Live data from Hacker News

French police free kidnapped Ledger executive

moneycheck.com

101–110 of 154 posts

Re: French police free kidnapped Ledger executive

#101

I've been thinking for a while that the current security methodology for wallets is not great. YES, that statement is extremely obvious on the face of it. But, I mean, think of some of the basic measures people take. This hardware wallet crap, okay great, your keys are kept somewhere safe and there's offline signing, but so what? Boop the users head until they give up the wallet. H4xt funds. We should be able to desi…

Many or all of these already exist- look up smart contract wallets.

...and they wouldn't have helped in this case, see other comment about that.

Re: French police free kidnapped Ledger executive

#102

I've been thinking for a while that the current security methodology for wallets is not great. YES, that statement is extremely obvious on the face of it. But, I mean, think of some of the basic measures people take. This hardware wallet crap, okay great, your keys are kept somewhere safe and there's offline signing, but so what? Boop the users head until they give up the wallet. H4xt funds. We should be able to desi…

hardware wallets are a safe transaction signing device NOT a seed storage device

You use them to sign transactions that are perfectly safe even if your computer / phone where you initiated the transaction is infected with malware. They give you a chance to confirm that the transaction you're signingon the hw wallet is the one you initiated on your computer.

> daily spend limit

> different panic codes

> Co-signing by third-parties

What you describe already exists in "software multisig wallets" on smart contract blockchains. In essence they're smart contracts that require n of m signatures to initiate a transaction and can handle variable spending rules, custom signing schemes, 3rd party signers, things like 2FA / email for signing. In theory they can be implemented for non-smart contract blockchains like Bitcoin using multi party computation schemes like FROST (https://github.com/ZcashFoundation/frost) but that's a lot harder

Re: French police free kidnapped Ledger executive

#103
post #61

I remember a while back seeing a story from SE Asia about cops finding a guy walking along the road clutching a bleeding hand. Turned out thieves had robbed him off his car, which had a fingerprint reader so they'd taken a finger with the car. Found the article: https://www.theregister.com/2005/04/04/fingerprint_merc_chop...

That's why I never use biometric autentication. After seing movies where the bad guys took the guy's eye to do a retina scan, you can imagine.

Re: French police free kidnapped Ledger executive

#104
post #41

Earlier quoted context omitted.

Or you overestimate how many competent psychos are out there scheming to do anything to make money. Doing a kidnapping and getting a ransom is probably not too hard, but being on the run forever afterwards might not be worth it to most. People with money can hire their own bounty hunters/or plain criminals to go after them afterwards. Or just announce a bounty high enough (in dark channels, your high profile security…

But there’s already a decent chunk of people committing organized violent crime. Cartels set up their own shadow cellphone networks and run submarines. Maybe there are just easier crimes that pay better with a lower risk profile

Like what, Russian and NK ransomware? Of course the perpetrators need to we physically in those countries, which is unattractive. Everywhere else the'll get caught.

Re: French police free kidnapped Ledger executive

#105

Earlier quoted context omitted.

Exactly, and ip address does not give precise location (unless a third company, the ISP, is also compromised).

I've long dreamed about having "anonymous" internet through coaxial/DOCSIS because the modems should work anywhere on the same node (or maybe even beyond) as long as your connection point is physically connected. I could put down any name and nearby(ish) address I want...

Upstream is shared by less subscribers than downstream. Usually in the same neighborhood. So, it is easy to spot a wider place and then put boots on the ground to do the rest.

Any of widely used VPNs is much more generalized. Chain two or more in case of real concern.

Re: French police free kidnapped Ledger executive

#106

How does the government of France decide whether your kidnapping is worth sending military tactical teams to rescue you?

Probably as much as possible. Those are expensive teams to maintain and deploiment is probably not much compared to it. If you are cynical you could see it as just training for an important case.

Re: French police free kidnapped Ledger executive

#107
post #104

Earlier quoted context omitted.

But there’s already a decent chunk of people committing organized violent crime. Cartels set up their own shadow cellphone networks and run submarines. Maybe there are just easier crimes that pay better with a lower risk profile

Like what, Russian and NK ransomware? Of course the perpetrators need to we physically in those countries, which is unattractive. Everywhere else the'll get caught.

[deleted]

Re: French police free kidnapped Ledger executive

#108
post #41

Earlier quoted context omitted.

Or you overestimate how many competent psychos are out there scheming to do anything to make money. Doing a kidnapping and getting a ransom is probably not too hard, but being on the run forever afterwards might not be worth it to most. People with money can hire their own bounty hunters/or plain criminals to go after them afterwards. Or just announce a bounty high enough (in dark channels, your high profile security…

But there’s already a decent chunk of people committing organized violent crime. Cartels set up their own shadow cellphone networks and run submarines. Maybe there are just easier crimes that pay better with a lower risk profile

"Cartels set up their own shadow cellphone networks and run submarines. Maybe there are just easier crimes that pay better with a lower risk profile"

Indeed, selling drugs is apparently easier. And I can imagine the cartels don't want to risk their daily buisness, by kidnapping the wrong person from the west, as that would mean more heat on their buisness. But they surely do kidnappings and worse. Mostly in their fight for local control as far as I know.

Re: French police free kidnapped Ledger executive

#109
post #28

Earlier quoted context omitted.

This isn't true at all. Ledger has not been a laughingstock of the cryptocurrency community. Their hardware wallet has survived multiple attacks that Trezor has not. It has the strongest security model and easiest to use interface of any cryptocurrency wallet intended for regular use.

This sounds a lot like a sales pitch by Ledger, is the next service you are going to sell me involving me sending my seed, online, to Ledger so it can be sent to 3 third parties... because that is what made so many people laugh at them last year. They can add as many layers of cryptographic schemes on this, it so antithetical to what you should do with a seed you want to secure that it ruined their reputation for a l…

Do you HAVE TO send your seed for backup? Do they use dark patterns to force you to upload your seed?

Do you realize some people value (probably wrongly in this case) convenience over absolute security?

There’s nothing wrong with offering additional options.

Re: French police free kidnapped Ledger executive

#110
post #28

Earlier quoted context omitted.

This isn't true at all. Ledger has not been a laughingstock of the cryptocurrency community. Their hardware wallet has survived multiple attacks that Trezor has not. It has the strongest security model and easiest to use interface of any cryptocurrency wallet intended for regular use.

This sounds a lot like a sales pitch by Ledger, is the next service you are going to sell me involving me sending my seed, online, to Ledger so it can be sent to 3 third parties... because that is what made so many people laugh at them last year. They can add as many layers of cryptographic schemes on this, it so antithetical to what you should do with a seed you want to secure that it ruined their reputation for a l…

I'm not familiar with the seed uploading incident. I'm just evaluating the device on how easy it is to compromise vs Trezor and competitors.
Post reply on HN