Last Year's ICOs Had Five Security Vulnerabilities On Average, Say Researchers (bleepingcomputer.com)
An anonymous reader quotes a report from Bleeping Computer: Security researchers have found, on average, five security flaws in each cryptocurrency ICO held last year. Only one ICO held in 2017 did not contain any critical flaws. According to Positive.com, a security firm specialized in ICO security audits, most of the vulnerabilities they found, they discovered in the smart contracts at the base of the ICO itself.
"71% of tested projects contained vulnerabilities in smart contracts, the heart and soul of an ICO," the company said. "Once an ICO starts, the contract cannot be changed and is open to everyone, meaning anyone can view it and look for flaws. Typically, these would consist of non compliance with the ERC20 standard (the token interface for digital wallets and cryptocurrency exchanges), incorrect random number generation and incorrect scoping amongst others," Positive.com experts say. "Generally, these vulnerabilities occur due to lack of programmer expertise and insufficient source code testing." According to the researchers, all the mobile apps ICO organizers have launched in 2017 contained security flaws. "The most common flaws in mobile apps are the use of insecure data transfer methods, storage of user data in phone backups, and disclosure of session IDs that an attacker could capture and use against the user," reports Bleeping Computer. Security bugs were also found in the web apps.
"71% of tested projects contained vulnerabilities in smart contracts, the heart and soul of an ICO," the company said. "Once an ICO starts, the contract cannot be changed and is open to everyone, meaning anyone can view it and look for flaws. Typically, these would consist of non compliance with the ERC20 standard (the token interface for digital wallets and cryptocurrency exchanges), incorrect random number generation and incorrect scoping amongst others," Positive.com experts say. "Generally, these vulnerabilities occur due to lack of programmer expertise and insufficient source code testing." According to the researchers, all the mobile apps ICO organizers have launched in 2017 contained security flaws. "The most common flaws in mobile apps are the use of insecure data transfer methods, storage of user data in phone backups, and disclosure of session IDs that an attacker could capture and use against the user," reports Bleeping Computer. Security bugs were also found in the web apps.
... why I should invest some $$$ in the shitcoin "du jour"?
I have always said that computer security is a huge mess. As the crypto-currencies gain value, they provide more and more incentives to bad guys to hack your computer to get at your wallet.
The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
but so what, banks are insured, 'coins are insured. You are covered. Don't worry. Be happy. Invest! Invest! Invest! 'coins are safe.
"Only one ICO held in 2017 did not contain any critical flaws."
And that one would be...?
Who the heck thinks these things are a good idea, beyond the fraudsters at the top of the pyramid?! Of course shortcuts are taken... after the first round of suckers, who really gives a s#!t?
"According to the researchers, all the mobile apps ICO organizers have launched in 2017 contained security flaws."
My, that's awkward. Maybe they'll do better in 2018. ... or 2019 ... or 2020.
I'm confident that if they prsevere, they can create a cryptocurrency that is merely pointless instead of being pointless and fatally flawed.
You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
Folks, haven't you realized that many of the ICO's are actually a Ponzi scheme. If you set up any other form of Ponzi scheme, authorities would shut you down real fast. Why don't you think they are shutting the ICO Ponzi schemes down?
The answer is simple. because the NWO is behind it. Authorities WANT you to be indoctrinated to the idea and even the practice of using a crypto currency because they are going to try and force you to use the crypto of their choice.
ANY Crypto currency that is currently out is either under the control of central bankers and government, or it can easily fall under their control via government gun point.
All Cryptos will make you into a slave.
So, basically these ICOs are being pushed out the door by lazy and incompetent people who are more concerned with cashing in than making anything of actual quality.
Why am I not surprised?
As usual with this kind of stuff, the marketing happens long before the technology. And then the technology is crap.
Are (any) fiat-currency and (any) cryptocurrency really equivalent, as cryptocurrency fans claim?
For example, US Dollar and Bitcoin are really equals?
Value/validity/authorization of US dollar is provided/guaranteed by US Government (and in-turn whole US Public)!
Also, not to mention, US Dollars in any US Bank is insured by US Government!
