Live data from Hacker News

If you don't own your OS, you don't own your BTC

combatnerd.com

41–50 of 64 posts

Re: If you don't own your OS, you don't own your BTC

#41
post #20

Earlier quoted context omitted.

I wonder what percentile of users have suffered financial harm on Windows versus Linux do to system insecurities. I have zero data on this, but history would imply Windows is far less safe.

In practice I would say Apple =~ Linux However I think Linux's security is partly an artifact of a more techie user base. For a non-technical or too busy to be technical user I would say Apple offers the best security out of the box.

A file that sitting on Windows that's been encrypted with a piece of well-audited encryption software is pretty safe. And if you want to be really certain, don't keep the machine connected to the internet except for software updates, and never while you're accessing your encrypted BTC archive.

Re: If you don't own your OS, you don't own your BTC

#42

Earlier quoted context omitted.

I wonder what percentile of users have suffered financial harm on Windows versus Linux do to system insecurities. I have zero data on this, but history would imply Windows is far less safe.

Windows is targeted more (not exclusively, however), due to its popularity. If everyone moved over to Linux for the "security benefits", Linux would be targeted just as heavily. Both Linux and Mac users have been hit with ransomware.

The other factor is that the vast majority of Windows security administrators (i.e., random users) are incompetent.

In terms of the security of the operating system itself, Windows may well be more secure than Linux. Many Windows applications, however, are going to be much less secure than the OS--although it's not like Linux applications are stellar in this regard as well (e.g., Docker).

Re: If you don't own your OS, you don't own your BTC

#43

A number of comments in this thread strawmanning the OP's argument. The main point is simply that if you don't have complete legal control, in perpetuity, of the system that you are storing your cryptocurrency on, then if your license is cancelled by legal means, you may lose your data [1]. OP is not talking about whether FOSS or proprietary software has more bugs or has more chances of having backdoors. OP is not ta…

> if your license is cancelled by legal means, you may lose your data

Maybe I'm missing some legal nuance. But if the license is revoked, wouldn't you still be able to recover your Bitcoin using a FOSS OS? Especially if it is stored on a separate disk or partition from the OS.

Re: If you don't own your OS, you don't own your BTC

#44
I love FOSS, but there's a lot of problems with the arguments in this article.

>"it is highly recommended to run on Free and OpenSource Software...This way, you know exactly what is running on your system"

I get this feeling as well: that when I use FOSS I know exactly what my computer is doing.

But I don't. Linux is about 14 million lines of code, and that doesn't include your distro. You might be able to cut this down by compiling it yourself, but you'll still have to be an expert to understand everything that is happening on your computer.

It's the same thing with Windows, millions of lines of source code written by thousands of people.

I think that until you hear that someone lost their wallet key and MS was to blame, you're probably safe. Key theft (through keylogging) may be harder to detect on a closed-source OS, but there are still a lot of people (outside of MS) working on MS security and playing around with the OS to learn things about it.

That all being said, Linux is easier to become an expert on due to all of the public resources/documentation. Microsoft tends to clam up when it comes to documentation about their OS.

Re: If you don't own your OS, you don't own your BTC

#45
If you don’t trust MacOS or Windows, why would you trust Linux? With the first two, sure, they could “do something bad” to compromise you, but why would they? With Linux, yes, you have access to the source, but can you absolutely guarantee that someone hasn’t “done something bad” to compromise your system?

It’s not a matter of idealism, it’s a matter of reality. How long would it take a person of the Posters level of paranoia to guarantee they weren’t somehow compromised? And how long would it take to recheck on update?

There’s a point where the fear of bad actors becomes counterproductive.

Re: If you don't own your OS, you don't own your BTC

#46
I get the point the article is making, but as others have pointed out you could extend this logic to the entire stack of your software/hardware and conclude you're not safe unless you audit every bit. At some point you're going to have to trust software you haven't personally reviewed, as the article awkwardly demonstrates.

It's obviously a matter of risk management (a term I was surprised to not see in the article); the more crypto you have the more care you should put into storing the wallet.

