13 ms·
How Jason Bourne Stores His Bitcoin
- ing33k 13y agovictim of homokov's cookie attack.
- Zr40 13y agoThe cookie attack is an attack against browsers, not against sites. The effect is that the server refuses your request.
- meowface 13y agoSounds to me like it'd be better to encourage people to pick longer passphrases (8 - 10 words instead of 4), in addition to using scrypt.
- vbuterin 13y agoAll you really need is to always prepend your username to your password. If people all did that, then 99.9%+ of these brainwallet thefts would already not have happened. Slow KDFs are just icing on the cake.
- panic 13y agoYou could also train yourself (using e.g. http://en.wikipedia.org/wiki/Mnemonic_major_system http://en.wikipedia.org/wiki/Mnemonic_major_system) to memorize a completely random private key.
- fsiefken 13y agoWhat if you suffer from memoryloss? Forgetfullness, traumatic experiences, dementia, headtrauma?
- vinceguidry 13y agoAlso you need to change passwords every so often, you're inviting disaster of the "holy holy holy fucking shit" variety if you start doing this and change every six months.
- aspensmonster 13y agoHappened to me relatively recently, actually. Had an encrypted machine that hadn't been rebooted in months. No backups (it's not production related, just a personal box, but still). Power outage hits. MFW when I can't remember the login after trying for an hour: https://31.media.tumblr.com/a5edfd83a17768f9f9dd4366e34ecad6/tumblr_inline_myycwy2dzv1raprkq.gif https://31.media.tumblr.com/a5edfd83a17768f9f9dd4366e34ecad6...
- atmosx 13y agoHappened to me too. I got this freebsd server, I use ssh keys to login. But I hadn't login for a while, so I couldn't remember the user's password (which gave access to 'root' via sudo). After 37 tries, I hit nailed it! I was that close from re-installing the system. It had automated backups so, no big deal... Just two-three hours (maybe more) would be lost.
- mike-cardwell 13y agoIf that was a Linux box, I would have booted into single user mode and changed the password. Or temporarily mounted the hard drive in a different machine and modified /etc/shadow directly. I assume you can do something similar in FreeBSD? Quicker then a re-install.
- atmosx 13y agoYes you're totally right. The machine was/is a embedded low consumption headless server, but you can do that using a FreeBSD image and VMware.
- matdes 13y agohttps://xkcd.com/538/ https://xkcd.com/538/
- oleganza 13y agoExcept you can lock your bitcoins in 5-of-9 multisignature transaction among 9 of your friends in San Francisco, London, Paris and Moscow with an agreement to not sign the transaction unless you are safe and can talk directly to them.
- reinhardt 13y agoBecause obviously everyone considering bitcoins has a dozen cryptogeek friends spread out in half a dozen countries.
- patrickaljord 13y agoIt's easy to get friends this way with irc and the internet you know. Besides, even if they are only spread around the country or a couple of countries it already makes things way harder. Regardless, passwords, even regular banking passwords are not meant to protect you against people that are willing to abduct you and torture you so I've always found this xkcd kind of unfair. Most passwords are meant to protect you from regular hacking attacks or internet thieves, not your local crazy mafia gang.
- kaoD 13y agoToo bad the Bitcoin protocol is hard-wired to accept at most m-of-3 transactions. More than 3 signatures is considered non-standard and rejected by peers/miners.
- sirsar 13y agoThe key, however, can be split an unlimited number of ways using Shamir's Secret Sharing Scheme or a similar protocol. http://en.wikipedia.org/wiki/Shamir's_Secret_Sharing http://en.wikipedia.org/wiki/Shamir's_Secret_Sharing
- Crito 13y agoI feel like Jason Bourne stores it in a sub-dermal implant.
- aspensmonster 13y agoIn his head, of course.
- DrStalker 13y agoI read the book. The first two thirds is all about him trying to withdraw money from a bank using 80s technology and processes; really painful to read and nothing that would come close to working today.
- n3m6 13y agoWAIT!!! Doesn't Jason Bourne forget everything?
