Live data from Hacker News

“My PGP key is compromised, and at least many of my bitcoins stolen”

twitter.com

221–230 of 564 posts

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#221

Earlier quoted context omitted.

1. Disable JavaScript. 2. Access (almost) any website in the internet 3. ????? 4. Profit edit: Mastodon doesn't work without JavaScript, holy hell. We truly are living in a dystopia. Thankfully you can still access his profile from another trusted instance such as mastodon.social at https://mastodon.social/@lukedashjr@bitcoinhackers.org

I always have JavaScript disabled by default (uMatrix policy), but (0) there's many other attack vectors, to my layman understanding, and (1) at any rate that one's a Mastodon instance and those are blank pages without JS. I'm electing to add new URL regexps to my uBlock filters, to reduce the risk of accidentally clicking a link similar to this. I don't think I want to visit any web domain that caters to people who…

> one's a Mastodon instance and those are blank pages without JS

Not all of them. Those still running Mastodon v3.5 (rather than v4.0) seem to work fine.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#222

Earlier quoted context omitted.

If the level is millions of dollars, that device could be physically stolen, or some aspect of the cryptography/auth scheme could be attacked through a 0-day. Of course, it's also possible he just wanted something closer to the convenience of a bank account/credit card instead of a pile of cash and failed in the opsec.

That’s why you don’t store millions of dollars in your physical location. You break up the seed and disperse it among several bank lock boxes. (See https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing) . Keep a small amount in a hot wallet for convenience and a larger amount (but not too large) in a cold wallet accessed via hardware. But the bulk shouldn’t be accessible without breaking into at least two lock vaul…

Shamirs still requires having the (single) private key present for signing.

Multisig is far superior for Bitcoin security. The keys can remain geographically separate at all times. Each signing operation requires only the partially signed transaction (PSBT) and the other public keys.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#223

Context now that the editorialised title has changed, this is a core Bitcoin developer. These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion)

Exactly! if the experts can’t secure their accounts, what hope does anyone else have? Soon you will see people saying you should have done this or that complicated thing, or how somebody so smart could should have known better. No matter what they say it is never enough. This is why lack of consumer protections suck.

Give someone enough incentive and they will hack you.

Internet security is 99% "nobody gives enough damn to do it".

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#224

Earlier quoted context omitted.

Why just two lock vaults and not some army bunkers, together with the nuclear codes preferably? At some point this level of care becomes more than absurd.

> makes up hypothetical situations > attacks his own hypothetical situations

[flagged]

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#225
post #175

Earlier quoted context omitted.

Bitcoin isn’t anonymous. The transfers of coins are there permanently for all to see.

Satoshi is (so far)

Satoshi got away, which is a very different phenomenon from Bitcoin as a protocol being anonymous.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#226

Earlier quoted context omitted.

If a Bitcoin Developer with >$3M in Bitcoin didn’t use a hardware wallet… God help the typical Bitcoin user. It’s a tragedy, and inexcusable.

fraud and reconciliation are fundamental in our finance systems. To claim this as anything other than a failing of bitcoin as a whole is "inexcusable".

[deleted]

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#227

Earlier quoted context omitted.

This is ridiculously ahistorical: the early Bitcoin releases had all kinds of bugs in them[1], and there was a reasonably large enthusiast community looking at it for years before widespread adoption. The US government doesn't need to burn coal to fund the clandestine services. They just put it in a budget line item whose contents are classified. [1]: https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposu...

FWIW the GP didn’t say US; there are many more intel orgs and govs desperate for money than the US.

Sure; I'm curious which intelligence organization you (or the GP) think is most likely, then.

Keep in mind that (1) most intelligence organizations and clandestine services operate with even less oversight than the US's, and (2) all available evidence points to Satoshi Nakamoto being an L1 English speaker who was mostly active in Western European timezones.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#228
post #139

Earlier quoted context omitted.

The experts told NASA not to launch, and exactly why, and were right. Management chose not to listen.

[flagged]

Why are you tone-policing someone for pointing out that a given example is not supporting the actual theory?

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#229
post #188
post #88

Earlier quoted context omitted.

Gavin Andresen, a lead Bitcoin developer, sent me a 10 BTC donation ($3000 at the time) when he meant to send $10 worth of BTC. Yes, I refunded. https://news.ycombinator.com/item?id=14720921

Great example of how "Bitcoin is trustless" means "Bitcoin only works is the trust is provided externally".

It's not just Goodness of heart. This case can fall under existing laws. You are not allowed to keep obvious transfer mistakes like these.
Post reply on HN