create account

My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys by robertdurst10

View this thread on: hive.blogpeakd.comecency.com
· @robertdurst10 ·
$2.85
My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys
<center><h1>A Lesson in Security</h1></center>
<center>https://media1.giphy.com/media/13MhSTF0RNjF4c/giphy.gif</center>
If you haven't heard the news, $30 million were stolen in ETH from party multi-sig wallets. Unfortunately this included 44k ETH from Swarm City, but luckily some good guy hackers came in and saved the day. Read more about it <a href="https://www.cryptocoinsnews.com/hackers-seize-32-million-in-parity-wallet-breach/">here</a>.

<center>**I AM NOT REHASHING THE NEWS in this post!!! Instead I am raising a concern of mine.**</center>

On cryptocoinnews.com, it was noted that:
> The breach only affects multi-sig wallets; normal wallets appear to be safe.

Thus, the attack was on multi-sig wallets. Let's dive into this a little bit.

<h3>Typical Wallet:</h3> there is one owner, and one private key. The owner uses the private key to sign off and confirm transactions. If owner keeps wallet private key from attackers, owner is safe.

<h3>Multi-sig Wallet:</h3> there are at least two owners, and each owner has their own private key. Thus, there are many different situations here. You can have one owner sign off on transactions, you can have both, you can have 2-of-3... this is supposed to be more secure. However, anytime **SOMEONE ELSE CAN ACCESS YOUR MONEY YOU NEED** to be suspicious and uncomfortable.

In the case of Parity, the issue here was a very simple coding error. I found this awesome info on StackExchange:

<center>![Screen Shot 2017-07-21 at 10.53.36 PM.png](https://steemitimages.com/DQmfCLx6TAkYrZZ6HES82dwzy85UKUwCk1AzqG67k9TdjMd/Screen%20Shot%202017-07-21%20at%2010.53.36%20PM.png)</center>

Bottomline, even if companies claim to have the safest or most secure wallets, always be very weary of multi-sig wallets or any situation where you are not in 100% control of your wallet keys. As you saw here, all it takes is a little slip and $30 million can disappear right before your eyes!

***
<h4> Hope y'all got something out of this! As a dev working on a project with a wallet, events like these are great learning experiences for me. If you have any questions, or need some clarification, I am glad to help! Just respond in the comment section below. Cheers and Steem on!</h4>
***
<center>![SteemEngineBannerForSteemit.gif](https://steemitimages.com/DQmT9vMpSgFU1n7X4rYbbruNAJM6AYqUijpmnULLdaievSS/SteemEngineBannerForSteemit.gif)</center>
***
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorrobertdurst10
permlinkmy-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys
categoryethereum
json_metadata{"tags":["ethereum","security","cryptocurrency","crypto"],"image":["https://media1.giphy.com/media/13MhSTF0RNjF4c/giphy.gif","https://steemitimages.com/DQmfCLx6TAkYrZZ6HES82dwzy85UKUwCk1AzqG67k9TdjMd/Screen%20Shot%202017-07-21%20at%2010.53.36%20PM.png","https://steemitimages.com/DQmT9vMpSgFU1n7X4rYbbruNAJM6AYqUijpmnULLdaievSS/SteemEngineBannerForSteemit.gif"],"links":["https://www.cryptocoinsnews.com/hackers-seize-32-million-in-parity-wallet-breach/"],"app":"steemit/0.1","format":"markdown"}
created2017-07-22 06:08:36
last_update2017-07-22 06:08:36
depth0
children6
last_payout2017-07-29 06:08:36
cashout_time1969-12-31 23:59:59
total_payout_value2.306 HBD
curator_payout_value0.544 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,391
author_reputation5,401,785,748,657
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id9,273,147
net_rshares729,989,530,209
author_curate_reward""
vote details (59)
@bigdeej ·
$0.09
Very insightful! I agree if you really want security it should be 100% code verified by trusted sources as well as single private key! Paper wallets and secure offline wallets!
👍  
properties (23)
authorbigdeej
permlinkre-robertdurst10-my-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys-20170722t075644905z
categoryethereum
json_metadata{"tags":["ethereum"],"app":"steemit/0.1"}
created2017-07-22 07:56:45
last_update2017-07-22 07:56:45
depth1
children0
last_payout2017-07-29 07:56:45
cashout_time1969-12-31 23:59:59
total_payout_value0.071 HBD
curator_payout_value0.023 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length176
author_reputation24,177,354,907,334
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id9,280,604
net_rshares24,352,022,356
author_curate_reward""
vote details (1)
@cryptohazard ·
$0.10
Slightly disagreeing as companies would have a real hard time dealing with only one key. Of course you could do a multisig to generate the private key that lock a normal account. But this requires more organization for the company in general.

