Researchers cracked an 11-year-old password to a $3M crypto wallet
wired.com
wired.com
This is so true for stocks too
There’s a whole world of shady crap going on in the ‘legitimate’ financial space.
But crypto bros are often delusional about what intrinsical value exists in the normal market, compared to crypto coins where they invent the value. Therefore manipulation of value compared to real world markets becomes a lot more abstract.
"For the love of money is the root of all evil: ..." -- 1 Timothy, 6:10
It's not the money that is evil, it is the things we do because of the desire we have for it.
Further correction though, it actually says “the love of money is the root of all kinds of evil.”
If you really go down the rabbit hole, pride is probably the root of all evil. It’s certainly the root of greed.
That depends on the translation you're using[0] ... it might be interesting to go back to the original (as best we can).
Also "all kinds of evil" can be interpreted in (at least) two ways, so it's ambiguous anyway.
But as with all these things, it's perhaps best to use the text to spark a search for a truth, or at least a useful guiding principle.
[0] https://www.biblegateway.com/verse/en/1%20Timothy%206:10
9 and those wishing to be rich, do fall into temptation and a snare, and many desires, foolish and hurtful, that sink men into ruin and destruction,
10 for a root of all the evils is the love of money, which certain longing for did go astray from the faith, and themselves did pierce through with many sorrows;
That is worth more than most any other use for crypto.
That's exactly the use of crypto. Illegal being based on a random law by a random government in a random country.
Had I been able to transfer Eth, which I didn’t see as an option last August, I would have been delighted with such a choice.
Bitcoin did not solve any real problem and you still need an additional mechanism to make sure that the thing you get back, actually happens.
You can do those same transfers cheaper and faster on an Ethereum layer 2.
Hedera is the way.
What happens when the product is faulty or not even arriving?
That's part of proof of stake of our society.
The same with lawyers and normal contracts.
All of it is part of our proof of stake.
Visa provides insurance and fraud detection.
Crypto promised solving the issues of the fiat.
It just doesn't do that at all and need all of the mechanics of our proof of stake system while consuming a lot of energy for it's own proof of work.
I can sell crypto to anyone, anywhere.
That cannot be used to purchase anything, anywhere.
Its only useful for a very narrow subset.
So, yeah, the "no questions asked" part is wrong. You can send money to anyone on earth, after a middleman takes a cut on your fiat exchange, the transfer, and the next fiat exchange, with questions asked, public for the world to see.
Unless you're actually going to directly use the cryptocurrency (which is generally impossible), it needs to be converted to/from fiat, which requires a bank transfer.
So after 20 mins of clicking some buttons I get my fiat currency in my bank account. And it costs 2 usd + some negligible amount.
That's because being tied to something, or having intrinsic value is not how things gain value.
Things, crypto, dollars, gold, and towels, have value because people WANT them. That's it.
You even touched on it: "some sort of service that people want, and therefore have value" - crypto provides a service people want, therefore by your own words it has value.
The mining network is a lot more productive than the US military which has vastly negative economic output. At least ASICs doesn't wander around wrecking countries in a semi-random fashion. The mining network even operates at a profit, which is much better than the US government by a huge margin. Someone thinks they are worth the money.
> Things, crypto, dollars, gold, and towels, have value because people WANT them. That's it.
People would want a lot of things if those things were free, question is what the demand curve is.
It's being tied to US state law, via the Uniform Commercial Code (UCC Article 12 for Digital Assets), https://www.clearygottlieb.com//news-and-insights/publicatio...
Article 12 – dealing directly with the acquisition and disposition of interests (including security interests) in “controllable electronic records,” which would include Bitcoin, Ether, and a variety of other digital assets ... Control under Article 12 is designed to be a technology-neutral functional equivalent of “possession.” It generally encompasses circumstances when a party has the “private key”It is very in demand, for instance, in helping dictators evade sanctions, or helping criminals extort or trade illegally.
Let's be realistic here, most of dictators evading sanctions do it (i) with good ol' bags of $/€/CHF/£, (ii) gold/platinum/diamonds/..., (iii) whatever ad-hoc currency satisfies the two parties (promises, shares, goods, ...); in short everything but traceable-in-the-open digital currencies where most of the in/egress feature mandatory KYC.