- AlexanderDhoore 13y agoI'm creating the JSON Bourne Shell btw. Totally got dibs on that name!
- deleted 13y ago[deleted]
- ye 13y agoThe private key storage part is bad. What if you have a house fire and your laptop and all your clues burn? Just save your private key into something like KeePass with a long ass password and a couple of million of hashing rounds. Email the KeePass database to yourself, your family, put it on your server, all your computers, your cell phone, etc.
- altrego99 13y agoWhy can't I just store it in a password protected 7Zip file. What will happen?
- maxtaco 13y agoYou still need to remember a good password, but now you have to worry about keeping track of the file. If you lose either, you lose your coin. Plus 7Zip uses a PBKDF2-like key stretcher, but you're probably better off with scrypt, and you're certainly better off with a composition of PBKDF2 and scrypt.
- deleted 13y ago[deleted]
- lhgaghl 13y agoAm I missing something, or is it easier to just come up with a password that's not in a wordlist/rainbowtable than to trust (audit) this 13K lines of code HTML file? Also, I find this laughable: > Leave little cryptic notes around your house and office to remind you of what your passphrase is in case you ever forget.
- maxtaco 13y agoIt's likely the password you come up with will be better than the the unbroken 10 BTC WarpWallet challenge, so you have that assurance. Also, we implemented the protocol twice, using two different software stacks, and checked we came up with the same answer. You can probably convince yourself that WarpWallet works as advertised with about 10 lines of Python. We did something like that when building it. Because we encourage running this thing on an airgapped machine, you mainly need to convince yourself that we're generating keys as advertised (and not from a small known pool). The airgap would prevent this page from sending data back to a server, even if there was logic to do so (which there isn't).
- lhgaghl 13y ago> You can probably convince yourself that WarpWallet works as advertised with about 10 lines of Python. If only life were that simple.
- jcalvinowens 13y agoWarpwallet in C: https://github.com/jcalvinowens/miscellaneous/tree/master/fun-hacks/warpwallet https://github.com/jcalvinowens/miscellaneous/tree/master/fu...
- skorgu 13y ago> Copy the HTML to your AGM using a USB-stick. Good enough for the Iranians, good enough for you.
- maxtaco 13y agoSeriously, the centrifuges connected to your 2008-era Lenovo netbook might be totally rooted after this transfer.
- lukev 13y agoI like the idea of bitcoin, but way too many people (like this article) are just being stupid about it. It's baffling and depressing. Your retirement, really? At worst bitcoin is a speculative balloon. At best it is a novel, useful way to conduct online transactions. In no conceivable future is it a good place for a long-term investment of the majority of your assets!
- maxtaco 13y agoSorry, that was a little joke. I don't think anyone should hold more than a small portion of their total assets in cryptocurrencies.
- ericb 13y agoInteresting that we are now to the point where that wasn't obviously a joke.
- deleted 13y ago[deleted]
- smtddr 13y agoThat's because it's almost reality... sorta ...Fidelity ended up changing their mind for now, but for a moment it was real. http://www.businessinsider.com/fidelity-retirement-bitcoin-option-2013-12 http://www.businessinsider.com/fidelity-retirement-bitcoin-o... >>"The Bitcoin Investment Trust was previously approved by Fidelity as an eligible investment for accredited clients in their self-directed IRA accounts and investments began closing last week. We understand that Fidelity has decided to reevaluate this decision."
- patrickaljord 13y agoReally? You took that obvious joke seriously?
- lukev 13y agoHead over to /r/bitcoin sometime... Full of people figuring out how to buy bitcoins with a credit card, etc. Something about it drives people crazy.
- fharper1961 13y agoWhat is the recovery procedure if you lose access to the AGM? If I've understood correctly it is just to reinstall WarpWallet on another machine using the same passphrase. But what if we also can no longer access WarpWallet? What then?
- Gnewt 13y agoLuckily, WarpWallet's algorithm is public and therefore can be reimplemented even in the case of their disappearance.
- pippy 13y agoSometimes simple is good. Why not print off a few QR codes, and hide them around your house?