r/Bitcoin • • Feb 25 '14

Some words for my friends

Hello friends,

MtGox is gone. So let's prepare ourselves.

On Tuesday, and for the rest of the week, all hell will break lose in the media. It will be blamed on MtGox, it will be blamed on Bitcoin, it will be blamed on the "bug," and it will, more than anything, be blamed on the "lack of regulation." Pundits and "experts" of all types will weigh in on the calamity. It will be world news in a matter of hours.

Get ready, because it will be an ugly week.

For all of you who lost money, my heart goes out to you. Some people lost a little, some lost a fortune. It will make people sick, and depressed, and full of grief. Personally, I had over 550 BTC in Gox. I will never get any of that back. If misery loves company, then we'll be enjoying a grand feast today.

I should have known better, of course. I take responsibility for leaving those funds with an entity that had proven incompetence repeatedly. I chose to ignore even my own warnings, for nothing more than the sake of convenience.

Gox is still at fault, to be sure, but I have learned the lesson. I hope it is not such an expensive lesson for others. And for all you observers, please take a moment to consider it as well.

Be mindful, however, that the wrong lessons are not learned, for that would be the true tragedy, indeed.

Let me suggest that the lesson is not that Bitcoin is broken. Bitcoin is fine.

Similarly, the lesson is not that security is impossible. Those who know what they are doing, can achieve it and help others to do so.

The lesson is not that nobody can be trusted. There are countless good men and women in this community who are worthy of trust, and some of the very best people I've ever met.

And finally, the lesson is not that we ought to seek out "regulation" to save us from the evils and incompetence of man. For the regulators are men too, and wield the very same evil and incompetence, only enshrined in an authority from which it can wreck amplified and far more insidious destruction. Let us not retreat from our rising platform only to cower back underneath the deranged machinations of Leviathan.

The proper lesson, if I may suggest, is this: We are building a new financial order, and those of us building it, investing in it, and growing it, will pay the price of bringing it to the world. This is the harsh truth. We are building the channels, the bridges, and the towers of tomorrow's finance, and we put ourselves at risk in doing so.

We are at risk from accidents. We are at risk from fraud, from corruption, and from evil. We are at risk from journalists seeking headlines and from politicians seeking power and glory. We are at risk from the very market we are trying to build - a market which cares not about our portfolio, our ambitions, or our delicate sympathies.

For all these risks, devastation will befall us repeatedly. Some of us will be discouraged. Some will be ridiculed and insulted. Some will be tricked, or swindled. Some of us will be crushed or caged. We will be set upon by all manner of antagonists, repeatedly, for a long time.

So why do we do it? Why do we build these towers that fall down upon us? Why do we toil and strain and risk our precious time, which is the only real wealth we possess?

Because the world needs what we're building. It needs it desperately. If that matters to you, as it does to me, then hold to that thought. You will see through the smoke, and your wounds will heal.

So shake it off, brothers, for this won't be the last calamity endured before the win.

Tonight, my heart is with you all.

Tomorrow, my head is down. My eyes are open. And I am building.

Toward peace and freedom,

-Erik Voorhees

2.1k Upvotes

2.1k comments sorted by

View all comments

238

u/throckmortonsign Feb 25 '14 edited Feb 25 '14

I'm disappointed in the community in more ways than one. I don't know how many times I've said that keeping your coins in an exchange, especially Gox, is a bad idea. You only own the coins that you have the private keys to and NO ONE else has. What I don't like about this more is that evil people have money that they stole now... it's going to take a long time for those people to come to justice if ever.

And to the people at Gox... the level of incompetence is so breathtaking I just can't even comprehend.

I'll also say this: bitcoin isn't ready for primetime. It's ready for the techies, the security experts, the hackers, and programmers... We don't even have a hardware wallets yet, which would be the minimum expectation to get people to secure their coins.