If you believe e.g. that the US/EU firms still doing business in Russia are doing it in ETH/BTC, I have a port in Serbia to sell you.
If you are in the circles where having to move $10M illegally is a common occurrence, paying a guy $10k to take a train between Russia and China with a bag of cash and bribe the border guards another $10k is much better than trying to weasel your way through the KYC process of Coinbase.
But I wouldn't.
Of course, people there may use it for that purpose, but that demand is a negligible part of the overall demand for cryptocurrencies.
Actual definition: In the Western world, a "criminal" is any person tried and convicted of breaking the law.
Your definition is, however, correct for how it sometimes works and how "they" would like it to work. (where your use of the word "mandate" means "whichever direction the wind is currently blowing").
https://www.nber.org/system/files/working_papers/w29396/w293...
> For example, illegal transactions, scams and gambling together make up less than 3% of volume.
Sure there's the odd dumb criminal who doesn't understand the prosecutorial implications of an immutable public ledger. But it pales in comparison, according to the actual data.
That source says, when it comes to the demand in terms of spending crypto for goods or services:
> 46% of transactions are due to illegal transactions
If Bob transfers $10 back and forth between both of his bank accounts 99 times and then buys $10 worth of crack, would you say that 1% of Bobs money was used for illegal purposes or 100% of it was used for illegal purposes? Depends on what specifically you're trying to measure.
There are two things here that are simultaneously true:
1. A small percent of BTC transactions are for illicit purposes.
2. A large percentage of the goods and services purchased with BTC are illicit.
"We first document that 90% of transaction volume on the Bitcoin blockchain is not tied to economically meaningful activities".
How much of the actually meaningful use is legal? E.g. buying good and services, not evading laws, regulations, sales taxes etc.
Global GDP is $101T. Global yearly forex volume is $2738T. So by this logic you should conclude that 96% of transaction volume in the traditional financial system is also not tied to economically meaningful activities. You're going to be disappointed if you want to believe society as a whole is any less financialized than bitcoin.
What do you think would be an acceptable percentage of speculation?
https://www.compareforexbrokers.com/forex-trading/statistics...
Surely what we actually care about is how many useful, legal, meaningful transactions there are.
For example if for every 1 legal transaction there is 3 illegal transactions and 96 speculative or maintenance transactions... it starts looking like this is predominantly for criminal uses even though only 3% of transactions are criminal.
Why didn't you name one?
If you're buying illegal black market shit, you're darn well gonna do it using the Red, White, and Blue's Green!
This is also proof of cryptocurrency's use-case as a method of value transfer (ie. currency). Crime and porn are the traditional testing grounds for new disruptive technologies. I remember this thing called the Internet...
You'd do better to argue 'currencies are usually tied to a productive country with some measurable GDP and therefore [...]'.
Bank system is terribly inefficient comparatively and it is a huge market
Unfortunately others owned Sears Roebuck, or Enron.
Who could have guessed they'd pass on digital even though they practically invented it.
I had to stop watching because of all the cringy tweenertainment funny faces and jerky body movements and hands waving all over the place.
I agree with you that entertainment has taken over too much (it inevitably attracts a wider audience), but there is room for both.
me: closes YouTube.
However, it goes to show why hacking will never be made interesting in movies without a bunch of fake nonsense like hacking the Gibson's 3D virtual environment.
One is flying through the holographic city of files.
The other depiction is quite realistic: they show the protagonist spending all night reading through many pages of assembly to reverse engineer a virus, people do social engineering, etc. “Hackers” made this seem cool too!
"Hackers" - 1995
Sneakers had them going through the trash, setting up a mark on a fake date, and staking out a building and the security company it used with all sorts of stuff not once looking at a computer screen to "hack" three years earlier.
I like Hackers for the campy side of things, but Sneakers will still take a higher spot on my list.
That ssh exploit was so cool...
They also found the seed was from time and knew when he had created it.
He got lucky there a little.
Who is he in that sentence? Do you mean the owner of the wallet who is absouletly very lucky, or the hackers that did a lot of investigating and reverse engineering to learn that the datetime was the seed. Was that luck or l337skillz?
