Why you have to hire a hacker in 2020

The stakes have never been so high

State sponsored hacking wreaked havoc in 2016 when Yahoo revealed that 1billion accounts were compromised in the largest data breach in history. And as cyber crime becomes increasingly advanced, the threat hackers pose to businesses will only increase. Leave your organisation open to a data breach and it could cost you a massive £4.25m (on average). And that's without considering the painful remediation and brand damage you'll be subject to as a result. These attacks aren't restricted to huge multinationals, the latest Government Security Breaches Survey found that 74% of small organisations reported a security breach in the past year.
The stakes have never been so high
State sponsored hacking wreaked havoc in 2016 when Yahoo revealed that 1billion accounts were compromised in the largest data breach in history. And as cyber crime becomes increasingly advanced, the threat hackers pose to businesses will only increase. Leave your organisation open to a data breach and it could cost you a massive £4.25m (on average). And that’s without considering the painful remediation and brand damage you’ll be subject to as a result. These attacks aren’t restricted to huge multinationals, the latest Government Security Breaches Survey found that 74% of small organisations reported a security breach in the past year.
For any organisation, a security flaw passing undetected is a huge risk, and when GDPR hits in 2018 the stakes will only increase.
How to hire a hacker (legally)

It's important to understand what you actually want from your ethical hacker. Do this by creating a clear statement of expectations, provided by the organisation or an external auditor. Ethical hackers shouldn't be hired to provide a broad overview of your policies, these professionals are specialised experts with a deep knowledge of IT security. Instead, ask specific questions like "Do we need to review our web app security?" or "Do our systems require an external penetration test?" Before hiring an ethical hacker to conduct a penetration test, businesses should ensure an inventory of systems, people and information is on-hand. Instead of hiring, many organisations develop ethical hacking skills in their own businesses by up-skilling team members through ethical hacking courses, like EC-Council's CEH or the more advanced ECSA.
Your staff will get the skills they need to conduct ethical hacking activities on your own businesses, finding and fixing security flaws that only a hacker could find.
How to hire a hacker (legally)
It’s important to understand what you actually want from your ethical hacker. Do this by creating a clear statement of expectations, provided by the organisation or an external auditor. Ethical hackers shouldn’t be hired to provide a broad overview of your policies, these professionals are specialised experts with a deep knowledge of IT security. Instead, ask specific questions like “Do we need to review our web app security?” or “Do our systems require an external penetration test?” Before hiring an ethical hacker to conduct a penetration test, businesses should ensure an inventory of systems, people and information is on-hand. Instead of hiring, many organisations develop ethical hacking skills in their own businesses by up-skilling team members through ethical hacking courses, like EC-Council’s CEH or the more advanced ECSA.
Advertisement Your staff will get the skills they need to conduct ethical hacking activities on your own businesses, finding and fixing security flaws that only a hacker could find.
Secure your business now
Complex threats -- like rapid IoT expansion -- are set to dominate 2020. To defend your organisation in 2020, you’ll need to think like a hacker.
submitted by tonyrogerz to Tech_And_Hacking_News [link] [comments]

Don't blindly follow a narrative, its bad for you and its bad for crypto in general

