BitShares Forum

Main => General Discussion => Topic started by: emski on November 04, 2014, 11:42:29 am

Title: Warning: Accounts similar to current delegates
Post by: emski on November 04, 2014, 11:42:29 am
I've noticed someone just registered accounts on the blockchain that are very similar to current delegates.

For example:
Nov 4, 2014 10:18:50 AM   30426   delepuppy
Nov 4, 2014 10:17:00 AM   30425   emskibitdelegate
Nov 4, 2014 10:15:30 AM   30424   dacbts500
Nov 4, 2014 10:14:00 AM   30423   daccoolspeed
Nov 4, 2014 10:11:50 AM   30422   btsapp
Nov 4, 2014 10:02:00 AM   30421   dogep2p
Nov 4, 2014 10:01:30 AM   30420   ltcp2p
Nov 4, 2014 10:01:10 AM   30419   dacp2p

If you are going to vote, please double-check the names.
I've shown how robohashes are inefficient for protection (see the first reply).
Until a better system for user protection is implemented (see https://bitsharestalk.org/index.php?topic=9109.0 (https://bitsharestalk.org/index.php?topic=9109.0)) everyone should be extra careful when sending money or voting.
Title: Re: Warning: Accounts similar to current delegates
Post by: Bytemаsteг on November 04, 2014, 11:44:26 am
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).
Title: Re: Warning: Accounts similar to current delegates
Post by: Overthetop on November 04, 2014, 12:02:36 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

wow , you scared me   :P
Title: Re: Warning: Accounts similar to current delegates
Post by: emski on November 04, 2014, 12:18:49 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

wow , you scared me   :P

The technique I used to get the same robo-hash for the forum account name will likely not work well in the bitsharesX client.
However exploiting similar techniques might produce identical robohashes and visibly similar account names.
Title: Re: Warning: Accounts similar to current delegates
Post by: bytemaster on November 04, 2014, 02:20:28 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

Can we update the forum rules to prevent people from taking the same name with a slightly different capitalization?  This is crazy that someone could impersonate me so easily.
Title: Re: Warning: Accounts similar to current delegates
Post by: emski on November 04, 2014, 02:45:44 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

Can we update the forum rules to prevent people from taking the same name with a slightly different capitalization?  This is crazy that someone could impersonate me so easily.

Capitalisation isnt an issue. I can get visually exact name like yours if using homoglyphs. And still get identical robohash.
There could be implemented a function that calculates visual similarity of 2 strings though.
Title: Re: Warning: Accounts similar to current delegates
Post by: Troglodactyl on November 04, 2014, 02:53:07 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

Can we update the forum rules to prevent people from taking the same name with a slightly different capitalization?  This is crazy that someone could impersonate me so easily.
If only there were some way to sign messages with some kind of publicly verifiable signature... ;-)
Title: Re: Warning: Accounts similar to current delegates
Post by: bytemaster on November 04, 2014, 04:28:30 pm
An example of similar robohash to bytemaster's .
I have another one closer resembling BM's robot (and with lowercase first letter).

Can we update the forum rules to prevent people from taking the same name with a slightly different capitalization?  This is crazy that someone could impersonate me so easily.
If only there were some way to sign messages with some kind of publicly verifiable signature... ;-)
You can verify if a message is from me.. but that doesn't mean people will actually check the signature and thus harm can still be done.
Title: Re: Warning: Accounts similar to current delegates
Post by: Methodise on November 10, 2014, 04:59:01 pm
I feel that the community would benefit from more people familiarising themselves this thread. That is to say, bump.
Title: Re: Warning: Accounts similar to current delegates
Post by: nyse on November 10, 2014, 09:57:46 pm
I remember that there is a guy with ID "dacsunlimited.com", but not related to Dacsunlimted at all. Forum administrators should ban such IDs which are similar to well known IDs.
Title: Re: Warning: Accounts similar to current delegates
Post by: emski on November 10, 2014, 10:17:26 pm
I remember that there is a guy with ID "dacsunlimited.com", but not related to Dacsunlimted at all. Forum administrators should ban such IDs which are similar to well known IDs.
The IDs mentioned in the first post are registered on BTSX blockchain and not on the forum.