Author [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] Topic: Proposal to enhance the Fund Transfer Security  (Read 285 times)

Offline ripplexiaoshan

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 1947
    • View Profile
  • BTS: xiaoshan
Proposal to enhance the Fund Transfer Security
« on: July 22, 2014, 08:25:36 PM »

Some friends complain that many accounts names similar to theirs' were created by changing one letter in their ID. Indeed, some letters are very similar, like 1 and l, 0 and o. When we transfer the fund to someone, all similar IDs will be displayed too. If you are not cautious, there is chance to mistakenly choose the wrong recipient.
 
One proposal to resolve this issue is that when someone want to receive fund from others, he'd better announce his public key besides his ID, so when we input the ID of the recipient, its public key can be automatically displayed, thus we can verify whether the ID matches the public key. 

I think it's possible to achieve this function through modifying the code of GUI. What the dev team think?     
BTS ID:xiaoshan                   www.btsabc.org

Offline bytemaster

Re: Proposal to enhance the Fund Transfer Security
« Reply #1 on: July 22, 2014, 08:28:33 PM »
This was a major topic at lunch time... I too am paranoid about this.   

Step 1) Place a Star next to your favorite accounts and WARN if you are about to send to an account not in your favorites.
Step 2) Generate Random Art Icon for each account:  http://www.random-art.org/about/
« Last Edit: July 22, 2014, 08:35:06 PM by bytemaster »
For the latest updates checkout my blog: http://bytemaster.bitshares.org
Anything said on these forums does not constitute an intent to create a legal obligation or contract between myself and anyone else.   These are merely my opinions and I reserve the right to change them at any time.

Offline CalabiYau

Re: Proposal to enhance the Fund Transfer Security
« Reply #2 on: July 22, 2014, 08:32:00 PM »
Some friends complain that many accounts names similar to theirs' were created by changing one letter in their ID. Indeed, some letters are very similar, like 1 and l, 0 and o. When we transfer the fund to someone, all similar IDs will be displayed too. If you are not cautious, there is chance to mistakenly choose the wrong recipient.
 
One proposal to resolve this issue is that when someone want to receive fund from others, he'd better announce his public key besides his ID, so when we input the ID of the recipient, its public key can be automatically displayed, thus we can verify whether the ID matches the public key. 


I think it's possible to achieve this function through modifying the code of GUI. What the dev team think?     

I support this important proposal - at least the option to show the corresponding pubkey +5%

Offline xeroc

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 11951
  • ChainSquad GmbH
    • View Profile
    • ChainSquad GmbH
  • BTS: xeroc
  • GitHub: xeroc
Re: Proposal to enhance the Fund Transfer Security
« Reply #3 on: July 22, 2014, 08:32:31 PM »
I remember discussing a scheme like this
name-firstpartofkey
ie.
xeroc-BTSX14afa

or maybe use ":"
ie.
xeroc:BTSX14afa

hoever ":" breaks the 'doubleclick-select-all' feature of most OS! :(
Give BitShares a try! Use the http://testnet.bitshares.eu provided by http://bitshares.eu powered by ChainSquad GmbH

Offline bytemaster

Re: Proposal to enhance the Fund Transfer Security
« Reply #4 on: July 22, 2014, 08:36:02 PM »
Step 1) Place a Star next to your favorite accounts and WARN if you are about to send to an account not in your favorites.
Step 2) Generate Random Art Icon for each account:  http://www.random-art.org/about/
For the latest updates checkout my blog: http://bytemaster.bitshares.org
Anything said on these forums does not constitute an intent to create a legal obligation or contract between myself and anyone else.   These are merely my opinions and I reserve the right to change them at any time.

Offline xeroc

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 11951
  • ChainSquad GmbH
    • View Profile
    • ChainSquad GmbH
  • BTS: xeroc
  • GitHub: xeroc
Re: Proposal to enhance the Fund Transfer Security
« Reply #5 on: July 23, 2014, 05:31:37 AM »
Step 1) Place a Star next to your favorite accounts and WARN if you are about to send to an account not in your favorites.
Step 2) Generate Random Art Icon for each account:  http://www.random-art.org/about/
+5%

just link for the random arts:
http://meta.stackexchange.com/questions/17443/how-is-the-default-user-avatar-generated
Give BitShares a try! Use the http://testnet.bitshares.eu provided by http://bitshares.eu powered by ChainSquad GmbH

Offline 8bit

  • Full Member
  • ***
  • Posts: 56
    • View Profile
Re: Proposal to enhance the Fund Transfer Security
« Reply #6 on: July 23, 2014, 05:41:18 AM »
This was a major topic at lunch time... I too am paranoid about this.   

Step 1) Place a Star next to your favorite accounts and WARN if you are about to send to an account not in your favorites.
Step 2) Generate Random Art Icon for each account:  http://www.random-art.org/about/

Great ideas! Especially the random art. A couple of questions, though. Will it be possible to skip the warning, through a "dont ask me again" checkbox in the GUI and a -f flag in the CLI? Also, can we have a something like random art but for the CLI? Maybe either a string of randomized words that form a sentence or a random art ASCII.

EDIT: Here's another idea. Add a trusted nodes system. All of the names that people who I favorite favorite come up as 'trusted' and also do not prompt before sending. People can also be flagged 'untrustworthy'. If someone you favorite marks one of your trusted nodes as 'untrustworthy', then they are removed from your list of trusted nodes. Also, the user's trust level is listed in their account, on the delegates pages, etc... This is a friend-to-friend, decentralized implementation of a 'ring of trust'. This also potentially creates a new industry: delegates (and other community members) who maintain easylists of trusted/untrusted nodes.
« Last Edit: July 23, 2014, 05:59:31 AM by 8bit »
Code: [Select]
wallet_approve_delegate eightbitA VOTE FOR EIGHTBIT IS A VOTE FOR CRUDE DICK ART

Offline testz

Re: Proposal to enhance the Fund Transfer Security
« Reply #7 on: July 23, 2014, 06:32:55 AM »
Step 1) Place a Star next to your favorite accounts and WARN if you are about to send to an account not in your favorites.
Step 2) Generate Random Art Icon for each account:  http://www.random-art.org/about/
+5%

just link for the random arts:
http://meta.stackexchange.com/questions/17443/how-is-the-default-user-avatar-generated

 +5%

 

Google+