Live data from Hacker News

If you don't own your OS, you don't own your BTC

combatnerd.com

1–10 of 64 posts

Re: If you don't own your OS, you don't own your BTC

#3
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

ElementaryOS's repos were hacked a while back. The trojaned images didn't stay up long, but it illustrates your point. (Not singling out ElementaryOS... any software with a repo or updater could be trojanized, including software from big companies.)

Re: If you don't own your OS, you don't own your BTC

#4
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

this says it all :D LOL

Re: If you don't own your OS, you don't own your BTC

#5
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

Not to mention, you have to evaluate this in context. What would MS stand to lose if they actually did this? Far far more than whatever Bitcoin they'd be able to steal that much is certain.

But in any case, if you care about security, you have a hardware wallet and store the seed somewhere secure.

Re: If you don't own your OS, you don't own your BTC

#6
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

We already know Windows has some pretty excessive telemetry, it is not unreasonable to assume this or other elements of the OS can be exploited to gain control of a wallet.

At least with Linux we have thousands of open source developers keeping an eye on things, chances are much higher that an issue would be caught with Linux since Windows is closed source.

Re: If you don't own your OS, you don't own your BTC

#7
The real question is: why he is not using an Hardware Wallet? A ledger wallet is cheap enough if you get worried about your BTC being in an unsafe device. Yes, then you have to trust the company selling it for you, but isn't that the whole business to not compromise their own devices?

Re: If you don't own your OS, you don't own your BTC

#8
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

Not to mention, you have to evaluate this in context. What would MS stand to lose if they actually did this? Far far more than whatever Bitcoin they'd be able to steal that much is certain. But in any case, if you care about security, you have a hardware wallet and store the seed somewhere secure.

It wouldn't have to be Microsoft exploiting this though, a few rogue employees that can modify their telemetry system could do this on their own. There is no external oversight for Windows but on Linux there are thousands of people looking at changes even if you aren't looking yourself.

Re: If you don't own your OS, you don't own your BTC

#10
post #6
post #2

This guy is a downright idiot if he thinks that he has any more control over his keys on desktop Linux without actually auditing all the source code himself. The idea that ElementaryOS is less likely to steal your coins than Windows or OS X is simply laughable.

We already know Windows has some pretty excessive telemetry, it is not unreasonable to assume this or other elements of the OS can be exploited to gain control of a wallet. At least with Linux we have thousands of open source developers keeping an eye on things, chances are much higher that an issue would be caught with Linux since Windows is closed source.

> At least with Linux we have thousands of open source developers keeping an eye on things

A bit of pithy sarcasm for your morning: Those thousands of eyes worked so well with OpenSSL, didn’t it?

Those eyes are less vigilant than you might think, especially when the eyes aren’t being paid to monitor a particular chunk of code.

Post reply on HN