Bitcoin thieves threaten real violence for virtual currencies(cnbc.com)
cnbc.com
Bitcoin thieves threaten real violence for virtual currencies
https://www.cnbc.com/2018/02/19/bitcoin-thieves-threaten-real-violence-for-virtual-currencies.html
51 comments
I've been following these sort of cases and I haven't found one article that actually publishes the alleged transaction hashes of the event.
For better or for worse, there would be tons of vigilantes who would be happy to track down the current location of these funds.
That is, until the robbers figure out they can require the hostage to convert into Monero first.
For better or for worse, there would be tons of vigilantes who would be happy to track down the current location of these funds.
That is, until the robbers figure out they can require the hostage to convert into Monero first.
> For better or for worse, there would be tons of vigilantes who would be happy to track down the current location of these funds.
But for what good? Couldn't the criminals just as easily create a throwaway wallet?
> That is, until the robbers figure out they can require the hostage to convert into Monero first.
Can't the criminals convert it to monero themselves after it's transferred to the throwaway wallet? Why does the hostage have to be the one to do it?
But for what good? Couldn't the criminals just as easily create a throwaway wallet?
> That is, until the robbers figure out they can require the hostage to convert into Monero first.
Can't the criminals convert it to monero themselves after it's transferred to the throwaway wallet? Why does the hostage have to be the one to do it?
So they're on the hook with the IRS.
Has anyone done a serious audit on Monero? I have a feeling people are overconfident about it's anonymity.
Picture Tor. Now picture your browsing history is stored forever so if there's ever a bug in the protocol, it all goes clear...
Picture Tor. Now picture your browsing history is stored forever so if there's ever a bug in the protocol, it all goes clear...
That's basically the current state of things with Tor, under the what I think is very real assumption that all traffic is stored.
> That's basically the current state of things with Tor, under the what I think is very real assumption that all traffic is stored.
I mean, systems like Tempora[1] and the NSA's Utah data center[2] are known. Tempora apparently stores data for 3 days and metadata for 30 days.
I'd concede they may store metadata, but I seriously doubt they're storing the full traffic. That doesn't seem doable from a logistical standpoint.
[1] https://en.wikipedia.org/wiki/Tempora [2] https://en.wikipedia.org/wiki/Utah_Data_Center
I mean, systems like Tempora[1] and the NSA's Utah data center[2] are known. Tempora apparently stores data for 3 days and metadata for 30 days.
I'd concede they may store metadata, but I seriously doubt they're storing the full traffic. That doesn't seem doable from a logistical standpoint.
[1] https://en.wikipedia.org/wiki/Tempora [2] https://en.wikipedia.org/wiki/Utah_Data_Center
> That doesn't seem doable from a logistical standpoint.
Surely you're not going to cite budgetary constraint.
Surely you're not going to cite budgetary constraint.
As a crypto-outsider I wonder what would happen if the transaction hashes of these robberies we're being flagged as robberies?
Doesn't the blockchain allow for tracking of any sufficient transactions and thus allow for descendants of flagged transactions to be prohibited from ever being converted into real currency again?
I guess, the "leverage" in this case would be that any platform/exchange/etc. that wants to go "official" (eg. IPO, or paying capital gains taxes) will have a problem if there are flagged funds in their books.
(Sorry, if this sounds ridiculously stupid for crypto guys)
Doesn't the blockchain allow for tracking of any sufficient transactions and thus allow for descendants of flagged transactions to be prohibited from ever being converted into real currency again?
I guess, the "leverage" in this case would be that any platform/exchange/etc. that wants to go "official" (eg. IPO, or paying capital gains taxes) will have a problem if there are flagged funds in their books.
(Sorry, if this sounds ridiculously stupid for crypto guys)
The problem is that thieves will often quickly mix the stolen coins with untainted coins. So, there will be a large number of descendants of "tainted" transactions, the majority of which are held by completely innocent people. A real-life analogy would be taking stolen gold nuggets to an unknowing goldsmith who melts them together with gold nuggets from other customers and gives back freshly minted gold pieces.
