-
boog900[m]
> nacl.bindin.crypto_scalarmult_ed25519_noclamp throws an error when I try to multiply by 8 (int(8).to_bytes(32, byteorder="little")).
-
boog900[m]
libsodium checks if the point is on the prime-order subgroup before performing the multiplication and as the point your multiplying isn't it returns an error
-
boog900[m]
> nacl.bindings.crypto_core_ed25519_is_valid_point says the original hash_to_point value (before adding it to itself 8 times) is not a valid EC point.
-
boog900[m]
This function checks (among other things) if the point is on the on the prime-order subgroup and as the original point isn't it returns false.
-
boog900[m]
<anonimauzanto[m]> "After many hours of searching it..." <- monero's hash to point is non-standard IIRC and the documentation for this function says `The point is guaranteed to be on the main subgroup.` so i would say this is not equivalent
-
anonimauzanto[m]
Am I incorrect in assuming that the prime order subgroup is the same thing as the main subgroup?
-
boog900[m]
nah they are the same thing
-
anonimauzanto[m]
If I have time in the next few days I may try to modify the pynacl library to include crypto_core_ed25519_from_uniform to test against key_image calculation. I do not use C/C++ so I cannot test the source functionality. Thank you boog900~
-
anonimauzanto[m]
Interesting, I modified the pynacl wrapper to expose the crypto_core_ed25519_from_uniform function, and with modulus applied to the keccak hash results it produces almost the appropriate hashed point. With a slight change to the point compression encoding I have matching key image results.
-
anonimauzanto[m]
Here is the python code I used. It requires pynacl to be modified to expose the function.
-
-
alandamjanic[m]
<bcrumb> "I use local, it's weird that it..." <- sdd it says, i am syncing, takes whole day, occupies a lot of local memory space, internet is so so but enough for most things. but monero jams things usually. is it possible that remote nodes are much faster? and how are they less secure, what most of monero users are using, local or remote. for example, who ever doed it from smartphone it has to be remote?
-
tevador
-
DanIsnotthemanBr
Why not post in dev room if its a world ender
-
ofrnxmr[m]
dev presumably already knows
-
ofrnxmr[m]
as this went through hackerone and hasnt been disclosed yet
-
DanIsnotthemanBr
Looks like there going to disclose it
-
ofrnxmr[m]
yep. i wonder if it mostly effects simple-mode users
-
xfedex[m]
i wonder if it also affects remote nodes throughout tor, but probably yes
-
ofrnxmr[m]
or if hes referring to s*th traitor type nodes (/s)
-
DanIsnotthemanBr
Maybe
-
DanIsnotthemanBr
Sith lord
-
DanIsnotthemanBr
Lets guess the vul
-
ofrnxmr[m]
thats probably the crux of the issue. a lot of people use sith nodes.
-
ofrnxmr[m]
decoy poisoning
-
DanIsnotthemanBr
Morbs break decoys
-
xfedex[m]
or maybe the issue is linked to Known ring does not include spent output
-
DanIsnotthemanBr
Yeah cake,feather use sith
-
ofrnxmr[m]
xfedex[m]: so poisoning with fake decoys? dig dig dig
-
ofrnxmr[m]
im gonna check hackerone
-
DanIsnotthemanBr
Ima go to sleep
-
ofrnxmr[m]
how can you sleep knowing seth is sleeping well?
-
ofrnxmr[m]
s/seth/sith/
-
DanIsnotthemanBr
His asmr voice puts me to sleep
-
ofrnxmr[m]
i should try that
-
ofrnxmr[m]
ive never actually heard him speak. im just a hater who hates him for not acknowledging me
-
modul8[m]
Should have used my own node. SHUMON
-
DanIsnotthemanBr
-
ofrnxmr[m]
hopefully disclosed soon
-
DanIsnotthemanBr
Who would they report it to anyway?
-
DanIsnotthemanBr
On dev team
-
modul8[m]
Would be interesting to know what is meant by more than loss of privacy but no fund loss
-
mlcboss[m]
what app can i use for having multiple numbers for sms & calls?
