12 ms·
Casa Client Case Study: The Tinder Trap
- akarma 5y ago> If a stranger mentions being into crypto but then does not actually seem to know much about it, consider that they may simply be fishing for a specific type of victim. Or, more likely, they're just trying to impress you and find common ground! I've seen this many times on dating apps but have never been drugged. A lot of this advice is great, regardless of whether you're into crypto, but this point is a bit much.
- deregulateMed 5y agoThis is one of my biggest fears. As a result I use the supposedly not ok, security by obsecurity. (Along with other normal precautions) I don't tell people which Bitcoin wallet I recommend, I simply say "I don't tell people where I hide gold". Although not sure if I could survive devil's breath.
- tppiotrowski 5y agoDidn’t this comment make you a potential target?
- afavour 5y ago23 day old account, no bio listed... I don't think there's much personal information leaking out there.
- deleted 5y ago[deleted]
- deregulateMed 5y agoWhat information in particular did I give away? This is important to me, please let me know.
- tppiotrowski 5y agoYou implied that your biggest fear is getting your crypto stolen which implies that you have crypto to steal. From your comment history someone could now attempt to find your real world identity: you use a Samsung phone, you went to engineering school, you run a website, etc.
- deregulateMed 5y agoGross, I won't buy Samsung products ;)
- tppiotrowski 5y agoSecurity through obscurity. Your crypto is safe :)
- tablespoon 5y ago> As a result I use the supposedly not ok, security by obsecurity. Security by obscurity is perfectly OK as part of a layered defense, where your systems are also secured properly. Where it is not OK is when you don't bother to secure your systems because you assume they're hidden and no one will find them.
- deregulateMed 5y agoYep. It's one of about 5 methods I use, depending on how you count them. I don't even offer security advice or mention the 5.
- hugi 5y agoI prefer to use security by obesity. Meaning I won't get any Tinder dates so my accounts are safe.
- MaheshC 5y agoYou the man. Loughed out Loud.
- ctur 5y agoOverweight people are worthy of, and capable of, finding love. I know your comment is in jest but it also propagates negativity in a way that is corrosive to others’ self-worth. For those who read your comment and feel bad that the humorous angle is reality to them… it isn’t. Don’t let the world make you feel bad about yourself. For those who read it and get a chuckle about fat people… your world view may benefit from some compassionate adjustment.
- eloff 5y agoI'm going to get downvoted to hell for saying this, but instead of "not letting the world make you feel bad about yourself" you could also harness that negative feeling as a motivation to do something about it. Because being overweight is not you being the best version of yourself. Your health, energy, romantic life, and likely even career would improve if you did something about the problem. It is something that's entirely within your control to do something about. Life is short, it's too short to spend it fat. The best time to take action is now.
- norvvryo 5y agoPractically everyone finds fat people less attractive. Lying to them about their prospects will only cause cognitive dissonance when the truth eventually presents itself.
- lordnacho 5y ago> As a result I use the supposedly not ok, security by obsecurity. (Along with other normal precautions) It's not that it's somehow wrong, the problem with security-by-obscurity is that it's often mistaken for cryptographic security of the Kerchoff kind, where you can reveal the entire scheme, minus the secret key. Something like port-knocking is a form of security-by-obscurity that is technical enough that someone might mistake it for cryptographic security.
- polote 5y agoHonestly I wouldn't put too much trust into a SEO blog article. A better title would be. "If you get drugged and use Casa, you will be able to save your money"
- arcturus17 5y agoIt’s fine to sell something in a blog post if you’re providing something of value in return. They are also pretty overt about the fact that they are selling something. I’m not interested in the service in the slightest but I did get something from it. The read was somewhat entertaining and if I see a friend getting in a similar situation I will be quicker to warn them. As far as SEO drivel goes, I see much worse than this dozens of times per day.
- BelenusMordred 5y ago> SEO blog article The writer is Jameson Lopp. There's good solid advice in there for anyone, not just crypto holders, yes he's promoting his own company but it's a big stretch of the imagination to say the bloke is some SEO spammer. https://www.lopp.net/ https://www.lopp.net/
- user-the-name 5y agoIf it's Jameson Lopp, I would assume the whole story is just plain made up.
- statoshi 5y agoYou're free to believe that I (the author) made up this story. I'm not a fiction writer; the Bitcoin security space is exciting enough without needing to waste time making stories up. I'll note that we have seen several folks report being victims of similar attacks since we published this article. https://twitter.com/Disruptepreneur/status/1413149865475907598 https://twitter.com/Disruptepreneur/status/14131498654759075... https://twitter.com/jayzalowitz/status/1413165187205455882 https://twitter.com/jayzalowitz/status/1413165187205455882 https://twitter.com/e_acorral/status/1413168523250180097 https://twitter.com/e_acorral/status/1413168523250180097
- arbuge 5y agoRelated (though no Tinder involvement in this one): https://timesofmalta.com/articles/view/victim-describes-his-disbelief-as-700000-disappeared-under-his-nose.882790 https://timesofmalta.com/articles/view/victim-describes-his-...