I mostly lurk around here but I see a pattern repeating over and over again here and in multiple communities so I have to post. I'm just posting this here because I appreciate the fact that this sub is a place of free speech and maybe something productive can come out from this post, while bitcoin is just fucking censorship, memes and moon/lambo posts. If you don't agree, write in the comments why, instead of downvoting. You don't have to upvote either, but when you downvote you are killing the opportunity to have discussion. If you downvote or comment that I'm wrong without providing any counterpoints you are no better than the BTC maxis you despise.
In various communities I see a narrative being used to bring people in and making them follow something without thinking for themselves. In crypto I see this mostly in BTC vs BCH tribalistic arguments:
- BTC community: "Everything that is not BTC is shitcoin." or more recently as stated by adam on twitter, "Everything that is not BTC is a ponzi scheme, even ETH.", "what is ETH supply?", and even that they are doing this for "altruistic" reasons, to "protect" the newcomers. Very convenient for them that they are protecting the newcomers by having them buy their bags
- BCH community: "BTC maxis are dumb", "just increase block size and you will have truly p2p electronic cash", "It is just that simple, there are no trade offs", "if you don't agree with me you are a BTC maxi", "BCH is satoshi's vision for p2p electronic cash"
It is not exclusive to crypto but also politics, and you see this over and over again on twitter and on reddit.
My point is, that narratives are created so people don't have to think, they just choose a narrative that is easy to follow and makes sense for them, and stick with it. And people keep repeating these narratives to bring other people in, maybe by ignorance, because they truly believe it without questioning, or maybe by self interest, because they want to shill you their bags.
Because this is BCH community, and because bitcoin is censored, so I can't post there about the problems in the BTC narrative (some of which are IMO correctly identified by BCH community), I will stick with the narrative I see in the BCH community.
The culprit of this post was firstly this post by user u/scotty321 "The BTC Paradox: “A 1 MB blocksize enables poor people to run their own node!” “Okay, then what?” “Poor people won’t be able to use the network!”". You will see many posts of this kind being made by u/Egon_1 also. Then you have also this comment in that thread by u/fuck_____________1 saying that people that want to run their own nodes are retarded and that there is no reason to want to do that. "Just trust block explorer websites". And the post and comment were highly upvoted. Really? You really think that there is no problem in having just a few nodes on the network? And that the only thing that secures the network are miners?
As stated by user u/co1nsurf3r in that thread:
While I don't think that everybody needs to run a node, a full node does publish blocks it considers valid to other nodes. This does not amount to much if you only consider a single node in the network, but many "honest" full nodes in the network will reduce the probability of a valid block being withheld from the network by a collusion of "hostile" node operators.
But surely this will not get attention here, and will be downvoted by those people that promote the narrative that there is no trade off in increasing the blocksize and the people that don't see it are retarded or are btc maxis.
The only narrative I stick to and have been for many years now is that cryptocurrency takes power from the government and gives power to the individual, so you are not restricted to your economy as you can participate in the global economy. There is also the narrative of banking the bankless, which I hope will come true, but it is not a use case we are seeing right now.
Some people would argue that removing power from gov's is a bad thing, but you can't deny the fact that gov's can't control crypto (at least we would want them not to).
But, if you really want the individuals to remain in control of their money and transact with anyone in the world, the network needs to be very resistant to any kind of attacks. How can you have p2p electronic cash if your network just has a handful couple of nodes and the chinese gov can locate them and just block communication to them? I'm not saying that this is BCH case, I'm just refuting the fact that there is no value in running your own node. If you are relying on block explorers, the gov can just block the communication to the block explorer websites. Then what? Who will you trust to get chain information? The nodes needs to be decentralized so if you take one node down, many more can appear so it is hard to censor and you don't have few points of failure.
Right now BTC is focusing on that use case of being difficult to censor. But with that comes the problem that is very expensive to transact on the network, which breaks the purpose of anyone being able to participate. Obviously I do think that is also a major problem, and lightning network is awful right now and probably still years away of being usable, if it ever will. The best solution is up for debate, but thinking that you just have to increase the blocksize and there is no trade off is just naive or misleading. BCH is doing a good thing in trying to come with a solution that is inclusive and promotes cheap and fast transactions, but also don't forget centralization is a major concern and nothing to just shrug off.
Saying that "a 1 MB blocksize enables poor people to run their own" and that because of that "Poor people won’t be able to use the network" is a misrepresentation designed to promote a narrative. Because 1MB is not to allow "poor" people to run their node, it is to facilitate as many people to run a node to promote decentralization and avoid censorship.
Also an elephant in the room that you will not see being discussed in either BTC or BCH communities is that mining pools are heavily centralized. And I'm not talking about miners being mostly in china, but also that big pools control a lot of hashing power both in BTC and BCH, and that is terrible for the purpose of crypto.
Other projects are trying to solve that. Will they be successful? I don't know, I hope so, because I don't buy into any narrative. There are many challenges and I want to see crypto succeed as a whole. As always guys, DYOR and always question if you are not blindly following a narrative. I'm sure I will be called BTC maxi but maybe some people will find value in this. Don't trust guys that are always posting silly "gocha's" against the other "tribe".
EDIT: User u/ShadowOfHarbringer has pointed me to some threads that this has been discussed in the past and I will just put my take on them here for visibility, as I will be using this thread as a reference in future discussions I engage:
When there was only 2 nodes in the network, adding a third node increased redundancy and resiliency of the network as a whole in a significant way. When there is thousands of nodes in the network, adding yet another node only marginally increase the redundancy and resiliency of the network. So the question then becomes a matter of personal judgement of how much that added redundancy and resiliency is worth. For the absolutist, it is absolutely worth it and everyone on this planet should do their part.
