mtgox – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Mon, 22 Feb 2016 02:47:20 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png mtgox – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 Bitcoin is Legal-ish | Plan B 20 https://original.jupiterbroadcasting.net/41947/bitcoin-is-legal-ish-plan-b-20/ Tue, 20 Aug 2013 15:57:44 +0000 https://original.jupiterbroadcasting.net/?p=41947 A landmark ruling in Germany combined with the media’s attempt to label Bitcoin collide this week on the Plan B show.

The post Bitcoin is Legal-ish | Plan B 20 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

A landmark ruling in Germany combined with the media’s attempt to label Bitcoin legal status collide this week on the Plan B show. Plus the security warning Blockchain.info users need to know, and Butterfly Labs pokes the hornets nest!

Downloads:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | Video Feed | Torrent Feed | iTunes Audio | Ogg Feed

\"coinbaseqr\"

— Support the Show —

— Feedback —

Help spread the word on iTunes with a Rating and Review:

Call or txt the Show:

1 (352) 587-5262

(352) 58-PLANB

— Discussion —


Bitcoin now \’unit of account\’ in Germany

The German Federal Ministry of Finance said on Monday that Bitcoin is not a full-fledged currency but that it is permissible to use it in private transactions.

But if companies want to use Bitcoins for commercial transactions, they need the permission of the Federal Financial Supervisory Authority (BaFin), said Martin Chaudhuri, ministry spokesman.

While not putting Bitcoins on the same footing as formal currencies such as the pound or dollar, Germany\’s move does mean that people who have speculated in the online cryptocurrency could be liable for capital gains taxes if they sell them less than a year after acquiring them.

People who have held on to them for longer will not be liable, the ministry told German MP Frank Schaeffler, who raised the question with the ministry. German authorities are trying to work out how — or whether — they could determine taxes due on Bitcoin transactions between individuals.

The most interesting aspect of the German ruling may be the consequences for the rest of the EU. The designation means that any exchange that wants to sell Bitcoin in Germany knows exactly what it needs to do: get a license from BaFin under Article 32 Kreditwesengesetz. Once an exchange is licensed in Germany, it would be allowed to operate anywhere in the EU — a stark contrast from the US, which requires a federal registration in addition to separate licenses from the states.


BFL 600 GH Bitcoin Mining Card

Performance Specifications

  • 600 GH/s nominal performance ( + / – 20% )
  • 350w (0.6w/GH conservative estimate)

Connectivity

  • USB 2.0 – Monarch cards can be used as an external computer peripheral and chained via USB hub. In this mode it can be controlled via an Android host or standard Linux or Windows computer.
  • PCI Express – Monarch cards consume two PCI slots when installed in a standard ATX motherboard. The PCIe format used is 1X for maximum compatibility.

Mining Software compatibility

  • EasyMiner software is provided for Android, Windows & Linux operating systems.
  • BFGminer – Open source available
  • CGminer – Open source available
  • BitMinter – Java Client

Prior to this announcement, BFL’s largest mining rig ran at 500 GH/s and cost $22,484. It required over 100 chips and an enclosure of almost two cubic feet. The new 600 GH/s device will be the first ASIC miner to take the form factor of a standard graphics card.


Blockchain.info Users Need to Update Browser Plugin/Clear Cache

Jesse James has informed me of a problem with the rng used by blockchain.info javascript clients being poorly seeded when initialised in a background webworker task. In some browsers this could lead to duplicate R values being used when signing transactions (Firefox is likely to be particularly vulnerable). This issue effects the transaction signing code only, not the generation of private keys.

Patches have now been deployed, Please ensure you upgrade to the latest version of your Blockchain.info client.

  • Chrome extension – v2.85
  • Fixefox extension – v1.97
  • Mac client – v0.11

Users of the web interface should clear their browsers cache before next login.

Only a handful of addresses are known to be affected thus far. Likely if you have been affected by this problem your coins will have been taken already. All affected users will be refunded in full, please PM me or email help@blockchain.info.

Bitcoin Pick

Let\’s clear up some common Bitcoin misconceptions.

