Post
Topic
Board Announcements (Altcoins)
Re: cracking nimiq
by
nimiqshitcoin
on 20/06/2019, 16:37:43 UTC

This is simply not true and shows you have no idea about what you are talking about. You are just embarrassing yourself at this point.
- Nimiq is completely client-side and non-custodial so your information (encrypted keys) are stored only in your device, like MyEtherWallet does. Do you also have a problem with them?
- Users have multiple ways to interact with the Blockchain, Nimiq Safe is just one option provided by Team Nimiq. If you are concerned about security you can always run a Nimiq Full Node, it's very easy with Docker.
- The minimum character count on Nimiq passwords is 8, not 6. There are numerous client-side checks done on the password to help the user be secure (like avoiding 12345678 and such).
- Users are welcome to choose a longer password but for usability-sake 8 characters safe enough considering the file encrypted by the password is only stored in your device.

I think you must be stupid. I quote again what I fucking said.

So much buzz here about this shitcoin. The beauty of this shitcoin is that they can install at any given time a honeypot js script (1 line of code) to sniff all private keys used in browser by users and crack them in a few minutes as the password is really weak ( 6 letters ) by default. What a fucking joke. This is exactly how you would make a blockchain insecure, just like Nimiq.

Regarding your stupid identicons, anybody can crack your identicon making an identical clone in 2 minutes. I proved it with real numbers. so your security is fucked up. I think I can get you. You smoked to much crack.
Let's crack.

Please go ahead and try to "crack" Nimiq. There is a Bug Bounty Program managed by HackerOne where anyone that finds a real vulnerability can cash out up to $20'000. We encourage all serious programmers and researchers to join  Cool

Do I get a bounty for my vulnerability report, that in 2 minutes you can vanity generate any identicon ? This would not be possible with Ethereum identicons. I guess you are just ignorant and don't care about these, as you are just promoting the shitcoin to get some quick buck.

The way it works is you Send it to HackerOne and let them decide. They are an unbiased external Bug Bounty and Vulnerability Validation company trusted by more than 1'000 software companies like Ethereum, Monero and GitHub.

Post the link to the vulnerability report here and until then stop spamming about something that is really not a vulnerability.

FYI If you consider Ethereum and identicons check /weakicons]this blog post.

Philipp, you must have smoked way to much pot.

https://i.imgur.com/nnzKdXh.png

45 fucking minutes to get something that doesn't even look like the original. Your stupid identicon can be cracked in 2 minutes on an average computer. IDENTICAL IDENTICON. If we make some tweaks to avoid some similar colors, you can crack the nimiq identicon in 1 sec on a normal computer.