Mtgox, which is frozen while it is trying to fix its problems, has issued a press released explaining what is the problem
Bitcoin transactions are subject to a design issue that has been largely ignored, while known to at least a part of the Bitcoin core developers and mentioned on the BitcoinTalk forums. This defect, known as "transaction malleability" makes it possible for a third party to alter the hash of any freshly issued transaction without invalidating the signature, hence resulting in a similar transaction under a different hash. Of course only one of the two transactions can be validated. However, if the party who altered the transaction is fast enough, for example with a direct connection to different mining pools, or has even a small amount of mining power, it can easily cause the transaction hash alteration to be committed to the blockchain.
thread on bitcointalk forum
The The Open Web Application Security Project (OWASP) has just released several handy cheat sheet about security in diverse languages, situations, platforms... you name it.
You can find them here
This is a story about 5 Low-Severity bugs I pulled together to create a simple but high severity exploit, giving me access to private repositories on Github.
the full story
discussion on HN
Question on superuser.com : Why are people so bothered about truly random numbers instead of ones generated by a program?
discussion on HN
Ken Shirriff has posted an amazing post on his blog on how he managed to manually make (meaning, he didn't use the official bitcoin application) a transaction in the bitcoin ecosystem.
I'm reading through it as I'm typing this, and it's really well explained, you get to see exactly what he does in Python and there are pictures!
you can read it here
Jean-Jacques Quisquater, a renowned Belgian professor in cryptography got his computer hacked, seems like NSA has something to do about it.
So this guy owned @N on twitter and got extorted his account by a phishing attack.
The story is well written and you should read it here : https://medium.com/p/24eb09e026dd
but for a tl;dr the attacker called his paypal account to ask them for his credit card's last 4 digits. Then he called godaddy to ask them to reset the password. They only asked him for the 2 first digits and the last 4s. The attacker just had to guess the 2 first digits (and he did it on the first try, he could have kept calling and trying otherwise).
Now that he had @N's domain's name, he could now see his emails. Took over @N's facebook account and started mailing him "threats".
It's pretty crazy how easy phishing is.
I have to code a whitebox using DES encryption in a class. Which is pretty cool (I would have prefered doing it with AES but the other group got tails and we got heads).
Here is where the Stanford course I passed on Coursera shines. The explanation of DES on it is brilliant. I was wondering about the initial and final permutations that occurs in the algorithm though and Dan Boneh doesn't really talk about it besides saying it's not for cryptographic purposes.
I found a solution on a new sub-stackoverflow dedicated to Cryptography : http://crypto.stackexchange.com/questions/3/what-are-the-benefits-of-the-two-permutation-tables-in-des
That kind of stuff happens and it's always pretty hard to know it happened and how it happened.
Here's an article about a guy who doesn't seem to know much about security but does a fine job finding out what happened to him and what he can do to avoid future hacks.
Dogecoin, the bitcoin parody, just saw its price reaching a new level AND is going to allow the jamaican bobsled team to go to the 2014 winter Olympics.
Direct Matin Bordeaux, which is a free magazine in Bordeaux that is handed at tram stations everywhere in the city, just wrote an article about me and my last project : 3pages.fr
you can read it here
Constantly, when I start a new project, I try to look for better tools to do the job.
I've been noticing numerous people from the CodeIgniter community moving to Laravel, which seems to be pretty awesome. So I look at Laravel, and I think to myself "gosh this looks fun to learn, but I don't have time and I have a lot of projects in mind". And then as I read more and more about Laravel, I see people talking about how RoR is better. And then about how Django is better... This seems like a never ending search for a better technology.
I read somewhere that good coders code, great coders re-use. And more importantly, amazing coders ship. I have to ship code, I have to be productive, and I don't think I should be wasting too much time learning new technologies.
The difficult thing is to judge whether or not the time wasted in learning a new technology would be less than the time wasted coding with an outdated one.
So I want to learn, and I want to ship. And it's hard to do both.
The Monty Hall problem is to me one of the most fascinating probability problem (for it's simpleness and unintuitive results) that got my mind blown since I learned about it in high school.
One day in high school, in my Math class, the teacher told us about that famous problem.
Monty Hall was an old and popular TV show in the states were you had to choose a door to open from three different ones. Behind one of them was a car, behind the two others were goats. Obviously, the goal of the game was to win the car (except if you were really into goats, but then I guess you could have bought a lot of those with a car).
Anyway, the tricky part was that when you made a choice, the host asked you to wait before opening it and would open another door, revealing a goat. Then he would give you the opportunity to waive your initial choice and swap door one last time.
Here lies the probability problem. Do you think you would have more chance of winning if you changed your choice?
My math teacher said yes, and I could not believe that, I remember loudly objecting, telling the teacher it was not possible, that it was not logical. I declined what seemed grotesque at the time, I refused to acknowledge such an unintuitive result, such a simple thing, my brain could do the calculation easily so why would you tell me I was wrong on such a trivial thing.
But yes, I was wrong. I knew I was wrong. I was upset at my own mind. I didn't understand how I could be so convinced that changing choice wouldn't change my chances of winning the car. The problem was simple, so simple. And yet my mind couldn't make its way around it.
After many years of training my brain to think differently about probabilities, I can know see how this problem works. 7 years after my first introduction to this problem, I can now grasp a part of it. I understand it, I know the probabilities enrolled in the resolution of this problem, I've learned them at uni and I made the effort to think about that problem quite a lot during those last years. I actually often ask that problem to my friends, to blow their mind.
But still, 7 years after being introduced to that problem, I still have troubles finding its probabilities "natural". My brain still cannot process the fact that it HAS to work that way, that the world is turning in that direction and no others.
I hope I didn't send you to sleep with this. If you want to know more about the mathematician who published this result and got insulted by numerous math PHD for being wrong, you can take a stroll on the wikipedia page.
My technique to wire my brain on the right path? Thinking about a hundred doors, 1 car, 99 goats. I open one door, the host closes 98 others.
It feels easier to process when told this way, but there is still a part of me, somewhere, that tells me it wouldn't change a thing. Even with 98 doors opened. What is wrong with my brain?
If you still don't believe me, there is a short and visually clear explanation here.
PS: this is one of my go to when I want to be amazed at how unintuitive or how little we know about how things work. If you like that kind of thing, you can also check the twin paradox or the biography of Milton H. Erickson.
posted December 2013
I've changed the way I handle articles on this blog. I used to type plain html, but I'm now using the markdown syntax with the php parsedown parser.
So if you see any display errors, please tell me.
There's an AMA on reddit right now from one of the Winklevoss brother. If you never heard of them, they were the one who originally came up with the idea of facebook but got it stolen after trying to hire Zuckerberg to code it. They're pretty famous in the bitcoin community for having bought 11million $ of bitcoins before April's big crash. The wonderful thing is, they hold on to their bitcoin during the crash. They must be very clever people because they're now, richer than ever.
Some of the interesting stuff from that AMA :
Have he sold any bitcoin?
I have yet to sell a single bitcoin.
What's the future of bitcoins?
small bull case scenario for Bitcoin is a 400 billion USD dollar market cap, so 40,000 USD a coin, but I believe it could be much larger. When this will happen, if it happens, I don't know, but if it happens, it will probably happen much faster than anyone imagines.
How did he learn about bitcoins?
Partying on a beach in Ibiza, where else?
I have not invested in any altcoins because I don't believe that any of the "problems" or issues that they address can't be addressed by Bitcoin itself.
There is a dog coin that seems to be a big joke : www.dogecoin.org