5 ms·
Would be interesting to know how his BTC were stolen. Because he is a BTC core developer, I believe he followed the best practices, like not writing down his pa
by mccorrinall 4y ago
Would be interesting to know how his BTC were stolen. Because he is a BTC core developer, I believe he followed the best practices, like not writing down his password. So infection or keylogger?
- sosodev 4y agoStoring most of his bitcoin in a single hot wallet seems to go against the best practices, no?
- mateuszf 4y agoHe said it was not most of his bitcoins. https://twitter.com/LukeDashjr/status/1609618498027753472 https://twitter.com/LukeDashjr/status/1609618498027753472 EDIT: Right, maybe it's all
- sosodev 4y agoFirst he said "at least many of my bitcoins stolen" and then followed up with "Nevermind many. It's basically all gone" Which implies that it is indeed most of his bitcoins.
- kube-system 4y agoHe then said it was basically all: https://twitter.com/lukedashjr/status/1609647203890372609 https://twitter.com/lukedashjr/status/1609647203890372609
- blibble 4y agoirreversible transactions are a feature!
- gnull 4y agoWhat is hot wallet, btw?
- sosodev 4y agoI don't know if it has a concrete definition but I generally say it to mean a crypto wallet that is directly or indirectly exposed to the internet. It's possible to create a bitcoin wallet completely offline in a secure environment. The details to the wallet are then stored physically in a secure location/medium. This is called a cold wallet. People typically use a cold wallet for long-term storage of coins.
- dns_snek 4y agoThis is my personal view on the topic. I don't claim it strictly matches any "official" definition. A "hot" wallet is a type of wallet that's typically stored in internal storage of a network-connected device, such as your personal computer or your smartphone. This is riskier way of storing funds because they can be exfiltrated by malware. You would typically use a hot wallet for day to day transactions. A "cold" wallet is a type of wallet where private keys to control the funds are never in contact with a network-connected device. They're typically stored in the form of recovery phrases written on paper or metal (in a secure location), or some kind of a smart card that securely stores private keys and exposes an interface to sign individual transactions (e.g. Ledger devices). Funds stored in a cold wallet are much harder to access, but are extremely (or completely) resistant to theft, short of physical access. In crypto a "hot" wallet should be treated as cash, while a "cold" wallet is more like a savings account.
- throwaway9870 4y agoI am not a security person, but I can't help but wonder where the advice of not writing things down comes from? I think my wife's password book on her desk is a lot more safe than most computer experts.
- rileymat2 4y agoIt comes from the threat model, having a password book on your desk in a cubicle is absolutely not secure. On a desk at home? It is marginal, certainly a burglary is a low frequency event, but we also have events like fire that make it insecure in other ways.
- cma 4y agoSomeone kept theirs in their wallet, and their passphrase showed up on a publicly released police body cam the other day when their insurance was checked or something.
- andrewstuart 4y agoSay your wife is a well known Bitcoin billionaire. And your wife bought something from my eBay store. Now I have your home address. And if I am a ruthless character then I quietly break into your house one day with th3e objective of leaving no sign I was ever there. Search for written down passwords, take a photo, leave.
- nemo44x 4y agoWhy make it so complex? Just do a title search online and you’ll get access to their address if they own a home.
- andrewstuart 4y agoOf course its obvious there's many ways to get someone's address. The point is that companies put vast effort into digital security but in many cases it's easily compromised by going to the home of the person that is the hacking target.
- nextaccountic 4y agohe should been using a hardware wallet and the bulk of it should be on a paper wallet, in the vault of a bank or another real world institution. the hardware used to generate this key should be wiped out. so if he followed best practices, he didn't lose this money edit: just found out that the btc was stolen from a dedicated server on ColoCrossing. this makes no freaking sense. no server connected to internet should have access to the keys to your btc (or access to any keys that could be used to later on grab cryptocurrency keys). hot wallets should be hardware wallets, cold wallets should be acid free paper
- treeman79 4y agoHow on earth are normal people supposed to trust bit coin. When best practice is to treat it like paper money.
- thebeardisred 4y agoTechnically, it's more like "treat it like any non-fungible asset". Plenty of "normal people" use combinations of physical security to protect their assets. Safes, deposit boxes, tamper proof materials etc.
- throwaway290 4y agoWhat... paper money and gold bars are non-fungible now?
- paulpauper 4y agoIf BTC is $1/coin , it is fine to not be paranoid. $16,000+ changes the game completely.
- hgsgm 4y agoThat's not how it works at all. "Bitcoin" is just a unit of measure, except for the brief moment of mining a new one. Would you be less paranoid if your savings were denominated in pennies vs dollars?
- paulpauper 4y agowriting down password does nothing when there is a digital copy too and your computer is compromised