Earlier quoted context omitted.
It may come as a surprise you to that the recovery rate for BEC incidents that are not immediately detected is very low and that victims often spend years suing their banks for faulty fraud protection in court for either only a partial settlement or nothing in return.
Having worked in banking for 20 years and knowing how many fraud transactions are reversed, I do indeed find that false information to be surprising.
“My PGP key is compromised, and at least many of my bitcoins stolen”
541–550 of 564 posts
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#542Most people don't think about it: they have a bank holding their "balance", a broker "holding" their stocks, an employer "holding" their salary, and maybe even a crypto exchange "holding" their tokens - until they don't.
Only when you get into the nitty-gritty of self custody, you understand it's a security hassle: you need to save a seed for crypto, or boxes of gold ingots, or precious art in special climate-controlled packaging etc.
People traded this insecurity, this chance of losing it all in one unfortunate event, for the warm comforts of having someone else custody your assets. But ask Greek people in 2008 (or Lebanese people now) how does it feel to come to a bank where you've had an account until yesterday, and find out there's no money to go around.
We're starting to see some strides being made into simplifying and securing crypto custody (MPD, Multi-sig etc.). But at its core, if you want to truly hold your asset, you will need to keep ahold of something (safe key, seed phrase, physical item etc.).
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#543Earlier quoted context omitted.
What do you think banks do? When you store a -lot- of value like a pile of gold bars, you are going to need more than a foam and aluminum hotel safe.
For me as a consumer, storing money in a bank is far simpler and more convenient and more likely to not get me burned than it is to store various hardware tokens with various banks (having to physically retrieve them when I actually want a purchase). So, if the only way to secure BTC is to this cold wallet dance, then it's clear BTC is not a usable store of value compared to USD.
Most people do not store millions in cash or gold at home.
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#544Earlier quoted context omitted.
Speaking of paranoid, that link you've posted, isn't that a link to a server that's known to be compromised, and also an apparent watering hole for crypto wallet holders? Am I unreasonable in thinking that's a very scary link?
1. Disable JavaScript. 2. Access (almost) any website in the internet 3. ????? 4. Profit edit: Mastodon doesn't work without JavaScript, holy hell. We truly are living in a dystopia. Thankfully you can still access his profile from another trusted instance such as mastodon.social at https://mastodon.social/@lukedashjr@bitcoinhackers.org
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#545Earlier quoted context omitted.
Agreed. The average user owns zero servers.
There are posts about OP’s server being hacked, but there’s zero evidence that they put any leaked secret key on their server. Someone more connected to OP suggests that it might be backdoored desktop software.[1] Your average user will install whatever crap they find on the Internet. Hell, a friend of mine (in their 20s, not a grandma) recently installed god knows what when “Windows support” called. And it’s not the…
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#546Earlier quoted context omitted.
Can you go into more detail about how multisig helps? I assume one of the signatures is my hardware wallet. Who holds the other signature? Do they have SIPC insurance? What happens if my wallet is lost or destroyed?
Let's say I have a 3-of-5 multisig. That means there are 5 hardware wallets. I put a hardware wallet in my safe in my house, one in a bank deposit box, and 3 with 3 friends or relatives. Now a thief needs to steal 3 of these to steal the coins. That's going to be hard for a thief to do. If a fire or natural disaster happens, it needs to destroy 3 wallets before I lose my money.
If we are all just taking these coins out of circulation to make them as hard as possible for anyone to access, including ourselves -- then what was the point of the entire thing again?
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#547One thing I'm not seeing mentioned here is discussion of the password for that wallet.dat. This reminds me of back during the 2017 bull run, when I tried to help a friend recover a forgotten password for a bottom 6-figures Dash coin wallet. We went even so far as spinning up some EC2 GPU instances to run Hashcat. In the end, considering the modest value of the wallet, it wasn't cost effective to brute-force. I think we got up to the threshold of 7-9 characters where the time/cost becomes prohibitive.