What is the magical number of nodes that makes it counterproductive to add new nodes? Did he do any math? Does BCH achieve this holy grail safe number of nodes? Guess what, nobody knows at what number of nodes is starts to be marginally irrelevant to add new nodes. Even BTC today could still not have enough nodes to be safe. If you can't know for sure that you are safe, it is better to try to be safer than sorry. Thousands of nodes is still not enough, as I said, it is much cheaper to run a full node as it is to mine. If it costs millions in hash power to do a 51% attack on the block generation it means nothing if it costs less than $10k to run more nodes than there are in total in the network and cause havoc and slowing people from using the network. Or using bot farms to DDoS the 1000s of nodes in the network. Not all attacks are monetarily motivated. When you have governments with billions of dollars at their disposal and something that could threat their power they could do anything they could to stop people from using it, and the cheapest it is to do so the better
You should run a full node if you're a big business with e.g. >$100k/month in volume, or if you run a service that requires high fraud resistance and validation certainty for payments sent your way (e.g. an exchange). For most other users of Bitcoin, there's no good reason to run a full node unless you reel like it.
Shouldn't individuals benefit from fraud resistance too? Why just businesses?
Personally, I think it's a good idea to make sure that people can easily run a full node because they feel like it, and that it's desirable to keep full node resource requirements reasonable for an enthusiast/hobbyist whenever possible. This might seem to be at odds with the concept of making a worldwide digital cash system in which all transactions are validated by everybody, but after having done the math and some of the code myself, I believe that we should be able to have our cake and eat it too.
This is recurrent argument, but also no math provided, "just trust me I did the math"
The biggest reason individuals may want to run their own node is to increase their privacy. SPV wallets rely on others (nodes or ElectronX servers) who may learn their addresses.
It is a reason and valid one but not the biggest reason
If you do it for fun and experimental it good. If you do it for extra privacy it's ok. If you do it to help the network don't. You are just slowing down miners and exchanges.
Yes it will slow down the network, but that shows how people just don't get the the trade off they are doing
I will just copy/paste what Satoshi Nakamoto said in his own words. "The current system where every user is a network node is not the intended configuration for large scale. That would be like every Usenet user runs their own NNTP server."
Another "it is all or nothing argument" and quoting satoshi to try and prove their point. Just because every user doesn't need to be also a full node doesn't mean that there aren't serious risks for having few nodes
For this to have any importance in practice, all of the miners, all of the exchanges, all of the explorers and all of the economic nodes should go rogue all at once. Collude to change consensus. If you have a node you can detect this. It doesn't do much, because such a scenario is impossible in practice.
Not true because as I said, you can DDoS the current nodes or run more malicious nodes than that there currently are, because is cheap to do so
Non-mining nodes don't contribute to adding data to the blockchain ledger, but they do play a part in propagating transactions that aren't yet in blocks (the mempool). Bitcoin client implementations can have different validations for transactions they see outside of blocks and transactions they see inside of blocks; this allows for "soft forks" to add new types of transactions without completely breaking older clients (while a transaction is in the mempool, a node receiving a transaction that's a new/unknown type could drop it as not a valid transaction (not propagate it to its peers), but if that same transaction ends up in a block and that node receives the block, they accept the block (and the transaction in it) as valid (and therefore don't get left behind on the blockchain and become a fork). The participation in the mempool is a sort of "herd immunity" protection for the network, and it was a key talking point for the "User Activated Soft Fork" (UASF) around the time the Segregated Witness feature was trying to be added in. If a certain percentage of nodes updated their software to not propagate certain types of transactions (or not communicate with certain types of nodes), then they can control what gets into a block (someone wanting to get that sort of transaction into a block would need to communicate directly to a mining node, or communicate only through nodes that weren't blocking that sort of transaction) if a certain threshold of nodes adheres to those same validation rules. It's less specific than the influence on the blockchain data that mining nodes have, but it's definitely not nothing.
The first reasonable comment in that thread but is deep down there with only 1 upvote
The addition of non-mining nodes does not add to the efficiency of the network, but actually takes away from it because of the latency issue.
That is true and is actually a trade off you are making, sacrificing security to have scalability
The addition of non-mining nodes has little to no effect on security, since you only need to destroy mining ones to take down the network
It is true that if you destroy mining nodes you take down the network from producing new blocks (temporarily), even if you have a lot of non mining nodes. But, it still better than if you take down the mining nodes who are also the only full nodes. If the miners are not the only full nodes, at least you still have full nodes with the blockchain data so new miners can download it and join. If all the miners are also the full nodes and you take them down, where will you get all the past blockchain data to start mining again? Just pray that the miners that were taken down come back online at some point in the future?
The real limiting factor is ISP's: Imagine a situation where one service provider defrauds 4000 different nodes. Did the excessive amount of nodes help at all, when they have all been defrauded by the same service provider? If there are only 30 ISP's in the world, how many nodes do we REALLY need?
You cant defraud if the connection is encrypted. Use TOR for example, it is hard for ISP's to know what you are doing.
Satoshi specifically said in the white paper that after a certain point, number of nodes needed plateaus, meaning after a certain point, adding more nodes is actually counterintuitive, which we also demonstrated. (the latency issue). So, we have adequately demonstrated why running non-mining nodes does not add additional value or security to the network.
Again, what is the number of nodes that makes it counterproductive? Did he do any math?
There's also the matter of economically significant nodes and the role they play in consensus. Sure, nobody cares about your average joe's "full node" where he is "keeping his own ledger to keep the miners honest", as it has no significance to the economy and the miners couldn't give a damn about it. However, if say some major exchanges got together to protest a miner activated fork, they would have some protest power against that fork because many people use their service. Of course, there still needs to be miners running on said "protest fork" to keep the chain running, but miners do follow the money and if they got caught mining a fork that none of the major exchanges were trading, they could be coaxed over to said "protest fork".
In consensus, what matters about nodes is only the number, economical power of the node doesn't mean nothing, the protocol doesn't see the net worth of the individual or organization running that node.
Running a full node that is not mining and not involved is spending or receiving payments is of very little use. It helps to make sure network traffic is broadcast, and is another copy of the blockchain, but that is all (and is probably not needed in a healthy coin with many other nodes)
He gets it right (broadcasting transaction and keeping a copy of the blockchain) but he dismisses the importance of it
submitted by r0bo7 to btc [link] [comments]

