Live data from Hacker News

If you don't own your OS, you don't own your BTC

combatnerd.com

21–30 of 64 posts

Re: If you don't own your OS, you don't own your BTC

#21

Earlier quoted context omitted.

> At least with Linux we have thousands of open source developers keeping an eye on things A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it? Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.

Yes, they worked pretty well for OpenSSL. The issue was found eventually. In a proprietary system, it may have been there forever.

It was not found by general developers doing security audits, it was found by a security company doing fuzzing attacks against SSL libraries.

And not to mention that Windows - the explicitly called out alternative from this article - makes their source available for security companies (as well as general developers who sign up for their MSDN program).

Re: If you don't own your OS, you don't own your BTC

#22
1) "... am sure you entered the password into some input field, which means that you have handed your password over to your Operating System"

...

2) "The easiest way to get started is to install Linux in a Virtual Machine and get yourself familiar with the system."

Therefore, enter your password into an input field, in a virtual machine inside your proprietary Operating System key logging you?

Re: If you don't own your OS, you don't own your BTC

#24

The real question is: why he is not using an Hardware Wallet? A ledger wallet is cheap enough if you get worried about your BTC being in an unsafe device. Yes, then you have to trust the company selling it for you, but isn't that the whole business to not compromise their own devices?

Even if he would have somebody would mention, 'yeah but if you did not make the hardware yourself, you dont own your BTC'

I guess at least :)

Re: If you don't own your OS, you don't own your BTC

#25
post #3

Earlier quoted context omitted.

ElementaryOS's repos were hacked a while back. The trojaned images didn't stay up long, but it illustrates your point. (Not singling out ElementaryOS... any software with a repo or updater could be trojanized, including software from big companies.)

I wonder what percentile of users have suffered financial harm on Windows versus Linux do to system insecurities. I have zero data on this, but history would imply Windows is far less safe.

Windows is targeted more (not exclusively, however), due to its popularity. If everyone moved over to Linux for the "security benefits", Linux would be targeted just as heavily.

Both Linux and Mac users have been hit with ransomware.

Re: If you don't own your OS, you don't own your BTC

#26
post #19

I am torn on this article. If I read it through my developer lens, I’m not impressed - this cranks up the paranoia to a near useless level and the panacea offered is really a false hope. But, when I look at it through a more compassionate lens, I worry about this individual’s health. Hey writer, if you’re reading this and you need someone to talk to, my email is on my profile. Have a happy 2020.

To me, your offer of "help" reads like a thinly disguised attack / insult. I guess we all know about the "humblebrag", this is "backhanded empathy". Or something.

The author is not saying anything that is not true. Given everything that happened and was disclosed in the past decade, I don't think one has to be paranoid to be deeply suspicious of black box software controlled by big tech.

Re: If you don't own your OS, you don't own your BTC

#27
This is also an issue for Android and iOS. And some of the newer cryptocurrencies are more or less restricted to those platforms.

And with smartphones, adversaries can access the OS using StingRay etc.

Edit: I should have said "devices like StingRays". Perhaps StingRays can only track, and maybe see traffic. But the baseband is poorly secured, and has privileged access.

Re: If you don't own your OS, you don't own your BTC

#28

Earlier quoted context omitted.

Yes, they worked pretty well for OpenSSL. The issue was found eventually. In a proprietary system, it may have been there forever.

You're discounting the risk that, because it's open source, everyone assumes that someone else has done the security analysis. That is precisely what happened with OpenSSL--everyone assumed, since it's a big open source package, that somebody was keeping on top of this sort of issue, but nobody was. That there have been two major OpenSSL security fumbles (first was the Debian OpenSSL fiasco, second Heartbleed) sort o…

How's that different to MS Windows, we assume the code is good, but some of the errors/oversights that crop up beggar belief.

Re: If you don't own your OS, you don't own your BTC

#30

The better question is why does he not build his own OS. He could build his own OS and make his own computer parts with his own tools and machinery and nobody would ever be able to access his BTC ever again. He would probably need to invent his own internet though.

That's the beauty of the open protocols: you can make anything talk HTTPS over TCP/IP.

This, of course, is quite an academic worry in comparison to the gargantuan quest "bootstrap yourself from raw materials to a computer...and don't make any mistakes along the way."

Post reply on HN