— Watch Live —

Tuesday 2pm PDT / 5pm EDT / 9pm GMT

— Plan B Subreddit —

— Contact us —

— Music —

\"coinbaseqr\"

— Support the Show —

The post Bitcoin is Legal-ish | Plan B 20 first appeared on Jupiter Broadcasting.

]]>
Spending Your Coins | Plan B 6 https://original.jupiterbroadcasting.net/37176/spending-your-coins-plan-b-6/ Tue, 14 May 2013 16:24:59 +0000 https://original.jupiterbroadcasting.net/?p=37176 We’ll cover some of our favorite ways to buy things with bitcoin, and chat with Forbes writer Kashmir Hill about her week of Living on Bitcoin.

The post Spending Your Coins | Plan B 6 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We’ll cover some of our favorite ways to buy things with bitcoin, from the new and exciting, to the dark and shady.

Plus we chat with Forbes writer Kashmir Hill about her week of Living on Bitcoin, tackle the big stories of the week, answer your emails, and more!

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | Video Feed | Torrent Feed | iTunes Audio | Ogg Feed

— Show Notes: —

— Feedback —

Frequently n00bed

Help spread the word on iTunes with a Rating and Review:

Call or txt the Show:

1 (352) 587-5262

(352) 58-PLANB

— Discussion —

Microsoft Chairman Bill Gates and Berkshire Hathaway’s Warren Buffett and Charlie Munger on Bitcoin, tax rates, bank regulation and the Federal Reserve policy.


New York City-based Liberty City Ventures is announcing its Digital Currency Fund, a $15 million commitment to Bitcoin and other digital currency startups.

The latest buzz comes by way of the Bitcoin Boost Fund, a new Silicon Valley fund that announced on Tuesday that it will hand out $50,000 to seven or so Bitcoin startups.

All of the startups will be graduates of Boost VC, an accelerator program that seeks to mentor would-be Bitcoin barons. The accelerator, created earlier this year, is run by Adam Draper, who describes himself as a “fourth generation VC” and who is hosting a hackathon at the “Bitcoin: Future of payments” conference in San Jose this weekend.


In this episode of the Keiser Report, Max Keiser and Stacy Herbert discuss the currency of an independent Scotland. Max argues that bitcoin will force the banking system to reinvent itself or die, for what can be more of an invisible hand but a cryptologically guarded, invisible currency.


The bitcoin network hashrate estimate on bitcoinwatch.com passed 1 exaFLOPS (1,000 petaFLOPS) this week – over 8 times the combined speed of the top 500 supercomputers.

The FLOPS estimate is based on the opportunity cost of computers using their hardware for mining instead of other applications. Miners are using their graphics cards to perform hashes instead of other FLOPS-based distributed computing.


The Department of Homeland Security appears to have shut down the ability to use Dwolla, a mobile payment service, to withdraw and deposit money into Mt. Gox, a Bitcoin trading platform. A Dwolla representative confirmed the move to Betabeat.

— Spending Your Coins —

I lived on Bitcoin for a week. This is what I learned.


Humble Bundle, known for its flash sales of millions of $s worth of games from high quality developers, is now accepting Bitcoin using Coinbase merchant tools.


Mobile gift card company Gyft has partnered with BitPay to start accepting bitcoins within its app.

This is a big partnership for both, as BitPay’s CEO, Tony Gallippi, says that the company currently processes $5 million per month in bitcoin transactions for its merchants. Gyft allows you to purchase gift cards at more than 50,000 retail locations in the U.S., including Brookstone, Lowe’s, GAP, Sephora, Gamestop, American Eagle, Nike, Marriott, Burger King and Fandango. So, technically, you’ll now be able to use bitcoin to pay for a Whopper.


BitPremier’s mission is to provide astute buyers in the Bitcoin community with access to unique, high-end luxury items and opportunities. We believe in a customer-centric, secure, and friendly marketplace environment where we give individual attention to every item proudly listed on our site.

BitPremier is backed by the NYC-based Bitcoin Opportunity Fund. Other investments of the fund include CoinLab, BitPay, BitSpend, OpenCoin/Ripple, Coinsetter, TradeHill, and Coinapult.


“We’re just looking for a solution where we can bank legitimately like any other industry,” Smith said. “Wherever you stand on the marijuana issue, it serves everybody’s interest to have banking access.”

Aaron Smith, executive director of the Washington-based National Cannabis Industry Association

  • Bank officials say they are complying with federal law:

At Wells Fargo, “our policy of not banking marijuana dispensaries is based on applicable federal laws and our own assessment of our responsibility,” said Seitz, the bank’s spokesman.

American Express Co. (AXP), the biggest U.S. credit-card issuer by customer purchases, “has made a decision to not allow card acceptance for medical marijuana,” Sanette Chao, a spokeswoman for the New York-based company, said by e-mail. “It is our policy to adhere to federal law in such matters.”

U.S.-based BitPay, has refused to enter the fray. As a processor, BitPay offers same-day conversion of merchant bitcoin into a US dollar bank account. CEO Tony Gallippi explained in an interview that although several have applied, “medical marijuana is not allowed in our terms of service.” Of course to be consistent, other merchant types not allowed by BitPay include ecstasy, MDMA, any controlled substances, weapons, gambling, and sports betting. They will however support transactions for file sharing, storage/backup services, and VPN services, because “freedom of information is important.”


Enter the Silk Road

Making small talk with your pot dealer sucks. Buying cocaine can get you shot. What if you could buy and sell drugs online like books or light bulbs? Now you can: Welcome to Silk Road.

— Watch Live —

Tuesday 2pm PDT / 5pm EDT / 9pm GMT

— Plan B Subreddit —

— Contact us —

— Music —

\"coinbaseqr\"

— Support the Show —

The post Spending Your Coins | Plan B 6 first appeared on Jupiter Broadcasting.

]]>
Inside BitVegas | Plan B 4 https://original.jupiterbroadcasting.net/36531/inside-bitvegas-plan-b-4/ Tue, 30 Apr 2013 16:40:53 +0000 https://original.jupiterbroadcasting.net/?p=36531 We chat with the creator of BitVegas, how it works, his plans for the future, and how he keeps users bitcoin's secure. Plus his thoughts on litecoin & more

The post Inside BitVegas | Plan B 4 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We chat with the creator of BitVegas, how it works, his plans for the future, and how he keeps users bitcoin\’s secure. Plus his thoughts on possible legal issues facing bitcoin gambling sites, Litecoin for gambling, and more.

Plus we run through some of the best Bitcoin news we’ve ever heard yet, using bitcoin for a cause, and some practical security tips.

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | Video Feed | Torrent Feed | iTunes Audio | Ogg Feed

Show Notes:

— Feedback —

Hey Drew and Chris what do you guys think of this idea: BCtip – Printable Bitcoin Tips

Help spread the word on iTunes with a Rating and Review:

Call or txt the Show:

1 (352) 587-5262

(352) 58-PLANB

Call in and briefly describe your mining setup. We’re prepping for a mining edition of Plan B, and want to hear what you’ve got! From one GPU to a super secret CIA lab full of ASICs!

— Discussion —

So I\’ve been spending a lot of time looking at it, and it\’s truly fascinating actually: the way that the currency\’s been designed, and the way that inflation is built in to pay for miners, and all that is truly fascinating. I think that for us at PayPal, it\’s just a question whether Bitcoin will make its way to PayPal\’s funding instrument or not. We\’re kinda thinking about it.

Chris Dixon is co-founder and CEO at Hunch at a co-founder at Founder Collective. In the past he has served as CEO and co-founder at SiteAdvisor.

He has invested in technology companies including Skype, Foursquare and Kickstarter. In 2010, BusinessWeek magazine named Dixon the top angel investor in the technology industry.

Chris Dixon, like many other Silicon Valley investors, is really excited about Bitcoin. He says he\’s invested a significant amount of money into it.

Dixon spoke about why he and the rest of Silicon Valley are excited about Bitcoin, and what types of Bitcoin startups he\’s looking to invest in.

