Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Horseshoe theory
Mar 7, 2005

There Bias Two posted:

Wow that guy really hosed himself over financially.

Probably a fakepost, but if true, good.

Adbot
ADBOT LOVES YOU

Satchel and Trunk
Nov 4, 2008

ghosTTy posted:

debtor prison doesn't exist anymore

I’ve got some bad news for you...

Harveygod
Jan 4, 2014

YEEAAH HEH HEH HEEEHH

YOU KNOW WHAT I'M SAYIN

THIS TRASH WAR AIN'T GONNA SOLVE ITSELF YA KNOW

Satchel and Trunk posted:

I’ve got some good news for you...

Fame Douglas
Nov 20, 2013

by Fluffdaddy

Adar posted:

you guys know that's a troll right? cryptonerds are very easy to troll but don't gaze into the abyss too long

Yep, every time someone posts about losing money on cryptocurrency it's a "troll". The only people posting earnestly are the ones bragging about their huge gains.

Waltzing Along
Jun 14, 2008

There's only one
Human race
Many faces
Everybody belongs here
My balls are at $6000. WTF!

Minimalist Program
Aug 14, 2010

Waltzing Along posted:

My balls are at $6000. WTF!

Nice,but, have you ever heard about my rear end?!

ghosTTy
Sep 22, 2008

Fame Douglas posted:

Yep, every time someone posts about losing money on cryptocurrency it's a "troll". The only people posting earnestly are the ones bragging about their huge gains.

nobody loses money in crypto unless they sell, and if a coiner sells they're probably a troll or some dumbass nocoiner who tried to day trade and will spew FUD for eternity

Spatial
Nov 15, 2007

the fountain of FUD

stab
Feb 12, 2003

To you from failing hands we throw the torch, be yours to hold it high

Minimalist Program posted:

Nice,but, have you ever heard about my rear end?!


https://www.youtube.com/watch?v=is2U-V2kdMM

Waltzing Along
Jun 14, 2008

There's only one
Human race
Many faces
Everybody belongs here

Minimalist Program posted:

Nice,but, have you ever heard about my rear end?!

No, but you have piqued my curiosity.

Zil
Jun 4, 2011

Satanically Summoned Citrus


Minimalist Program posted:

Nice,but, have you ever heard about my rear end?!

No, do you have a prospectus?

Burt Sexual
Jan 26, 2006

by Jeffrey of YOSPOS
Switchblade Switcharoo

ghosTTy posted:

realistically that's not a bad plan. debtor prison doesn't exist anymore so there's literally nothing a bank can do to you once you declare bankruptcy and HODL your private keys. get hosed banksters

Living in abject poverty and financial ruin to trigger the bankster

klafbang
Nov 18, 2009
Clapping Larry

Zil posted:

No, do you have a prospectus?

Or at least a wipe paper.

Burt Sexual
Jan 26, 2006

by Jeffrey of YOSPOS
Switchblade Switcharoo

Waltzing Along posted:

No, but you have piqued my curiosity.

Stock in minimalist programs rear end is over valued atm

Devian666
Aug 20, 2008

Take some advice Chris.

Fun Shoe

Zil posted:

No, do you have a prospectus?

Like all cryptos things up only go up up up his rear end.

ghosTTy
Sep 22, 2008

Burt Sexual posted:

Living in abject poverty and financial ruin to trigger the bankster

Financial ruin isn't having millions worth of crypto living it up in Puerto Rico, it's hodling a scam coin like the USD

thethreeman
May 10, 2008
Fallen Rib
https://twitter.com/bascule/status/962740918053888000

bvj191jgl7bBsqF5m
Apr 16, 2017

IÃÂÃŒÂÌ° Ó̯̖̫̹̯̤A҉mÃÂ̺̩ Ç̬A̡̮̞̠ÚÉ̱̫ K̶eÓgÃÂ.̻̱̪̕Ö̹̟

If you go to developer meetups, you will frequently find that the guys obsessed with cryptocurrency and blockchain are dumb and bad at development, so this is hardly surprising at all

Bip Roberts
Mar 29, 2005

Capitalism is good as heck.

QuarkJets
Sep 8, 2008

ghosTTy posted:

Financial ruin isn't having millions worth of crypto living it up in Puerto Rico, it's hodling a scam coin like the USD

*oscar the grouch pops out of his trash can* I invested all of my worthless fiat into altcoins, just waiting for vendors to start accepting all of them

Khorne
May 1, 2002
I had to deal with this at work recently. It was in place for 5+ years and somehow had never been exploited. The only reason they had me look at it was because a spambot came by, auto filled out a form, and submitted invalid data.

You just gotta question, why would you only do checks on the client side? The server side checks are the only important part. Money on that site being vulnerable to SQL injections? Maybe not with all the, often pointless, NoSQL hype and bad people saying "SQL is hard" or "SQL is complicated".

Khorne fucked around with this message at 20:37 on Feb 11, 2018

stab
Feb 12, 2003

To you from failing hands we throw the torch, be yours to hold it high

Uhhh i know poo poo about programming


Let me see if i understand

If they went server side instead of client side...they could theotetically just withdraw rverything because it wouldnt check to see if you had anything????

Khorne
May 1, 2002

stab posted:

Uhhh i know poo poo about programming


Let me see if i understand

If they went server side instead of client side...they could theotetically just withdraw rverything because it wouldnt check to see if you had anything????
Their server just went "okay, sure" to requests whether they made sense or not. It'd be like SA allowing me to post as Lowtax by changing Khorne to Lowtax somewhere. He says he's lowtax so he must be!

