Welcome, Guest. Please login or register.

Author Topic: A simple approach to increase significantly the security of NXT.  (Read 460 times)

0 Members and 1 Guest are viewing this topic.

Offline Sebastien256

  • Nxter
  • **
  • Posts: 93
    • View Profile
A simple approach to increase significantly the security of NXT.
« on: December 25, 2013, 07:51:32 AM »
I believe that NXT client should:

1) Implement a button to generate a random passphrase of optimal security.
2) This button should be at the beginning of the login procedure.
3) People could then use these random strings for their passphrase.
4) When generating a random passphrase, a message should also CLEARLY state to keep (copy and paste) that passphrase somewhere to avoid the lost of the NXT account.

This simple addition would decrease significantly NXT stealing.

Note that when people say out loud that their NXT was stealed, it is a very bad press. With this simple addition, some form of NXT stealing can be avoid right away. I believe that this should be implement before the NXT official launch.

If you like my advice, plz donate: 653922166310279418
« Last Edit: December 25, 2013, 07:58:49 AM by Sebastien256 »
Like my comments, please donate NXT: 653922166310279418

Offline joefox

  • Senior Nxter
  • ****
  • Posts: 393
    • View Profile
    • The Nxt Wiki
Re: A simple approach to increase significantly the security of NXT.
« Reply #1 on: December 25, 2013, 08:54:54 AM »
The Nxt client you're using now (NRS) is a simple, bare-bones, web-based client that interfaces with the Nxt software.  It was never meant to be permanent and will likely be completely removed once a proper client is built.

Someone (nexern) is working on a client but I don't think we'll see it until January. And once the source is released on January 3 other people will be able to build clients as well.

I would hope that a proper client would implement some better account security features :)
Administrator of the Nxt Wiki at  http://wiki.nxtcrypto.org/

Like my advice OR the wiki? Please donate to account 1234567740944417915

Offline Sebastien256

  • Nxter
  • **
  • Posts: 93
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #2 on: December 25, 2013, 09:20:34 PM »
Well, an option like that I propose should be implement fast as possible it the future client. It just a thought. It would propably avoid some deceptions in the future about NXT.
« Last Edit: December 25, 2013, 09:33:28 PM by Sebastien256 »
Like my comments, please donate NXT: 653922166310279418

Offline DBG

  • Fresh Nxter
  • *
  • Posts: 4
  • Sushi Lover
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #3 on: December 27, 2013, 01:58:41 AM »
Well, an option like that I propose should be implement fast as possible it the future client. It just a thought. It would propably avoid some deceptions in the future about NXT.
Right now things are not tightly organized and some commands don't even have a web prompt to make use of.  With that being said, I would hope that security would be at the top of the list for any NXT client developer.  I still find it interesting that I'm using a 16 digit password full of true randomness (including non a-z, 0-9 characters) and it still tells me my password isn't secure enough when I use it  ;D
Token for NXT 8971899496880386552 - here

Offline 2Kool4Skewl

  • Nxter
  • **
  • Posts: 124
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #4 on: December 27, 2013, 08:47:24 AM »
Well, an option like that I propose should be implement fast as possible it the future client. It just a thought. It would propably avoid some deceptions in the future about NXT.
Right now things are not tightly organized and some commands don't even have a web prompt to make use of.  With that being said, I would hope that security would be at the top of the list for any NXT client developer.  I still find it interesting that I'm using a 16 digit password full of true randomness (including non a-z, 0-9 characters) and it still tells me my password isn't secure enough when I use it  ;D

16 characters is NOT SECURE!  USE SOMETHING MUCH, MUCH LONGER!!!!

NRS supports passwords up to 100 characters in length.  Please use something at least 80+ characters long.  Transfer all your Nxt to your new account.  Your funds will be stolen with a 16 character password.

Offline SomeoneWhoIsntYou

  • Nxter
  • **
  • Posts: 54
  • We are human-shaped fractals.
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #5 on: December 29, 2013, 01:56:25 AM »
I think this conversation is proof that this functionality needs to be added  ;D
"Programming is 90% logic and 10% Magic." -SomeoneWhoIsntYou
Cryptocurrency enthusiast, Non-Genesis NXT Stakeholder, C# and Java Programmer
NXT Generation Foundation Android Developer

Offline allwelder

  • Nxter
  • **
  • Posts: 85
  • nxts.org
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #6 on: January 25, 2014, 03:48:44 AM »
with a "one button client",the price of Nxt will rocket again.
Website:nxts.org  Forum:nxts.info
Video:i.youku.com/nextcoin Weibo:weibo.com/nxtcoin
Donation welcomed for Nxt 14698193345900192135

Offline KingCole

  • Fresh Nxter
  • *
  • Posts: 22
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #7 on: January 25, 2014, 10:53:50 PM »
Is it possible to change the password once set and if so how?

KC

Offline CryptKeeper

  • Fresh Nxter
  • *
  • Posts: 18
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #8 on: January 26, 2014, 11:18:35 AM »
Well, an option like that I propose should be implement fast as possible it the future client. It just a thought. It would propably avoid some deceptions in the future about NXT.
Right now things are not tightly organized and some commands don't even have a web prompt to make use of.  With that being said, I would hope that security would be at the top of the list for any NXT client developer.  I still find it interesting that I'm using a 16 digit password full of true randomness (including non a-z, 0-9 characters) and it still tells me my password isn't secure enough when I use it  ;D

16 characters is NOT SECURE!  USE SOMETHING MUCH, MUCH LONGER!!!!

NRS supports passwords up to 100 characters in length.  Please use something at least 80+ characters long.  Transfer all your Nxt to your new account.  Your funds will be stolen with a 16 character password.

lol - his account contains 1nxt  :)

Offline pat

  • Nxter
  • **
  • Posts: 113
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #9 on: January 26, 2014, 02:27:17 PM »
Is it possible to change the password once set and if so how?

KC

No it's not. That's not how NXT "accounts" work. When you enter a passphrase the client uses it's algo to calculate an address. The same passphrase will always yield the same address. If you'd like to change that you'd have to change the algo :)

Offline KingCole

  • Fresh Nxter
  • *
  • Posts: 22
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #10 on: January 26, 2014, 04:57:30 PM »
I thought that maybe the case. I guess I could install the client on another PC, use a different passphrase and move the coins from the old client to the new?

KC

Offline mgburks77

  • Fresh Nxter
  • *
  • Posts: 21
    • View Profile
Re: A simple approach to increase significantly the security of NXT.
« Reply #11 on: February 09, 2014, 05:44:22 AM »
You can do it on the same PC with two accounts running in different tabs, I think
8657296860115679183