Chamath Palihapitiya, venture capitalist, former head of the AOL Instant Messaging division, former Facebook executive, part owner of the Golden State Warriors (NBA)

Think the recent collapse in Bitcoin\’s value was the end of the experimental currency\’s, um, currency? Not even close, says Chamath Palihapitiya, the longtime Facebook executive who now runs The Social + Capital Partnership.

Likening Bitcoin to the \”red pill\” from the movie \”The Matrix,\” which exposes those who take it to a hidden reality, Palihapitiya sounded as bullish as could be during a Q&A at TechCrunch Disrupt NY on Monday morning.

BitVegas

BitVegas is a Minecraft casino that operates on Bitcoins. It has a very friendly community as well as fun games.

If you enjoy gambling, bitcoins or socializing then you should come and join this server. It usually has at least fifteen players online during the day and up to forty at night (usually thirty). Upon joining you get 5 play BTC to gamble with. These can not be exchanged for any real Bitcoins. However, you also get half a real mBTC (possibly going up soon to 1 mBTC or more) per fifteen minutes. You can use these to gamble on games such as poker(still in beta), roulette, blackjack, pig racing(think horse racing with pigs), minefield, and a lottery (the lottery ticket seller is a chicken who usually hangs out in the roulette room).

The Bitcoins in this server can be exchanged for real Bitcoins to be sent to your wallet.

The player base is very friendly and we often have discussions and debates both related and unrelated to Bitcoins. It\’s a very friendly community as well as a source of free Bitcoins and entertainment.

— Litecoin —

The Tokyo-based exchange said in a news release it was planning to support litecoin two weeks ago \”but events derailed that plan. Right now we are focused on overall stability of the exchange and will launch LTC [litecoin] when we are ready.

A good reminder to use a different password at every pool you try, periodically check your payout address to make sure no one hacked you and changed it to pay them instead of you.

— Watch Live —

Tuesday 2pm PDT / 5pm EDT / 9pm GMT

— Plan B Subreddit —

— Contact us —

— Music —

\"coinbaseqr\"

— Support the Show —

The post Inside BitVegas | Plan B 4 first appeared on Jupiter Broadcasting.

]]>
BETA | Plan B 1 https://original.jupiterbroadcasting.net/35166/beta-plan-b-1/ Wed, 10 Apr 2013 20:15:08 +0000 https://original.jupiterbroadcasting.net/?p=35166 We look at the media’s slowly improving bitcoin coverage, discuss the major selloff today, and why people shouldn’t fixate on the price.

The post BETA | Plan B 1 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

From the trenches of discount Wednesday, we launch the beta of our new show: Plan B. We look at the media’s slowly improving bitcoin coverage, discuss the major selloff today, and why people shouldn’t fixate on the price.

Plus: the Mt. Gox problem that faces the bitcoin community, and how it gets gamed.

Then a look at the self appointed “face of bitcoin” Max Keiser and the big money he’s trying to get involved in bitcoin speculation, and brief Litecoin chat…

And so much more!

Direct Download:

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Show Notes:

— Getting Started —

Through the lens of the ever increasing media coverage of Bitcoin, we\’ll explain some of the reasons we find bitcoin fascinating. And the fundamentals we believe show bitcoin\’s about to see an availing of new uses and speculators.

Previous Jupiter Broadcasting Coverage of Bitcoin:

— Discussion —

— Litecoin —

— Watch Live —

Tuesday 2pm PDT / 5pm EDT / 9pm GMT

— Plan B Subreddit —

— Contact us —

— Music —

— Support the Show —

The post BETA | Plan B 1 first appeared on Jupiter Broadcasting.

]]>
Amplifying the Hype | TechSNAP 104 https://original.jupiterbroadcasting.net/34646/amplifying-the-hype-techsnap-104/ Thu, 04 Apr 2013 16:52:44 +0000 https://original.jupiterbroadcasting.net/?p=34646 It’s been called the largest DDoS attack in history, we’ll bust past the hype and explain how a DNS Reflection attack works.

