French police free kidnapped Ledger executive
moneycheck.com
moneycheck.com
Physical security primer for Bitcoin (2019), https://www.youtube.com/watch?v=HUgPhPkS2yc
I’m gonna go out on a limb and say that ransom was paid and that’s how they were able to locate the Ballands.
We'll probably have more details about this in a few days just goes to show how you can't hide on public blockchain ledgers.
It's not a political "cap on how much to spend on saving somebody's life". There have of course been rescue operations more expensive than that per person, and some medical expenditures exceed that cap as well.
And in the US, these drugs are much more expensive.
In many countries, including those with both socialized and private healthcare, insurance companies routinely pay for treatments costing much more than the statistical value of life.
Also, these incredibly expensive single-dose cures usually are that expensive because they don't benefit from any economies of scale and/or haven't recouped their investment yet. In competent healthcare systems, the price is driven down substantially sooner rather than later for almost all drugs through negotiations.
In any case, if there is any sort of kidnapping or hostage taking they send the tactical units.
To foreigners, GIGN is perhaps best known for being one of the counter-terrorist teams in the Counter Strike game.
Here's an example of an intervention, a video where they shoot in a guy's leg (long distance, with a submachine gun...), to prevent him from shooting himself:
It's just a matter of time when this information falls in the hands of organized crime. I have since then moved to another wallet and am thinking of selling my house and moving. I have taken steps to ensure that none of the apps that have my crypto balance do not access my location (graphene os with location disabled and always on VPN etc.)
This news bothers me. Maybe the criminals asked for data access as well?
https://www.bitdefender.com/en-au/blog/hotforsecurity/hacker...
Probably the most dangerous and costly data leak ever. Can't believe Ledger was able to stay in business after that.
Luckily, we were renting.
Because, apparently, my product was "f*cking it up for other businesses."
My usernames like here are random words.
If you know what you're doing, it's worth it. I plan to sell my company within 12-18 months and retire. And, yes, I'm certain that I will do it.
I can't imagine being a celebrity. Fame must be a nightmare.
I know the details cause I work in the field. It's quite crazy that they are still in business.
Coldcard if you aren't into shitcoins, and Keepkey if you partake in them would be my choices. I would have recommended Trezor at some point but their customer data leak tainted their image for me, they've made a lot of their customers targets just because they chose to use a third party to handle customer data for marketing purpose, if you run a business this sensitive, do this in-house and apply banking standards for this data handling, seems like a no-brainer.
Like so much in this space people think with their wallet and will villainize anyone who doesn't help sell their bags.
I'll add that even if that didn't make them a joke to you, I am just as concerned by their customer data leak (similar to what I've mentioned above for Trezor) and that alone makes me not want to recommend them, I just didn't mention it as the other point is egregious enough on its own.
Do you realize some people value (probably wrongly in this case) convenience over absolute security?
There’s nothing wrong with offering additional options.
I'm guessing there has been far more crypto lost through people forgetting/losing their keys than by having been hacked. Though personally I prefer to lose it speculating on the futures markets. People are idiots a lot of the time.
If these red flags are not red enough for you, go on, use them, I refuse to recommend them anymore for the stated reasons, especially when there are alternatives with better security/track records.
Well that's not even close to true. Only the hardcore Bitcoin maximalists were pushing that lie because ledger was supporting Bitcoin cash. What a weird pathetic lie to keep telling all these years later.
The no-brainer is thinking that cryptobros are going to do the opposite of whatever banking standards are. Following existing standards in not what disrupters do. It's not what someone flaunting all of the traditional rules of "fiat currency" do. Expecting a scorpion to not sting you is on you.
Are you sure that's not just for Bluetooth access (which shows the same message, since it can indeed be used to derive somebody's location)? What business reason do they have to send users' location to their servers?
> graphene os with location disabled and always on VPN etc.
If you don't trust Ledger – how much do you trust your VPN provider? They know both your original IP and what you're doing on the Internet (or at least to which services you're connecting).
It’s because companies were using Bluetooth scanning in apps combined with known location beacons to work out users locations.
VPN is just an extra layer. I'm sure VPN can see I'm connecting to the wallet's servers, but they can't see my crypto balance (I hope the communication is encrypted by the app).
Well, the big difference (for what OP is worried about) is that two distinct companies would need to be compromised instead of just the one.
I could put down any name and nearby(ish) address I want...
Any of widely used VPNs is much more generalized. Chain two or more in case of real concern.
Alternatively, a smart contract could require large transfers to escrow for X months, and could have a secret poison pill such that it would abort after 30 days if you used a trap password.
Edit: Given the downvotes I guess people just wanted to snark? I interpreted this as a technical question but maybe I misread.
Bitcoin literally has timelockS (multiple kinds) built-in in its scripting since its first release...
The point was not that this alone would make bank obsolete, but rather that this isn't just something "new" cryptocurrencies feature.
Oh I see, and I agree with you. Sorry, my mistake.
If you have a bank account in the same country, you also have an owner.
Though doing a kidnapping in the middle of France is pretty ballsy anyway.
If it is, then we'd be fools not to try, and having the trusted third party is just the better of several bad alternatives.
But it is a pretty audacious claim. I wish there were more radical optimists among us pursuing such things. Pity that that's not what most crypto is these days.
I draw a pretty thick line between what we're seeing out of it today and what we should be demanding of it.
That seemed to rely more on good policing than the second amendment.
Except that having achieved feature parity, we'll then be in a position to consider new features which may not have been possible on the previous architecture.
good point, but you're not taking into account the deflationary spiral
But its not bitcoin, so somehow its the shitcoin and the glacially frozen development environment that is bitcoin is what all the get rich quick cryptobros obsess about. I will never understand.
Also it's not clear that that would work. If I got a call:
> They're gonna kill me if you don't sign this transaction.
