log☇︎
651800+ entries in 0.43s
asciilifeform: RebeccaBitcoin: will it get stolen within 90 days << this is an uncommonly poor tactic (yes, popular in the 'computer insecurity' business, but it sucks still) - would you test, say, a door lock this way?
decimation: you can't run it if you don't have the source
RebeccaBitcoin: is it that easy?
decimation: if you can't find the source of the javascript on your webpage you are in a world of hurt
asciilifeform: exercise for student (or bored person of any other species) - log a typical 'mouse wiggle' session; fit to curves (your choice.)
RebeccaBitcoin: they say open source but I can't find the source
RebeccaBitcoin: Safe = If I put 10btc in a wallet and post the public key here, will it get stolen within 90 days
decimation: 3.) does the javascript upload privkey to the server?
asciilifeform: RebeccaBitcoin: seems like two separate questions in your original question. 1) mouse movement as method of generating key and 2) particular web-based gizmo for doing so
decimation: rebeccabitcoin nothing that runs on a von neumann machine connected to the internet using unaudited untrusted firmware is safe
RebeccaBitcoin: Obviously you're completely misreading this. Anthony is a little dweeb.
fluffypony: you're assuming that he is impervious to stupidity or error
RebeccaBitcoin: Next time someone is like "omg Rebecca Rushwallet is awesome you should totally use it" - I want to be able to say "No, its not safe because blah blah blah"
RebeccaBitcoin: now he made this
fluffypony: asciilifeform: now you understand why those "trust seals" are so popular on websites :-P
decimation: yes, you put a n00b who failed landing 101 in the cockpit, how did that happen?
decimation: asciilifeform this is basically "don't blame the pilot" in the air-crash investigations
asciilifeform: i still can't fathom what people mean when they ask 'is X safe'
fluffypony: Electrum isn't cold storage, it's a hot wallet to use every day
RebeccaBitcoin: I'm obviously not asking for that reason
asciilifeform: in oil prospecting, salvage diving, etc. there is a concept where safety measures that the crew will not follow because they 'seen ridiculous' - are useless ☟︎
decimation: to do a proper job would require thousands of good man hours, which you can't afford
fluffypony: RebeccaBitcoin: again - for ordinary users you simply need something that is completely under your control, and for your purposes Electrum is fine. It is small and lightweight, it doesn't download the full blockchain (about 20mb in downloads is all it needs thus far), and it has a 12 word mnemonic you write down to backup your wallet. It's literally all I need.
asciilifeform: nerd safe = the type of people who print a paper wallet then toss the printer << this subject is worth exploring at length
cazalla: RebeccaBitcoin, you bought ether, correct? theft is not a concern if you're giving your bitcoins away
RebeccaBitcoin: "If I compile the php script and then reconcile it with a mysql database, then reconfigure it to your home computer's settings I can find your brain wallet"
mircea_popescu: RebeccaBitcoin you know, before you can think yourself better than everyone else you must put your tits in the tit gallery.
decimation: yeah it's more than keyboard mouse I know
mircea_popescu: decimation not rly. it's not great, but it still takes ethernet disks etc
RebeccaBitcoin: argh, now this is a typical nerd debate.
decimation: sigh, that's not even the issue, the real issue is how random is your linux or windows or mac's random
mircea_popescu: like a layer of meh on top of urandom's meh.
mircea_popescu: peterl no, and i hope that was being funny
mircea_popescu: RebeccaBitcoin you know we didn't steal any of the OTHER btc that got stolen, either.
mircea_popescu: (seriously tho, here's a good approach : make your dices out of ice. they will melt, yes, and not be even, yes.
RebeccaBitcoin: if I put 10 bitcoin in a wallet there
mircea_popescu: preferably made out of the bones of your enemies
decimation: roll dice to generate your ecdsa key :)
fluffypony: mircea_popescu: we already told her why
RebeccaBitcoin: This particular site has been done to death?
mircea_popescu: this has been done to death.
mircea_popescu: because of many reasons which you will find reading the logs
RebeccaBitcoin: I don't know how to do the thing that makes your name light up
RebeccaBitcoin: anyway back to my question
assbot: Fototeca de Haur pe Trilema - Un blog de Mircea Popescu.
fluffypony: well I guess the title of the site is a giveaway
RebeccaBitcoin: http://trilema.com/ thats mircea right?
cazalla: what's this prejudice against bald folk?