The post Amplifying the Hype | TechSNAP 104 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

It’s been called the largest DDoS attack in history, we’ll bust past the hype and explain how a DNS Reflection attack works.

Plus a privacy surprise in Blackberry 10, the return of an old segment, a big back of your questions, and so much more!

Thanks to:

Use our code hostdeal4 to score economy hosting for $1 a month, for one year.

35% off your ENTIRE order just use our code go35off4 until the end of the month!

 

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

 

Support the Show:

   

Show Notes:

Get TechSNAP on your Android:

Browser Affiliate Extension:

  • Jupiter Broadcasting Affiliate Extensions for Chrome and Firefox
  • DNS Reflection Attack creates internet scare

    • There has been much talk recently about the Cyberbunker DDoS attack against Spamhaus, and the ‘internet breaking’ size of the attack
    • In truth, the attack did not break the internet, and was not that unusually large (described by one of the providers as only 10–15% larger than the regular large attacks they see)
    • The attack made use of ‘DNS Reflection Attack’, which basically sends UDP packets with a forged from address, requesting the answer to a large DNS query to machines around the globe that run ‘open dns resolvers’, which are recursive DNS servers that do not restrict queries to only those inside their local network
    • The forged from address in the header results in the DNS servers sending the response to the unexpecting victim, rather than the original requestor
    • There are millions of these misconfigured DNS servers around the globe
    • A possible resolution to this issue would be for ISPs to block traffic leaving their network with a from address that is not actually from inside their network (and therefore most likely forged)
    • That might not have helped in this case, since the attacker, Cyberbunker, has their own AS and is responsible for that type of configuration on their network
    • The real details have started to emerge and while it was reported that the attack was so large it that it disrupted the London internet exchange, that is not entirely true
    • Response from someone who works for one of CloudFlare’s upstream providers
    • What actually happened was that Cyberbunker managed to attack parts of LINX (London Internet Exchange) via IP addresses that are not normally announced to the internet, but had leaked due to misconfiguration by some members of LINX
    • Looking at the Spamhaus DDoS from a BGP Prospective
    • Cyberbunker (the attackers) did a BGP hijack via NL-IX (the Netherlands Internet Exchange) for the IP address of 0.ns.spamhaus.org, creating a more specific route and disrupting traffic to destin for that IP, routing it to a rouge server at Cyberbunker
    • In the past Cyberbunker has executed similar BGP hijacks, including against a usually unroutable IP range of the US Department of Defence

    How the world of tax havens actually works

    • The ICIJ (International Consortium of Investigative Journalists) has come into possession of 30 years worth of files, emails and other data from 10 of the most popular offshore tax havens in the world
    • The files cover more than 120,000 offshore entities (such as shell corporations, trusts, private foundations, and IBCs) that involve people from more than 170 different countries
    • The leak totals over 260 gigabytes of data, making it 160 times larger than the Wikileaks US Cables dump
    • The data details the structure of a number of different schemes and includes details that the holders of these offshore accounts would much rather keep secret
    • The documents create the links between people and their offshore money that governments have been unable or unwilling to create themselves
    • It is not yet clear if governments will use the data to prosecute tax cheats
    • CBC Coverage
    • The CBC has also created an Interactive tool that allows you to step through the process of hiding your money offshore, including:
      • Choose which Tax Haven to send your money to? what are the taxes rates like? Do they have a tax information sharing agreement with your home country?
      • Then you must create your ‘secret identity’ that will hide the true ownership of the funds. Offshore Trust, Private Foundation, LLC, IBC, Shelf Corp or Individual Account?
      • Next, choose the bank you will place your deposit with. Where are they based? How secretive are they? Will your home government be able to influence them?
      • Now it is time to actually move your money. If you’ve already paid tax on it, you could just wire it, but then the tax man may wonder if you’re earning any income with it…. Suitcase of cash (Illegal but usually pretty easy to get away with)? Phony Lawsuit? Money Swap?
      • Then you have to decide how to invest the money, the entire point of getting it offshore was to avoid paying tax on the income it generates
      • Now the hard part, spending the money. Move offshore? Back-to-back Loan? Insurance Scam? Offshore Credit Card? Fixed Gambling?
    • The reasons for moving funds offshore are numerous, beyond just avoiding taxes, this data shows efforts by many to hide wealth from the courts, to avoid losing it in legal and civil lawsuits or costly divorces
    • This data exposes the collective efforts of some of the greediest people in the world to hide their wealth from taxes and the law