Start with the time, in the milliseconds (not seconds, i.e. epoch time). Use that seed to create a random number. That random number is now your master_seed.
Once every 10 seconds, measure the temperature of the CPU, and every other temperature sensor in the system, and put that into a new random seed. Create a random number using this seed. XOR it with the mast_seed and store it as the new masted_seed.
Every time someone moves a mouse, use the timestamp and the pixel offset to update the master_seed similarly as above.
Every time a packet comes into the ethernet interface, use the timestamp and a hash of the packet contents, and update the random seed.
XOR the contents of the video buffer.
Track the timing of keyboard clicks.
There are lots of sources of entropy that you can use to make the seed effectively unguessable.
I was hoping to illustrate the the grandparent post where more entropy can come from.
What a bunch of bozos.
Anyway the major benefit of using a password manager isn't generating difficult to guess passwords.
It's being able to generate unique passwords so when you're details end up on https://haveibeenpwned.com people can't take the password that's leaked and try it on all the other services you've used.
Sniffing traffic (yes even encrypted) would be enough to see if you’re going through the login or initial user establishment flow, and that would give you a precise time when the password was generated.
This is a serious flaw.
Password management is one of those fundamental security foundations- essentially serving as the 'root of trust' for your own personal digital life. If you mess that up, you're in for a world of hurt. I don't mess around with passwords. Taking your analogy, would you intentionally stand outside under a tree in a thunderstorm, figuring that the risk of getting hit by lightning is so small?
Yes it’s obviously not good that they used the date as a seed, but the realistic risk is pretty much non existent. Even in this case where literal millions of dollars were on the line the “attackers” still had to collaborate heavily with the owner to narrow down the search space. On their own they likely would never crack it.
Absolutely no one is going through all this to get in to your Facebook account when they can just call up some grandma and ask them to transfer a $1000.
So that Facebook account may allow you federated login to something you do care about. Or your Facebook account is the front page for your business, where a defacement or outage could cost you thousands of $$$. Or you reused your Facebook account's password as the password for your email, which probably was the recovery email for every online account you have... meaning you can now log into every service given access to your email.
Real security is about threat modeling and risk mitigation. Risk mitigation is simply the application of a rough economic model of both the attacker and defender to find a median where you are comfortable. Essentially a fancy way of determining how fast you need to run so that the bear eats the slower person first. Your example is apt- the grandma who is scammed out of $1000 is running much slower than the grandmas who were not, all things being equal.
So when it's "just" a Facebook account on the line, yes, nobody is going to go through massive effort to crack it. But that's not what the original post was about - it was about unlocking millions of $$ worth of Bitcoin. That's worth some effort. Remember also that, in this story, the person who retrieved the password does not end up with 100% of the proceeds, as you would in an adversarial scenario. In the adversarial scenario, the adversary's risk calculus is vastly different and they would be willing to spend a lot more effort (time, money, resources) into cracking that password.
Password managers are kind of a "defence in depth" thing; practical speaking, a passwords.txt opened with notepad is probably fine for many people. No one is in your computer checking your files. You have a password manager for when that does happen, just in case. And usually this tends to be a targetted attack, which can range from some country's secret service to a jealous spouse to a trolling sibling. If that extra protection is ineffective ... yeah, that's not great.
This really is "better safe than sorry" type territory. Password managers (including Roboform) already do this by notifying users a password may be insecure after a leak. A lot of the time that's not really needed if your password is sufficiently secure, but "better safe than sorry". This is not all that different.
You can then try to log into every account, with passwords generated with the default settings.
i.e threat model.
A lot of security processes are not designed for say state actors with library of 0- days or monopoly on violence(i.e. $5 wrench) that doesn’t make them bad.
Security is a spectrum, perhaps some subset users needed a more secure system most probably still benefited from this tool ?
When a password manager maker finds a vulnerability they should absolutely tell their users to regenerate their passwords!
Just because there aren't million at stake doesn't mean you can't bring someone to ruin.
You may be using it to protect extremely sensitive information that could have people killed - that’s more important than a few million dollars in imaginary money
Now, had I spend the same amount of money on bitcoin that I did on the janky underpowered miner setup I put together by not quite understanding the math, my lost-password fortune would approach $1MM.
