Live data from Hacker News

If you don't own your OS, you don't own your BTC

combatnerd.com

11–20 of 64 posts

Re: If you don't own your OS, you don't own your BTC

#11
post #3
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

ElementaryOS's repos were hacked a while back. The trojaned images didn't stay up long, but it illustrates your point. (Not singling out ElementaryOS... any software with a repo or updater could be trojanized, including software from big companies.)

I wonder what percentile of users have suffered financial harm on Windows versus Linux do to system insecurities. I have zero data on this, but history would imply Windows is far less safe.

Re: If you don't own your OS, you don't own your BTC

#12
post #8

Earlier quoted context omitted.

Not to mention, you have to evaluate this in context. What would MS stand to lose if they actually did this? Far far more than whatever Bitcoin they'd be able to steal that much is certain. But in any case, if you care about security, you have a hardware wallet and store the seed somewhere secure.

It wouldn't have to be Microsoft exploiting this though, a few rogue employees that can modify their telemetry system could do this on their own. There is no external oversight for Windows but on Linux there are thousands of people looking at changes even if you aren't looking yourself.

Linux Desktop isn't just the kernel, there's a lot of stack to exploit between that and the user, and history has shown that "many eyes" doesn't stop security problems from getting through. Hell, sometimes package maintainers introduce problems themselves independent of the developers.

That isn't even counting the hardware stack underneath your kernel. What parts of your machine were manufactured in China? Is Intel IME trustworthy? What about all those firmware blobs?

Re: If you don't own your OS, you don't own your BTC

#13
The better question is why does he not build his own OS. He could build his own OS and make his own computer parts with his own tools and machinery and nobody would ever be able to access his BTC ever again.

He would probably need to invent his own internet though.

Re: If you don't own your OS, you don't own your BTC

#14
post #6

Earlier quoted context omitted.

We already know Windows has some pretty excessive telemetry, it is not unreasonable to assume this or other elements of the OS can be exploited to gain control of a wallet. At least with Linux we have thousands of open source developers keeping an eye on things, chances are much higher that an issue would be caught with Linux since Windows is closed source.

> At least with Linux we have thousands of open source developers keeping an eye on things A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it? Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.

Yes, they worked pretty well for OpenSSL. The issue was found eventually. In a proprietary system, it may have been there forever.

Re: If you don't own your OS, you don't own your BTC

#15
post #8

Earlier quoted context omitted.

Not to mention, you have to evaluate this in context. What would MS stand to lose if they actually did this? Far far more than whatever Bitcoin they'd be able to steal that much is certain. But in any case, if you care about security, you have a hardware wallet and store the seed somewhere secure.

It wouldn't have to be Microsoft exploiting this though, a few rogue employees that can modify their telemetry system could do this on their own. There is no external oversight for Windows but on Linux there are thousands of people looking at changes even if you aren't looking yourself.

There is no external oversight to ensure that the compiled binaries in the Elementary OS iso match the published Linux kernel code, either.

Re: If you don't own your OS, you don't own your BTC

#16

Earlier quoted context omitted.

> At least with Linux we have thousands of open source developers keeping an eye on things A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it? Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.

Yes, they worked pretty well for OpenSSL. The issue was found eventually. In a proprietary system, it may have been there forever.

You're discounting the risk that, because it's open source, everyone assumes that someone else has done the security analysis. That is precisely what happened with OpenSSL--everyone assumed, since it's a big open source package, that somebody was keeping on top of this sort of issue, but nobody was.

That there have been two major OpenSSL security fumbles (first was the Debian OpenSSL fiasco, second Heartbleed) sort of suggests that the value of "many eyes" for ensuring security is vastly overrated.

Re: If you don't own your OS, you don't own your BTC

#19
I am torn on this article. If I read it through my developer lens, I’m not impressed - this cranks up the paranoia to a near useless level and the panacea offered is really a false hope. But, when I look at it through a more compassionate lens, I worry about this individual’s health.

Hey writer, if you’re reading this and you need someone to talk to, my email is on my profile. Have a happy 2020.

Re: If you don't own your OS, you don't own your BTC

#20
post #3

Earlier quoted context omitted.

ElementaryOS's repos were hacked a while back. The trojaned images didn't stay up long, but it illustrates your point. (Not singling out ElementaryOS... any software with a repo or updater could be trojanized, including software from big companies.)

I wonder what percentile of users have suffered financial harm on Windows versus Linux do to system insecurities. I have zero data on this, but history would imply Windows is far less safe.

In practice I would say Apple =~ Linux However I think Linux's security is partly an artifact of a more techie user base. For a non-technical or too busy to be technical user I would say Apple offers the best security out of the box.
Post reply on HN