- abstractbarista 5y agoWhile the article seems part-advertisement, the risk is real. Best not to let strangers know your worth, and use multi-factor authentication everywhere. It's a disgusting (and beautiful) world we live in!
- declnz 5y agoBut one point of the article was that he did have MFA - and it's no use in this scenario (attacker had physical access to second factor)
- mustafa_pasi 5y agoIt's not really MFA if it's all done on your phone.
- declnz 5y agoFair point! The article mentioned his laptop but it's unclear to me. Aside: It's something I worry about sometimes too on phones...
- tablespoon 5y ago> While the article seems part-advertisement It's all advertisement. The first paragraph is "Spoiler alert: their funds secured via Casa multisig remain safe." > the risk is real. I'm not so sure, I think there's a good chance this was made up. Unless this victim let on how much cryptocurrency he had early on in the conversation, this whole scenario seems too high-risk/low-reward to be very real. I mean, a Tinder account backed by a real person (supposedly with real photos to not put off the mark), waiting for people interested in cryptocurrency to steal it? Not drugging a lot of small fish who were bragging and attracting the attention of the police before finding a whale?
- Cthulhu_ 5y agoHere's one take: You don't go around calling yourself a crypto trader if you do not have a significant stake. The victim engaged with the thief because they too had "I am a crypto trader" in their bio, which indicates they may be equally wealthy. It's a kind of financial classism, common financial ground, possibly "falling into wealth" from low investments, etc.
- deleted 5y ago[deleted]
- lordnacho 5y agoBut if you don't have the keys to move your money, it becomes a lot less useful as money. It's still like gold though, something that you have a sort of vault that you rarely visit. If you got drugged and someone took your phone to do a bank transfer, I would imagine there would be some hope of reversing the transfer, with a whole lot of painful steps. With crypto it's pretty futile if they manage to move it. Also the $5 wrench attack can evolve, right? Just because you have your keys in different places doesn't mean you can be coerced into getting them together.
- break_the_bank 5y agoI suppose you can have a spend wallet and a net worth wallet.
- devoutsalsa 5y agoMakes sense to me. I keep maybe $1200 USD in the account tied to my debit card, and anything above that in an account w/o a debit card.
- Cthulhu_ 5y agoYup, same, it's pretty common sense to only have about what you need for a month in your checking account. That's something the banks themselves promote as well, since it's in their best interest to limit damage as well, since they will put the money back if you've been defrauded.
- echelon 5y agoThis is all too complicated for all but a handful of people. Crypto just doesn't work. It's far more harm than good. Every time a weakness is unveiled, we get hand waving from those most invested. It's bad for the environment, bad for crime, bad for laymen, undemocratic (vote with money), no knobs to adjust monetary/fiscal policy, and it poses as an alternative to government institutions that serve society with things like roads and health care. Why are we propping up the crypto whales to enable this trash fire?
- therol 5y agoTypical female bs, this is the kind of stuff that causes misogyny.
- joefife 5y agoU ok hun?
- BitwiseFool 5y ago"Not your keys, not your Crypto" is good advice, but I personally prefer to leave my wallet in the hands of a trusted large exchange like Gemini, Coinbase, or Kraken. Not only do they have better security than I do, they also have a whole slew of extra barriers in the event a malicious actor wants to drain my funds. I can freeze withdrawals, whitelist specific addresses, and put time/wait barriers to all of these things. Edit: I'm not recommending everyone do this. This is a personal risk-management calculation I have made based on my outlook.
- joemazerino 5y agoWhat if any of those exchanges get hacked or exit? Store offline.
- Retric 5y agoWhat happens if you get hacked? You lose all your money. The question isn’t what happens, but rather how likely it is to happen. I wouldn’t trust any of the current exchanges with my life’s savings, but up to around 20% is a different story.
- BitwiseFool 5y agoYes, but it's a risk I'm willing to accept because I think the odds of my own setup getting hacked or compromised is much higher.
- Cthulhu_ 5y agoOr like in this article, the victim gave access to their phone to the thief - that's 2nd factor authentication broken, and if their password manager is also unlocked (e.g. via Face ID or by coercion to put their password in) that'll give the thief full access to the account. Of course, they could put in a 24 hour delay as well for larger transactions. But that's a setting that the user should probably engage themselves. Also don't use Face ID or fingerprints to open up your phone or especially your password manager or 2FA app.
