Live data from Hacker News

Exodus Bitcoin Wallet: $490k swindle

popey.com

31–40 of 297 posts

Re: Exodus Bitcoin Wallet: $490k swindle

#31
post #5

What I don't get about the Snap store is why there's no verified link back to a website? If you have the technical ability to create an app, you probably have the ability to upload something to /.well-known/ or to add a DNS TXT record. That way the Snap store could say "This app came from this website." OK, it doesn't help if someone goes to the trouble of registering a homograph address, but it would at least give n…

This assumes the user would actually pay attention to that. (spoiler: they won't)

> OK, it doesn't help if someone goes to the trouble of registering a homograph address

Doesn't even have to be homograph, it can just be something that has "exodus" in it (coming back to users not paying attention, this would work, and is also the reason phishing and other fake sites work), if "exodus-wallet.com" was verified then many people would still fall for it.

The entire thing would've been avoided if users paid attention and going to the official website instead of blindly trusting the Snap Store (and following VERY common advice, such as don't enter your secret phrase or password anywhere)

Re: Exodus Bitcoin Wallet: $490k swindle

#32
I'm still not exactly sure, to be honest, why Snap exists.

The desktop on Linux has gone Flatpak.

If I'm running a server, why the heck would I trust Snap, a platform that until recently didn't even let me control updates, over Docker? If something goes wrong, who do I call? If I need a custom storage arrangement, who do I call? If I need a custom network arrangement, who do I call? If I need to scale up, who do I call? Why would I subject myself to this?

Is it IoT? Maybe it has a market there - but why doesn't it focus on being the best it can be, solely for that market, then?

One more note: Snap even allowing unapproved repackaging of apps was, in my opinion, a very bad idea in the first place. Case in point: Even the Snap homepage is advertising a community repackage of a password manager ("NordPass" - developer not verified). Why the heck should Snap be proud of that?

(Edit: Apparently NordPass's website does point to it - but the developer remains unverified. What's the point of verification...)

Re: Exodus Bitcoin Wallet: $490k swindle

#33
post #5

What I don't get about the Snap store is why there's no verified link back to a website? If you have the technical ability to create an app, you probably have the ability to upload something to /.well-known/ or to add a DNS TXT record. That way the Snap store could say "This app came from this website." OK, it doesn't help if someone goes to the trouble of registering a homograph address, but it would at least give n…

DNS isn't quite as adversary resistant as the crypto space likes to have things.

I'm not sure what Bitcoiner's preference would be exactly, but I'm sure they've got something involving signed wallet hashes published on the chain.

The hard part, as with anywhere else, is getting users to check it.

Re: Exodus Bitcoin Wallet: $490k swindle

#34

This is scary and even a hardware wallet might not help. When I create a transaction with Electrum on my computer, I use a hardware wallet to sign the transaction. When I sign the transaction, the hardware wallet shows the amounts, and the output addresses. But if my copy of Electrum was backdoored and smart about what it did, it could use an output address for the remaining amount that went to another wallet. And si…

Reading this, it is bonkers to me that people think cryptocurrencies are ready or appropriate for mainstream use, either as a currency or as an investment.

Line could go up, but if you aren’t extremely careful with processes that most people don’t and won’t comprehend—and don’t even realize are something you need to do—you can just straight up lose everything.

Re: Exodus Bitcoin Wallet: $490k swindle

#35
Canonical should not have displayed a "safe" icon at scam app page. The proper text should be something like "Not verified. Review the code and check the publisher before using the app.".

The same should be at Google Play and Apple Store. Scam apps and sanctioned apps are regularly passing through reviews.

Re: Exodus Bitcoin Wallet: $490k swindle

#36
post #16

> They likely saw a button like this in the "App Centre", which gave them some confidence in the application. [...] Furthermore the title of the Snapcraft web frontend says "Snaps are containerised software packages that are simple to create and install. They auto-update and are safe to run." Sounds like assurances made by UX and Marketing, which engineering might've been able to tell them they can't make. If it ends…

However, the app is already installed on many other devices, and likely affected many others too.

Re: Exodus Bitcoin Wallet: $490k swindle

#37
post #13

Earlier quoted context omitted.

I don't know jack about crypto but surely we shouldn't expect a distro provider to be vetting financial instruments?

There was malware in the Snap store! This could've just as easily been a password manager and wiped out the guy's bank account.

There's malware everywhere

Re: Exodus Bitcoin Wallet: $490k swindle

#38
post #5

What I don't get about the Snap store is why there's no verified link back to a website? If you have the technical ability to create an app, you probably have the ability to upload something to /.well-known/ or to add a DNS TXT record. That way the Snap store could say "This app came from this website." OK, it doesn't help if someone goes to the trouble of registering a homograph address, but it would at least give n…

How would someone know what the right url to expect would be in this case? It's just moving the trust problem elsewhere.

Re: Exodus Bitcoin Wallet: $490k swindle

#39
post #5

What I don't get about the Snap store is why there's no verified link back to a website? If you have the technical ability to create an app, you probably have the ability to upload something to /.well-known/ or to add a DNS TXT record. That way the Snap store could say "This app came from this website." OK, it doesn't help if someone goes to the trouble of registering a homograph address, but it would at least give n…

I suppose the problem is that Canonical wants to make the Snap store the default place for users to get GUI programs, so they've been willing to take the risk of letting random community members maintain Snaps of popular software so the store looks more active.

Re: Exodus Bitcoin Wallet: $490k swindle

#40

This is scary and even a hardware wallet might not help. When I create a transaction with Electrum on my computer, I use a hardware wallet to sign the transaction. When I sign the transaction, the hardware wallet shows the amounts, and the output addresses. But if my copy of Electrum was backdoored and smart about what it did, it could use an output address for the remaining amount that went to another wallet. And si…

> if my copy of Electrum was backdoored

While it’s not foolproof, it’s a good reason to compile things yourself from source instead of using the binaries. Unless someone trusted is validating build reproducibility, but that isn’t as common as we’d all like.

Some 4y old discussion of how some OSs for electrum are built reproducibly: https://old.reddit.com/r/Bitcoin/comments/dcz0my/what_is_not...

Post reply on HN