Live data from Hacker News

“My PGP key is compromised, and at least many of my bitcoins stolen”

twitter.com

261–270 of 564 posts

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#261
post #24

I've never been a fan of crypto (despite holding some for diversification), but I think some tweaks could be made to make it safer and more reasonable without comprising what its proponents like about the system. Crypto prtocols need a way to reverse transactions if the original address as well as some quorum of elected "supervisory overseers" agree [1] to it within a week or so. There should also be a mechanism to m…

Since nobody has offered a response, I'll offer my 2c. Your suggestion flies in the face of what Bitcoin and other cryptocurrencies that operate according to the same principles were designed to be (trustless, some degree of anonymous) and it would make the system ripe for abuse (more than it already is). What if Luke Jr is lying and he spent those bitcoins in return for goods and services? Suddenly you have to estab…

Thanks for the response! I appreciate it much more than the downvotes, and it gives me a position to consider.

I still find myself in disagreement - there need to be safeguards at the protocol level, and not just for ordinary people.

Escrow and restitution could be built as a feature where trustless and anonymous transactions can still take place. Taking into account my previous post, imagine this setup:

There are now two types of wallets/addresses. One type functions exactly as Bitcoin does today. The other type, however, automatically subjects transactions to temporally-gated restitution systems and allows you to recover funds if a side channel refund request is made.

Funds in the original Bitcoin wallet type experience transactions that are instant and non-refundable, and you can keep "hot" funds here. The "cold" wallet type requires more time to pass before the funds "settle". It can function as your bank and offer lots of additional security.

It'd be easy to make the wallet type an identifiable part of the address so that all parties know what types of transactions they're involved in.

This extension to the protocol could be 100% opt-in.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#262

Context now that the editorialised title has changed, this is a core Bitcoin developer. These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion)

Exactly! if the experts can’t secure their accounts, what hope does anyone else have? Soon you will see people saying you should have done this or that complicated thing, or how somebody so smart could should have known better. No matter what they say it is never enough. This is why lack of consumer protections suck.

Experts are also bigger targets and face more risks than ordinary people.

Like in the non-crypto world, banks are the experts on storing money securely, but people still try and rob banks despite ordinary people being much easier targets.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#263

Update: https://twitter.com/naka_frodo/status/1609655813789949959/ph... Looks like possibly a supply chain attack targeted specifically at Luke Jr's server.

He put info connected to 3.6m BTC onto a colo crossing server? Jikes

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#265
post #167

Earlier quoted context omitted.

Yes, but implementation errors-- not fundamental flaws in the theory or underlying mathematics. It's not a statement about such things being impossible, just unlikely to come from a single individual working in complete isolation up until the bitcion whitepaper release. Additionally this alone would be merely peculiar on it's own, coupled with the lack of retrospective investigations uncovering -anything at all- sign…

You're placing way more value on this than makes sense: Bitcoin makes use of good primitives, but no better than any expected familiar with the SoTA in the late 2000s would have selected for a greenfield project. Maybe the most unusual primitive selection in Bitcoin is secp256k1 for ECDSA, instead of one of the more common NIST curves. But even that is understandable, given that Nakamoto was active in the cypherpunk…

The primitive selection looks rather informed with the hindsight of NSA compromising the security of NIST curves

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#266

Context now that the editorialised title has changed, this is a core Bitcoin developer. These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion)

> These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion) Because no one can create secure software yet, Bitcoin isn't 100% secure.

This has nothing to do with the security of Bitcoin. No one has ever compromised the Bitcoin protocol.

This is a case of someone expecting a single machine connected to the internet that had been compromised in the past, to not be compromised again.

Very little software has rigorous security review, even the Linux kernel. Linux Odays sell for $50-100k. If you are storing anything more valuable than that on an internet connected Linux machine, it will eventually be stolen.

Use an offline machine or a hardware wallet for anything that matters to you.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#267

Earlier quoted context omitted.

That's why hardware based security is really the only way at this point. He might be a bitcoin core Dev but does he use ledger/trezor etc? Is his PGP key on his hardrive or a smartcard? In this day and age your computer not a bastion it once was. (It never really was but it's more of a problem in 2022 than 1982).

When someone writes: > Soon you will see people saying you should have done this or that complicated thing and you answer: > Is his PGP key on his hardrive or a smartcard? you're proving their point.

But is it a reasonable point?

I would assume that if you are a major player in the bitcoin world, you should do complicated things to secure yourself.

Its sort of like if someone wins the lottery, and tells the world they are putting the money under their mattress in their home. Its not unreasonable to say that such a person faces more risk than an ordinary person and should install an alarm system or something.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#268

Earlier quoted context omitted.

If the level is millions of dollars, that device could be physically stolen, or some aspect of the cryptography/auth scheme could be attacked through a 0-day. Of course, it's also possible he just wanted something closer to the convenience of a bank account/credit card instead of a pile of cash and failed in the opsec.

That’s why you don’t store millions of dollars in your physical location. You break up the seed and disperse it among several bank lock boxes. (See https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing) . Keep a small amount in a hot wallet for convenience and a larger amount (but not too large) in a cold wallet accessed via hardware. But the bulk shouldn’t be accessible without breaking into at least two lock vaul…

I just love the idea of going around creating accounts at multiple different banks for storing of parts of the key.

Then, when you're finally ready to access you funds, creating appointments at all those different banks, driving to them all, and then finding out enough of the keys are completely missing that you now cannot access any of your funds:

https://www.nytimes.com/2019/07/19/business/safe-deposit-box...

Or... you know... you could just store your funds in one or more bank accounts.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#269

Context now that the editorialised title has changed, this is a core Bitcoin developer. These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion)

Looks like possibly a supply chain attack targeted specifically at Luke Jr's server: https://twitter.com/naka_frodo/status/1609655813789949959/ph...

Let's see:

1) he thinks that "dedicated servers" are in any way secure

2) discovers malicious intrusion, but doesn't burn down the whole server and re-key everything

3) is supposed to be knowledgable enough to be a core Bitcoin developer but stays on a "dedicated server" after finding malicious intrusion.

This is highly suspect. Either you have stuff that's not worth much, and therefore you don't pay to physically colocate your own server, or at very least you don't pay enough to get a server from a smaller company where you're dealing with real humans with names and reputations... Or you're storing things that really matter, have a large value, or likely both, and you'd pay extra to get better things.

What kind of hubris would lead to continuing to use a compromised server, particularly when the compromise appears to have come from the hosting provider?

Perhaps we need to wait for more information, but from what I've seen so far, there's something not right here.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#270

Earlier quoted context omitted.

That’s why you don’t store millions of dollars in your physical location. You break up the seed and disperse it among several bank lock boxes. (See https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing) . Keep a small amount in a hot wallet for convenience and a larger amount (but not too large) in a cold wallet accessed via hardware. But the bulk shouldn’t be accessible without breaking into at least two lock vaul…

Shamirs still requires having the (single) private key present for signing. Multisig is far superior for Bitcoin security. The keys can remain geographically separate at all times. Each signing operation requires only the partially signed transaction (PSBT) and the other public keys.

Non-issue if you only use the key once, then do a new split each time. Plenty of tooling exists to make this easily in reach with a simple shell script.
Post reply on HN