Live data from Hacker News

Researchers cracked an 11-year-old password to a $3M crypto wallet

wired.com

41–50 of 196 posts

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#41
post #13

So Roboform has almost certainly thousands (of not millions) of users with weak passwords, and not only didn't they tell anyone, all they give is a shrug when asked about it. What a bunch of bozos.

Because the vast majority of ppl who use it will not be storing millions of dollars of crypto with it. Crypto changes the game totally.

People have bank passwords, social media accounts (which can be used in all sorts of nefarious ways), etc. Some may be 2FA protected, some may not be. Some may be protected by bad faux-2FA.

Just because there aren't million at stake doesn't mean you can't bring someone to ruin.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#42
post #30
post #13

So Roboform has almost certainly thousands (of not millions) of users with weak passwords, and not only didn't they tell anyone, all they give is a shrug when asked about it. What a bunch of bozos.

I mean how weak are they really? These guys knew the algo and still struggled and pestered the user over and over for the other parameters. They also had what I would describe as an extreme motivation to crack this.

Hard to say without details; but now that the weakness is known it may become a lot easier. It's one thing if you think it may work if you have the correct parameters but aren't sure, and quite another if you know it will work.

Password managers are kind of a "defence in depth" thing; practical speaking, a passwords.txt opened with notepad is probably fine for many people. No one is in your computer checking your files. You have a password manager for when that does happen, just in case. And usually this tends to be a targetted attack, which can range from some country's secret service to a jealous spouse to a trolling sibling. If that extra protection is ineffective ... yeah, that's not great.

This really is "better safe than sorry" type territory. Password managers (including Roboform) already do this by notifying users a password may be insecure after a leak. A lot of the time that's not really needed if your password is sufficiently secure, but "better safe than sorry". This is not all that different.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#43
post #6

So the version of password manager he was using was vulnerable because it was generating low entropy passwords. They also found the seed was from time and knew when he had created it. He got lucky there a little.

> He got lucky there a little. Who is he in that sentence? Do you mean the owner of the wallet who is absouletly very lucky, or the hackers that did a lot of investigating and reverse engineering to learn that the datetime was the seed. Was that luck or l337skillz?

I’m going to guess it’s the same “he” from the sentence that came immediately before the one you quoted

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#44
post #6

So the version of password manager he was using was vulnerable because it was generating low entropy passwords. They also found the seed was from time and knew when he had created it. He got lucky there a little.

> He got lucky there a little. Who is he in that sentence? Do you mean the owner of the wallet who is absouletly very lucky, or the hackers that did a lot of investigating and reverse engineering to learn that the datetime was the seed. Was that luck or l337skillz?

Seems like they all were lucky that he luckily used a vulnerable password manager and knew the approximate parameters and time it was created. If he didn't get lucky, they might not have been paid.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#45
post #33

Earlier quoted context omitted.

I’m no shill for crypto, but you can’t with a straight face claim that all non-crypto financial instruments are ‘tied to … some sort of service that people want’. There’s a whole world of shady crap going on in the ‘legitimate’ financial space.

Oh absolutely. Money is the root of all evil. But crypto bros are often delusional about what intrinsical value exists in the normal market, compared to crypto coins where they invent the value. Therefore manipulation of value compared to real world markets becomes a lot more abstract.

The original saying is:

"For the love of money is the root of all evil: ..." -- 1 Timothy, 6:10

It's not the money that is evil, it is the things we do because of the desire we have for it.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#46

"Michael... now has 30 BTC, now worth $3 million, and is waiting for the value to rise to $100,000 per coin." What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.

FYI he's not gambling the bitcoin, he's holding onto it, and given it's history, which is the sub-story, it seems to be the smart thing to do not the risky/ dumb thing to do, especially in the current stage of the cycle.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#47

Earlier quoted context omitted.

Highly recommended, didn't think I'd watch the whole thing but the production quality was great and it explains everything much better than the wired article.

After your reco after the GP's reco, I would have to agree. This is well done. However, coming from a coding/dev background, it was easy to follow and it all makes sense. However, it goes to show why hacking will never be made interesting in movies without a bunch of fake nonsense like hacking the Gibson's 3D virtual environment.

The best and worst examples were in the same movie, IMO: Nedry's finger-wagging admonishment and all hell breaking loose, then later, "it's a Unix system, I know this!" and some exotic file manager visualization.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#48

Earlier quoted context omitted.

Oh absolutely. Money is the root of all evil. But crypto bros are often delusional about what intrinsical value exists in the normal market, compared to crypto coins where they invent the value. Therefore manipulation of value compared to real world markets becomes a lot more abstract.

The original saying is: "For the love of money is the root of all evil: ..." -- 1 Timothy, 6:10 It's not the money that is evil, it is the things we do because of the desire we have for it.

Yep, greed.

Further correction though, it actually says “the love of money is the root of all kinds of evil.”

If you really go down the rabbit hole, pride is probably the root of all evil. It’s certainly the root of greed.

Re: Researchers cracked an 11-year-old password to a $3M crypto wallet

#50

Earlier quoted context omitted.

After your reco after the GP's reco, I would have to agree. This is well done. However, coming from a coding/dev background, it was easy to follow and it all makes sense. However, it goes to show why hacking will never be made interesting in movies without a bunch of fake nonsense like hacking the Gibson's 3D virtual environment.

The best and worst examples were in the same movie, IMO: Nedry's finger-wagging admonishment and all hell breaking loose, then later, "it's a Unix system, I know this!" and some exotic file manager visualization.

Mr Robot has some decent hacking scenes. At least they put up prompt windows with commands that are generic enough to not be hackTheGibson.exe type lame.
Post reply on HN