-
mlcboss[m]
it will be great if it accept monero but im ok with paying with cc / appstore
-
mlcboss[m]
i need one with asian numbers (Singapore , India , etc)
-
mlcboss[m]
not western (US,UK,Canada)
-
DanIsnotthemanBr
Sounds decoy issue
-
DanIsnotthemanBr
* Sounds like decoy issue
-
DanIsnotthemanBr
Security response team
-
DanIsnotthemanBr
luigi1111
-
DanIsnotthemanBr
moneromooo
-
ofrnxmr[m]
our main devs, yeah
-
ofrnxmr[m]
koe, vtnerd, luigi, mooo etc respond to hackerone
-
ofrnxmr[m]
ooo doesnt seen to like H1 lolol
-
mlcboss[m]
is it risky to use a web wallet?
-
ofrnxmr[m]
(he reported and fixed multisig)
-
ofrnxmr[m]
mlcboss[m]: duh
-
ofrnxmr[m]
when has ysing a web wallet ever been a good idea?
-
mlcboss[m]
ofrnxmr[m]: can they track my spendings?
-
ofrnxmr[m]
aside from"when it was the only option"
-
ofrnxmr[m]
mlcboss[m]: yes
-
ofrnxmr[m]
thats what a light wallet is. it does the scanning for you
-
mlcboss[m]
is it bad to run xmr node on VPS?
-
ofrnxmr[m]
while the view key TECHNICALLY doesnt show your spends, its a simple matter to them to fingerorint change
-
ofrnxmr[m]
mlcboss[m]: yes
-
ofrnxmr[m]
... but define bad? for who?
-
ofrnxmr[m]
centralizing nodes on 1 provider helps with purchasing bandwidth to seed tge network
-
modul8[m]
I guess we gotta take the bad with thr good
monero-project/monero #8827
-
ofrnxmr[m]
it also opens up centralized attack points
-
mlcboss[m]
ofrnxmr[m]: is there a way to hide my xmr wallet on my computer?
-
ofrnxmr[m]
?
-
ofrnxmr[m]
from who?
-
ofrnxmr[m]
from your wife?
-
ofrnxmr[m]
from your isp?
-
mlcboss[m]
ofrnxmr[m]: i can't tell you but i need it to be hidden
-
ofrnxmr[m]
good luck
-
ofrnxmr[m]
i cant help if im expected to be psychic
-
modul8[m]
Use a vpn and store your monero on a portable ssd
-
ofrnxmr[m]
my psychic powers are exhausting. i only use them occasionally
-
ofrnxmr[m]
modul8[m]: that doesnt hide from isp or wife
-
mlcboss[m]
ofrnxmr[m]: is
-
mlcboss[m]
not an ISP
-
ofrnxmr[m]
maybe from coffe shop wifi
-
modul8[m]
Prison wallet cant kind a portablr nvme usb adapter?
-
modul8[m]
*hide
-
DanIsnotthemanBr
Like encrypted drive?
-
ofrnxmr[m]
border agebts? delete the wallet
-
mlcboss[m]
why is it matters anyways , i just don't want having a coin that used for illegal shit wallet in my PC
-
ofrnxmr[m]
only keep seed in an encrypted backup
-
modul8[m]
Without knowing the goal nobody can give you a good answer
-
DanIsnotthemanBr
^
-
ofrnxmr[m]
mlcboss[m]: eat s rooster then
-
ofrnxmr[m]
a*
-
ofrnxmr[m]
go use btc
-
ofrnxmr[m]
and give me all of your cash please
-
DanIsnotthemanBr
I put mine in btrfs drive
-
DanIsnotthemanBr
Is that the answer your looking for?
-
modul8[m]
mlcboss[m]: Spend some monero on a new laptop that only you use and nobody knows about. Easy.
-
ofrnxmr[m]
"illegal shit money"
-
ofrnxmr[m]
insanity
-
ofrnxmr[m]
get out of your dumbass crypto bubble
-
ofrnxmr[m]
money IS private
-
modul8[m]
Oh hang on..he is judging us!!