- lordnacho 5y agoInsurance?
- break_the_bank 5y agoWas wondering how vulnerable my traditional bank accounts are to this attack. I’m assuming this is one of those times that a daily limit could be useful, though that can also be bypassed to some extent by phone banking.
- Cthulhu_ 5y agoTraditional bank accounts have a number of securities in place. Depending on the bank: - You can't transfer money without filling in 2FA credentials - Suspicious transactions will be flagged (e.g. account draining amounts to another account you've never transfered money to) - Banks have insurance and will reimburse you the money, whether they can revert the transactions are not. Which leads me to: - Bank transactions are reversible - Bank accounts need ID. If money is transfered to someone, they will know the identity of the person receiving money. For dumb people it'll be themselves, for smarter people it'll be their money mule. (never allow strangers or new friends to transfer money through your account no matter how lucrative or trustworthy it may seem). Crypto exchanges are catching up, but crypto doesn't need to be transferred between exchanges. - Banks are licensed and pay to a national bank; if a bank goes bankrupt (ha), said national bank has you covered. See cases like Icesave and DSB Bank. But yeah, reversibility, anti fraud / theft prevention and insurance is banks' advantage that the crypto crowd is either unaware of or simply doesn't want to pay for, even if banks are cheap (because they get to play with your money)
- asdfasgasdgasdg 5y agoIf the money were in a bank or investment account, the worst this guy would have to deal with (in the US) is a little aggravation when getting the fraudulent transactions reversed. Personally I wouldn't reveal to strangers that I'm into crypto. It's like broadcasting the fact that you've got thousands of dollars of cash in your pocket.
- papito 5y agoI got roofied once in a bar and the next thing I knew I was going back to my place in the back of a car. They gave me weed, too. You are completely out of it, you will say whatever they ask you. This is how truth serum works, at its core. So, the girl(s) called Chase posing as my wife and transferred $500 out of my account. A nice chunk of cash, but not too greedy so I could let it go and not pursue it any further. You swallow the embarrassment and move on with your life.
- seibelj 5y agoThat is extremely scary. I hope you filed a police report? That person is a serious criminal.
- dannyw 5y agoEhh, for a lot of people $500 is the "I'd rather just move on" amount. If that happened to me I would move on, particularly because you don't know the criminals here and whether they'd seek retribution if you made a police report. If someone roofied you, they'd probably be willing to do worse things to you if you hassled them. Just some advice; speaking from life experiences.
- seibelj 5y agoA person drugging you at a bar, illegally entering your house, and then robbing your bank accounts. Felonies on top of felonies!
- 5y ago
- deleted 5y ago[deleted]
- klenwell 5y agoThis Simpsons joke was funny in the 90s because of its absurdity: https://www.youtube.com/watch?v=70ZMzE-wQOQ&t=80s https://www.youtube.com/watch?v=70ZMzE-wQOQ&t=80s Now it's funny because it's true! Download to Papa. Yoink-dot-adios-backslash-losers.
- vishnugupta 5y agoI've been working in the payments industry on and off for 15 years. I am yet to work with a payment method that does not support reversal (except for physical cash). As a last resort victims can file chargeback with their issuers or police. To begin with there are several layers of protection built in at acquirer, issuer, network and so on. Almost at each step there's an option to reverse the payment (or issue a compensating transaction) and finally the chargeback and legal recourse. Bear in mind that each of the business process of the current payment systems exists for a reason. They are the result of decades of learnings and trial and error. Are there plans to build equivalent features on Blockchain for crypto currencies? Or do their users have to go through the same painful failures?
- ramesh31 5y ago>Are there plans to build equivalent features on Blockchain for crypto currencies? The entire plan of crypto is to not ever allow that. That's the big innovation.
- _Nat_ 5y ago> That's the big innovation. You're right that a lot of folks don't want features like that, though I just had to point out that this isn't an "innovation" by any wild stretch of the imagination, but rather simply a policy in some implementations. It's mutable, too, for both banks and crypto: either could allow/disallow such a policy if those involved cared to make it work that way.
- saba2008 5y ago>simply a policy in some implementations Reversals would mean that there is some authority that can declare arbitrary transaction to be valid or not, and cryptocurrency is exercise in creation of payment system without such trusted party. So no, would not call it simply a policy.