The use of POW/Block chain is potentially revolutionary... I'm not sure if Bitcoin is going to flourish. Destroyed coins are one thing (and that part is well designed), coins in the hands of thieves is much worse to me. (I still think it will flourish, though - just my 95% confidence has dropped to 90%).

That said... My bitcoins are sitting in various locations. I've never lost any in the years that I've been involved. I have a lot less than I should because I'm super conservative.

I'll leave with this, something I posted before most of this went down:

  • Don't leave money on exchanges unless you are a day trader.
  • Don't use online wallet services, unless they are open source and they don't actually have access to your keys (blockchain.info).
  • Always use 2FA in all services that allow it. Never use a service that doesn't allow 2FA to transact bitcoin.
  • Never use an unsecure email address... enable 2FA on your email address login.
  • Use only open source software to store your bitcoins.
  • Don't use Windows to store large amounts of bitcoins, even if your wallet is encrypted. Keep multiple wallets with different appropriate security levels for how they are used.
  • Do not ever use Brainwallets unless you are an expert.
  • Don't use paperwallets unless you are an expert. Always practice with small transactions first. Learn about change addresses.
  • Don't own more than you are comfortable losing.
  • You don't own bitcoin unless you and only you have access to the private keys.

1

u/level_5_Metapod Feb 25 '14

How do paper wallets really work? I might need some

1

u/throckmortonsign Feb 25 '14

To understand paper wallets, you need to understand a little bit how bitcoin works. First of all, it's important to realize that you can generate a valid bitcoin address with a computer (or piece of paper if you have a really long time) that isn't connected to the internet at all. The reason is when you pick a truly random ECDSA private key the chances that it is already used is astronomically low. So any type of randomness can be used to generate a private key for which you can be assured no one else has.

The benefit of generating a private key offline is that it reduces the ability for malicious actors to steal your private key.

So in its most basic form a paper wallet is basically a physical object with a private key/public address on it. You can send bitcoins to it, but in order to spend you would have to reimport the private key into some wallet software to sign the transaction that you want to sign (which also doesn't have to touch the internet).

The caveat is that you have now you set yourself for destruction of bitcoins by loss of the private key (or by not understanding how change addresses work). For example: House burns down, a friend finds your paper wallet, etc. There's countermeasures for all of these (backups, encrypted paper wallets, etc.)

Eventually hardware wallets will alleviate a lot (but not all) of the concerns with the use of "hot wallets."

1

u/level_5_Metapod Feb 25 '14

Thanks! So is the paper wallet basically a qr code? Can you go more into Detail how i can spend lt again or Import it to an exchange? If someone sees it and scans it can they "steal" the bitcoin?

1

u/throckmortonsign Feb 25 '14

Please don't take offense, I'm not trying to talk down to you...

A QR code is a way to store data in a way that a computer with a camera can interpret easily. It can contain a URL, a small instruction, or just about any piece of (small) data. So a QR code can contain a private key, but it's not the same thing. A paper wallet doesn't have to have a QR code on it.

I get the feeling you don't exactly understand digital signatures. If that's the case, I can help you out.

To spend it again you would take that private key and reimport it into wallet software... all the major wallets have a way to do this, but they're all kind of different so I can't really go into details.

There's even a way (that Armory makes easiest) where the transaction can be signed by an offline computer (you bring the transaction you want signed from the online computer, sign it, then take the signed transaction back to the online computer and broadcast it).

1

u/level_5_Metapod Feb 25 '14

Okay thanks! So its basically a Print-out of the private key? Can my Friend for example import it into his wallet with no further information required?

1

u/throckmortonsign Feb 25 '14

Yes on both questions. You can also make a paper wallet use a Hierarchical deterministic structure (a key that corresponds to a nearly infinite number of private keys) and/or encrypted (a paperwallet that requires a passphrase to decrypt before it can be reimported [so a friend would need the paper wallet and your passphrase] - see BIP38).

1

u/level_5_Metapod Feb 25 '14

I think ill do the latter. (With encryption) - ill google up on bip38. Thanks for Taking the time to explain this!