pull down to refresh

From their update on X:

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.

Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed.

All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.

Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.

Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security.

NEVER share your wallet backup with anyone or type it into a website.

We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.
reply

where do I order it to? serious question, I’ve struggled with this for a while

reply

It's a real problem, which is why I'd like to discuss. My current solution is to never order for delivery, always buy in person / pick-up at the merchant location. Then they wont card you (unless you're buying a phone.)

Especially since you even need to do ultimate beneficiary KYC for LLC PO boxes / remailers since 2018 or so... which is insane.

In the US your best bet is an LLC agent with a mail service that you can drive to, for a DE or NM LLC where the agent is the only named party, and then hope the IRS (and in DE, the state) doesn't get breached. There was a trick in the US by registering yourself as a nomadic resident in SD, and then get a DL - then your DL doesn't lead anywhere. Not sure if that is still actual / doable tho.

In Europe you're generally f-ed - I haven't found any way to not have to register with 3rd parties or state owned postal services at all. Those 3rd parties (and national post services, DHL, UPS and so on) are insecure af and low hanging fruit the moment Kimibois move on from Bitcoin to data theft (as in: over the coming weeks.) Even if you manage to deliver to an obscure pickup point with an obscure courier service, they'll still have to scan your ID at the counter when you pick up in every EU country I tried it out with benign things, like a mifi thingy or a pi.

reply

It seems to me that this is a major point in favor if using generic hardware for Bitcoin operations.

I realize that a hardware signing device has a much smaller attack surface than a laptop or desktop, however it brings along this and several other major concerns (honeypot risk, man in the middle risk).

Is the benefit one gets from reduced attack surface on the device worth the increased privacy risk of buying a Bitcoin specific device?

I find it difficult to weigh these tradeoffs against each other.

reply

You can reduce the attack surface on the device yourself.

reply

Okay, so I can remove the WiFi card and install very basic software.

Do you think a hardware signing device provides any benefit over a generic device that has been carefully hardened?

reply

Let's say opti suddenly doesn't have to work anymore. Maybe opti will get himself a good little ESP32, maybe even with wifi like a C5, solders a secure element on top and then opti spends 3-6 months coding himself a signer. I think my signer will be more secure than whatever you buy, whatever laptop or phone you can get your fingers on. I can also choose to do this with a phone - some rock5 based thing perhaps.

So I can answer both ways with 'YES'.

Yes, I can make a dedicated hardware signer more secure than a generic device.
Yes, I can probably also make a generic device more secure than a hardware signer.

The problem is opti needs to work sometimes to not lose even more weight and actually stay alive, and preferably get off the skeletor look in the first place. So, can I practically make a generic device more secure than a dedicated hardware signer that I buy? Probably not right now.

reply

I see that, and I doubt that I will ever have enough Bitcoin to merit learning how to do what you describe above.

However, my question is, given my current capabilities (slightly tech savvy non-dev), how do I weigh the risks of using generic hardware (with what feeble hardening I am able to achieve) against a purpose built device (but which comes with increased privacy risk, honeypot risk, and so on)?

It seems that there is no case where I want to use a single sig because the likelihood that I screw something up is relatively high and I like the idea of avoiding single points of failure. However, an exposed home address linked to a known Bitcoin balance is also a single point of failure, no matter how many signatures is my threshold. So even including a single purchased hardware device opens a while new risk factor.

All of this may not be helpful though as the risks are difficult to enumerate and likely quite different for different individuals.

284 sats \ 2 replies \ @Wumbo 4 Sep

There is no "Perfect" answer in my opinion.

Check this old post out for different thoughts.

#435261

Some decent options that came out of the post:

  • Ship to a business - your place of work or a hotel you are staying at.
  • Get a Mailbox at UPS.
reply

Those delegate your operational security to the hotel (or worse: chains), your employer and a postal service, because they all take KYC. I don't think these are the fortresses they make themselves out to be. After all, UPS' entire Salesforce got breached last year, Marriott (Starwood) got famously breached in 2018, employers are smaller targets but since 90% of them use Azure, your data can already be out there for purchase anyway since a couple of weeks now[1].

Crime lords have agentic AI too so, don't think that no one will run a match between different breach datasets. That wasn't out of reach before, but it is not even out of reach for the most retarded trolls now.

  1. https://m.stacker.news/154958 - ever worked at McD, anon?

reply

heh, I’m on that post too lol

reply

Rock out to a Bitcoin conference expo near you with red light glasses and a fake cypherpunk beard and buy directly from the signing device merchant booths and pay with Lightning from your own node.

reply

Never have, but then both my mom and a friend drop shipped Bitcoin swag.

Entropy of the universe is undefeated.

reply
reply
108 sats \ 0 replies \ @OT 4 Sep
and are working to ship anonymous delivery ASAP

Should have always been this way

reply
reply
Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.

Lawsuit? Feds had a mole at Shipmonk?

reply

And PRIVACY matters!

reply

Wonderful. More phishing incoming

reply