The Best Cryptocurrency Mining Pools in 2020

This review is not sponsored! Neither it is an ad.
How to choose a mining pool? How to avoid stale shares? The pros and cons of different services.

What is a cryptocurrency mining pool?

A “mining pool" is a server that distributes the task of calculating the block signature between all connected participants. The contribution of each of them is evaluated using the so-called “shares”, which are potential candidates for receiving a signature. As soon as one of the “shares” hits the target, the pool announces the readiness of the block and distributes the reward.
However, if you participate in the pool, then you will have to share the profit with all the participants in the pool, but for the majority, this usually is the most profitable option.

Which pool is better for mining?

The best mining pools should meet the following criteria:

Key selection criteria

To select a good pool for each specific cryptocurrency, you need to carefully study all the information available about it on its website and on the forums.
To reduce the number of stale shares, it is better to mine on the pool closest to the miner. You can choose the fastest mining pool by studying the information about the processing speed of the share in the mining program or by pinging the time it takes for the signal to pass from the miner's computer to the servers of the pool.

10 most popular and powerful pools: Description


Commission: 3%, lifetime discount: 1%


Commission: 0%. There is a donation option: 0.5% of the income


Coins: ETH, ETC, ZEC
Commission: 1%


Coins: BTC, LTC, and many other coins
Commission: 3-5%


Coins: XMR, ETH, ETC, SiaCoin, ZEC, PASC, ETN

Mining Pool Hub

Commission: 0.9%


Commission: 2-5%


Commission: 1-1.5%

Monero Mining Pool

Coins: XMR
Commission: 2%


Commission: 0.5-1%

Independent Pool Statistics

To make sure that the pools work and really exist, check independent sources. These are:
Keep up with the news of the crypto world at Follow us on Twitter and Medium. Subscribe to our YouTube channel. Join our Telegram channel. For any inquiries mail us at [[email protected]](mailto:[email protected]).
submitted by CoinjoyAssistant to dogemining [link] [comments]