    DDoS attacks against Mt.Gox may be attempt to game the exchange

    • The BBC reports that an ongoing denial of service attack against Mt.Gox, the most popular Bitcoin exchange, may actually be an effort to influence the trading price of bitcoin
    • Mt.Gox suggests that the pattern of the attacks makes it seem like the attackers sell their bitcoins at the peak price, then use the attack to disrupt trading (which causes the price to fall) and create fear, uncertainty and doubt about bitcoin, which causes the skittish to sell, further dropping the price
    • The attackers then swoop in and buy up more bitcoins with the recent proceeds from that sales, getting back more bitcoins than they started with
    • The DDoS then stops, and the price climbs, then the cycle is repeated
    • During the attack, bitcoins dropped to as low as $110 USD from $145
    • This seems to underscore the need for a more robust and diverse trading and exchange system

    Feedback:

    Round-Up:

    Bitcoin Blaster

    The post Amplifying the Hype | TechSNAP 104 first appeared on Jupiter Broadcasting.

    ]]> Perfect Passwords | TechSNAP 11 https://original.jupiterbroadcasting.net/9666/perfect-passwords-techsnap-11/ Thu, 23 Jun 2011 23:38:50 +0000 https://original.jupiterbroadcasting.net/?p=9666 We cover why you always want a little salt with your passwords, and what makes a secure passowrd. !Plus Dropbox’s shockingly bad security issue this week!

    The post Perfect Passwords | TechSNAP 11 first appeared on Jupiter Broadcasting.

    ]]>

    post thumbnail

    We’ve got the details of an FBI raid that knocked several popular sites off-line.

    The WordPress plugin repository was compromised, and backdoors were added to a few popular plugins, and we’ll share the details.

    Plus Dropbox’s shockingly bad security issue this week, and we’ll cover why you always want a little salt with your passwords!

    All that and more, on this week’s TechSNAP!


    Direct Download Links:

    HD Video | Large Video | Mobile Video | MP3 Audio | OGG Audio | YouTube

    Subscribe via RSS and iTunes:

    [ad#shownotes]

    Show Notes:

    TechSNAP has a new Sub-Reddit, submit links and questions for the show, and vote away!


    Topic: FBI raids data center and takes 3 entire racks

    • At 1am on Tuesday the FBI raided the Virginia, USA data center of Swiss web hosting company DigitalOne.
    • DigitalOne’s website was still offline late Wednesday
    • DigitalOne does not have any staff on-site, and relies on remote hands from the data center operator, CoreSite. DigitalOne was not aware of what the problem was until hours later when the data center contracted them and passed along the name of the agent in charge and a phone number for DigitalOne to contact the FBI.
    • When requested DigitalOne had given the FBI information on the IP address they inquired about and told them the exact location of the server. However the FBI seized 3 entire racks of servers rather than only the server they were after.
    • There are rumours that this raid was related to an investigation in to LulzSec
    • A number of services like Pinboard and Instapaper were effected.

    Topic: WordPress.org gets hacked, plug-ins compromised

    • WordPress.org is not sure exactly what happened
    • Plug-in repository compromised
    • Malacious code was found in commits to popular plugins like W3 Total Cache, AddThis and WPTouch
    • WordPress took the prophylactic step of forcing all users to reset their passwords to prevent any further compromised code from being pushed out.