What authorization/guarantee/insurance is behind Bitcoin? Nothing!
Sorry but that is the end of discussion then!
Why do you think Satoshi Nakamoto is really hiding his identity, if Bitcoin is really such a great innovation?
He is just someone does not like media/fan attention?
Or, could it be really because Bitcoin (and all cryptocurrencies followed it) are actually Ponzi Schemes?
(So he knew very well that law enforcement would come after him sooner or later?!)
If so-called cryptocurrencies are really good innovation, why they attract so many criminals/criminal activity?
Could it really be because, all cryptocurrencies themselves are scams, and that is why they attract all kinds of criminals/criminal activity?
If so-called cryptocurrencies are really currency, why no company/store can use Bitcoin as currency anymore?
Because the price of Bitcoin proved to be extremely unstable to use as a currency?
Would the result be different, if Bitcoin replaced by any other "cryptocurrency"?
Aren't all work the same way?
If so-called cryptocurrencies are really money; isn't people issuing their own money, illegal already, in all countries?
If so then, why they are still not banned in all countries?
Or, they are not actually virtual currency but virtual investment?
But, if they are actually investment, why we need/want them?
What would happen to world economy, if people invested in virtual investments, instead of real investments?
Or, all so-called cryptocurrencies are actually just a modified (made decentralized and paying variable interest) Ponzi Schemes?
(Price of cryptocurrencies would keep increasing in the long term (by their design), so it is equivalent of paying variable interest to all long term investors.)
Also, since all so-called cryptocurrencies are actually financial scams (Ponzi Schemes), that means, they cannot be the solution for any of existing financial problems of our world!
As more and more people invest in cryptocurrencies, it will become harder and harder to ban their trading everywhere (because people invested in cryptocurrencies, would try to stop anyone trying to ban cryptocurrencies)!
All cryptocurrencies need to be banned globally before it is too late!
What's an ICO? Editing is dead, I'm kicking a horse, there's glue on my shoe.
See subject: Khyber we saw u start crap w/ me & fail technically https://news.slashdot.org/comm... & I point out why https://news.slashdot.org/comm... you're so twisted!
* You ruined your LIFE yourself, Khyber/Alex McQuown - nobody else (it's your OWN fault, not mine OR anyone else's).
(ENJOY YOUR DOWNMOD!)
APK
P.S.=> ... & since you're SUCH a miserable self-wreckage you try take it out on others to fill them w/ your self-created hell but you can't - we just have to LAUGH @ "your kind", lol... apk
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ bugs (DNS/AntiVir) + their overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux
APK
P.S.=> See subject: "hosts trick to block the Coinhive or Crypto-Loot" - https://www.bleepingcomputer.com/news/security/a-new-player-joins-coinhive-on-the-browser-cryptojacking-scene/ ... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
(APK's work), I've flat out said it's good by BronsCon February 11 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* See subject: Best part's the Linux 64-bit model's faster & more efficient (does 2x the work in 1/2 the time)
APK
P.S.=> Enjoy a faster/safer/more reliable internet... apk
They were already ICOs. Since they're worth roughly the same as snake oil, I'm not sure it matters how many vulnerabilities there were.
Behind AV or browser addons matters? Hosts do MORE for LESS natively (not "Bolt-on-''MoAr'" illogic logic using more resources & moving parts EXPLOIT vs. using a 45++ yr. PROVEN IP stack (more cpu precedence faster in KERNELMODE vs. slower usermode) + speeds up 2 ways (hardcodes + adblocks + securing you both ways) & others SLOW U or don't DO as much as hosts by themself (ask Tavis Ormandy on AV security errors he found & TREND had more recently)
Browser addons = inferior+slower, more messagepass & RAM overhead & NONE do as much as hosts for FAR less + FASTER!
Afraid to stand behind your words? Yes. I'm not.
* You HIDE behind UNIDENTIFIABLE ac STALKING me!
(Why not use ur FAKE NAME 4 ur FAKE LIE of a WASTED "so-called 'life'" REGISTERED 'lusername'? Answer = I've TORN U UP under those too as I did above easily).