Leon Li founded Huobi in 2013, a former computer engineer at Oracle. Huobi Global is a digital asset and crypto currency exchange headquartered in Singapore. Huobi also has local exchanges in South Korea, Japan, and through its strategic partner, the United States.
The Huobi Group, the parent company of Huobi Global, has received venture capital finance from prominent Beijing based ZhenFund and American VC firm Sequoia Capital.
The Huobi Global exchange serves traders in 130 countries. Through Huobi Global, traders can access almost 200 crypto and stable coin assets. Huobi users can download trading clients on both mobile and desktop devices.
Huobi has traded over US$1.2 trillion in digital assets, and at one time it was the world’s leading exchange by volume, capturing 50% of all global trading volume.
In terms of security, Huobi has adopted a decentralized exchange structure, which helps to resist DDOS attacks. However, Huobi has implemented the ‘Huobi Security Reserve, in which Huobi has set aside 20,000 BTC reserved for users who have lost funds either due to hacks, or exchange failures.
Ease of use
The UI is clean, user-friendly and perfectly designed with all the basic requirements for a crypto-trader. The charting software is provided by Tradingview, which is exactly what you want.
Huobi OTC
Huobi’s OTC exchange is a good initiative. The Huobi OTC exchange allows users to trade funds peer-to-peer which doesn’t affect the market price of the underlying asset. The OTC trading-desk, with transfer options like bank-transfers, PayPal, WU, Paytm, UPI, IMPS, Alipay & many others, is an easy to use payment gateway. With a secure exchange to diversify your investment, right next door, too with effective list of Buy and Sell options for BTC, ETH, USDT and EOS coins.
Huobi Lite
Huobi Lite App provides a convenient channel for everyone to buy cryptocurrencies at the best prices. Tailor-made for beginners, traders, and users.
We can download the App directly from the respective iOS Store or Google Play Store. Alternatively, we may access via the link:
On Huobi Lite, you can buy Bitcoin with your local currencies, credit card, or exchange cryptocurrencies tokens, with zero fees at competitive prices. Huobi Lite currently supports MYR / HKD / VND / USD (Credit Card deposit only), with more to come in the future.
Huobi Derivative Market (Huobi DM)
Margin Trading
Huobi Global launched Huobi Derivative Market (Huobi DM) exchange to selected countries. It provides margin trading, with very low daily loan interest rates of 0.1%. Margin Trading allows users to increase their investment exposure given a limited base principal to enjoy multiple returns.
3-Steps taken in Margin Trading:
  1. Request for Loan
  2. Trade on Margin (Long/Short)
  3. Repay Margin Loan and Interest
With the introduction of Cross Margin on Huobi, users will have to explicitly input the respective margin type before executing the above 3 steps. Balances on the Cross Margin balance does not show on the Isolated Margin balance.
Huobi Futures
Huobi Futures is a kind of digital currency derivatives. Users can make a profit from the rising/falling of digital currencies prices by going long or selling short based on their own judgment.
The Huobi Futures Contract adopts spread delivery. When the contract expires, all open positions will be closed at the index-based last-hour arithmetic average price, instead of physical delivery.
BTC/ETH/EOS/LTC/XRP/BCH/TRX/BSV/ETC Contracts are available on Huobi DM. Contracts are priced in USD, with corresponding digital currency (BTC/ETH/EOS/LTC/XRP/BCH/TRX respectively) as margin to open positions, and PnL is also settled in corresponding digital currency.
Weekly, bi-weekly and quarterly contracts are available in Huobi DM. Weekly contracts will be settled on imminent Friday; Bi-weekly contracts will be settled on next Friday; Quarterly contracts will be settled on the last Friday of March, June, September and December.
Choices of leverage: 1x, 5x, 10x, 20x
Huobi Perpetual Swap
Huobi introduced Perpetual Swaps on March 27, 2020 (GMT+8). Huobi Perpetual swap is a kind of digital currency derivatives. Users can make a profit from the rising/falling of digital currencies prices by going long or selling short based on their own judgment. Similar to a margin spot market, its price is close to the price of the underlying reference index. The main mechanism for anchoring spot prices is the cost of funds. Perpetual swap have no delivery date. Users can always hold it. Perpetual swap are settled every 8 hours. After each settlement, the realized profit/loss and unrealized profits/losses are transferred to the user account balance.
Partial Liquidation
Huobi Futures adopted partial liquidation to help position holders reduce liquidation risk. Users with large positions and high leverage bear high risk. Huobi Futures releases partial liquidation with the aim to lower possible losses due to high price volatility thus giving users better trading experience.
Under partial liquidation mechanism, when liquidation is triggered, instead of liquidating all positions at once, the system reduces positions gradually till a grade whose margin ratio is great than 0. Full liquidation will only occur when the margin ratio of tier 1 upper limit net position still fails to be great than 0.
Trading Fees
