Live data from Hacker News

“My PGP key is compromised, and at least many of my bitcoins stolen”

twitter.com

401–410 of 564 posts

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#401

Earlier quoted context omitted.

So you’re saying that to use crypto properly, I have to secure a physical object that grants irrevocable ownership of my wealth? That sounds bad. Is there a way I can get my crypto held my an institution with SIPC insurance, the way I hold stocks at a brokerage, so I can outsource this issue to someone else who is backed by a government guarantee? (I obviously don’t expect them to guarantee the value of the crypto, j…

It's not about money, it's about power. If you hold a physical item, you have the maximum power over it as possible. If you want to entrust someone else with it, go ahead, but at the end of the day your access to the item will be subject to their whims and those of the greater political establishment / woke clergy / corrupt and powerful.

And if you entrust it to a safe deposit box, then... ?

And if you trust it to a safe in your bedroom, and your house burns down, then... ?

Which is more likely?

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#402
post #271

Earlier quoted context omitted.

>These things happen every day, but happening to a core developer (if confirmed!) who has a deep understanding of the systems and security indicates just how fragile crypto can be (in my opinion) Based on the other comments in this thread it looks like he didn't bother using a hardware wallet (which is literally something that's recommended on bitcoin.org[1]), and kept his wallet.dat on a server exposed to the intern…

So you’re saying that to use crypto properly, I have to secure a physical object that grants irrevocable ownership of my wealth? That sounds bad. Is there a way I can get my crypto held my an institution with SIPC insurance, the way I hold stocks at a brokerage, so I can outsource this issue to someone else who is backed by a government guarantee? (I obviously don’t expect them to guarantee the value of the crypto, j…

>I have to secure a physical object that grants irrevocable ownership of my wealth?

Not really. Can be a file copied across dozens of public places that is well-encrypted (say AES256+Blowfish) using a key securely derived (say PBKDF2 with many iterations) from a random password you don't use anywhere else.

That said, if you do that, have a system that will drill you for that password weekly, or you will just forget it. And make sure this system can't be compromised to record your password as you type it.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#403

Earlier quoted context omitted.

Experts make mistakes all the time, fail to see hidden risks, like Challenger explosion. This will never see mainstream adoption at this rate. If the hacker is smarter, being smart is not good enough.

This is not quite the same. Experts did make mistakes for the challenger explosion, but they did much better than the average person. Put 1000 people at complete random into a room and say design and build a rocket, I suspect they won't even get to the build phase after several years. When it comes to something everyone should be able to do, an expert making a mistake is a bad omen for the rest of us.

You underestimate the power of the Dunning-Kruger effect.

That 1000 random people will build it, get it on the launchpad, and press the button. That's not the problem. It's getting to orbit (and back) that would be highly unlikely.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#404
post #298

Earlier quoted context omitted.

His PGP key got stolen, so someone else could have been submitting code as him. Hopefully he didn't also lose any SSH keys with push rights to the repo.

he doesnt have those keys, and never had. His fellow devs dont trust him too much.

And we know this how?

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#405
post #96

One of the linked transactions: https://www.blockchain.com/explorer/transactions/btc/432ded9... The destination address ( https://www.blockchain.com/explorer/addresses/btc/1YAR6opJCf... ) seems to have received ~216 BTC yesterday in the span of 4 minutes

Isn't it surprising that an early Bitcoin adopter has "only" 216 Bitcoin? Didn't he join at a time where you'd be mining full blocks solo? (One of his later tweets claimed that "it's basically all gone" or something like that, implying this wasn't just a small fraction of his total coins.)

It looks like his oldest commit is from February 28, 2011[1], and the first pool was created in 2010[2]. I'm not sure when he started using bitcoin.

[1] https://github.com/bitcoin/bitcoin/commits?after=d8bdee0fc88...

[2] https://compassmining.io/education/bitcoin-mining-pools-hist...

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#407
post #205
post #186

It’s unfortunate. Though what do you expect when possession is ownership and there’s no mediating institution to help you with theft. If your brokerage account somehow gets hacked and all your funds gets stolen that’s not an unsolvable problem. You’ll likely get made whole after a while. There’s people, institutions, and laws to help you. Store digital cash in your mattress and someone will steal it, and no one will…

It may come as a surprise you to that the recovery rate for BEC incidents that are not immediately detected is very low and that victims often spend years suing their banks for faulty fraud protection in court for either only a partial settlement or nothing in return.

Not only BEC, the recovery rate for ridiculously named authorized push payment fraud fraud (i.e. craigslist car scams) is also very low.

Reg E at least protects consumers from some banking malware, but still does not provide protections for phishing victims (despite new non-binding CFPB guidance)

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#408

Earlier quoted context omitted.

Say your wife is a well known Bitcoin billionaire. And your wife bought something from my eBay store. Now I have your home address. And if I am a ruthless character then I quietly break into your house one day with th3e objective of leaving no sign I was ever there. Search for written down passwords, take a photo, leave.

So the "Live, Laugh, Love" sticker on the kitchen wall isn't safe? /s

Hilarious

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#409
post #270

Earlier quoted context omitted.

Shamirs still requires having the (single) private key present for signing. Multisig is far superior for Bitcoin security. The keys can remain geographically separate at all times. Each signing operation requires only the partially signed transaction (PSBT) and the other public keys.

Non-issue if you only use the key once, then do a new split each time. Plenty of tooling exists to make this easily in reach with a simple shell script.

Why would you use Shamirs when the Bitcoin protocol has a superior mechanism built in?

SSS is a good solution for other key material, and for storing a paper key to be used for recovery purposes, but it's completely inferior to multisig for normal management of a shared and/or large Bitcoin wallet.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#410

Earlier quoted context omitted.

If it was that simple and easy why wasn't he doing it. It's simply a ridiculous failure mode that you can lose your entire life savings with no recourse if you make a silly mistake. What a dreadful idea to foist upon ordinary people as the future of finance. We've never accepted this before and let's never accept this again. Every random walk down the timeline results in 100% of coins lost or stolen. [edit] You can o…

No one has to use it if they don't want to. Keep your money in whatever currency you want or your wealth in art or precious metal

Tell that to everyone in El Salvador and everyone exposed passively through the silliness of Elon and Jack, or OTPP or CDPQ. It's strictly false to say nobody is forced to use it - they are. Almost 7M of them in El Salvador. Their legal tender law isn't like the US, acceptance is compulsory and non-acceptance is punishable by prison.

But even if that weren't true, that doesn't mean its a good idea to use it or advocate for it or pretend it doesn't have these glaring flaws as folks march onward toward the abyss and take down the normies with them.

It's everyone's responsibility to call out bad ideas that harm us all. Especially when as soon as anything goes wrong, the afflicted yell "HELP! POLICE!!" just like our tweeter down-thread. That's a draw on public resources which puts this discourse squarely in the public interest. Not to mention spending like 0.6% of the world's electricity on coal-powered lotto ticket scratcher machines undergirding the whole charade.

The worst part is when things start to go wrong all the talking heads jump in and start saying "nobody could have seen this coming!!" and "crypto deserves better critics!!" It has fantastic critics - you just have to listen. Critics aren't supposed to say things you want to hear.

Post reply on HN