1, Informative) by Anonymous Coward on Sunday November 26 2017, @09:09PM (4 children)

      by Anonymous Coward on Sunday November 26 2017, @09:09PM (#601832)

      Probably typing too slowly. Hit the back button, copy the stuff you were trying to post, request another form, paste and submit.

      • (Score: 0) by Anonymous Coward on Monday November 27 2017, @01:36AM (3 children)

        by Anonymous Coward on Monday November 27 2017, @01:36AM (#601906)

        Compose your comment in a text editor.
        When you have it all ready, THEN call for a comment page.

        This isn't rocket surgery.

        -- OriginalOwner_ [soylentnews.org]

        • (Score: 0) by Anonymous Coward on Monday November 27 2017, @02:52AM (2 children)

          by Anonymous Coward on Monday November 27 2017, @02:52AM (#601922)

          "Not rocket surgery"? More like lame workaround for a half-assed website.
          Other websites don't give me this problem.

          • (Score: 0) by Anonymous Coward on Monday November 27 2017, @05:26AM (1 child)

            by Anonymous Coward on Monday November 27 2017, @05:26AM (#601950)

            ...the insecure ones, one supposes.
            (Clearly, something* is changing your IP address in the time it takes you to compose a comment.
            That isn't S/N's fault; our guys are doing things right.)

            * TOR? A proxy? Your gratis ISP?

            -- OriginalOwner_ [soylentnews.org]

            • (Score: 0) by Anonymous Coward on Monday November 27 2017, @05:57AM

              by Anonymous Coward on Monday November 27 2017, @05:57AM (#601957)

              See here [soylentnews.org].