The Huobi exchange has a fair trading fee structure. Every asset traded via Huobi Global is subject to a 0.2% trade fee, for both market makers and takers. Further, Huobi Global has introduced a tiered fee system which offers competitively lower fees for high volume traders. VIP membership gives access to various fee reductions and other benefits.
Huobi Prime
Huobi Prime, the Launchpad platform which we can call Direct Premium Offering (DPO), does share some similarities with initial exchange offerings (IEO) like Binance Launchpad, but it is unique as it is not a fundraising platform, and any coins purchased on the platform are immediately deposited into the users’ wallets and tradable on Huobi Global. Huobi Prime offers its users early access to the coins of premium projects, which can be bought using its native crypto currency, the Huobi Token. To avoid dumping, Huobi has implemented an innovative idea of a period of tiered price limits.
Huobi FastTrack
Huobit FastTrack, rebranded from Huobi Prime Lite, is a new listing model. Wherein, all participants will have a direct say in what projects are listed on Huobi Global and when. In addition, winning voters will get access to quality tokens at below market rates. The program also provides much needed exposure and a straightforward listing process.
Huobi Wallet
Huobi Wallet is the official mobile wallet of Huobi Group, a leading global digital asset financial service provider. It is a multi-chain asset management tool that provides native support for various types of blockchains and all of the ERC20 tokens. So far Huobi Wallet supports BTC, BCH, LTC, ETH, ETC, USDT and all ERC20 tokens.
Huobi wallet is the first wallet to expand support to cover seven stablecoins including, Paxos Standard Token (PAX), TrueUSD (TUSD), USD Coin (USDC), Gemini Dollar (GUSD), Dai (DAI), Stasis EURS (EURS), and Tether (USDT).
Huobi Wallet is built based on the core principle of security-first. The wallet gives back its users, complete control of their private keys. In simple terms, You own your assets. The wallet is backed up with mnemonics, so in future when you want to import your wallet, it’s just simple few clicks.
Currently, the wallet is compatible with both iOS and Android devices and you can download both from here (
Huobi Chain
Huobi launched Huobi Chain’s Testnet (“the Testnet”) on February 29th 2020 (GMT+8). Huobi Chain is China’s autonomous cum compliant-ready blockchain platform, and is committed to providing a global, blockchain-based, digital asset infrastructure. Huobi Chain is committed to providing a high-performance, blockchain-based, global digital asset infrastructure. Once the Mainnet goes live, Huobi Chain will announce HT- related events: e.g. pledge HT to be a Super Node, etc.
HT Lock & Mine (Huobi Pool)
Huobi launched HT Lock and Mine operations on 25th July 2019 (GMT+8). Users who lock HT tokens receive daily HPT rewards. Specific reward quantity will depend on lock option period selected, quantity locked and Huobi Pool’ s mining hash power and daily float.
DPOS Rewards: All Huobi Global users with more than 1,000HPT holdings in their HBG account will receive DPOS mining rewards. Currently, token reward received under DPOS mining include EOS, TRX, CMT, ONG, IOST, ATOM, IRIS, LAMB。
Huobi Support
Users of the Huobi exchange can access 24/7 live chat and Huobi help center. Those facing issues can also open a support ticket to have their issue resolved by an expert representative immediately.
The Huobi Group has a very active YouTube channel, featuring Huobi Talk, where it posts user tutorials, detailed guides, and crypto currency information for traders.
What I like the most about Huobi
  1. An established platform that’s been operating since 2013, which is a long time in the crypto world.
  2. Highly secured with decentralized exchange structure, which helps to resist DDOS attacks. Huobi has never suffered a large hack.
  3. Huobi Security Reserve of 20000 BTC to compensate users’ loss of funds.
  4. Dedicated, fast and 24/7 customer support.
  5. Regulated in major jurisdictions.
  6. User interface is very smooth and clean.
  7. Over 230 crypto assets are available.
  8. User education program is good initiative.
  9. Separate trading desk for institution and firm size users.
  10. Very transparent about its operations, listings and projects.
  11. Huobi Wallet is secured and very easy to operate.
  12. Huobi mobile app is smooth and very easy to use.
  13. Competitive fees.
  14. Has taken serious steps towards avoiding wash trading.
  15. Impressive array of trading pairs.
  16. Has given more important on community participation, like voting for listing, mining pool, Huobi Knights program etc.
  17. I like Huobi Prime because of following reasons: -
(a) Purchased tokens are immediately deposited into user’s accounts,
(b) As projects launch exclusively through Huobi Prime from day one, all users get assets at the best price.
(c) Tiered price limits on the platform protect both investors and projects from immediate dump.
  1. Huobi screen projects and launches which are only the best. I don’t have to worry about poor or scammy projects.
  2. Burning of HT is a great move and it would benefit long term holders.
Join Huobi by click here:
Huobi Global:
Join Indian Group:
Global telegram Channel:
Join Huobi by click here:
submitted by VinayTM to HuobiGlobal [link] [comments]

