TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Alleged Coinomi exploit shows how easy it is to have Bitcoin stolen

131 点作者 timcc50大约 6 年前

13 条评论

rory096大约 6 年前
To <i>Google Chrome&#x27;s</i> spellchecker. It&#x27;s a bad vulnerability, but it&#x27;s unlikely that it&#x27;s really the attack vector here.
评论 #19263994 未加载
评论 #19263818 未加载
评论 #19263733 未加载
评论 #19263825 未加载
评论 #19263890 未加载
ccnafr大约 6 年前
It&#x27;s not an exploit. It&#x27;s a vulnerability baked in the wallet app source code. There&#x27;s a difference.<p>The article seems to have been written by someone who has a poor grasp on security terms.<p>I&#x27;d recommend reading the researcher&#x27;s write-up and avoid getting the wrong idea of what&#x27;s happening there: <a href="https:&#x2F;&#x2F;www.avoid-coinomi.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.avoid-coinomi.com&#x2F;</a>
评论 #19264964 未加载
wcoenen大约 6 年前
If I were a security consultant, I would be a bit more hesitant about telling the world that I casually entered a seed phrase worth $60K into an online device, never mind which software it was. The report mentions that the seed phrase originally came from his exodus wallet (desktop software), which is also a wallet that is not suitable for storing such large amounts.<p>For those amounts, use a hardware wallet, or software that supports generating the transactions offline so that the device with the key never has to go online.
评论 #19265423 未加载
评论 #19265063 未加载
评论 #19264244 未加载
paraxisi大约 6 年前
The video in the article essentially shows nothing; the claim is &quot;Google stole my coins.&quot;<p>Possible? Sure. Likely? No.<p>The corroboration with the two users from Reddit is useless because they didn&#x27;t use a seed phrase.<p>edit&#x2F; To clarify: Yes, this is a stupid practice. You should be doing this locally or ideally not at all. But thinking Google is stealing your coins is a pretty big stretch.
40acres大约 6 年前
Decentralized currency is simply not viable for the mainstream, an economy needs institutions that can be relied upon and a certain level of centralized control to take the wheel when things go sour. There are still gains to be made via speculation but the dreams of folks like Nick Szabo will not be realized with crypto in its current state.
评论 #19264504 未加载
评论 #19264204 未加载
anjc大约 6 年前
Between people losing their keyphrase, to software wallets being hacked, to hardware wallets being compromised...at what point is it more safe to just keep your coins on a reputable, insured, exchange? I think the odds of Coinbase doing a Mt. Gox are a lot more slim than the odds of a random person screwing up their own storage solution.
评论 #19266487 未加载
dontbenebby大约 6 年前
Why would you spell check a password? Passphrases are in vogue, but a field whose very mature is to be high entropy probably doesn&#x27;t conform to traditional spelling&#x2F;grammar...
api大约 6 年前
Why does a <i>spell checker</i> need to live in the cloud?<p>To harvest user text for marketing analytics of course. Never mind.
评论 #19264016 未加载
评论 #19263895 未加载
评论 #19263919 未加载
评论 #19263911 未加载
评论 #19263915 未加载
评论 #19263905 未加载
yingw787大约 6 年前
I still don&#x27;t get cryptocurrencies. Yes, a blockchain works when zero trust is needed&#x2F;desired for transactions, but that&#x27;s still an implementation-level concern, and implementations aren&#x27;t perfect. Without legal means of redress, somebody is always going to get burned. If there are legal means of redress, then by definition you trust somebody, right?<p>I think a blockchain fits well when you need to verify a legal authority, like a felonies database (can you trust the cop that filed the report?), but otherwise it kind of just goes around the legal system; by doing so, you&#x27;re just re-inventing the wheel.
评论 #19264081 未加载
评论 #19263884 未加载
评论 #19263957 未加载
评论 #19264046 未加载
评论 #19263959 未加载
评论 #19263921 未加载
评论 #19263923 未加载
评论 #19264460 未加载
评论 #19266207 未加载
评论 #19264362 未加载
评论 #19264309 未加载
评论 #19264541 未加载
评论 #19264212 未加载
arisAlexis大约 6 年前
so if an unknown mail provider in Zimbabwe gets hacked email is insecure. Logical
YeahSureWhyNot大约 6 年前
the crypto tech was marketed as the most secure financial instrument but so far it has been repeatedly proving itself to be quite the opposite:)
MusaTheRedGuard大约 6 年前
This entire thread: &quot;Why don&#x27;t you just use the post office why do you need email?&quot;
chdaniel大约 6 年前
You know what&#x27;s the most painful thing? If (I&#x27;d say when) years go by and Bitcoin value is a significant multiple of what it is today... Much like those who lost their wallets in 2011-2012-2013, most probably it will be haunting
评论 #19263774 未加载
评论 #19263819 未加载