Exmo Bitcoin exchange chief executive kidnapped in Kiev
bbc.com
bbc.com
The hard part of extortion has always been getting paid. It's always involved exposure ("meet me there with a bag of money") or been subject to limitations (wire transfer clawbacks, cash withdrawal limits, etc), until now.
Right now anyone in the world can fill an insulin syringe with cyanide solution, walk into supermarkets (too big to properly secure, and there's too many supermarkets to prevent it), and inject it into random plastic coke bottles. People will stop drinking coke, and then Coca-cola will be willing to pay hundreds of millions of dollars to make it stop. Ten years ago, the extortionist would then have to meet somewhere to collect a bag full of money, and that's where the risk comes in. But now they can simply send coca-cola a bitcoin address and get paid anonymously risk-free. You can design extremely profitable low-risk crimes.
The question then becomes, if more people were given the ability to steal risk-free, would they? Anyone who has spent time in the crypto ecosystem has already learned the answer. They will. This is why nearly every exchange gets 'hacked' and so many darknet vendors pull exit scams. It turns out a lot of the reason most people are good all the time has more to do with fear of getting caught than virtue.
The world is about to become a very scary place.
Be the change that you wish to see. Money won't make you happy.
So to sum up... I think it’s mor appropriate to say the fundamental issue is how we design around human nature to create a world worth living...
2) Do whatever you're planning to do.
3) Transmit another message to the company you're blackmailing in which you reveal the message that matches the original SHA1 hash.
That being said, most people are peaceful. Crime-wise, they are slightly willing to do bad things (like stealing quietly from the market). Those ready to kill or cause great damage, are not normal people and are not most people.
Go to Japan and see how people behave their. America is violent and so is many places in the world. But I would not lose faith yet.
That's a very lofty assertion. Most people assign a very very very high value to "avoid getting caught". Over time we have developed a system to increase probability of getting caught for any crime. Should the system fall apart, the crime spikes
Most humans are not slathering animals just avoiding being caught.
It wouldn't be exactly something that can be done overnight, but it wouldn't be impossible. Depending upon how strongly they implement the laws, it would kill currencies that don't offer protection from being tainted.
[1] https://cointelegraph.com/news/ukraine-security-service-alle...
It took me like 2 months to cash out the first time.
Seriously, I don't think this will scare off anyone, especially not exchanges. They make so much money right now they can just hire bodyguards.
Which won't be able to carry weapons in most places. You'll have a hard time finding people who'll fight back when you're being kidnapped at gunpoint.
I imagine its quite easy to find mercenaries that are willing to fight back. There is an entire industry for hiring people to fight wars.
Bill Browder can't eat at the same restaurant twice because his food may be poisoned. If you are a high profile target you have to change your patterns to remain safe.
Okay, now the kidnappers dress up as cops and "arrest" you. Perhaps they bribe the actual cops to do it for them?
Armed bodyguards do not seem like a substantial increase in difficulty for someone who intends to kidnap a person.
Most places? Places like what? Even Germany, with its rather restrictive gun laws, has exemptions for private security companies allowing to carry weapons.
While I don't know any specifics, I doubt that it's gonna be that much more difficult, in Eastern Europe out of all places, to get a legal carry permit.
https://www.nytimes.com/2017/12/24/world/europe/ukraine-gren...
I met an old school mate years ago she was working as a PA for deutsche bank in the uk and she mentioned that the senior mangers where annoyed as the UK would not allow them to have armed body guards.
You don't need people boasting about their crypto fortunes. As soon as you set up a Bitcoin tip jar, anyone can look directly at the blockchain to determine how much money you have - and how much you have had at any point in time and where the money went.
Only if you use static addresses. If you're receiving thousands of BTCs, you can easily afford to write a widget that generates a new address for each donor (behind a captcha, to avoid DoS).
For every rich person that openly shows their wealth.
Same thing is inevitably going to happen IRL. I always say exchangers are Bitcoins weakest link. All it takes is one compromised employee at Coinbase or another large exchanger (intentional or some kidnapping scenario) for the price to come crashing due to the damage they can be forced to do.
Never ever keep your coins on an exchange wallet. Never.
It's exactly the thing I would do.
Let this be a reminder that physical security is a necessary precursor to computer security. And I also hope that Exmo's succession plan executor takes the precaution of staying up late tonight to move all their reserves to new wallets.
If the whole idea of a kneecap-breaking plot fails because transferring the funds requires multiple signers then they arent going to break kneecaps
2 of 2, 3 of 5, 7 of 10, etc...
Also, it's a fairly well-known system, so I don't see it being collectively "forgotten" on the timescale of a few decades (it's been around since the late 70's i believe).
I'd love to get it integrated into wallet software, as it's such a safe and reliable way of storing secrets that lets you be as "secure" or as "reliable" as you want with just a slider.
Rather you have a private key p of n bytes. Create two cryptographically random keys k1 and k2 of n bytes each. Derive a key k3=(p XOR k1) XOR k2. k1, k2 and k3 are your distributed keys. To recompute p you need to do p = (k3 XOR k2) XOR k1.
A XOR is trivial to implement and I would expect be reasonably robust.
For me, my biggest threat is loss, followed by theft, so it makes sense to have some redundancy even if it means reducing the security against theft.
One of the keys could be controlled by a law office on the other side of the planet with contractual obligations to only sign the hot-wallet-refill transaction with a certain amount when the hot wallet falls below a certain amount and when the exchange requests it. The cold-wallet that they're funding from could itself be funded by a timelocked transaction to guarantee that the cold-wallet isn't emptied out too fast, and an entirely different set of law offices that the exchange doesn't regularly contact control the keys that allow the cold-wallet to be emptied out faster. If the different types of on-chain controls like timelocked transactions aren't enough, then some of the keys could be in tamper-proof hardware-security-modules that further restrict how the keys can be used.
I also tried to get my Euros out of Exmo, but verification is already taking more than a week. My trust is gone in them. And thats the whole point. Exchanges are still based on trust, thats not what decentralized cryptos are about. It only works if everybody works on the blockchain only.
Structure things so if they betray you, they have a very high chance of getting detected and needing to go on the run - e.g. access control records, CCTV and whatnot.
Then hire guards who would have to sacrifice a lot if they went on the run permanently. e.g. guards with partners, school-age children, extended family nearby, friends, and community ties like membership of voluntary organisations, churches or clubs.
Multi-sig does not prevent anyone from kidnapping me and distributing a video "sign us all your btc funds or this dude is going to get tortured".