APK
P.S.=> Don't TRY tell me "it doesn't go on @ /." SOCKPUPPETERRING as Zontar The Mindless = TrollingForHostsFiles https://slashdot.org/comments.... = PROOF
See subject (u FAIL right there alone): Are you trying to say those I quoted didn't say they like & use my ware + saying it's GOOD work?
APK
P.S.=> ANSWER that simple question & we'll SEE who the REAL "phalussy" (lol it's you) is... apk
Khyber attacked me there 1st FAILING HUGELY on his erroneous hosts file entries he typed saying "hosts don't work" https://news.slashdot.org/comm... & he has THREATENED MY LIFE + breaks MORE laws on threats to SUE ME but NOT doing so (for years now a FEW times & there too - ATTEMPTING his EXTORTION he's been CONVICTED OF BEFORE ON NO LESS).
Khyber/Alex McQuown wouldn't last 10 seconds where I'm from (1 of the MOST violent cities in the USA) acting as he does & the fact he's a 135 lb. WHIMP faggot (Truth).
* WHO are you TRYING to fool? Yourself?? Please... lol!
APK
P.S.=> Listen up & LISTEN good: I try to live by Christ's fine model but I CANNOT turn the other cheek (where I am from you get it up the ASSCHEEKS, you know, like Khyber the HOMO likes) but even Jesus GOT VIOLENT in righteous indignation vs. the PHARISEE JEWS & literally beat their ASSES w/ a whip outta the temple - so I am JUST doing the same when ATTACKED first & successfully (no f'ing around when I am attacked & NO "PC BULLSHIT" either for pussies)... apk
WHITELISTS = maintenance nightmare vs. blocked users bitching, NO DNS level security (vs DNS security issues/tracking/slower resolution vs. hosts) + NO SPEED GAIN (hosts give you 2 in adblocking + hardcodes USERS SPEND MOST TIME @ ONLINE + DNS bennies whitelists don't).
Heuristics/Wildcards = falsepositives!
DNS & AV = security issues (Tavis Ormandy) complexity in moving parts + SLOW YOU vs hosts speed up 2 WAYS & protect you vs. DNS security/tracking/slowup issues in resolution vs hosts.
AV's + Addons = REACTIVE "noted 1st" by YOU bs performs LAST in security/speed/resource use/complexity 4 exploit vs. hosts (both get updates).
Hosts on smartphones = GodMode/iPhone & ADB/Droid!
(more coming - funny you can post TONS & I can't after you post eh? Not you cheating bastards).
APK
P.S.=> Hosts' native/ free/LESS is MORE = superior vs. "Bolt-on-'MoAr'" ILLOGIC logic!
MY program = hosts EZ 2 manage & interior = EASIER vs. addon regex (slower, messagepass overhead ridden SLOWER inefficient RAM hogs vs. hosts 'SOULED-OUT' to not work by default not doing their 1 job (hosts do more for less vs 'em) + vs. AV dll's sigs/dns rules.
Block a non 3rd party script via OPERA classic BY SITE prefs (no slow usermode tag parse NoScript needed)!
ADDON TO MY OTHER POST as 'suddenly' I can't post a post as big as the ac stalker I just blew away here https://it.slashdot.org/commen...
LESS size vs. UNIDENTIFIABLE ac stalking me & LOSING as usual but HE CAN POST LARGER POSTS than I but after he replies I SUDDENLY CAN'T post 1/2 the size of his post?
ANYONE can compare post sizes & SEE his post is larger & more character vs. my post I just replied to & SUDDENLY when I try to reply I have to HACK MY POST to worse grammar to fit it in vs. asshole AC UNIDENTIFIABLE stalker I kicked the SHIT out of.
APK
P.S.=> FUCK YOU whipslash
See subject: Is it because I KICKED THE SHIT out of your bullshit like I did here https://it.slashdot.org/commen...
Thats where anyone can COMPARE the size of your post I replied to vs. mine there - yet YOU can post encyclopedia brittanica size as AC but when I try reply to it "SUDDENLY" I can only post 1/2 the size you did?
