Live data from Hacker News

Researchers cracked an 11-year-old password to a $3M crypto wallet

wired.com

21–30 of 196 posts

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#21
post #18

Earlier quoted context omitted.

No it doesn't. What kind of an excuse is that? When a password manager maker finds a vulnerability they should absolutely tell their users to regenerate their passwords!

didn't the vendor fix it?

They are supposed to disclose the vulnerability after fixing it, so their users know they need to take action. That's what the original commenter rightly complained about.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#22
post #7

Time for a new investment strategy that involves buying whatever (index funds?) then losing your password to force a hold till the encryption algo has been cracked or compute power makes it easy to brute-force. Call it the Moore’s Law Fund.

This is already how bitcoin mining works. Compute is used to calculate partial hash collisions via brute force. The number of bits required in the collision adjusts dynamically based on the duration of the last 2016 blocks. If you're the first to find a valid collision for the next block, you get 3.125 BTC.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#23
"Michael... now has 30 BTC, now worth $3 million, and is waiting for the value to rise to $100,000 per coin."

What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#24
post #3

> Michael says he was lucky that he lost the password years ago because, otherwise, he would have sold off the bitcoin when it was worth $40,000 a coin and missed out on a greater fortune. This is so true for stocks too

Yes but stocks are usually tied to a business producing some sort of service that people want, and therefore have value. Crypto is tied to, checks notes nothing.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#25
post #22
post #7

Time for a new investment strategy that involves buying whatever (index funds?) then losing your password to force a hold till the encryption algo has been cracked or compute power makes it easy to brute-force. Call it the Moore’s Law Fund.

This is already how bitcoin mining works. Compute is used to calculate partial hash collisions via brute force. The number of bits required in the collision adjusts dynamically based on the duration of the last 2016 blocks. If you're the first to find a valid collision for the next block, you get 3.125 BTC.

Less fun with a 10 minute lockup till the next block

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#26

"Michael... now has 30 BTC, now worth $3 million, and is waiting for the value to rise to $100,000 per coin." What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.

How do you know he isn’t hedged?

NOT keeping it in Bitcoin is some next-level stupidity, by the simple analysis of trends over the time he’s held it.

And the inflation produced by the creation of broad money over the last 3 years hasn’t even come home to roost, yet.

I’d say he’s being ruthlessly analytical, not greedy.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#27
post #5

The original video by Joe Grand: https://youtu.be/o5IySpAkThg

Highly recommended, didn't think I'd watch the whole thing but the production quality was great and it explains everything much better than the wired article.

After your reco after the GP's reco, I would have to agree. This is well done. However, coming from a coding/dev background, it was easy to follow and it all makes sense.

However, it goes to show why hacking will never be made interesting in movies without a bunch of fake nonsense like hacking the Gibson's 3D virtual environment.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#28
post #13

So Roboform has almost certainly thousands (of not millions) of users with weak passwords, and not only didn't they tell anyone, all they give is a shrug when asked about it. What a bunch of bozos.

Because the vast majority of ppl who use it will not be storing millions of dollars of crypto with it. Crypto changes the game totally.

Crypto doesn’t change the game. Products that generate passwords should do so securely.

You may be using it to protect extremely sensitive information that could have people killed - that’s more important than a few million dollars in imaginary money

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#29
post #6

So the version of password manager he was using was vulnerable because it was generating low entropy passwords. They also found the seed was from time and knew when he had created it. He got lucky there a little.

> He got lucky there a little.

Who is he in that sentence? Do you mean the owner of the wallet who is absouletly very lucky, or the hackers that did a lot of investigating and reverse engineering to learn that the datetime was the seed. Was that luck or l337skillz?

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#30
post #13

So Roboform has almost certainly thousands (of not millions) of users with weak passwords, and not only didn't they tell anyone, all they give is a shrug when asked about it. What a bunch of bozos.

I mean how weak are they really? These guys knew the algo and still struggled and pestered the user over and over for the other parameters. They also had what I would describe as an extreme motivation to crack this.
Post reply on HN