- _Nat_ 5y agoIt's definitely a policy, in that it's a design-decision that could be changed to make it operate differently. For example, if a good majority of a crypto-currency's miners elected to fork to a new policy, then it'd just happen. And cryptocurrency isn't really about lacking a trusted-party so much as decentralizing the trusted-party. Which might sound pedantic, but it's an important distinction: there can be an authority that makes decisions, just it'd be decentralized. Future crypto-systems, e.g. probably a next generation that'll replace early systems like Bitcoin, would probably take a smart-contract approach. For example, a payment could be reversed under conditions encoded in a smart-contract. A well-developed system would likely end up including a system of checks-and-balances, appeals, manners of collecting evidence, etc., where trust is decentralized. For example, most folks would generally agree that a mature, well-developed system should allow someone to recover funds extracted from them under threat-of-violence if everyone agrees that that's what happened. That current systems are too limited to make such an obviously-desirable thing happen is an obvious non-ideality. Once someone makes a good system that fixes such problems, in a generally agreeable way that people can trust, it'll likely become a preferred system; it and its clones, etc., would displace older systems, and this whole no-reversible-transactions thing would become a minor footnote in early history.
- bpsh 5y agoSounds like a made up story for the purpose of self promotion to me
- statoshi 5y agoI wish that were the case. Unfortunately, while still rare, there are physical attacks perpetrated against bitcoin owners. I've been tracking them for several years. https://github.com/jlopp/physical-bitcoin-attacks https://github.com/jlopp/physical-bitcoin-attacks
- SV_BubbleTime 5y agoDidn’t you read about the part where Casa’s MultiSig easily protected him from financial ruin though!? I hear it’s better than having all your money at CoinBase. Plus there was the hard hitting advice that “always have a friend who knows all your plans check in with you, to make sure a crime organization isn’t plotting to steal your money”.
- deleted 5y ago[deleted]
- mabbo 5y agoCryptocurrencies offer a single property that is both good and bad: there is no authority who can reverse or block a transaction against the will of the participants. Lawsuits and criminal proceedings can cause government authority to direct banks and financial institutions to do what they say. Government can set rules to block transactions, or to demand more identification to be tied to a transaction. Even cash can be physically seized and taken by the government. I'm not arguing this is good or bad, just that it is. You can come up with a list of circumstances where this authority is a bad thing, or a good thing. And in cases like this, we see why that overriding authority can be a good thing. If your bitcoins are stolen, there is nothing anyone can do to get them back. They are gone.
- leifg 5y agoGovernment can also seize your crypto but that’s besides the point. When does non-reversal ever benefit the average Joe? The only scenarios I can think of is when you transact with non-trustable sources. E.g. buying “stuff” off the darknet (and even here you usually have an escrow). And that’s just not a use case in most people’s everyday life.
- heynk 5y agoYou might be interested in this "database" of wrench attacks. It's maintained by the same author of this article (Jameson Lopp). https://github.com/jlopp/physical-bitcoin-attacks/blob/master/README.md https://github.com/jlopp/physical-bitcoin-attacks/blob/maste...
- dannyw 5y agoThis is such an interesting account. I wonder to what scale this happens. Surely after you get roofied after a tinder date with an attacker draining your crypto accounts, you'd file a police report and maybe we'd hear about it in the media?
- statoshi 5y agoIt's still pretty rare, but as the space goes mainstream I expect the frequency of such attacks to increase.
- analyst74 5y agounrelated, but this basically describes a large number (possibly majority) of tinder profiles. > Compare the person's profile photo when you meet them in real life. If it is questionable that the photos are actually of themselves, that is a red flag.
- m3kw9 5y agoCouldn’t Coinbase just add a hardware key to match this feature? It still doesn’t prevent internal theft but it will protect such fishing cases.
- etc-hosts 5y agoIt is funny that a man so obsessed with privacy, anonymity and his physical security still uses online dating apps. https://www.nytimes.com/2019/03/12/technology/how-to-disappear-surveillance-state.html https://www.nytimes.com/2019/03/12/technology/how-to-disappe...
- MattReigns 5y agoHow I recouped stolen crypto currency coins and tokens from scam hackers on telegram: People all over the world are hearing about the fast profits early investors are making on Bitcoin and other coins and want to join the party and make a fast profit .But be sure, where big money is, there are also companies that are abusing and taking advantage of this situation. Such was my situation , I had a fake telegram group admin contact me and gave me a phishing link in which my 12 recovery phrase were compromised. These evil persons gained access to my crypto-wallet and stole all my coins and tokens worth over $230,000 . I was in great despair due to this situation, I was confused till a group member on the telegram referred me to Coinwalletrecoup dot com. This recovery agent is really God sent. After relating all of my predicaments, details of incidence and necessary requirements for my recovery program , it took them less than a week to track and recover all of my tokens and coins back, they helped me hack the perpetrators wallet and all of my coins were returned to me .I am so amazed , joyous and appreciative. I don't know what I would do without this specialist. They specialize in chargeback disputes and their team knows how to identify these types of scams.If you invested in Crypto and believe you have been scammed contact their experts today and they will help you recover your losses. Contact : Coinwalletrecoup dot com