Bitcoin Private Key Necromancy
pxdojo.net
pxdojo.net
Frustratingly, the author titled his post "Bitcoin Private Key Necromancy" but titled his Reddit submission "I wrote a tool to pull private bitcoin keys off dead harddrives" which is a far better title.
He recovered about 46 coins.
For physical problems: http://www.wikihow.com/Fix-a-Physically-Broken-Hard-Drive
I assume you already knew this, as you keep them on your freezer... and that this may not be applicable to your case, but this could be useful for other people anyway.
Do not replace the controller on a Seagate. You may have better luck with other manufacturers.
If there is valuable data on there, and it sounds like there is, pay the price to have it professionally recovered.
They have insurance.
It has the iPhoto library from the months before and a few years after my son was born. All I have from that period is whatever I emailed to friends, family, and Facebook. Music was restored from my iPod, movies were on DVD/Bluray, so only the leaving 60GB of photos.
First thing to do is to pull the drives out of the freezer and never ever do that again. Put them into a bowl of rice for 10 hours or so in order to get rid of that humidity quickly. Why doing that in a first place? What are you trying to achieve? This procedure was applicable only to one model of Fujitsu MPG drives that were selling 10 years ago. Pull the drives out. Seagates have a number of issues. Let me know what the symptoms are and I will let you know what you might be looking at $-wise.
Last I heard you had to have a backup to be eligible for this and they will pay to get the files that are updated since last backup.(!)
Of course, once a recovery lab is on the case they will most likely give you everything there is.
Point in case: Have some kind of backup, anything is better than nothing, it might worth something even it is a couple of months old.
If they can't detect which of the admins did it then what are they going to do?
Yeah, that's the only reason hosting companies don't mass harvest credit card numbers from their customer's websites
[1]: https://github.com/bitcoin/bips/blob/master/bip-0032.mediawi...
[2]: https://github.com/bitcoin/bips/blob/master/bip-0038.mediawi...
Edit: adding a strong pass-phrase /does/ give you a significant level of protection; While it doesn't offer protection from an evil maid type attack (where the attacker trojans your server, then you decrypt your key after said server was compromised) it does offer quite a bit of protection, say, from an attacker who has access to old backups but not your production system. So I think a passphrase on all of your important private keys is a worthwhile thing to have.
I just want to make it clear, once you decrypt that key from within a compromised system? all bets are off.
[1]https://www.schneier.com/blog/archives/2009/10/evil_maid_att...
[2]https://news.ycombinator.com/item?id=6148347 (of course, this specific attack wasn't as scary as it could have been, say if the same sort of thing was remotely accessible)
[3]http://theinvisiblethings.blogspot.com/2010/04/remotely-atta...
I suspect the answer is similarly that, unsurprisingly, most hosting providers are in the business of providing hosting, as opposed to running a front for criminal activities. And that anyone caught running this criminal activity would likely be fired and prosecuted.
And of course that there is an inverse correlation between the type of person interested in petty theft, and the type of person with the skills required to do this and not get caught.
For example it would save 17000 BTC that bitomat.pl exchange lost when upgrading Amazon EC2 instance to add RAM.
So while I trust device/disk wiping tools are effective, I'm much less trusting of my own memory about the files on any given storage device. Moreover, and perhaps more importantly it's rarely possible to guarantee that software is consistently doing the right thing with your sensitive data.
Therefore my rule is now to donate unwanted hardware but never to donate or dispose of storage devices without being certain the data is unrecoverable. This is a harder problem than it might at first appear.
Secure disposal of hardware is a problem growing worse in proportion to the number of devices we allow (or by inaction permit) to manage our personal data.
I use Derek's Boot and Nuke bootdisc for this purpose. http://www.dban.org/
It's straightforward to use, but it's also configurable if you want to be extra certain the data is gone. I think the default is 3 passes of filling the harddrive with random data generated via Mersenne Twister.
The bigger problem is what to to with a dead hard disk. It's usually easier to buy a new one rather than replace it, but an attacker could perhaps repair the disk to steal the data. At work we send any non-wipable disk to be physically shredded. At home I think I'd just hold on to all disks indefinitely.
For a drive with bitcoin on it, just move the coins to new addresses before disposing of it.
http://www.youtube.com/watch?v=vzodemYzswQ
"Is It A Good Idea To Microwave A PlayStation 3?"
http://www.youtube.com/watch?v=4rWyJXpezPs
"Is It A Good Idea To Microwave A Nintendo Wii?"
If you're paranoid it won't matter how many passes of zeroes you do. After 1 it's done.
If you're still paranoid, hard drives make great rifle targets.
Yet if you ask how to wipe a disk on a forum, you'll get user-space ideas like `dd` and `shred` :(
Computers with hard disks are obvious, but also consider mobile phones, tablets, games devices (that increasingly ask for sensitive information), PVRs, and so on.
There may be a point, if we haven't already reached it, where I can't dispose of a toaster without worrying about how to wipe its memory.
unlink(filename)
create(filename)
write(filename, random)
?
Though something that opens the file in append mode then seeks to 0 would probably overwrite the same HDD locations.You can avoid this with the 'conv=notrunc' option of 'dd'[1]. It will overwrite existing blocks instead of truncating (and possibly reallocating):
notrunc Do not truncate the output file. This will preserve
any blocks in the output file not explicitly written by
dd. The notrunc value is not supported for tapes.
[1]:https://developer.apple.com/library/mac/documentation/Darwin... > secrets.txt
the file is truncated, freeing blocks 1-999 (usually block 0 is zero-filled.) If you proceed to write random data it will go to newly-allocated blocks. Then a raw read of the original blocks will expose your secret data.With dd and notrunc, the random data goes to the original blocks, overwriting your secrets.
Are you saying this will not overwrite some of the blocks?
Here's a blog post about it http://alicious.com/secure-drive-data-wiping/ including references to some papers where they looked at the probability/possibility of recovery.
No rewriting or deleting. Mechanical only.
We remove platters, break them. After that, the value of data is far less for these things than the cost of recovering.
I lost some Bitcoins on an old phone that used Bitcoin Wallet (https://github.com/schildbach/bitcoin-wallet) by doing "Settings > Reset".
I tried using this app to find them by dumping the /data partition, but no luck. Apparently it uses a different wallet format:
The wallet file format is not compatible to wallet.dat (Satoshi client). Rather, it uses a custom protobuf format which should be compatible between clients using bitcoinj.
Any ideas on how to find such coins?
Then I'll examine the bitcoinj wallet format and write a tool to search for the private key within the phone.image file.
My email's in my profile.
That sounds like remarkably horrible UI design.
Being purely digital and having no institutional overhead, Bitcoin seems to "uncover" a lot of security and design problem in modern apps.
Depending on the type of filesystem used, it may have walked through all the blocks of the NAND Flash, erased them, and then marked them as 'ready for use'.
If you are very serious about this, your best bet is to (A) stop using the phone now, (B) dump the raw partition contents using the Android tools.
The situation might be better or worse if the phone uses eMMC, but the above holds. The chip itself does the Flash management (wear leveling, bad block detection, etc.). So it can hide more, but there may be leftover data from the old /data partition still in the unused blocks.
How would I find out?
Once the 256-bit private ECDSA keys were dumped in hex, I didn't even bother finding/writing a converter to WIF format. I just used brainwallet.org for that purpose (pasting the value in "secret exponent", and making sure to select "compressed" as Bitcoin Wallet creates compressed pub keys), then imported the WIF into a local bitcoind instance.
If I remember correctly, you need a special tool to pick the platters up out of the drive without rotating them, but aside from that just a new controller/assy.
It would be pretty unfeasible to attempt a brute-force, due to the number of encryption rounds.
More likely you have obtained someone elses wallet.dat file that they have encrypted and they do not know you have a copy of this wallet.dat so they are still using it, and you do not know their key but would quite like to access their coins.
send any new coins to a new address, sure you may remember the password but hedge against that possibility with another wallet, please. for my sake, for my sanity, do it for me.
smart and driven criminals will solve a lot of problems in ingenious ways you never thought of