That practice would stop immediately if there was some risk to the non-criminals/other criminals, to lose there money by mixing it, wouldn't it?
Can you pitch an example of this risk that wouldn't make the currency useless (like too risky to have anyone else hold it or arbitrate it) or ridiculous (KYC-style constraints)?
What is the mechanism of punishing the tainted the money going to be and the mechanism for deciding which money is tainted?
What is the mechanism of punishing the tainted the money going to be and the mechanism for deciding which money is tainted?
Oh, there's like twelve problems with trying to implement colored coins; I'm just saying the existence of mixers isn't one of them.
Who is the 'judge' in these cases responsible for updating the blacklist? How do you verify certain coins were stolen as opposed to an angry/regretful buyer?
In the real world, you'd file a police report and then tell your bank. And let the bank put a hold on the transaction.
That way if it was buyer's remorse you would have committed a crime by filing a police report in the first place.
That way if it was buyer's remorse you would have committed a crime by filing a police report in the first place.
In the cryptocurrency world, involving a central authority really doesn't work.
Is that a bug or a feature?
Edited to add:
There is this idea of trust in centralized and decentralized currencies, and they're both different.
In the centralized currency I can trust that if someone was ripped off there's recourse, However, in a decentralized one I cannot trust there's recourse?
Edited to add:
There is this idea of trust in centralized and decentralized currencies, and they're both different.
In the centralized currency I can trust that if someone was ripped off there's recourse, However, in a decentralized one I cannot trust there's recourse?
It's a fundamental architectural decision that has both advantages and disadvantages. It means that there is no single point of failure, but it also means that it's difficult or impossible for the system to remedy things such as theft.
Yes, and even the "no single point of failure" thing is overrated. For people using cryptocurrency to try to do things (as opposed to the system perpetuating itself), there are lots of risks caused by irreversibility.
> in a decentralized one I cannot trust there's recourse?
Bingo. How you acquire, secure, and use your currency should come from the trustless nature (of course, speculation and Bitcoin as a "better Visa" has tainted perspective which is why hacks and thefts are common)
That said, most physical assets have no recourse either, aside from legal recourse. Same as Bitcoin.
Bingo. How you acquire, secure, and use your currency should come from the trustless nature (of course, speculation and Bitcoin as a "better Visa" has tainted perspective which is why hacks and thefts are common)
That said, most physical assets have no recourse either, aside from legal recourse. Same as Bitcoin.
> That said, most physical assets have no recourse either, aside from legal recourse. Same as Bitcoin.
But bitcoin is electronic. And many asset transactions done electronically (credit card, checks, bank transfers) do have some form of recourse.
Even with cash, one can record the serial numbers of your bills and give those to the FBI if they're stolen. In fact, it's pretty common for high end bill counters to offer this capability.
But bitcoin is electronic. And many asset transactions done electronically (credit card, checks, bank transfers) do have some form of recourse.
Even with cash, one can record the serial numbers of your bills and give those to the FBI if they're stolen. In fact, it's pretty common for high end bill counters to offer this capability.
Physical assets can be, and frequently are, insured. If they’re very valuable, the insurer will undertake investigations, and involve law enforcement if needed.
Definitely a feature. Bitcoin is a response to centralization; decentralization is its raison d'être
To me, it just seems like if a decentralized currency is the future, fraud protection might be a necessary component before
people jump on board en masse.
Otherwise stories like this make crypto currency look like the wild west.
Otherwise stories like this make crypto currency look like the wild west.
In the case of major hacks, the exchanges are already doing something along this line internally; it's just not baked into the protocol.
It's also ridiculously easy to DoS. I've heard stories of exchanges freezing funds that were two hops away from gambling sites. Now, buy something with a gambling withdrawal and watch exchanges freeze the merchant's account.
Last week a lottery winner requested anonymity and has yet to claim the millions as anonymity is not how it works.
I wonder if a PR company helped with this article as there are lots of references to experts with products to sell.
I wonder if a PR company helped with this article as there are lots of references to experts with products to sell.
