Live data from Hacker News

“My PGP key is compromised, and at least many of my bitcoins stolen”

twitter.com

211–220 of 564 posts

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#211

Earlier quoted context omitted.

Why is that inconsistent? There’s a lot of people that believe governments only legit purpose is to protect people and their property.

In order for governments to do that the systems have to have a way for an authority to intervene and reverse the transaction... Which is expressly impossible to do without creating a fork of the chian... Which is pretty contrary to the ethos of the white papers for Bitcoin.

To recoup the loss possibly, but that’s not necessarily governments job. The governments job would be to investigate the theft in an attempt to charge a suspect(s) with a crime against another person.

If the property is replaceable by the charged parties then that could be used by the government as a consideration in plea bargaining or sentencing. But if it’s gone then hopefully the plaintiff purchased insurance on it.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#213
post #131

Earlier quoted context omitted.

Experts make mistakes all the time, fail to see hidden risks, like Challenger explosion. This will never see mainstream adoption at this rate. If the hacker is smarter, being smart is not good enough.

The only mistakes experts made in the Challenger explosion was failing to draw pretty a enough picture to convince barely numerate management to stop the launch.

[flagged]

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#214
post #167

Earlier quoted context omitted.

>math and code were nearly perfect with zero peer review Bitcoin had to be forked in the early years due to critical errors in the original code. There was nothing perfect about it.

Yes, but implementation errors-- not fundamental flaws in the theory or underlying mathematics. It's not a statement about such things being impossible, just unlikely to come from a single individual working in complete isolation up until the bitcion whitepaper release. Additionally this alone would be merely peculiar on it's own, coupled with the lack of retrospective investigations uncovering -anything at all- sign…

There's good evidence that Satoshi is Adam Back:

https://www.youtube.com/watch?v=XfcvX0P1b5g

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#215
post #129
post #35

I still think the reason Satoshi vanished is that he lost his private key and couldn't handle the embarrassment.

Almost right. He spilled two (!) beers on the paper he wrote his private key upon, and he died of embarrassment.

Now, what was the brand of beer he was having?

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#216

Earlier quoted context omitted.

Speaking of paranoid, that link you've posted, isn't that a link to a server that's known to be compromised, and also an apparent watering hole for crypto wallet holders? Am I unreasonable in thinking that's a very scary link?

1. Disable JavaScript. 2. Access (almost) any website in the internet 3. ????? 4. Profit edit: Mastodon doesn't work without JavaScript, holy hell. We truly are living in a dystopia. Thankfully you can still access his profile from another trusted instance such as mastodon.social at https://mastodon.social/@lukedashjr@bitcoinhackers.org

> https://mastodon.social/@lukedashjr@bitcoinhackers.org

This just redirects me back to https://bitcoinhackers.org/@lukedashjr>.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#217
post #165
post #13

Earlier quoted context omitted.

Storing most of his bitcoin in a single hot wallet seems to go against the best practices, no?

What is hot wallet, btw?

This is my personal view on the topic. I don't claim it strictly matches any "official" definition.

A "hot" wallet is a type of wallet that's typically stored in internal storage of a network-connected device, such as your personal computer or your smartphone. This is riskier way of storing funds because they can be exfiltrated by malware. You would typically use a hot wallet for day to day transactions.

A "cold" wallet is a type of wallet where private keys to control the funds are never in contact with a network-connected device. They're typically stored in the form of recovery phrases written on paper or metal (in a secure location), or some kind of a smart card that securely stores private keys and exposes an interface to sign individual transactions (e.g. Ledger devices). Funds stored in a cold wallet are much harder to access, but are extremely (or completely) resistant to theft, short of physical access.

In crypto a "hot" wallet should be treated as cash, while a "cold" wallet is more like a savings account.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#219
post #150

Earlier quoted context omitted.

Assuming this physical access claim is truthful (and i have doubts), I would feel at this point its budget letting him down. If your threat model includes "targeted attacks from people with physical access", it's time to run a vm on aws or azure and use the tooling they make available to secure it further. If you want tonnes of resourcing at a quite low budget, there's only a certain amount of "calling out" the group…

I believe most of these "physical attacks" are datacenter support teams being socially engineered and not state-level actors. They hook up a USB rescue drive to "help" you back into your server, using full disk encryption or locking down the BIOS can thwart such attacks.

You know as much as I'm generally unhappy with what MS is doing with forcing TPMs on Windows 11, I have to say Bitlocker on Windows is basically single click and a perfect solution, and I'm a bit disappointed in the scale of every comparable Linux guide I just Googled up. I can see why the average company doesn't have it deployed.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#220

Earlier quoted context omitted.

That’s why you don’t store millions of dollars in your physical location. You break up the seed and disperse it among several bank lock boxes. (See https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing) . Keep a small amount in a hot wallet for convenience and a larger amount (but not too large) in a cold wallet accessed via hardware. But the bulk shouldn’t be accessible without breaking into at least two lock vaul…

Why just two lock vaults and not some army bunkers, together with the nuclear codes preferably? At some point this level of care becomes more than absurd.

> makes up hypothetical situations

> attacks his own hypothetical situations

Post reply on HN