Man has two more chances before $232M in Bitcoin is lost forever
au.finance.yahoo.com
au.finance.yahoo.com
Perhaps I'm ignorant of other aspects/solutions. But this is my take with being solely responsible for access to my own funds.
Most people are unbanked not because banks don’t exist for them but because they don’t have money to put into an account. In the US online banks like Ally or Schwab are way better for folks who are legitimately unbanked than a crypto wallet - esp one they are unlikely to properly custody. Postal banking is an approach that has been historically hugely successful too.
Outside the US honestly I don’t know how folks wouldn’t be better served with for instance access to an account at circle.com vs USDC.
People not having money is a social problem that deserves a meaningful social solution - not digital magic beans.
Not true at all, as the GP explicitly mentions Shamir's secret sharing:
> Shamir's secret sharing (SSS) is an efficient secret sharing algorithm for distributing private information (the "secret") among a group so that the secret cannot be revealed unless a quorum of the group acts together to pool their knowledge. To achieve this, the secret is mathematically divided into parts (the "shares") from which the secret can be reassembled only when a sufficient number of shares are combined.
* https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing
So you can trust various persons / entities such that m out of n need to come together before the secret is revealed. And each person doesn't need to have just one share out of n: if you trust one person more that you can give them two (or more) shares out of the n.
The irony, lol.
look at argent.xyz
If you don’t want to manage a wallet, just use Coinbase.
This guy is using one solution from nearly 10 years ago, and it has some user experience issues
all the UX improvements are developed in bear markets, and they onboard the next million users that help result in the next bull market
No, not really. It is the same kind of story as people putting all their money in a bag in a chimney to find out their family decided to finally lighten the mood by making a fire in long unused fireplace. It is an actual story about my neighbour when I was a kid.
People have been doing stupid things with money for thousands of years.
You can store crypto safely. It is essentially the same problem as storing encrypted backups. It has been solved.
As much as I hate cryptocurrency, I would actually be more at peace having lots of crypto than lots of stock on my account (if not for the fact that crypto is just a scam).
Something to keep in mind when talking to people about these ideas, they’re usually paired with some “apes together strong” kind of magnanimous idealism, where the community/market would come up with solutions.
When we don't want to be responsible with cash, we give it to a bank. Same with BTC.
A similar problem arises under other circumstances. And yes, there are off-the-shelf solutions now, eg: https://bitwarden.com/help/emergency-access/
Technically, "I forgot the key" access is not a difficult problem to solve. And because of they have digital contracts as part of their DNA, crypto currencies provide all the tools you need to solve it even without things like Bitwarden.
You are right about there being no "banks" in one aspect though. While there are any number of solutions out there to the crypto-currency key problem and some will do a better job than a bank, there is no easy and low risk way to find the solution that works for you. Certainly nothing remotely as easy and low risk as "walk into any USA bank and open an account". The real magic of a conventional bank is not all the protections in place (who hasn't been screwed over by a bank or credit card company at some point?), it is that it is a "well understand, everybody knows about it" convention.
However, I can't see any harm in offering a bug bounty of 1/4th of the stash, putting up the model and serial number of the drive, and seeing who can crack it the fastest.
I’m sure someone like Cellebrite or the other agencies that have done iPhone hacking could do something like this — or at least figure out how to clone the drive to do multiple attempts at getting into it - but I don’t know how many places would do it on someone’s word that the crypto is there.
Like, yeah, for 25%, I bet you could find people who could get it done. But I don’t know how many of those people who would undertake that work on a promise. What if it’s like Al Capone’s vault [1] and turns up empty?
[1]: https://en.m.wikipedia.org/wiki/The_Mystery_of_Al_Capone%27s...
"Sorry, we couldn't crack it, bye"
And if the bitcoins somehow move after they "fail" (remember, the blockchain is public), he knows who to sue.
Also here's a presentation on finding vulnerabilities in Ironkey flashdrive: https://www.youtube.com/watch?v=R8iAqA0pklw
I understand why it isn’t in Kingston’s interest to try to help him out, but if I had that much money trapped on something, I think I would do everything I could to actually free it, including paying people to look for vulnerabilities in the drive and reverse engineer. Getting those people to take me at my word might be tough, but I would do everything I could to release $200m in a wallet.
My guess is that GP does the same as me. Create a throwaway account, use for a few weeks, then abandon it to create a new one.
This account I'm posting from is close to EOL, for example.
Edited to add, it's also against the HN guidelines:
"Throwaway accounts are ok for sensitive information, but please don't create accounts routinely. HN is a community—users should have an identity that others can relate to."
I won't contribute any other way however. Perhaps I don't feel comfortable having an "identity others can relate to".
That said, off I go back to read-only mode. Arrivederci.
His losses will most likely increase next year as the bitcoin block reward halving is followed by an increase in price every cycle.
What's interesting here that even if Kingston would be able to help, it might not worth for them to do it because of their reputation (and $13B revenue)
Although I don't think they have the auto-destruct feature.
But with 200M+ at stake, I'd put out a bounty for someone to reverse engineer the firmware.
Edit: sibling commenter says it's IronKey, reading about it, reverse engineering won't be that trivial...
If it were me, I would easily give up half of it to get the money back.
>Thomas has just two attempts left to guess the password before it's encrypted and lost forever.
I suspect they meant the drive would wipe itself after another attempt.
You could attempt to pull the controller chip and decap to extract the secondary key which would allow you unlimited attempts
If nothing else find a university with an election microscope and give some CS students a project of reading the key bits directly.
Enclaves keep out petty thieves, not determined attackers with unlimited physical access. Chapter 1 of cybersecurity is no hardware can protect against that.
It just isn't believable that you can have a storage drive sitting in front of you which contains both encrypted data and the decryption key (or at least the password-encrypted decryption key) and yet not be able to access the data.
Easy scenario, someone DoS you by causing the device to self destruct thereby you losing large amounts of money.