Live data from Hacker News

“My PGP key is compromised, and at least many of my bitcoins stolen”

twitter.com

511–520 of 564 posts

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#511

Earlier quoted context omitted.

Let's say I have a 3-of-5 multisig. That means there are 5 hardware wallets. I put a hardware wallet in my safe in my house, one in a bank deposit box, and 3 with 3 friends or relatives. Now a thief needs to steal 3 of these to steal the coins. That's going to be hard for a thief to do. If a fire or natural disaster happens, it needs to destroy 3 wallets before I lose my money.

Yes, it's a low risk. Perfectly executed this is maybe a risk of one in ten million. So on a worldwide scale this means that it would happen every day, to someone. But it won't be perfectly executed. Let's say you need to do a transaction while you're moving house. And maybe one of your relatives is in financial trouble. You (probably) don't have the means to do what banks do, and hire an armored transport.

With collaborative custody companies like unchained, this is actually not as difficult to do right as you're making it seem.

Further, unlike an armored truck full of cash, security by obscurity is really easy here. That and for a short duration (say moving houses as you suggest) one could wipe a cold wallet clean and just remember a seed phrase. Personally, I don't have enough wealth to make this sort of maneuver at all worth it, but it's completely do-able.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#513

Earlier quoted context omitted.

Something is fundamentally broken. "We can write perfect software to prevent all attacks" is fundamentally broken, because we have empirically proven that we can't. (The previous model, "we can trust people", is even more broken. But maybe it's the same breakage? "If this packet that came over the internet passes all of our filters of known bad things, then we should go ahead and process it.") People have touted capa…

The answer is security through isolation. See: https://qubes-os.org . My daily driver for years.

Qubes, as great as it may be, is still another abstraction on top of an insecure base. The fact that things like spectre and meltdown are even possible is worrying. How does Qubes solve this?

As another poster said, we need some other computing paradigm, but I don't know what that would look like. All I know is something is broken if these behemoth companies with limitless resources still get it wrong.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#514

Earlier quoted context omitted.

It's not about money, it's about power. If you hold a physical item, you have the maximum power over it as possible. If you want to entrust someone else with it, go ahead, but at the end of the day your access to the item will be subject to their whims and those of the greater political establishment / woke clergy / corrupt and powerful.

Nope, not at all. Your hardware wallet is useless without the bitcoin trust frameworks and the implicit agreement among many people that these particular bits on your hardware denote anything of value. Both of these are completely beyond your control and reliant on mechanisms not fully understood. It’s a system boundary question: yes, your wallet is under your control (how do you know what’s baked into the silicone o…

>There is a huge amount of vested interest in persuading people bitcoin or ethereum require no trust in third parties.

It requires trust that third parties will act rationally in accordance with the incentives provided by the system, which is very different from trusting someone to custody assets for you.

At a larger level it requires trust that people will continue to see BTC/ETH/etc as being worth something, but that isn't a unique problem to blockchain based digital currency solutions.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#515

Earlier quoted context omitted.

So you’re saying that to use crypto properly, I have to secure a physical object that grants irrevocable ownership of my wealth? That sounds bad. Is there a way I can get my crypto held my an institution with SIPC insurance, the way I hold stocks at a brokerage, so I can outsource this issue to someone else who is backed by a government guarantee? (I obviously don’t expect them to guarantee the value of the crypto, j…

>I have to secure a physical object that grants irrevocable ownership of my wealth? Not really. Can be a file copied across dozens of public places that is well-encrypted (say AES256+Blowfish) using a key securely derived (say PBKDF2 with many iterations) from a random password you don't use anywhere else. That said, if you do that, have a system that will drill you for that password weekly, or you will just forget i…

This is what his colleague recommended. A cold wallet that is only worked with offline. It is on an encrypted file system and can be backed up. (passphrase protected)

I remember that Silk Road associated guy that was caught recently with 50000 BTC. I was wondering why he didn’t just encrypt his wallet?

There is no way crypto coin will work for society at large with such requirements.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#516
post #484

Earlier quoted context omitted.

You're not holding anything in your wallet. It's just fancy login systen to a transaction system that is bitcoin. It's no different from bank login in the end, once someone has it, it can be transferred at will. Sure, the difference is that in banking system bank doesn't need your credentials to do stuff with money but even that when big crypto bois money are involved stops being immutable as DAO ethereum fork proves…

> It's no different from bank login in the end, once someone has it, it can be transferred at will. Bank login credentials do not confer undisputed ownership of an account. If someone unauthorized gets ahold of them, the bank doesn't throw up its hands and say "welp, nothing we can do now, the account just belongs to the hacker".

At least partly because they're not allowed to do that because there are specific rules about it. If banks could just say "so sad, too bad", they absolutely would. I know someone who had to resort to the financial ombudsman to get their money after a hack because the "bank" (Revolut or Monzo) would not engage with them to even acknowledge anything had happened.

Pretty much this is what banks try if they can: https://youtube.com/watch?v=CS9ptA3Ya9E

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#517

Earlier quoted context omitted.

The answer is security through isolation. See: https://qubes-os.org . My daily driver for years.

Qubes, as great as it may be, is still another abstraction on top of an insecure base. The fact that things like spectre and meltdown are even possible is worrying. How does Qubes solve this? As another poster said, we need some other computing paradigm, but I don't know what that would look like. All I know is something is broken if these behemoth companies with limitless resources still get it wrong.

Qubes is not just an abstraction. Its isolation allows to overcome the problem of fundamentally insecure software. For example, my passwords are stored in an offline VM (where I don't run any apps) and my random internet browsing occurs in a disposable VM (which is reset every time).

Yes, Qubes does not solve the problems like Spectre and Meltdown. Yes, you must trust your hardware to use it. If you are looking to solve such problem, then you might be interested in a stateless laptop: https://blog.invisiblethings.org/papers/2015/state_harmful.p....

Apart from that, I believe, the best computing paradigm is free software and free hardware, but it does not seem too widespread now unfortunately. This would be the actual solution. The "behemoth companies" are not trying to solve computer security. They are trying to get as much profit as possible, and it goes against security of the users. This is why they are not supporting free software.

My current "good enough" solutions are disabled and neutralized ME in a laptop and Librem 5 phone.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#518
post #476
post #465

Earlier quoted context omitted.

People forget bitcoin wasn't worth anything for a long time. You take care of an asset worth millions very differently than an asset worth pennies and too much of a pain to transact for cash anyway.

Someone being around since 2011 and believing in bitcoin, and only having hundreds of BTC today is implausibly rare. Back in 2011, a desktop CPU would mine thousands of bitcoins per month.

You're thinking of 2009, when it was first released and nobody knew anything about it.

I know that by the time I even looked at it in 2011 you couldn't mine anything with a desktop CPU.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#519
post #496
post #463

Earlier quoted context omitted.

I've always believed that Satoshi is a pseudonym for a group of people working for some intelligence agency.

ability to move a lot of money outside of the banking system would be right in CIAs playbook

And be able to track it all as well? Absolutely.

Re: “My PGP key is compromised, and at least many of my bitcoins stolen”

#520
post #468

Earlier quoted context omitted.

The hacker will have a rough time converting these to USD without exposing himself. If they’re in Russia they probably don’t need to care, but there’s a reasonable chance they live in a country that the FBI can reach. On the other hand, no one can do anything until the coins are moved or more information is uncovered. What a nightmare to lose $3.6m overnight.

Does the FBI care about individuals losing bitcoins?

Yes, I think it funds their war in Ukraine
Post reply on HN