RebeccaBitcoin: I was hoping for Bitcoin Pete, but you'll have to do
RebeccaBitcoin: can that be demonstrated
ben_vulpes: we're trying to tell you that it ain't secure at all., honey.
RebeccaBitcoin: someone else pointed out that there are other issues
RebeccaBitcoin: my concern is that the mouse movey thing for like 5 seconds isn't all that secure
RebeccaBitcoin: apparently this is open source
fluffypony: not some third party
fluffypony: middle ground is anything where you are entirely, solely, and completely responsible for the safety of your funds
RebeccaBitcoin: to the earlier question, no, I'm not going to write a scathing review
fluffypony: a web wallet is not that middle ground
RebeccaBitcoin: so thats my distinction between reasonably safe and nerd safe
fluffypony: RebeccaBitcoin: those people are crazy
RebeccaBitcoin: its not a meaningless distinction. Someone told me yesterday that to make a paper wallet I should use a new laptpo, and a new printer, then I should take both and destroy them. Then I should put both in a fire
peterl: is it a risk to advertise which type of wallet you use?
RebeccaBitcoin: so nerd safe = the type of people who print a paper wallet then toss the printer over niagara fallls
fluffypony: RebeccaBitcoin: it's not even reasonably safe, given the track record of web wallets
ben_vulpes: for the bruteforcers...
fluffypony: well there you go
ben_vulpes: ;;8ball will the coins get stolen?
fluffypony: within what time frame
RebeccaBitcoin: would they get stolen
fluffypony: ben_vulpes: I guess it's using the normal random available to JS and sprucing it up
ben_vulpes: i mean it said "okay!" after a hilariously short period of time.
fluffypony: RebeccaBitcoin: is your aim to have a Bitcoin wallet so you can send and receive Bitcoin, or is your aim to write a scathing review?
fluffypony: as ben_vulpes points out there are other issues
RebeccaBitcoin: btw, this is owned by Kryptokit (ie Anthony) and his crew
fluffypony: I don't think the mouse movey thing is any worse than the the way /dev/urandom collects entropy from mouse movements / keyboard entry
RebeccaBitcoin: k, but why isn't this safe
ben_vulpes: RebeccaBitcoin: thou shalt not mix js and crypto, much less js and entropy.
ben_vulpes: i wonder if its trivially bruteforceable
RebeccaBitcoin: thank you for that elaborate answer
RebeccaBitcoin: is that mouse movement sae
RebeccaBitcoin: a few seconds later, tada you have a wallet
RebeccaBitcoin: is this site safe: rushwallet.com
Vexual: i dunno, one might ace the poop outta one sememster and let a good load of stuff done
mircea_popescu: ;;later tell dreadknight ever played solforge ?
gribble: dreadknight was last seen in #bitcoin-assets 4 days, 19 hours, and 31 seconds ago: <DreadKnight> that's not how you play frogger
decimation: !up thestringpuller
mircea_popescu: "I think Nine Inch Nail's cover of Johnny Cash's "Hurt" was better than the original."
mircea_popescu: "an entire fanbase" ? what's that ?
assbot: romantomet comments on What's one sentence you could say to piss off an entire fan base?
BingoBoingo: !up thestringpuller
decimation: dc is a swamp though, so I'm sure you will collect a variety of fauna
decimation: I thought studies showed that they were terrible at selecting mosquitos
asciilifeform: decimation: gets whatever flies through the mesh screens
decimation: asciilifeform: do you think the bug zapper does more than murder poor moths?
mircea_popescu: i can see teh argument.
asciilifeform: mircea_popescu: the 'bug zapper' on my balcony doesn't bring in 10 bux a day either. only bug parts. and yet i'm happy with it.
kakobrekla: yeah, scotland would techically work i think but england would be better.
asciilifeform: e.g. an 'amd opteron' wouldn't cost any less than what we pay for it here, wherever else on the planet you might go
asciilifeform: in that 'man does not live by bread alone'
asciilifeform: also brings to mind another topic that never quite comes up - that 'cost of living' is not really a complete picture of things