ActiveDen

Rubber-hose cryptanalysis. How AD can help to defence.

82 posts
  • Has been a member for 2-3 years
  • Exclusive Author
  • Sold between 1 and 100 dollars
  • Bought between 1 and 9 items
  • Europe
Gladreaman says

If AD will have a service of lie-passwords? I mean some passwords will inform (man->bandit->AD->police) that a man is under blackmail to help him if needed. If somebody live in a rather criminal country, big money for him can be a big problem.

Lie-password should work as simple password, but also to inform local police or interpol etc.

Posted 2 years ago Permalink
2965 posts
  • Has been a member for 3-4 years
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Contributed a Tutorial to a Tuts+ Site
  • Community Superstar
  • Interviewed on the Envato Notes blog
  • Grew a moustache for the Envato Movember competition
  • Community Moderator
  • Exclusive Author
  • Sold between 10 000 and 50 000 dollars
  • Bought between 1 and 9 items
  • Europe
  • Referred between 10 and 49 users
Enabled says
If AD will have a service of lie-passwords? I mean some passwords will inform (man->bandit->AD->police) that a man is under blackmail to help him if needed. If somebody live in a rather criminal country, big money for him can be a big problem. Lie-password should work as simple password, but also to inform local police or interpol etc.

Uhm… relax. :) Their site is pretty much bulletproof. If your password is not 123456 and you don`t have 5 trojans in your computer and 5 worms, there is no way to hack it.

Else… interpol would say ” We are on it ” and 5 years later, they would still be on ” it “

var it = a$$

Posted 2 years ago Permalink
Enabled is an Envato staff member
2309 posts
  • Has been a member for 4-5 years
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Envato Staff
  • Reviewer
  • Exclusive Author
  • Beta Tester
  • Sold between 100 and 1 000 dollars
  • Bought between 1 and 9 items
  • United States
  • Referred between 10 and 49 users
theflyingtinman says
Uhm… relax. :) Their site is pretty much bulletproof. If your password is not 123456 and you don`t have 5 trojans in your computer and 5 worms, there is no way to hack it.

Else… interpol would say ” We are on it ” and 5 years later, they would still be on ” it “

var it = a$$

I don’t think you quite understand the concept of rubber hose cryptanalysis. ... though I do have trouble envisaging thugs trying to beat an Envato password out of some author, no matter how criminal the country :).

Posted 2 years ago Permalink
theflyingtinman is an Envato staff member
4265 posts
  • Has been a member for 3-4 years
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Contributed a Tutorial to a Tuts+ Site
  • Contributed a Blog Post
  • Interviewed on the Envato Notes blog
  • Grew a moustache for the Envato Movember competition
  • Community Moderator
  • Exclusive Author
  • Beta Tester
  • Sold between 1 000 and 5 000 dollars
  • Bought between 10 and 49 items
  • United Kingdom
  • Referred between 1 and 9 users
Reaper-Media says

Oh no!!! What is someone went I ds’s house? :o

It needs to have plausable deniability, so it looks like the genuine account, but when they try to perform actions on the account, they are unable to, it will come up with something like “server error! Please try again later”

And also all the numbers and statistics should be able to be altered from the “master” account, so they don’t see earnings etc. If that’s what they’re after.

Wow I’m getting carried away here :D

Posted 2 years ago Permalink
Reaper-Media is an Envato staff member
2668 posts
  • Has been a member for 4-5 years
  • Won a Competition
  • Exclusive Author
  • Sold between 100 000 and 250 000 dollars
  • Elite Author
  • Bought between 10 and 49 items
  • United Kingdom
  • Referred between 50 and 99 users
Chuckanucka says
Uhm… relax. :) Their site is pretty much bulletproof. If your password is not 123456 and you don`t have 5 trojans in your computer and 5 worms, there is no way to hack it.

hmm… a little naive no?

Posted 2 years ago Permalink
6322 posts
  • Has been a member for 3-4 years
  • Won a Competition
  • Contributed a Tutorial to a Tuts+ Site
  • Contributed a Blog Post
  • Grew a moustache for the Envato Movember competition
  • Community Moderator
  • Exclusive Author
  • Beta Tester
  • Sold between 1 000 and 5 000 dollars
  • Bought between 50 and 99 items
  • United Kingdom
  • Referred between 10 and 49 users
MSFX says

Unless they know where you live then theres no issue unless they go to the area where you say you live and beat everyone until they find you?

Posted 2 years ago Permalink
MSFX is an Envato staff member
2668 posts
  • Has been a member for 4-5 years
  • Won a Competition
  • Exclusive Author
  • Sold between 100 000 and 250 000 dollars
  • Elite Author
  • Bought between 10 and 49 items
  • United Kingdom
  • Referred between 50 and 99 users
Chuckanucka says

or you could just not log out of your AD account on a public computer.

Posted 2 years ago Permalink
6322 posts
  • Has been a member for 3-4 years
  • Won a Competition
  • Contributed a Tutorial to a Tuts+ Site
  • Contributed a Blog Post
  • Grew a moustache for the Envato Movember competition
  • Community Moderator
  • Exclusive Author
  • Beta Tester
  • Sold between 1 000 and 5 000 dollars
  • Bought between 50 and 99 items
  • United Kingdom
  • Referred between 10 and 49 users
MSFX says
or you could just not log out of your AD account on a public computer.

thats probably far more likely…

Posted 2 years ago Permalink
MSFX is an Envato staff member
2668 posts
  • Has been a member for 4-5 years
  • Won a Competition
  • Exclusive Author
  • Sold between 100 000 and 250 000 dollars
  • Elite Author
  • Bought between 10 and 49 items
  • United Kingdom
  • Referred between 50 and 99 users
Chuckanucka says
or you could just not log out of your AD account on a public computer.
thats probably far more likely…

Or if your laptop gets stolen..

I think it would helpful if there was a “I am on a public computer” checkbox at login and maybe an auto log out after x minutes. The problem is all you have to do to withdraw money is type in your email address.

Posted 2 years ago Permalink
6322 posts
  • Has been a member for 3-4 years
  • Won a Competition
  • Contributed a Tutorial to a Tuts+ Site
  • Contributed a Blog Post
  • Grew a moustache for the Envato Movember competition
  • Community Moderator
  • Exclusive Author
  • Beta Tester
  • Sold between 1 000 and 5 000 dollars
  • Bought between 50 and 99 items
  • United Kingdom
  • Referred between 10 and 49 users
MSFX says
or you could just not log out of your AD account on a public computer.
thats probably far more likely…

Or if your laptop gets stolen..

I think it would helpful if there was a “I am on a public computer” checkbox at login and maybe an auto log out after x minutes. The problem is all you have to do to withdraw money is type in your email address.

Thats a pretty good idea… if you leave yourself logged into anything on a public PC it’s harsh but you’ll get what’s coming to you one day…

And maybe having to re-enter your password to withdraw would be a good security feature, thats what my online banking does when I try and send other people money…

Posted 2 years ago Permalink
MSFX is an Envato staff member
by
by
by
by
by