-
DanIsnotthemanBr
Sunno
-
DanIsnotthemanBr
* Dunno
-
ofrnxmr[m]
just because scam 1-1000 dog coin isnt, has nothing to do with fundanental properties on money
-
ofrnxmr[m]
"illegal shit"
-
ofrnxmr[m]
yall weirdos are trying to reinvent the wheel by adding corners
-
mlcboss[m]
modul8[m]: ok fine , someone suspect me I'm doing illegal stuff
-
mlcboss[m]
cause they once see my computer had a Tor Browser on it
-
mlcboss[m]
i can't tell you who it is cause is private
-
ofrnxmr[m]
so delete it
-
ofrnxmr[m]
or do like me
-
ofrnxmr[m]
and tell them to eat a rooster
-
DanIsnotthemanBr
Fyi its not illegal to use tor
-
ofrnxmr[m]
my exchange account was frozen a few days ago
-
DanIsnotthemanBr
Considering us navy created onion routing
-
ofrnxmr[m]
they wanted to know what im doing and why my ltc address is always empty
-
ofrnxmr[m]
said they trued to call me
-
ofrnxmr[m]
i told them "x m r, when are you relisting?"
-
ofrnxmr[m]
account > unblocked
-
mlcboss[m]
ofrnxmr[m]: i already did and only use mymonero web wallet on pc rentals
-
DanIsnotthemanBr
-.-
-
ofrnxmr[m]
mlcboss[m]: bananas
-
ofrnxmr[m]
mymonero > might as well just use monero from he police officers car laptop
-
DanIsnotthemanBr
Now gonna go to sleep tldr me later
-
mlcboss[m]
DanIsnotthemanBr: i know normies see Tor as a browser used by hacker and criminals
-
mlcboss[m]
they don't even know it was made for privacy & anonymity
-
ofrnxmr[m]
i use tor, i2p, moneo, torrents, youtube
-
DanIsnotthemanBr
Terrorist
-
ofrnxmr[m]
so because stupid people cab tie their shoes >> i will no longer wear shoes
-
ofrnxmr[m]
cmon man
-
DanIsnotthemanBr
Ok bye
-
ofrnxmr[m]
gnite D
-
ofrnxmr[m]
s/cab/cant/
-
modul8[m]
They say weed makes you paranoid
-
ofrnxmr[m]
these idiots say cooking burns down houses. only allowed to buy fast food > cmon man
-
ofrnxmr[m]
modul8[m]: coke*
-
ofrnxmr[m]
caffeine*
-
ofrnxmr[m]
nicotine*
-
modul8[m]
I think i misjudged how long ungoogle chromium takes to build
-
mlcboss[m]
<ofrnxmr[m]> "i use tor, i2p, moneo, torrents,..." <- sadly Youtube is very unfriendly towards Tor user
-
mlcboss[m]
to solve this , i searched the video title on the web and watch it on random website that reposted the same vid
-
mlcboss[m]
vimeo , daily motion , voice tube and other brick & mortar youtube clone
-
ofrnxmr[m]
youre not an android user, are you
-
ofrnxmr[m]
#monero-offtopic:monero.social lets cont. there
-
toralien[m]
someone should code a GPT (some FOSS derivative) / LLAMA / OpenAssitant based crypto wallet
-
toralien[m]
instead of having the user need to do txs and control stuff by themselves it should be a dialog based wallet
-
toralien[m]
this might be more something for ethereum though, who knows
-
monerobull[m]
Didn't some wallet do that as April fools
-
politicalweasel[
who needs tx_extra when you have output spam? 1095 bytes of data per tx. Aint it beautiful?
stagenet.xmrchain.net/tx/c394b0b982…8899c062806fdb0ac4b7d1ef5e97a125acb imgur.com/a/0NfBEL6
-
ofrnxmr[m]
Isnt that a typical 16 out
-
ofrnxmr[m]
3,2kb 1:2 looks pretty normal iirc
-
ofrnxmr[m]
-
kowalabearhugs-[
I'm surprised the dev and MRL channels have been quite since the announcement of a vulnerability in wallets that can be exploited by a malicious remote node. The latter were already questionable for an opsec POV, i believe logging and decoy selection were know issues, but this seems more severe.
-
toralien[m]
ofrnxmr is a fed
-
toralien[m]
* a fed MAYBE
-
toralien[m]
i am entitled to an opinion
-
toralien[m]
he talks so much shit constantly, according to the cia playbook
-
selsta
kowalabearhugs-[: it has always been known that remote nodes can feed you bad data
-
kowalabearhugs-[
selsta: Yes. Has "bad data" traditionally referred to the DSA?
