Live data from Hacker News

Exodus Bitcoin Wallet: $490k swindle

popey.com

171–180 of 297 posts

Re: Exodus Bitcoin Wallet: $490k swindle

#171
post #64

Earlier quoted context omitted.

Can you elaborate on this?

From a prior thread that didn’t get any constructive engagement: https://news.ycombinator.com/item?id=39205762 Essentially Ethereum can be used to codify financial contracts in order to provide a level of trust where one does not otherwise exist.

It doesn't. Let's take that comment.

> You could wire together a group of houses or neighborhoods with generators and batteries and make the electric company redundant by establishing contracts which buy and sell electricity between participants at rates which adjust in response to demand, forecast, and each battery’s reserves.

Who is this you, why would this group of houses trust you and not their established providers. And how will this group of houses verify that your contract even works (forget about "works correctly", start with just "works").

> Essentially Ethereum can be used to codify financial contracts in order to provide a level of trust where one does not otherwise exist.

No it can't. These are not contracts. These are programs written in esotheric programming languages that work only as long as there's a connection to the things they "manage". They are unenforceable, have significant issues with versioning and bugs (once deployed, its deployed forever), have no bearing on the physical world etc.

Re: Exodus Bitcoin Wallet: $490k swindle

#172
post #142

In which being your own bank continues to be undesirable. (Never understood why ‘be your own bank’ was meant to be at all appealing. Being a bank is terrible. And still realistically less risky than this sort of thing; apart from truly bizarre edge cases (see the Citi/Revlon drama), this sort of thing simply can’t happen.)

How is being a bank terrible? It's one of the most profitable businesses ever and continues to be.

… Wait, what? I mean, possibly if you’re a large investment bank , those can be quite profitable (until they’re abruptly not; see 2008). Retail banks (which the ‘be your own bank’ people are presumably referring to; if you want to be your own investment bank you can just skip the ‘bank’ bit) are generally not particularly profitable.

Re: Exodus Bitcoin Wallet: $490k swindle

#173
post #145

Earlier quoted context omitted.

> The base rule in crypto has always been “not your keys, not your coins” This is because blockchains have no way of enforcing laws, including property rights. Therefore it comes down to this. Imagine that whoever got hold of your car keys, automatically became the owner. This is what "not your keys, not your coins" means.

“Enforcing laws” with regard to what? Censoring transactions? Freezing accounts? If people want a system where this as well as excessive inflation are close to impossible, they now have an option, with the clear caveat of that ownership. It’s not like there aren’t other options to choose - custodial services and multi-signature wallets. Banks are custodial services too, and that’s fine.

> “Enforcing laws” with regard to what? Censoring transactions? Freezing accounts?

Fraud. Transaction rollbacks. Consumer protection laws.

Re: Exodus Bitcoin Wallet: $490k swindle

#174

It has been 10 years since I left Canonical (on good terms), but what popey describes (hi popey) about the intentional lack of human review in the Snap store sounds very Canonical to me. I agree with all the recommendations - add human gates. Yes, it's expensive, but still far cheaper than the unbounded reputational damage that just occurred around the untrustworthiness of the store (hi Amazon).

Hi Alex!

Re: Exodus Bitcoin Wallet: $490k swindle

#175
post #145

Earlier quoted context omitted.

No, this is usually (apologies if not in your case) a straw man, and representative of the usual HN blind spot for cryptocurrency. Ledger and Trezor hardware wallets do protect against this class of attack. We are rapidly approaching a world in which those with significant assets or job responsibilities should be carrying physical 2FA tokens, which can allow use of private keys while protecting them (a hardware walle…

> The base rule in crypto has always been “not your keys, not your coins” This is because blockchains have no way of enforcing laws, including property rights. Therefore it comes down to this. Imagine that whoever got hold of your car keys, automatically became the owner. This is what "not your keys, not your coins" means.