    Topic: Adobe patches two 0-day exploits in 9 days

    • Adobe issued a second ‘out of band’ security update for Flash player in only 9 days due to another exploit
    • Reportedly, one of the 0-day exploits was being used to steal users’ gmail passwords
    • The vulnerability was listed as critical, as it might allow an attack to take complete control of a system
    • Nightmare scenario is a trusted page is compromised and flash malware is inserted
    • Make sure you update to the latest version of Adobe Flash

    Topic: Dropbox goes passwordless, for 4 hours

    • A flaw at dropbox allowed users to login with any password, and access the account
    • This means anyone who knew your email address could have accessed your account and files. They could have authorized additional devices so they can continue to access your files even once this flaw was fixed.
    • Dropbox claims less than 1% of users logged in during that time (seems low)
    • Official Notice from Dropbox
    • If dropbox used proper encryption with one key per user, files could not be accessed without the correct password. However this security measure would take away a lot of the ‘easiness’ of dropbox that people are so fond of.

    Topic: Bitcoin currency exchange compromised

    • The major bitcoin currency exchange MtGox had it’s database compromised and was taken offline when a large number of fraudulent trades were made, swinging the market.
    • The compromised account sold all of it’s coins, forcing the market price down, then bought them all back, and tried to cash out
    • Accounts that had not been used recently, had not had their passwords upgraded from the original unsalted md5 hash to the standard FreeBSD crypt() md5 salted hash.
    • MtGox managed to get a hold of someone at google and google forced all users with gmail accounts at MtGox were forced to reset their passwords
    • Once MtGox is back up, they plan to switch to SHA-512 salted hashes.
    • MtGox claims that the computer of a 3rd party auditor who had read-only access to the database was compromised, and then insecurely hashed passwords were cracked and those accounts were then used by the attackers.

    Q: (Keith) Can you explain salted hashing and two factor authentication in more detail?
    A: Some websites, especially older forums and bespoke software, will store your password as a plain md5 or sha1 hash. These can easily be broken by a rainbow table, and can also be brute forced rather quickly using GPUs. To protect passwords against rainbow tables, modern password hashing algorithms use a ‘salt’. A salt is just some random characters added to the password to make it better. In the FreeBSD crypt() MD5, the default is 8 base64 characters. This means that the rainbow table would have to include those extra 8 possible characters to be able to crack the password. Also, the salt is different for each account, so that means a separate rainbow table would be required for each user, and that two users with the same password won’t have the same hash. What many people don’t realize when they try to implement their own password hashing using regular md5, is that the FreeBSD crypt() md5 does 100 rounds of hashing, not just one. This was sufficiently slow when ti was design, but is much less so now. That is why other algorithms, like SHA-512 and Blowfish have become more popular. On top of having larger salts (16 and 22 characters respectively), they use an adjustable number of rounds of the hashing algorithm. This allows the administrator to decide on a performance/security trade off that best fits their needs.
    Lecture notes by Allan on how Password Hashing Works

    To answer the other part of your question, multi-factor authentication means using more than one way to confirm the user is who they claim to be. Two-factor authentication just means using 2 of the 3 factors to confirm the users identity, rather than just one. The three types are:

    • Something you know (username/password, secret question, pin #)
    • Something you have (ID card, security token, RFID, Cell phone)
    • Something you are (Fingerprint, Retina Scan, Signature, Voice sample)

    So, the typical ATM card system, is who factor authentication, something you have (bank card) and something you know (pin number), however, the pin number is not a very strong authenticator. As we’ve seen in recent weeks, even a security token can be compromised, and some forms of attack like the ZeuS trojan, just wait until you authenticate to perform their attack.


    Bitcoin Blaster:

    AMD Announces new Fusion System Architecture – How will this effect bitcoin mining?
    Symantec finds virus that steals your bitcoins

    Lulz Roundup:

    LulzSec’s Primary tool? Havij v1.14 Advanced SQL Injection
    FAKE: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census
    LulzSec Ring Leader Arrested
    LulzSec-Exposed (counter hacking group) claims authorities are closing in
    LulzSec teams up with Anonymous for Operation AntiSec

    Lightning Round:

    Mozilla End-of-Life’s Firefox 4 – No more security updates
    Google builds plugin to detect unsafe DOM operations like XSS

    Download & Comment:

    The post Perfect Passwords | TechSNAP 11 first appeared on Jupiter Broadcasting.

    ]]>