-
kowalabearhugs-[
"The impact of the exploit is more than just privacy loss" makes it seem like a larger issues than a remote node simply feeding skewed decoys
-
ofrnxmr[m]
<toralien[m]> "ofrnxmr is a fed" <- 100%. tell em
-
boog900[m]
Well the fee bug is an example of an attack more than just privacy loss
-
selsta
the whole point of having a separate daemon and wallet is that you separate responsibilities
-
selsta
adding checks to the wallet can be done if they don't have too much of an performance impact
-
someoneelse49549
kowalabearhugs-[: The fact that this is a Medium CVE is already a flag. Now, this wouldn't (and isn't) a good idea, to disclose informations about the vulnerability while a decision hasn't been made.
-
toralien[m]
ofrnxmr[m]: as far as i know you are on some xmr communit something and you are the only person i express dissatisfaction with noting that i am a donator
-
toralien[m]
s/communit/community/
-
ofrnxmr[m]
toralien: before you start shitosting #monero-offtopic:monero.social
-
spackle_xmr[m]
selsta: Can you confirm this new announcement is genuine?
-
Alex|LocalMonero
selsta: are you aware of the details of the vulnerability?
-
spackle_xmr[m]
If it is, I am very surprised that it was decided to release a 'security advisory' on Reddit and nowhere else.
-
toralien[m]
toralien[m]: not due to work done but because of the constant manner of behaviour
-
ofrnxmr[m]
im not on anything
-
toralien[m]
then i am content
-
ofrnxmr[m]
rip
-
selsta
Alex|LocalMonero: yes
-
politicalweasel[
<ofrnxmr[m]> "Isnt that a typical 16 out" <- It's XOR'ed. If you take the first vout key and XOR with the first outPk, 2nd with 2nd, 3rd with 4rd, etc, you'll see it
-
politicalweasel[
s/4rd/3rd/
-
ofrnxmr[m]
yeahh i didnt even check more details first (didnt even see in in/out). apologies i had written a follow up reply but didnt send
-
r4v3r23[m]
is there an XMPP > gaytrix bridge?
-
lza_menace
Thought it is dANBs
-
lza_menace
maybe bridgerton
-
selsta
-
selsta
spackle_xmr[m] and others who asked
-
spackle_xmr[m]
selsta: Thank you. I still don't understand why Reddit was used as the only channel to communicate the advisory, but that certainly clears things up.
-
selsta
In the past we haven't put out advisories for medium severity bugs before they were fixed.
-
selsta
90 days had passed so tevador was allowed to post about it per the VRP.
-
xfedex[m]
oh, that "vulnerability" was known for a long time
-
lza_menace
reddit seems like the place with the largest audience
-
lza_menace
twitter would have been good, too, though
-
spackle_xmr[m]
I mention it more out of a concern for people using Reddit as an authoritative source for receiving security related announcements. I don't trust Reddit, and the situation seems exploitable to me.
-
spackle_xmr[m]
Anyways, I appreciate the information. I'll shut up and go back to polishing my tinfoil hat.
-
Rucknium[m]
It would be a good time to sign statements with PGP keys.
-
selsta
-
Rucknium[m]
Thanks. That is the memory that I recalled.
-
Rucknium[m]
It appears in this instance that tevador was free to choose to sign (or not) the statement with his/her PGP key.
-
DanIsnotthemanBr
So world is not ending?
-
uncle_rae
the sky is falling down
-
DanIsnotthemanBr
Sounds like i didnt get my way so i posted in reddit and made it bigger then ben-hur
-
DanIsnotthemanBr
Vulnerability
-
selsta
it's a valid vulnerability but definitely not world ending
-
selsta
I'm happy that tevador found a good solution with the RandomX change, otherwise we would have had to wait until Seraphis to mitigate this.
-
RavFX
Don't we still have to hardfork?
-
selsta
yes, but we will likely hard fork Bulletproofs++ and the RandomX change before Seraphis
-
RavFX
Oh, nice then
-
DanIsnotthemanBr
Out of all this at least i know there is hackerone reporting for monero now
-
kowalabearhugs-[
selsta: Given the next HF is likely more than 6 months away do you have any idea where things stand with OSPEAD and its potential inclusion?
-
selsta
Rucknium[m]: ^
-
Rucknium[m]
kowalabearhugs-: If the hard fork was 3 months away, we could include OSPEAD, but it would be close. If more than 3 months, we could easily include it.