You and me, of course, don't need a multisig contract.

[Vote for witness @cryptohazard](https://steemit.com/steemit/@cryptohazard/why-i-want-to-improve-steem-security-and-become-a-witness)
![cryptohazard.gif](https://steemitimages.com/DQmUfrbQ3sReStRjru49ikwfascKAxbJV83naDd7dzAGjE5/cryptohazard.gif)
👍  
properties (23)
authorcryptohazard
permlinkre-robertdurst10-my-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys-20170722t214349105z
categoryethereum
json_metadata{"tags":["ethereum"],"image":["https://steemitimages.com/DQmUfrbQ3sReStRjru49ikwfascKAxbJV83naDd7dzAGjE5/cryptohazard.gif"],"links":["https://steemit.com/steemit/@cryptohazard/why-i-want-to-improve-steem-security-and-become-a-witness"],"app":"steemit/0.1"}
created2017-07-22 21:43:48
last_update2017-07-22 21:43:48
depth1
children3
last_payout2017-07-29 21:43:48
cashout_time1969-12-31 23:59:59
total_payout_value0.075 HBD
curator_payout_value0.025 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length545
author_reputation17,111,780,434,071
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id9,350,969
net_rshares26,300,184,144
author_curate_reward""
vote details (1)
@robertdurst10 · (edited)
$0.02
Good point @cryptohazard. I was just thinking about you and I and hoping to spread the message to those individuals here less knowledgable about crypto.

Also redoing my witness voting tomorrow as I am setting up one myself :)
👍  
properties (23)
authorrobertdurst10
permlinkre-cryptohazard-re-robertdurst10-my-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys-20170723t051926367z
categoryethereum
json_metadata{"tags":["ethereum"],"users":["cryptohazard"],"app":"steemit/0.1"}
created2017-07-23 05:19:27
last_update2017-07-23 05:19:30
depth2
children2
last_payout2017-07-30 05:19:27
cashout_time1969-12-31 23:59:59
total_payout_value0.018 HBD
curator_payout_value0.006 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length226
author_reputation5,401,785,748,657
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id9,380,237
net_rshares6,557,377,220
author_curate_reward""
vote details (1)
@cryptohazard ·
$0.08
good luck on the witness set up. The main documentation is what past and current witnesses wrote.
👍  
properties (23)
authorcryptohazard
permlinkre-robertdurst10-re-cryptohazard-re-robertdurst10-my-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys-20170723t120906614z
categoryethereum
json_metadata{"tags":["ethereum"],"app":"steemit/0.1"}
created2017-07-23 12:09:06
last_update2017-07-23 12:09:06
depth3
children1
last_payout2017-07-30 12:09:06
cashout_time1969-12-31 23:59:59
total_payout_value0.060 HBD
curator_payout_value0.020 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length97
author_reputation17,111,780,434,071
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id9,409,909
net_rshares20,528,590,982
author_curate_reward""
vote details (1)
@minnowsupport ·
<p>Congratulations!  This post has been upvoted from the communal account, @minnowsupport, by cryptorob from the Minnow Support Project.  It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, and someguy123.  The goal is to help Steemit grow by supporting Minnows and creating a social network.  Please find us in the <a href="https://discord.gg/HYj4yvw">Peace, Abundance, and Liberty Network (PALnet) Discord Channel</a>.  It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.</p>

<p>If you like what we're doing please upvote this comment so we can continue to build the community account that's supporting all members.</p>
properties (22)
authorminnowsupport
permlinkre-robertdurst10-my-thoughts-on-the-parity-hack-a-lesson-in-security-avoid-multi-sig-wallets-and-maintain-100-ownership-over-your-keys-20170722t063630661z
categoryethereum
json_metadata{"tags":["ethereum"],"app":"cosgrove/0.0.1rc3"}
created2017-07-22 06:36:30
last_update2017-07-22 06:36:30
depth1
children0
last_payout2017-07-29 06:36:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length710
author_reputation148,902,805,319,183
root_title"My Thoughts on the Parity Hack - A Lesson in Security: Avoid Multi-Sig Wallets and Maintain 100% Ownership over your Keys"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id9,275,047
net_rshares0