Earlier quoted context omitted.
An important difference being that nobody ever expected users to use the x86 instruction set directly. Whereas the very clear initial expectation for Bitcoin was that it was an actual currency used for transactions by end users.
On what part of the stack exactly? Are they crafting RPC requests to a BTC node manually? Using wallet software? Using more advanced wallet software with social recovery features and named addresses? I think you may be forgetting, earlier users of computers were using punchcards ..
Crypto.com accounts had unauthorized withdrawals
311–320 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#312Earlier quoted context omitted.
People who are not criminals deserve transaction privacy, as well.
What would be the point of "transaction privacy"?
There are plenty of examples of that: https://github.com/jlopp/physical-bitcoin-attacks
Re: Crypto.com accounts had unauthorized withdrawals
#313Earlier quoted context omitted.
How is it different from “TOR/some VPN is a legitimate service that happens to be used by some hackers to cover their tracks”?
How many legitimate uses can you name for TOR? And how many can you name for a money laundering service?
Re: Crypto.com accounts had unauthorized withdrawals
#314Earlier quoted context omitted.
> and I'm pretty confident being a locally popular trading commodity amongst edge communities is not the central goal for bitcoin Given the transaction fees needed for a distributed-enough network, and the bureaucracy needed when trading, it is not very useful as a currency, at least not for small payments, excluding Lightning. So it's a commodity.
Excluding lightning and layer 2 solutions like rollups. Why would you make those exclusions though?
Re: Crypto.com accounts had unauthorized withdrawals
#315Earlier quoted context omitted.
No, that's normal pyramid scam behavior. I would say it was more likely that they were fraudulent if they were escalating their meaningless promo gestures to keep anybody from cracking as their scam gets too big to keep together. The bigger the risk, the bigger the colorful gesture. I'm imagining it as '$700 million IN CRYPTO, which is of course better than money'. For a name: which could easily be restored if it tur…
Even your basic Ponzi schemes often involved generous and public philanthropic gifts even as the scheme was falling apart behind the scenes, just to maintain the public image.
When it's designed from the start to be an expanding shell powered by new belief coming in, the philanthropy and big gestures are core to the nature of what it is.
Back in the day I read an old book by Harvey Mackay (iirc), one of those business-guy self-help books, and he had a chapter called never buy anything big in a room where there is a chandelier. :D The point being, it's normal for scamsters to influence people by making their pitch in a place all decked out to look like the most wealthy, influential place you could imagine, and there'd be a chandelier because it would look like everybody was rich. And so, never buy anything big in a room with a chandelier, because it probably meant you were being ripped off.
All this predates crypto by a loooooong way. There's nothing really new. Maybe back in the days of travelling traders on camels it was, never buy a camel in a room with a carpet that's bigger than the camel is :)
Re: Crypto.com accounts had unauthorized withdrawals
#316Re: Crypto.com accounts had unauthorized withdrawals
#317Re: Crypto.com accounts had unauthorized withdrawals
#318Earlier quoted context omitted.
How many legitimate uses can you name for TOR? And how many can you name for a money laundering service?
If you don't need financial privacy can you please post your bank statement here for everyone to see?
But I'm on record as being in favor of full financial transparency for everybody. Every charge, every bank statement. Money, after all, is inherently social. And full transparency, while causing some problems, would eliminate a ton of others. So if you can get a legislator to submit a bill, I'll happy call them up to back it.
Re: Crypto.com accounts had unauthorized withdrawals
#319This is why CRO requires 24 hours whitelist before you can transact withdrawals...
Re: Crypto.com accounts had unauthorized withdrawals
#320Earlier quoted context omitted.
I do a bit of the same and this seems to be a silly thing to communicate as part of a security audit. Ok, step 1 SMB insurance company paying me to audit - by not being in Afghanistan, you have a severely reduced risk of business invasion and extortion. Seems like a really wonky way to communicate a risk profile and first-exposure to security professionals by a SMB. Plenty of SMBs with janky POS systems get pretty na…
I'm advising people at the executive level. They do not care about the details of hashing PII, they want to know how likely it is that they will be targeted and how likely that attack is to succeed. And the fact is that an insurance company gets targeted far less often than crypto companies.
If you're auditing startup insurance fintechs in that case, the PII they have and platform exposure to all the APIs they are pulling from or pushing too (a) looks a lot like a crypto company spanning web2/web3, and (b) puts them square in the target of software supply chain hacks. An attacker cares about , but they do care about attacking the Equifax API that the insurance startup has an integration with. Excluding the crypto companies that do their own custody or run their own smart contracts, their risk profile and why ends up looking a lot like the fintech insurance startup haha.