That is how it works if done correctly. There was a process for her to get the money through a trust that wouldn’t be linked directly to her, but she signed for the winnings in a way that doesn’t allow that process anymore.
Relevant comic: https://xkcd.com/538/
I'd really like to see zero-knowledge transactions as default in the future, just to avoid the sendee seeing your wallet's balance.
I'd really like to see zero-knowledge transactions as default in the future, just to avoid the sendee seeing your wallet's balance.
Surprise - crypto does not solve physical violence. It’s meant to solve virtual economic violence by governments.
Well it certainly doesn't do that...
It certainly does, though not categorically. Nonetheless, I'm sure the people who manage to regain a measure of control in their lives by using Bitcoin welcome the opportunity. https://www.theatlantic.com/magazine/archive/2017/09/big-in-...
NK, Venezuela, and Russia disagree.
Perhaps this classic XKCD should be updated for Bitcoin:
https://xkcd.com/538/
https://xkcd.com/538/
a fairly well defined threat: https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
Safety deposit boxes are quite cheap, around $20/year. It will probably become a norm to store most of your coins in cold storage in a bank. Physical security is expensive, and banks are good at it.
>Safety deposit boxes are quite cheap, around $20/year. It will probably become a norm to store most of your coins in cold storage in a bank. Physical security is expensive, and banks are good at it.
Still doesn't change the fact that I can kidnap your family and hold them ransom until you go to your safety deposit box and get the bitcoin to send to me. The problem is with the non-reversible nature of the payment system, and the fact that it exists outside the realm of a justice system, not with physical security.
Still doesn't change the fact that I can kidnap your family and hold them ransom until you go to your safety deposit box and get the bitcoin to send to me. The problem is with the non-reversible nature of the payment system, and the fact that it exists outside the realm of a justice system, not with physical security.
But we're not talking about kidnapping. We're talking about someone breaking into your place, and hitting you with a wrench till you send your coins.
In the case of a kidnapping, it doesn't matter how you store your money, even if it's regular dollars, you will get them from your account and you will send them anywhere.
In the case of a kidnapping, it doesn't matter how you store your money, even if it's regular dollars, you will get them from your account and you will send them anywhere.
They could do the same if you store physical gold in your safe deposit, but rich people vault gold without any problems.
Gold is much harder to move around, and when you'll try to convert it back into dollars you'll find out that nobody buys bars of gold without extensive origin paper trail.
Bitcoin does not exist “outside the realm of a justice system”; it is as much subject to such systems as any other currency is.
Justice systems, like the thieves in this article, operate ultimately by the application of the threat (and reality, as necessary) of physical violence to ensure compliance, and they deal with non-physical subject matter all the time.
Justice systems, like the thieves in this article, operate ultimately by the application of the threat (and reality, as necessary) of physical violence to ensure compliance, and they deal with non-physical subject matter all the time.
This approach suffers from several different problems:
1) governments, banks, regulatory authorities can seize the contents of your deposit box at their discretion and often without due process
2) if the bank burns down, your funds are toast
3) not quickly accessible
There are much, much better options for bitcoin security that don't involve depending on steel bank vaults to keep numbers safe/secret.
1) governments, banks, regulatory authorities can seize the contents of your deposit box at their discretion and often without due process
2) if the bank burns down, your funds are toast
3) not quickly accessible
There are much, much better options for bitcoin security that don't involve depending on steel bank vaults to keep numbers safe/secret.
So none of the convenience of a bank, but all of the centralization.
AES256 + 40-char passphrase is more secure than any physical structure ever built. Just encrypt your wallet and save on multiple USB sticks / S3 / Dropbox / etc.
Ok, so if I'm a bad guy, I will threaten you with violence, that will be enough for most people to send the coins. There are very few people in the world that can withstand actual torture, especially of the loved ones.
Counterpoint which has already been proven effective re cryptocurrency: https://www.xkcd.com/538/
https://www.engadget.com/2017/12/30/cryptocurrency-expert-ki...
https://www.engadget.com/2017/12/30/cryptocurrency-expert-ki...
I don't want to be my own bank. There are many reasons why people stopped keeping their liquid wealth under their mattress.