I found a $600k BCH theft that has gone unnoticed

Hello all, I'm (among other things) a graduate student getting a master's degree in cybersecurity. This last quarter for one of my classes, I was tasked to examine and recreate an exploit. For the actual exploit I was examining the "anyone can spend" segwit addresses on the BCH chain, and in my research I found a $600k theft that seems to have gone completely unnoticed.
You all might recall this $600k theft of segwit addresses, but it happened again in mid-February 2018 and there has been zero news about it.
BCH block 517171 contains solely segwit-stealing transactions. If you look at any given transaction, the inputs are all segwit program hashes spending a P2SH segwit output. I only caught it by accident, as I was originally going to talk about the publicized November attack.
The interesting thing I discovered about this was that it's harder to have stolen that segwit money than most people think. Both Unlimited and ABC nodes do not relay segwit-spending transactions, and Bitcoin ABC hard-coded in fRequireStandard, so you couldn't even force-relay them with a conf option. On top of that, miners keep their node IPs private for obvious avoiding-ddos-and-sybil-attack reasons, which means it's impossible to directly send transactions to miners. This means that the only way to actually execute this attack was to setup one's own mining pool running on a custom-modified client to allow non-standard transactions. Then you'd have to get enough hash power to mine a block yourself. I estimated the cost of renting enough hash power to do this at the time as around $30k-$60k to have a greater than 90% chance of mining a block within a 3 month window.
In order to simulate the attack, I spun up BTC, LTC, and BCH nodes in Docker, and wrote a Python script. The Python script started at segwit activation on BTC and LTC and it scanned every transaction in every block looking for P2SH segwit inputs as well as native segwit outputs, since these are the necessary hash pre-images to spend P2SH segwit money on the BCH chain. The script then also scanned the BCH chain for any native segwit outputs, as well as recording all P2SH outputs. (This was all saved in a MySQL database.) Then, at any point in time, I could simply query for BCH unspent native segwit outputs as well as P2SH outputs for which I had a known segwit hash pre-image. (If this was an attack I was doing real-time, I would probably also have a large mempool on each node and monitor unconfirmed tx's for useful info as well, but since this was after the fact, I just queried blocks sequentially.)
For the mining node that runs the pool, it would need to be firewalled behind (i.e. only connected to) an unmodified node in blocks-only mode, so that the segwit hash pre-images aren't transmitted out to the network, and so that no other unconfirmed transactions are transmitted in to the mining node. (The mining node should only be filling its block with segwit tx's in order to maximize the gain from the attack.)
Then a script should run continuously to grab segwit utxos from the MySQL database and construct high-fee transactions to send directly to the mining node. Unlike the November attack, each input should be spent in its own individual transaction, so that in the event it is individually spent, I don't negate a tx with other inputs. The overhead on having different transactions for each input is only about 8 extra bytes (the tx version and the locktime), so I think this is a good trade-off.
Then, the attacker simply rents hashing power and points it at his secret pool.
By the time February rolled around and the attack happened, my MySQL database had about 40 million BCH P2SH outputs and each query took about 3 minutes to execute. This of course would have been fine in the 10-minute block world of Bitcoin and BCH, but it means that I stopped my Python script after that time, so I don't know about any possible other attacks that happened before the clean stack rule was hard-forked into BCH.
It was pretty interesting to work through how this attack must have happened, and it was significantly harder to execute than I thought it would be given that all the money was "anyone can spend".
However, the most interesting thing about all this is that nobody has noticed. There is literally no news or mention of block 517171 or any of the transactions in it. My theory is that it is money that nobody misses -- i.e. misprogrammed custom wallet software for BTC nodes accidentally also sent out BCH transactions to the same address, given that BTC and BCH shared the same history until August 2017. And whatever person or entity is running those nodes is only thinking about BTC money and is completely oblivious to its misprogrammed problem of shipping BCH to segwit P2SH addresses.
Obviously, that's just a theory, but I think it's pretty reasonable. Given the intense community divide, I think it's very possible that a number of BTC users simply ignored money on the BCH chain, even though it's "free money" for them, simply out of ideological hatred.
Whatever the case, nobody has posted anywhere complaining of money stolen in that block. It seems to have gone completely unnoticed. (Which is why I'm posting this.) It was an interesting case study and I'd be curious to hear if anybody has any addition information or thoughts about it. I believe this was a different person than the November theft, because the way it was done was different -- the November theft had all the money in one transaction, but this February theft was done with separate individual transactions. Additionally worth noting is that the address which received the bulk of the money is still active, which means they're still out there.
Anyway, I thought this was interesting and worth posting.
submitted by exmachinalibertas to btc [link] [comments]

Huobi Exchange Review

Huobi was founded in 2013 by their current CEO and chairman, Leon Li. Li’s background includes having attended Tshingua University, specializing in Automation. Before starting the Huobi Group, Li spent time as a computer engineer at Oracle. In December of 2013, Huobi was named as the largest digital asset exchange operating in China. 2017 saw Huobi extend their limbs into Korea, Singapore, and Japan.
Currently, Huobi has headquarters of various financial sectors based in: Singapore; South Korea; Japan; Australia; Indonesia; Russia; Argentina; Thailand; and China. The company has strived to give customers not only a great exchange, but a great resource for any service one may need. Despite the many difficulties faced with Chinese government in regards to cryptocurrency laws, Huobi has managed to adapt to the changes and thrive globally, eventually branching off into various sectors including venture capital, a cryptocurrency wallet project, and a division dedicated to working with mining pools.