Either way, I lost my password.
He doesn’t seem to be very thankful.
What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.
In the context of understanding that Bitcoin is the best performing asset over its admittedly small lifetime, then it just sorta kinda might just start the process of making sense to unthaw a little.
This justification is only valid for certain time-scales however, and once you get into a discussion of that it can easily degenerate into cherry-picking and misaligned points - and I can be accused of cherry picking in limiting my judgement to "over it's admittedly small lifetime".
Basically, it comes down to a difference of opinion in the long-term value of an asset that hasn't existed long-term. If using the only available data, being short-term, as a guide, then it could be predicted to be a great investment.
Past performance is not a guarantee of future returns. True of everything. I guess you and me both are just showing our different colours based on, potentially, the exact same reference data (although I'm going to assume my reference data set is larger and/or more varied than yours).
Alternate comprehension of your comment: He's not gambling his Bitcoin, he's holding it. At the "end" he will still have the same number of Bitcoin. I believe your misunderstanding is that it may represent a smaller US dollar value and therefore he's gambling his bitcoin, however this means he's actually gambling the value of his bitcoin - which I specifically didn't say.
This is the type of cultish speak that makes it insufferable to listen to your sermons.
Yes, he is "holding onto" his Bitcoin. But based on the interview it represents something like >90% of his net wealth. Putting >90% of your net wealth onto an extremely volatile asset like Bitcoin can fairly be called "gambling". Some gambles have positive expected values and some gambles have negative expected values, but taking risks of such level should be called "gambling".
There is very little meaningful distinction between "holding onto" Bitcoin and "buying" Bitcoin. The fact that he already owns the Bitcoin doesn't make it any less gamble-y.
> At the "end" he will still have the same number of Bitcoin.
Nobody here claimed otherwise. You're attacking some kind of weird strawman argument.
So trading Bitcoin for dollars is almost always a bad trade.
> What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.
This implied selling btc to get dollars is less risky than holding BTC. I replied to that statement. You will likely lose more value holding dollars than holding BTC. Neither is an investment, they are both an asset.
At no point in the story did the person "have" 3 million dollars worth of USD. They had Bitcoin worth 3 million dollars. The letters "$3,000,000" refer to the USD-denominated value of the Bitcoin. When they talk about "risking it", they refer to the idea of keeping the Bitcoin, as opposed to selling the Bitcoin and then doing something else with the money. It's not specified how exactly one might invest 3 million dollars, but no reasonable person would keep the whole amount in a bank account.
Nobody implied that holding 3 million USD in a bank would be a good idea.
Michael waited until it rose to $62,000 per coin and sold some of it. He now has 30 BTC, now worth $3 million, and is waiting for the value to rise to $100,000 per coin.
I'm betting his retirement math worked out to $4.4 mil before taxes. And, $100k is a human-bias round number that BTC is widely expected to hit in the next year.
Dollars are much less volatile and thus less risky than any crypto currency I know. A perfect intermediate step before investing in some equity or some other thing that produces value.
Bitcoin only has value because someone else is willing to pay for it. That can hold true until it suddenly doesn't. If Bitcoin disappeared today, the world would go on without blinking. Nothing would stop functioning. That is of how little use it actually is.
That said, I'm a great believer in the meme value of Bitcoin and the greater fools. I hold several, with the belief that someday enough other fools will pay me a lot more fiat money to allow me to retire in style.
NOT keeping it in Bitcoin is some next-level stupidity, by the simple analysis of trends over the time he’s held it.
And the inflation produced by the creation of broad money over the last 3 years hasn’t even come home to roost, yet.
I’d say he’s being ruthlessly analytical, not greedy.
Can someone help me understand this? If his 30 BTC are now worth $3 million, that comes down to $100,000 per coin. But he's waiting for the value to rise to... $100,000 per coin?
https://services.packetizer.com/btc/ says the current BTC price is ~$68K.
Call it the Moore’s Law Fund.
(Fyi, one very marketed video tape was discovered when the contents of a certain celeb's storage locker was put up for auction. Imagine the possibilities if one collected all the storage devices thrown away in a particular LA neighborhood. Or DC.)