It's a bit more like 'possession is 9/10 of the law'.

The "not your keys, not your coins" is more the fact that someone else holding your stuff happen to them and your stuff goes away. Or they never had it to start with. i.e. Counterparty risk.

`Cash` doesn't inherently have any mechanism for enforcing rights either. The difference is that real-world identities are easier to establish in situations where cash transactions go awry.

Re: Exodus Bitcoin Wallet: $490k swindle

#176
post #156

The operational security measures one has to take these days to secure crypto is insane. You have to build your own mini intelligence agency just to protect your digital crypto assets. You have to do: - Principle of least privilege. - Zero Trust. - Compartmentation. - Hardened Operating Systems with no malware and strong endpoint defense. - Firewalls that whitelist only your IP and disavow everything else. - 2FA/MFA/…

If you just want to buy crypto currencies and check again in a few years, the procedure is much simpler: 1. Make a paper wallet, laminate it, put it in a safe location or maybe two 2. Use any exchange and send the coins to the wallet. Never leave any coins on the exchange When you want to get them out again, this is the safest approach: 1. Boot Tails from USB 2. Enter your private key in Electrum (it's preinstalled i…

This essentially boils down to not using Bitcoin. If Bitcoin ever wants to achieve its goal of becoming a usable currency, hiding pieces of paper in safes is not the way to go. But you can of course speculate that in a few years someone else is willing to pay more than you did to enjoy the fun of storing a piece of paper in a safe.

Re: Exodus Bitcoin Wallet: $490k swindle

#178

Earlier quoted context omitted.

If you just want to buy crypto currencies and check again in a few years, the procedure is much simpler: 1. Make a paper wallet, laminate it, put it in a safe location or maybe two 2. Use any exchange and send the coins to the wallet. Never leave any coins on the exchange When you want to get them out again, this is the safest approach: 1. Boot Tails from USB 2. Enter your private key in Electrum (it's preinstalled i…

This essentially boils down to not using Bitcoin. If Bitcoin ever wants to achieve its goal of becoming a usable currency, hiding pieces of paper in safes is not the way to go. But you can of course speculate that in a few years someone else is willing to pay more than you did to enjoy the fun of storing a piece of paper in a safe.

Use a hardware-wallet like the Bitbox2 for your big stash. Use a lightning wallet like phoenix on your phone for smaller amounts which you could loose, like in a physical wallet.

Re: Exodus Bitcoin Wallet: $490k swindle

#179
post #164

Earlier quoted context omitted.

Ok. I use Ledger. And I would not have thought of being suspicious of there being two addresses to confirm. So rather than being “wrong”, maybe I am more similar to most regular user of hardware wallets, and that this kind of attack would indeed be a disaster for a lot of users who have hardware wallets. Myself included.

But.... if you did confirm two addresses, wouldn't the second one be suspicious solely because... if you're confirming it... it means you actually did something besides click a button right? And if it wasnt an address you owned?

I would think one was the target address and the other was the change address.

And then if I went so far as to double check that the other address was a change address, I’d do so by looking in the list of addresses for my wallet in Electrum.

But in our scenario I am using a backdoored Electrum. And therefore it could be showing a mixture of the real addresses that belong to me in that list alongside addresses belonging to a different wallet that was set to show up there by whoever backdoored my copy of Electrum.

Re: Exodus Bitcoin Wallet: $490k swindle

#180

Canonical should not have displayed a "safe" icon at scam app page. The proper text should be something like "Not verified. Review the code and check the publisher before using the app.". The same should be at Google Play and Apple Store. Scam apps and sanctioned apps are regularly passing through reviews.

Or maybe just write "sandboxed" or "isolated" since it's actually what safe means here, not that the code is actually doing what it says.

maybe if icon-fonts shipped a sandbox with the poo emoji inside it would make it easier for lazy UX designers to communicate it.

amazing how little effort goes into UX these days.

Post reply on HN