Re: If you don't own your OS, you don't own your BTC

#47

A number of comments in this thread strawmanning the OP's argument. The main point is simply that if you don't have complete legal control, in perpetuity, of the system that you are storing your cryptocurrency on, then if your license is cancelled by legal means, you may lose your data [1]. OP is not talking about whether FOSS or proprietary software has more bugs or has more chances of having backdoors. OP is not ta…

> if your license is cancelled by legal means

This basically never happens to private individuals - the license enforcement focuses on getting you to pay for it instead. The data in any case remains yours and you can theoretically lift it off the drive (or your backups!) with FOSS.

In the very unlikely event of getting raided for copyright infringement, they'll take all your hardware and sort it out later.

(Of course the whole thing is a tremendous anti-advert for bitcoin if it can't be safely used on normal computer systems...)

Re: If you don't own your OS, you don't own your BTC

#48
post #27

This is also an issue for Android and iOS. And some of the newer cryptocurrencies are more or less restricted to those platforms. And with smartphones, adversaries can access the OS using StingRay etc. Edit: I should have said "devices like StingRays". Perhaps StingRays can only track, and maybe see traffic. But the baseband is poorly secured, and has privileged access.

>And with smartphones, adversaries can access the OS using StingRay etc.

I was not aware of StingRay possessing any advanced capabilities, other than being used as a IMSI catcher and providing LE with 'tower dumps'?

https://en.wikipedia.org/wiki/Stingray_phone_tracker

https://eu.usatoday.com/story/news/nation/2013/12/08/cellpho...

Re: If you don't own your OS, you don't own your BTC

#49
post #19

I am torn on this article. If I read it through my developer lens, I’m not impressed - this cranks up the paranoia to a near useless level and the panacea offered is really a false hope. But, when I look at it through a more compassionate lens, I worry about this individual’s health. Hey writer, if you’re reading this and you need someone to talk to, my email is on my profile. Have a happy 2020.

To me, your offer of "help" reads like a thinly disguised attack / insult. I guess we all know about the "humblebrag", this is "backhanded empathy". Or something. The author is not saying anything that is not true. Given everything that happened and was disclosed in the past decade, I don't think one has to be paranoid to be deeply suspicious of black box software controlled by big tech.

First, you’re very wrong about my motives. At various points in my life, I have struggled with paranoid thoughts like that. When it happens, it’s lonely but I’ve learned to open up and talk about what’s worrying me. Sometimes there’s something there and I’ve actually started a few companies based on those ideas. Other times, perspective really helps.

In this case, let’s step back and add some perspective. Microsoft is one of the biggest companies in the world. Their valuation is buoyed by Microsoft’s role in the enterprise. Do you actually believe that Microsoft would want to sacrifice that position for some bitcoin?

Or, there’s the rogue employee hypothesis. Realistically, how many people at Microsoft could directly commit code into Windows without it going through a review? Do you think any of those people are interested in stealing bitcoin? Now, look at all the other employees who have to go through some sort of review before their code ships. Do you think one of them has teamed up with their entire review chain to steal bitcoin?

How probable is any of that? And if any of that was going on, how easy would it be to catch the offenders?

There is a massive gap between analyzing what I do for marketing purposes and stealing my keys.

Edit - We live in a very sad world where you can’t reach out and offer someone an ear without being accused of ‘humblebragging’. I can’t believe what the internet has become in the last 25 years. This is quite upsetting.

Re: If you don't own your OS, you don't own your BTC

#50

Earlier quoted context omitted.

Windows is targeted more (not exclusively, however), due to its popularity. If everyone moved over to Linux for the "security benefits", Linux would be targeted just as heavily. Both Linux and Mac users have been hit with ransomware.

The other factor is that the vast majority of Windows security administrators (i.e., random users) are incompetent. In terms of the security of the operating system itself, Windows may well be more secure than Linux. Many Windows applications, however, are going to be much less secure than the OS--although it's not like Linux applications are stellar in this regard as well (e.g., Docker).

Are they incompetent, or is the bar set so high that only trained professionals can be considered competent?

I believe the latter is true; I've seen some incredibly intelligent individuals fall victim to shady crap.

We (as in the entire software development community) need to lower that bar.

Post reply on HN