You make me hack up my writing's grammar + into 2 posts BOTH less in size COMBINED vs. STALKERS via UNIDENTIFIABLE anonymous posts I kick the crap out of on EVERY ONE OF HIS BULLSHIT easily beaten 'points' in that link above!
* Whimp, you STALK me via UNIDENTIFIABLE anonymous posts & I kicked the CRAP out of EVERY bullshit you threw point by pointeasily & yet my posts can't be big as yours?
FUCK YOU /. CHEATER BASTARDS!
Especially vs. YOU who can't STAND BEHIND YOUR WORDS stalking me UNIDENTIFIABLY fucker.
(That last part REALLY says it ALL about you weezil)
APK
P.S.=> Listen you chickenshit cheating little BITCH - NPD is the HOWL of an INJURED "ne'er-do-well" DO NOTHING like you that couldn't write a program like MINE to save your worthless WASTED life fucker & you know it - ESPECIALLY WHEN I KICKED THE SHIT OUT OF YOU IN THE LINK ABOVE (anyone normal does - cry of weezil's LOSING vs. someone superior is ALL your NPD cunt crap is)... apk
I post logged in. I just tick the AC box. And I'm restricted to 10 posts per day. But my 'day' is in Australia, so my posts spread out over what seems to you to be longer. I'll often hit limit replying to you, so I'll wait until I can post the reply. I have a life. I get on with it and check in when I'm waiting for something else. And don't forget, these days there's about 3-4 people posting replies.
But you hit limit and OMG! Persecution!
Or are you just noticing the 'lameness' filter that stops you using the same word more than (X) times? Why do you think I have to use host, hosts, hostfile, host-file etc. when I respond to you?
I thought you regularly switched VPNs or IP addresses to get around your posting limit.
APK. When bad things happen to other people, laugh. When they happen to APK, it's a CRIME!
You know, one of the things about freedom of speech is that we are only tested when it's someone saying something we don't agree with. That you've been let run your toxic mouth for so many years is a testament to Slashdot's tolerance. I admire it. Every other forum has banned you within 18 months. Here, you've been given an enormous gift, but all you can do is spit in the face of those who provide it.
---
whipslash, I see a lot of criticism thrown your way. It's a thankless task, and I've been guilty of not saying 'thanks' when things are going well. So thank you. Thank you for keeping Slashdot's stance on not censoring speech. Thanks for keeping this old dinosaur alive.
News aggregator sites or new site NOT in NO DNS bennies whitelist users blocked = maintenance!
Heuristics+wildcards make more fps vs hosts & hosts = EZ 2 edit (vs. AV heuristics/DNS rules/regex addon for NON-TECH USERS).
Time I save in hosts (1 min on a tiny daily intake & rare ALL sources update) & merge = 2 min PALES vs what I save vs ADS daily ALONE remotely calling to orig site, 3rd party ads servers, processing javascript LOCALLY on my power/time (hidden COST of script & ads w/ INFESTATION cleaning time = more & ads + script ARE main source of infection)
Remote DNS lookups I don't do (avoids dns security & tracking too) I save MORE time + gain speed & security.
WRONG - Security guides I wrote for windows 1997-2007 got me PAID unexpectedly http://pcpitstop.com/news/winn... no less that use CIS Tool (highly esteemed & they took FIXES from me too on errors THEY MADE) & LAYERED-SECURITY/DEFENSE IN DEPTH!
APK
P.S.=> See subject you lose
See subject: on shortening my AC posts https://it.slashdot.org/commen... vs. UR huge one https://it.slashdot.org/commen...
WHY AM I BEING RESTRICTED TO THAT SIZE (that's exactly ALL I could post & no more) vs. YOUR "RAMBLING BULLSHIT ENCYCLOPEDIA?
* Just because I am KICKING THE SHIT OUT OF YOU & yours POINT by POINT means /. has to CHEAT?
APK
P.S.=> Doesn't matter cheaters - FACT is kicking your ass & so am I easily point by point vs. your easily outsmarted bs... lol & you KNOW it as ANYONE can see BOTH posts to compare size AC's BOTH posting, losers! apk
See subject: So you're harassing me HIDING behind AC posts when you have a REGISTERED 'luser' acct? Punk bitch you are losing to my every post SHORTENED or not I tore up your bullshit EASILY point by point, you MENIAL moron.