Pretty much every piece of software not written by idiots verifies claims. Magic The Gathering Online eXchange fell to similar exploits. Just extremely naive code that never even tried to ask "what if someone wants to exploit us?"

Khorne fucked around with this message at 20:45 on Feb 11, 2018

univbee
Jun 3, 2004




stab posted:

Uhhh i know poo poo about programming


Let me see if i understand

If they went server side instead of client side...they could theotetically just withdraw rverything because it wouldnt check to see if you had anything????

Basically the “do you have money in your account to withdraw” check was done on users’ computers and not the server, so if someone tampered with the programming locally they could force it to tell the server “oh yeah I have money” and the server would just go “oh ok”.

100 HOGS AGREE
Oct 13, 2007
Grimey Drawer
Its like if the bank let you check your account balance at the teller's computer yourself and then just trusted you to not take cash out of the vault if your balance was too low.

stab
Feb 12, 2003

To you from failing hands we throw the torch, be yours to hold it high

univbee posted:

Basically the “do you have money in your account to withdraw” check was done on users’ computers and not the server, so if someone tampered with the programming locally they could force it to tell the server “oh yeah I have money” and the server would just go “oh ok”.

Yeah thats what i thought


Brb modifying my home computer files to make myself the King of Bitcoin

temple
Jul 29, 2006

I have actual skeletons in my closet
there no way someone accidentally programmed it that bad. its either they didn't care and knew they wouldn't get caught or intentionally placing faults.

Sten Freak
Sep 10, 2008

Despite all of these shortcomings, the Sten still has a long track record of shooting people right in the face.
College Slice

:ughh:

Eela6
May 25, 2007
Shredded Hen

temple posted:

there no way someone accidentally programmed it that bad. its either they didn't care and knew they wouldn't get caught or intentionally placing faults.

developers absolutely gently caress up that bad on the regular

AreWeDrunkYet
Jul 8, 2006

This is Bitcoin. Either they were grossly overconfident in their own abilities, found the cheapest possible vendor, or unconditionally trusted someone who vaguely agreed with their philosophy.

100 HOGS AGREE
Oct 13, 2007
Grimey Drawer
Usually when businesses mess up its because no one who makes decisions gave it much thought and anyone who had the knowledge or expertise to see it'd be a problem in the first place either was actively ignored or didn't bother to point it out because that decision is above their pay grade.

Khorne
May 1, 2002

100 HOGS AGREE posted:

Usually when businesses mess up its because no one who makes decisions gave it much thought and anyone who had the knowledge or expertise to see it'd be a problem in the first place either was actively ignored or didn't bother to point it out because that decision is above their pay grade.
This is a bitcoin exchange. The guy who made it was probably copy pasting from the wrong php tutorials.

Well, it's 2018, maybe he was copy pasting from the wrong nodejs tutorials.

I am not familiar with the site, but I'd put money on one of the following architectures:

(1) Some awful, untemplated abomination of html,css,javascript with php tags thrown in everywhere full of business logic
(2) Some awful abomination of javascript client and server side for "code reuse"
(3) Lots of effort put into the client-side with a "light" JSON api backend that literally does what the client tells it without any verification at all

Khorne fucked around with this message at 21:08 on Feb 11, 2018

Dolphin
Dec 5, 2008

by Jeffrey of YOSPOS
is there any reason why stealing bitcoin should carry any more repercussions than like... stealing warcraft gold.

especially if it doesn't involve violating any computer security laws

QuarkJets
Sep 8, 2008

temple posted:

there no way someone accidentally programmed it that bad. its either they didn't care and knew they wouldn't get caught or intentionally placing faults.

did you forget that this is a cryptocurrency exchange?

AreWeDrunkYet
Jul 8, 2006

Dolphin posted:

is there any reason why stealing bitcoin should carry any more repercussions than like... stealing warcraft gold.

especially if it doesn't involve violating any computer security laws

Legally speaking, in the US at least, it's about the same.

Telarra
Oct 9, 2012

Dolphin posted:

is there any reason why stealing bitcoin should carry any more repercussions than like... stealing warcraft gold.

especially if it doesn't involve violating any computer security laws

Bitcoin is something you can actually own. Legally speaking, in-game virtual goods are owned by the company who runs the game, players are merely allowed access to use them.

Nessus
Dec 22, 2003

After a Speaker vote, you may be entitled to a valuable coupon or voucher!



ghosTTy posted:

nobody loses money in crypto unless they sell, and if a coiner sells they're probably a troll or some dumbass nocoiner who tried to day trade and will spew FUD for eternity
Don't you "lose" the money you converted into butts, at least until the butts are sold?

Bip Roberts
Mar 29, 2005

Nessus posted:

Don't you "lose" the money you converted into butts, at least until the butts are sold?

Yes, once you turn cash into something worthless like a butt you lost it until you can find a rube bigger than yourself to swindle back to cash.

Moridin920
Nov 15, 2007

by FactsAreUseless

hahahahahahahahaha holy poo poo newgrounds flash games are better coded

Adbot
ADBOT LOVES YOU

EorayMel
May 30, 2015

WE GET IT. YOU LOVE GUN JESUS. Toujours des fusils Bullpup Français.

Moridin920 posted:

hahahahahahahahaha holy poo poo newgrounds flash games are better coded

the imagery is killing me :drat:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply