4 ms·
I hate the forbes.com website, but a great story. Guy's phone number got hijacked, then they reset his other accounts by sending codes to his phone number on fi
by dude01 10y ago
I hate the forbes.com website, but a great story. Guy's phone number got hijacked, then they reset his other accounts by sending codes to his phone number on file. Maybe we need 3FA?
- CodeWriter23 10y agoI still don't understand how jacking his phone yielded his wallet password.
- CydeWeys 10y agoOne of the accounts that ended up being compromised using his compromised email accounts was his Microsoft account, which he used to log in to Windows 10. Presumably the attackers were able to connect remotely, or maybe download his files out of the cloud, or something. They had the keys to the kingdom.
- thewavelength 10y agoAnyway, the wallet was password protected. Still don't get it.
- CydeWeys 10y agoIf you have access to the machine you can install a keylogger.
- TwoBit 10y agoThat may possibly work, but is uncertain and potentially requires a huge amountvof sifting over months.
- Xeoncross 10y agoWhat if the wallet was actually liquid in one of the online bitcoin banks which the browser helpfully logged them in as?
- CydeWeys 10y agoMany (most?) of the online wallets have 2-factor auth, though maybe that wouldn't come into play if the login appeared to be coming from a familiar computer.
- rebuilder 10y agoFrom what the article said, I understood the hard drive the wallet was on was encrypted. Once mounted, the wallet would be accessible to anyone with login access to the OS.
- iopq 10y agoThe wallet itself is usually encrypted as well. It's good practice, and it's available straight from the client.
- rebuilder 10y agoNowadays, yes. This wallet may have been quite old. Hmm, was there a spike in days destroyed recently...?
- TwoBit 10y agoI don't understand how they got into his computer in the first place. No amount of 2FA breaching could possibly get somebody into my Windows machine remotely. And not having a password for his wallet makes nonsense whatsoever. I'm thinking Forbes has something wrong.
- rebuilder 10y agoGoing by the article, gaining access to his Microsoft account was enough to provide access to his Windows machine. I'm not sure I'd trust Forbes to get this right, but a quick googling indicates that having access to the MS account the main Windows user is linked to will let you recover the admin password.
- ZenSwordArts 10y agoThe article says his password was 30 characters long. But maybe it still wasn't a strong password. Weak ones can be brute-forced pretty easily.
- bigiain 10y agoIf they knew what they had there (and the balance of the wallet was in the blockchain, they probably knew exactly who they were targeting here), you could throw an awful lot of resources at bruteforcing the password. (Lets face it, they had this guy's bank accounts and PayPal - I wonder how much of his own money they spent on AWS cracking his wallet password?)
- jschwartzi 10y agoTalk about adding insult to injury. Imagine someone using your credit cards to buy compute time to brute-force your passwords.
- TwoBit 10y agoYou can't brute force a 30 character password that has randomness. Not with all the computers on the planet together.
- bigiain 10y agoSure, depending on what you actually mean by "has randomness". "correct horse battery staple" is 29 characters, but it's _much_ more likely to fall to hashcat than "OckivpykophshifcuvTocJorj%opAd" I've only got 4 truly random passwords stored solely in my head, and they're all down at 12 chars because I need to write them down much above that instead of being reliably able to remember them (and yeah, I've got stuff I no longer have access to because I've forgotten the password...). There's a serious tradeoff to be made with a password for "millions of dollars worth of bitcoin" - where do you balance the "it's super secure" against the "Shit! I forgot the password!" (And if your first answer is "that's what password safes are for", then you've just moved the problem to the password safe's password...) (With a reasonable dictionary, "correct horse battery staple" will probably pop out from hashcat in under a second on a Raspberry Pi! ;-) )
- huh333i 10y agoHe was an early bitcoiner. This was an old drive he used for cold storage. wallet.dat was unencrypted in the early days.
- rebuilder 10y agoThat's the WTF for me here. I don't store anything valuable on the Windows 8 PC I run at home, but when I set it up, I remember feeling quite uneasy about the way the Microsoft account and the local user login apparently are one and the same. I assumed that surely it's just convenience and gaining access to the MS account isn't sufficient to give access to my PC - that would be insane, right? Is this being reported correctly? This sounds completely nuts.
- chillwaves 10y agoYou can create a local account independent of the MS network, they just make that option partially obscured.
- rebuilder 10y agoChanged my user account to local just now. Good thing I always assumed this computer is a sieve. I still have a hard time believing every single modern Windows OS is essentially intentionally backdoored. That's just completely, incredibly unacceptable.
- striking 10y ago"Ah, yes, I remember when I used to actually own my computer..."
- dgudkov 10y agoCould a Yubikey have prevented it?
- TwoBit 10y agoHow the hell does your Windows hotmail (or whatever) let you log into your machine? Those are unrelated systems with unrelated security schemes.
- kilroy123 10y agoSeems like he was very much targeted. Someone knew this guy and knew he had a LOT of bitcoin. If they actually remoted into his computer, waited until he mounted some external drive with the wallet and then acted. It's clear this was a targeted act. Poor guy.