So I'm wondering, assuming the guy even HAD a password on the database file, or that we didn't have a password.txt on this server, I wonder about the sequence of events where:
1. Server is hacked a few months ago, either knowingly (target a core dev), or farmed (searching for vulnerable servers, grabbing high value assets such as wallet.dats) 2. wallet.dat is copied. IIRC gives free access to the public key, therefore revealing a high value wallet 3. In the meantime, attacker employs compute resources to crack the private key 4. After some months of doing this, finds the passwords, empties the wallet
This would seem to match my quick reading of the events. I'm now intrigued to do some sums to work out the feasibility of doing this when a 7-figure wallet is found. This is assuming compute prices are that much cheaper than 5 years ago, and that this might be a independent attacker, not some NK-style state actor.
I may come back to this and do the calculations...
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#548Earlier quoted context omitted.
I think satoshi never really vanished. Google 'satoshi dorian nakamoto newsweek' and you get to know him. Unless the journalist made the whole thing up or at least a big part of the article is a lie. After reading that, you start asking youself very serious questions about the whole crypto charade.
I think the consensus was that he wasn't the guy. The guy didn't have relevant experience and didn't act like the guy, plus it would be very strange to use your real name but then not expect anything to come of it.
According to the article on Newsweek, he did have. He had experience as US army contractor (if I remember well, Tor network was itself the creation of 2 ex-US army contractors...). And he worked extensivelly for the financial sector. Both experiences as a computer engineer.
> it would be very strange to use your real name...
Vanity is a as old sin as the 6 others deadly sins.
That being said, I read reactions by other media outlets ('coin something' websites are not media outlet) and the concensus was the journalist should have let the guy alone and accused him of doxing, which is kind of a funny stance considering the market cap of Bitcoin was already at that time above 100 billions $. I mean, what kind of serious investor would put any money in a 100 billions market cap company created by an anymous guy on the web. In fact it would be impossible because the SEC wouldn't allow the company to be created in the first place.
That said, the word 'consensus' has absolutely no value in case of crypto, because of the shitload of money which has been thrown at paid shills, influencers, financial newspapers, media outlets and celebrities of all kind.
As I said, either the journalist made the whole thing up and should have been fired on the spot, either the whole Bitcoin charade is nothing of the kind we have been told.
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#549Earlier quoted context omitted.
Can you go into more detail about how multisig helps? I assume one of the signatures is my hardware wallet. Who holds the other signature? Do they have SIPC insurance?
There is no insurance for cryptocurrency. You are your own bank, with all that entails. If you want to do multi-signature, you determine where your keys go and who holds them. It's up to you to secure your finances.
https://www.lloyds.com/about-lloyds/media-centre/press-relea...
Re: “My PGP key is compromised, and at least many of my bitcoins stolen”
#550Earlier quoted context omitted.
Yes, it's a low risk. Perfectly executed this is maybe a risk of one in ten million. So on a worldwide scale this means that it would happen every day, to someone. But it won't be perfectly executed. Let's say you need to do a transaction while you're moving house. And maybe one of your relatives is in financial trouble. You (probably) don't have the means to do what banks do, and hire an armored transport.
With collaborative custody companies like unchained, this is actually not as difficult to do right as you're making it seem. Further, unlike an armored truck full of cash, security by obscurity is really easy here. That and for a short duration (say moving houses as you suggest) one could wipe a cold wallet clean and just remember a seed phrase. Personally, I don't have enough wealth to make this sort of maneuver at…
Since then I don't believe in short SPOFs.
You could get hit in the head by a robber on your way moving your furniture, because the robber thinks you may be hauling high value stuff, and lose the passphrase. If you back it up on paper then the unguarded house may be broken into, and they steal the bag that had the paper passphrase.
Extremely unlikely that it'll happen to you, but extremely unlikely things happen all the time to someone.