Why do I call YOU that? OK - the DAY you can show you create a program that our /. PEERS like & use as I do https://it.slashdot.org/commen... is the day I might respect you loser (my guess is @ best/most you're a MENIAL "ScryptKiddie" OpenSORES codethief (it's what they are, funny when they hit bugs in that stolen code vs. WRITING YOUR OWN from scratch as I do) OR a mere "SysAdmin" wannabe that is helpless minus coders like me merely USING our work as they're USERS w/ a better password & nothing more))
APK
P.S.=> Yup, you're an UNIDENTIFIABLE anonymous pussy no doubt about it... apk
See subject: Call me "big man behind a keyboard" but you are just a PUSSY punk big mouth little bitch from Australia doing AC when u have an acct here.
* I tore your bs COMPLETELY & EASILY apart point by "so-called bs 'point'" of yours vs. hosts here 1st https://it.slashdot.org/commen... & here after you vainly tried & F'd up on new sites not in whitelists meaning maintence & more (but more on your accusation I BLEW AWAY on layered security bitch) here after that 1st link too https://it.slashdot.org/commen...
APK
P.S.=> You laugh? I get the LAST LAUGH @ your sorry bullshitter ass dumbo on all levels (especially that you're AFRAID to use your REGISTERED 'lusername' facing me pussy boy bitch)... apk
See subject: Your NPD Howl of the injured ne'er-do-well isn't making you some pro for your "prognosis" moron & I state facts from reputable legal sources on Khyber the LOON who stalks me & f's up HUGELY when he does, lol... want to see another JERK I worked over today TOO since he's a KNOWN admitted mentalcase, druggie & threatened me too (even sending me a postcard out of butthurt that I took him down on tech? See FAKE NAME for his FAKE LIE of a WASTED druggie loon "so-called 'life'" in Zontar the Mindless https://news.slashdot.org/comm... )
* Between Khyber, Zontar, & the PUSSY from 'downunder' I tore apart today on tech too + his being a PUSSY hiding from me stalking me by AC posts https://it.slashdot.org/commen... when he HAS a registered 'luser' acct here butHIDES from me instead?
Please...
APK'
P.S.=> /. is RAPIDLY degenerating into a SHITHOLE full of troll losers who take shots @ guys like me FAR in advance of them in tech (my code ALONE proves that vs. you MENIAL scriptkiddie @ best OpenSORES thieves OR SysAdmins stitching together work GUYS LIKE ME MAKE FOR THEM TO USE minus us they're helpless)? Slashdot's become a home of trashbags (like you but NOT I)... apk
You're a punk HIDING from me not I vs you https://it.slashdot.org/commen...
You're a DISGUSTING hotair blowhard windbag talk NO SUBSTANCE do-NOTHING scared little JEALOUS "Jowie" waste of life "ne'er-do-well" I easily TORE APART in 2 posts https://it.slashdot.org/commen... & then here https://it.slashdot.org/commen... vs. your TRYING to bs YOUR WAY OUT to FAIL hugely EATING YOUR WORDS @ the end vs. me too
* Good luck "forums sliding" BURYING my posts w/ only 43 posts @ time I post this OR downmodbombing me to HIDE my posts & me having UNLIMITED ac posting unlike most ACs I nullify by reposting what you try "hide" by abused sockpuppet driven downmods per Zontar The Mindless = TrollingForHosts Files proof https://slashdot.org/comments....
APK
P.S.=> Replies of MINE that for 'some reason' (not) my posts are AC are forced SUPER SHORT vs. your AC ones (/. let you post LIBRARIES by AC but I'm shortened to 1/4 of yours "oddly" ('not'))!
Doesn't matter - I show EVERYONE what u r & /. too - pitiful, hiding from me COWARDLY unidentifiable AC & STUPID on tech I ate you alive on (WHY you hide by ac even though you ADMIT you have a registered LUSER acct)