I'd probably sign it rather than let my friend die to prove a point to the bad guys that you don't kidnap people on FooChain.
Or at least that's the only way I can see it working. It's gotta be based on consent, not scarcity.
The cryptocurrency proposition is that that solution can be improved upon without implicitly trusting the state. I don't have that solution myself, but I'm not convinced that it can't exist. We'll know they've found it when these things stop happening, and it starts feeling like the riskier thing is to keep your money in a bank. Or maybe what they come up with doesn't feel like money at all, who knows.
When I try to imagine such a protocol, it involves a web of trust and crowd-sourced metadata such that people can refuse to accept coins which don't also come with proof that they're involved in activity that those people consent to. (A deficiency of dollars being that when I accept one I have no idea whether the loan that created it is for a venture that helps me or harms me, or whether the previous owner got it as a kidnapping ransom).
In such a scenario, the ransomed coins become useless without a backstory that identifies them to the recipient as non-harmful. If that backstory becomes prohibitively difficult to fabricate, then perhaps the crime doesn't happen.
in this case most of the ransom has been blocked which isn't new. many of the major crypto heists ended with arrests due to traceability of the funds or unusable funds due to blacklists.
It's nice that there are tools available to prevent such things in theory, and it seems like there's some traction in the right direction, but what matters is whether it's safer in practice. I'd love it if that happened soon, but it doesn't seem likely.
In the real world the ultimate countermeasure is bullets. All the rest is to avoid reaching this last resort.
Doing a kidnapping and getting a ransom is probably not too hard, but being on the run forever afterwards might not be worth it to most. People with money can hire their own bounty hunters/or plain criminals to go after them afterwards. Or just announce a bounty high enough (in dark channels, your high profile security company has access to) so people will do the hunt for free.
Most people like to boast about their action - so competent here means keeping quiet about it forever and coming up with a good excuse for why they have that money.
Indeed, selling drugs is apparently easier. And I can imagine the cartels don't want to risk their daily buisness, by kidnapping the wrong person from the west, as that would mean more heat on their buisness. But they surely do kidnappings and worse. Mostly in their fight for local control as far as I know.
Last summer, a 25 year old crypto influencer got kidnapped and his body was found in my neighborhood a few months ago. [1]
[1] https://www.cbc.ca/news/canada/montreal/kevin-mirshahi-ident...
In Toronto it happens quite often, not everyday, but way more often than you'd believe.
I would probably start with how people use their money. If people have t funds, they usually aren't going to move it each day. So start with a fixed, daily spend limit. That's simple, to start with. Then past the spend limit, you might have extremely large, outlier transactions. This is an interesting phase because with actual non-shit-tier security you could have a secondary layer of confirmation. This could be based on different panic codes. Some could indicate that the transfer is being made under coercion and to notify law enforcement, some could indicate to accept the transfer and notify, and so on. You could outsource this to a third-party. Do you see what I mean? All this shit is easy to do with cryptography and actual good design. But no ones done it. I thought of this in the time it took to write this shitty post.
Provable deniability schemes can be done to make it look like a wallet only contains a certain amount, too, using various private transaction schemes. This is nothing new. These attacks of being forced to do reveal keys and so on are things cryptographers have thought of for a long time. It's why you had Truecrypt have the fake volume. There is other stuff you can add to the security scheme. Giving different persons a key and making them sign their portion. Co-signing by third-parties (already a thing -- the scheme I like best is keys.casa). Many different ideas to allow for funds to seem like they've been "sent" then allow for revocation later on. You could have all different enhancements to high value, anomalous transfers like forcing the incumbent of transfers to take longer and have a clearing phase and so on. I'm sure there are plenty of ways to improve it even further. Just some ideas for how to stop attacks like this.
Whenever I see headlines about hacked exchanges, hacked wallets, lots keys, broken transfers, etc... I just think that we're still at the stage where there's a fractal of shit and we have to do better. Make everything work flawlessly and without even thinking about it.
The transfer would be initiated by the associates who are free. What would a panic code help there?
The only thing which might change things is the ability to reverse transactions. That would make the kidnappers keep them longer. At the cost of making every transaction on the blockchain less trustworthy. Not really a clear win.
...and they wouldn't have helped in this case, see other comment about that.
You use them to sign transactions that are perfectly safe even if your computer / phone where you initiated the transaction is infected with malware. They give you a chance to confirm that the transaction you're signingon the hw wallet is the one you initiated on your computer.
> daily spend limit
> different panic codes
> Co-signing by third-parties
What you describe already exists in "software multisig wallets" on smart contract blockchains. In essence they're smart contracts that require n of m signatures to initiate a transaction and can handle variable spending rules, custom signing schemes, 3rd party signers, things like 2FA / email for signing. In theory they can be implemented for non-smart contract blockchains like Bitcoin using multi party computation schemes like FROST (https://github.com/ZcashFoundation/frost) but that's a lot harder
Found the article: https://www.theregister.com/2005/04/04/fingerprint_merc_chop...
I don’t have any crypto but I’m worried about those who have it at scale.
Guns and crypto both have unique properties: criminals want them, and they want there to not be a connection between their identity and the item they plan to do crime with. The obvious solution, for a criminal, is to steal someone else's guns or crypto, not for the value of the object itself but for the fact that it has your fingerprints on it and not theirs. It's a funny kind of identity theft.
yeah uhhhhhh, what about all of their newsletter subs and device sales shipping data though?
I wonder if he got one of the threatening ransom letters in the mail and didn't pay because they said it was a scam?
https://www.bitdefender.com/en-au/blog/hotforsecurity/hacker...
(Submitted title was "Kidnappers sever finger of Ledger co-founder David Balland".)
One wonders if the attackers were paid anonymously in crypto-currency.