-
selsta
definitely more than 3 months away since
-
Rucknium[m]
OSPEAD is a wallet-level change that doesn't require a hard fork. However, we have not evaluated the risk of having two significantly different decoy selection algorithms being used by the reference implementation (wallet2). It could be evaluated (I have some possible methods), but it is out of scope for the original OSPEAD CCS.
-
Rucknium[m]
The question is how easily an adversary could distinguish between the two decoy selection algorithms and whether that would give them an advantage in trying to guess what output in a ring is the real spend.
-
Rucknium[m]
We don't really have to answer that question if OSPEAD is implemented in a hard fork since all users who want to use the hard-forked chain would use the updated wallet2, either directly or through a "third-party" wallet.
-
Rucknium[m]
We know that there are "third-party" wallets that don't use the wallet2 decoy selection algorithm, but that's out of scope of this issue unless something like this is done:
monero-project/research-lab #87
-
Rucknium[m]
Another related issue is "Avoid selecting coinbase outputs as decoys"
monero-project/research-lab #109
-
Rucknium[m]
jeffro256 has written code to implement it. But an adversary may be able to guess that a user would be using the decoy selection algorithm that avoids coinbases.
-
Rucknium[m]
Implementing it ^ with a hard fork would mostly avoid the wallet software version distinguishability issue.
-
Rucknium[m]
Distinguishability is easier to analyze with the coinbase avoidance proposal because it's basically a set of binary choices, which would create a binomial probability distribution. The OSPEAD change is a change in the continuous probability distribution, which is harder to analyze.
-
Rucknium[m]
Harder, but not impossible. Like I said, I have some ideas about how it could be done. It requires research labour hours to check things to be sure, test, etc.
-
xxxmr[m]
🐟
-
L3M0R
Hi. Any recommendation for mobile wallets?
-
L3M0R
I tried Monerujo but it kept crashing
-
kico
L3M0R, android?
-
L3M0R
Yes
-
kico
hmm never had issues with monerujo on android
-
L3M0R
It crashed while grabbing keys from my password manager
-
kico
you can try cake maybe
-
L3M0R
Maybe?
-
kico
I dunno
-
L3M0R
lol. Alright I'll into it. Thanks
-
kico
try cake?
-
kico
-
kico
is your android up to date? also the app? re-install might help
-
kico
or just reach out to their support :)
-
kico
-
kico
np
-
L3M0R
Yes, and I got the app from play store
-
kico
what do you mean with the password manager?
-
L3M0R
keepassxc
-
kico
it interacts with the app?
-
L3M0R
keepass2android to be exact. It has its own keyboard which allows you to fill entries
-
kico
yeah no clue on that
-
L3M0R
As soon as I entered my key, it froze.
-
L3M0R
Now I feel like creating a new wallet :P
-
kico
good luck :)
-
kico
but maybe try add monerujo as exception on that thingy and see if it works
-
L3M0R
I'll try again.
-
L3M0R
one more thing, is LocalMonero a good way to buy XMR?
-
kico
yeah
-
kico
-
L3M0R
damn
-
L3M0R
Thanks!
-
kico
(: yw!
-
L3M0R
But are these reliable/trustable?
-
kico
DYOR iGuess otherwise it's just my opinion
-
L3M0R
fair enough
-
L3M0R
kico: I tried installing monerujo through Fdroid and Google play protect is displaying a warning "Harmful app blocked"
-
kico
lol
-
kico
sorry can't help :\
-
L3M0R
that's ok
-
kico
oh yeah fdroid
-
kico
will not work on normal android
-
L3M0R
But then Google play installed some old version
-
kico
only version on appstore will
-
kico
google play
-
kico
for fdroid you would need
f-droid.org
-
L3M0R
Yea I added the repo
-
L3M0R
and installed the app and the warning showed up
-
kico
but if you install the app from google play works?
-
L3M0R
It runs, but with no warnings
-
kico
not sure there is a chan for monerujo on irc
-
L3M0R
ok
-
kico
you should try support :)
-
L3M0R
let me try cake
-
L3M0R
But I like the aesthetics of Monerujo
-
jamss[m]
<L3M0R> "and installed the app and the..." <- There's an option in settings that allows apps to be installed from an unknown source
-
L3M0R
That is enabled
-
L3M0R
It was Google Play Protect warning
-
jamss[m]
Oh I think that's a setting inside Google play app