spot trading : Huobi offers several different platforms to serve any customer’s needs. For starters, Huobi offers a standard spot trading platform that operates similarly to many other spot trading platforms in the industry. The platform features a multi-timeframe chart, a depth chart, and integration with TradingView (including their tools). Customers are able to view the order book and the asset trading history, as well as their own personal order history. Limit orders, Market orders, and Stop-Limit orders are all available options for traders.
margin trading : For the trader that prefers to trade with a little more volume or risk, Huobi offers a Margin trading platform. Customers can apply for loans through Huobi to trade a greater quantity of cryptocurrencies and profit from the price spread. The original loan must be paid back, and accounts can be liquidated if the risk ratio falls below 110% (calculated as: [(Loaned Amount + Tradable Balance) Total Asset] / [(Interest Payable + Loaned Amount)] x 100%.) Traders can margin trade with Bitcoin; Ethereum; XRP; Litecoin; Bitcoin Cash; and EOS. These assets can be traded with USDT or BTC.
futures trading : Huobi also offers a Futures trading platform. While margin trading can be risky, trading contracts is said to be very high-risk. With that being said, Huobi offers Weekly, Bi-Weekly, and Quarterly contracts in Bitcoin; Ethereum Classic; Ethereum; EOS; Litecoin; Bitcoin Cash; XRP; TRX; and Bitcoin SV.
OTC(P2P) - The OTC, or over-the-counter, section of Huobi offers potential buyers and sellers a way to move large quantities of coins without exposure to the fickle exchange market. Certified merchants can register here, and slippage can be minimized by matching buyers and sellers directly instead of creating market orders.

While you do have the online trading interface, Huobi does have computer programs and mobile apps that you can use.
I found that the PC programmes were more functional as they did not have to rely on the PC browser and were hence much faster. They also have better charting and you are in more control of your trading parameters. These programs are available on Windows and Mac devices.
However, if you are a trader that is always on the go, that is where the Huobi mobile apps come in. These were developed for the main exchange but you can switch to the derivative markets on the futures and swaps platform.
This was a pretty well designed application and you have one-touch ordering as well as some basic charting functionality. The app is available in iOS and Android and you can head on over to the respective app stores to get a sense of the feedback.

Huobi operates a hot and cold wallet storage procedure. This means that they keep the vast amount of their coin holdings in an offline environment away from hackers. They then have a smaller percentage in “hot” wallets with multisig capability.
They also operate a decentralized server structure around the world which can ensure uptime irrespective of whether one of the servers goes down. You can think of this as effective load balancing.
Finally, they have anti DDoS measures in place. We all know that crypto exchanges are prime targets for Denial of Service attacks and it can be quite frustrating when these are perpetrated in peak market times.

Huobi, like many exchanges in the space, has had, at one time, some shady history, but for the most part, has managed to maintain a clean reputation. Historically, Chinese exchanges have shown to operate in accordance with different standards, with many exchanges having to suffer at the will and whim of the Chinese government. Some of the controversy Huobi has seen in the past has been a result of this (particularly with the Chinese ban on ICO tokens). It should be noted that in 2017, the exchange did invest into “wealth-management products” using idle customer funds. This sort of activity shouldn’t be taken lightly.
However, with that being said, the exchange continues to turn over a large amount of volume. For the most part, the exchange can be considered a trustworthy platform to trade popular and exotic cryptocurrencies. This does not mean it is entirely safe to store user funds on the exchange, as the exchange (or the user funds) can be susceptible to risk at any given moment. No matter how comfortable one may be with the internet, one should always remember that the internet is not as safe as many would like to believe. Huobi does have measures in place in the unfortunate event that an account is breached, and if verifiable, the customer may be able to retrieve lost funds.
A unique feature offered on Huobi is their Official Media Authenticator. This essentially lets users enter the URL of a content channel to see if the channel is authentic. A feature like this, while seemingly simple, could save anyone from potentially losing their funds due to a scam or phishing website.

Huobi Global offers a signficant host of features to its users and has maintained its credibility over a long period of time. This is largely one of the main reasons it a ranked as a top 4 exchange by liquidity as its users trust their funds there.
After establishing itself in Asia, Huobi is trying to branch out and take on other areas of the globe which is great news for Western traders. Additionally, the Huobi prime platform could provide some great opportunities for the exchange users moving forward.

Huobi Website:
Huobi Indian Community:
Huobi Global Community:
submitted by chamithasro to u/chamithasro [link] [comments]

