TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How to lose $8k worth of Bitcoin in 15 minutes with Verizon and Coinbase.com

63 点作者 jackgavigan将近 8 年前

9 条评论

zubat将近 8 年前
The two common BTC loss stories:<p>1. I left in the hands of other people 2. I failed to keep it accessible to myself<p>It&#x27;s easy to lean too far in one or the other direction by leaving stuff on a commercial service or forgotten on a single device without backups. For most folks, paper wallet and safebox is the appropriate mix since it follows traditional physical security patterns and ensures some protection from theft or damage. A strong secondary option is to be online but obscure and not advertise where your valuable data rests - perhaps your keys exist on a backup service, but they&#x27;re tucked away such that an attacker has to think to look for them, and to do some forensics to track down their location. This buys time to hear the alarm bells of &quot;your password was reset&quot; and rotate anything valuable out of the compromised accounts.<p>Under no circumstances would I keep the money within any of these dedicated services: even though I use Coinbase and exchanges, it&#x27;s too easy to employ social engineering and privilege escalation to get in and take everything, so any value stored in them has be considered &quot;hot&quot;, and I only keep the amounts I want to trade on them(which at this moment is $0).
评论 #14475341 未加载
nightcracker将近 8 年前
A subtitle from the article that irked me: &#x27;I’m not giving up on crypto.&#x27;<p>Why would you? You were never using it in the first place. Exchanges aren&#x27;t bitcoin.
评论 #14482930 未加载
i336_将近 8 年前
The thing is, Verizon&#x27;s not <i>killing</i> anybody by this disaster. Upper management there probably still sees cryptocurrencies as a fad toy. I&#x27;m being pragmatic.<p>Here is an open idea that I have long wondered about. If you think this would work, you are welcome to have it and turn it into a startup (it could work as a free service, it could work on a subscription).<p>Make a duress system that allows people to open a fast-loading webpage or app, scroll down to Gmail, and hit &quot;<i>Fight!</i>&quot;. Then they&#x27;d scroll to Coinbase and click&#x2F;tap the button there too.<p>This service would then immediately log into your account repeatedly and change your password, along with your recovery email address and other information that, if changed, would make logging in a hassle (such as your security recovery questions). It does this as many times a second as possible, for I&#x27;m not sure how long.<p>My thinking is that &quot;wat, 42 password resets in 18 seconds&quot; is probably going to freak most well-designed services out, which will then hopefully lock your account... possibly saving it.<p>Better yet (I just realized), the app could lock your account, if the service allows it, after resetting your password.<p>--<p>The way I envisage the site&#x2F;app working is that, you input your account details (your actual password) into a locked tome with a passphrase. When disaster strikes you unlock the tome, perhaps with your fingerprint. The reason for this is that service APIs might not universally provide enough access to &quot;do good&quot;, if you will, and there&#x27;s also the consideration that the site might be up but the API might be down (a bit like Verizon being closed!).<p>Also, about changing the email, gmail allows you to do things like youraddress+alias@gmail.com, so the app could simply change the email to things like youraddress+98ea6e4f216f2fb4b69fff9b3a44842c38686ca685f3f55dc48c5d3fb1107be4@gmail.com, or variants that won&#x27;t freak gmail out if they have alarms on that sort of behavior.
评论 #14467896 未加载
acastroe将近 8 年前
How did the guy get past the first factor authentication?<p>(e.g. How did he get past the normal password?)
评论 #14467322 未加载
pawadu将近 8 年前
Found this depressingly insightful recommendation in the comments:<p><i>&quot;And consider switching to a non-traditional phone company like Google Project Fi.. can’t socially engineer them because you can’t even contact them (and it’s same auth as your gmail)&quot;</i>
pawadu将近 8 年前
&gt; Call your cellphone company and tell them you are likely to be targeted for social engineering. Request more scrutiny for making requests.<p>Didn&#x27;t this have the exact opposite effect when someone else tried? (can&#x27;t find the store anymore)
totalZero将近 8 年前
Verizon really dropped the ball here....it&#x27;s totally negligent to send a text with a number nobody will answer. I would sue Verizon.
willow9886将近 8 年前
Same exact thing happened to my friend who was using T Mobile.
bitJericho将近 8 年前
Might I humbly recommend my own exchange? <a href="http:&#x2F;&#x2F;bitcoinsexchange.itmustbetrue.com" rel="nofollow">http:&#x2F;&#x2F;bitcoinsexchange.itmustbetrue.com</a>
评论 #14470555 未加载
评论 #14475333 未加载