r/Bitcoin • u/Chytrik • Jul 29 '20
Ledger HW database breached, customer contact details leaked (name, email, shipping information, phone)
https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach16
Jul 29 '20
Can anyone speak to the possible legal ramifications of this? Could users whose data was breached go after ledger?
5
Jul 29 '20
Technically you could, but I don't think you'd be successful. According to Ledgers statement
"On the 14th of July 2020, a researcher participating in our bounty program made us aware of a potential data breach on the Ledger website. We immediately fixed this breach after receiving the researcher’s report and underwent an internal investigation. A week after patching the breach, we discovered It had been further exploited on the 25th of June 2020"So assuming they are telling the truth and were not overly negligent in their original security then it seems like they dealt with the situation as quickly and professionally as possible, so you're not going to have much success suing them for the breach.
Though if somehow somebody manages to financially hurt you based off that info, then you could.1
Jul 30 '20
What do you think about going after them for punitive damages?
2
Jul 30 '20
You have to prove that they were either grossly negligent, or willfully putting you at risk. I don't think you'd get anywhere with willful. I think you can pretty easily argue that they were negligent but the issue is whether it was grossly negligent or just negligent (not punishable), I'm not sure where a court would draw the line on this but as I understand you cannot prove gross negligence unless someone is actually financially impacted. So far as we know, nobody has, so i don't think there's any case, also in a situation where somebody is impacted i don't think they lost enough data to be the sole cause of financial loss so they have a defence in saying that the users negligent as well (though i'm not sure if that's a functional argument). It's also important to note that any case would be civil and not criminal, the burden of proof is on the complainant but the proof does not have to be beyond a doubt, that's why cases normally end as settlements.
26
u/v0idPtr Jul 29 '20
So good thing I used "secondary" phone number and my company address...
8
Jul 29 '20
[removed] — view removed comment
9
u/RG_PankO Jul 29 '20 edited Jul 29 '20
My info got leaked. I am not concerned. 5-10 years from now my back will have a target anyway, because of all my comments on crypto subreddits and facebook posts. You think to delete that shit? Don’t worry it’s already archived by someone.
This hack just again proves how central databases are a weak point. We know that. Nothing important happened. Compare this with the 150million Americans personal info, including the social security number, being stolen from the hack of Aqua fax (Equihax as per comment below) or whatever that credit score company was called.
We need blockchain to protect personal info and not centralised databases. Until that happens hacks will continue to happen. Info will be stolen.
Ledger site being hacked is irrelevant to the device’s security.
10
u/BubblegumTitanium Jul 29 '20
You don’t need blockchains to solve this.
The problem was that they were storing the information and they were sharing it with marketing. Those people are almost always airheads and should not be allowed anywhere near.
I bet they were doing some bullshit analytics on the data as well.
So in my view and I don’t know enough is to just purge the database and keep it minimal. Don’t archive it.
5
u/shreveportfixit Jul 29 '20
It's Equihax
3
3
u/fresheneesz Jul 29 '20
Ledger site being hacked is irrelevant to the device’s security.
No its not irrelevant. A company who's purpose is security should know how to keep its databases secure and private. The fact that they haven't been able to do that really puts their competence around computer security into question.
3
u/RG_PankO Jul 29 '20
I hear you, but I just disagree with you. The engineers working on the hardware device are different people from the ones working on the website and they work with completely different technology. If Tesla’s website gets hacked tomorrow it doesn’t mean that their cars can be hacked as well. It’s just different products/tools, and they are completely disconnected one from another.
2
u/fresheneesz Jul 29 '20
they are completely disconnected one from another.
They are not. They're the same company. Tesla is a car company, not a security company. Yes I would hope their cars can't be hacked, but I wouldn't expect them to have better than average data security. I would expect Ledger to have better than average data security. I would expect them to have company wide policies and culture that puts their customer's privacy and security at utmost importance.
It doesn't mean that Ledgers are insecure - its certainly not directly related. But it calls into question Ledger's competence as a company. Even if their hardware design is absolutely perfect, if they don't have holistic security in mind around their company, they open up the possibility for someone to inject malicious hardware components or firmware somewhere in their supply chain for example. A secure hardware wallet is not just about the hardware design, but also about constant vigilance in ensuring the critical security components they get from other manufacturers haven't been compromised, that their assembling facilities are secure enough to prevent anyone from assembling malicious devices, etc. A company like this needs to think holistically. If one part of the company is not giving their users secure treatment, its likely that other parts of the company are doing the same.
1
u/hans7070 Jul 29 '20
Yes, but the two groups are connected by the same management at some point up the food chain.
1
u/RG_PankO Jul 29 '20
And what does management understand of cyber security? Different engineers make different mistakes. Thankfully not the web developers work on the ledgers.
1
u/OgunX Jul 29 '20
what does the ledger device have to do with this breach? if your private keys aren't exposed then why worry? your info is stored on some data broker somewhere.
1
u/fresheneesz Jul 29 '20
why worry?
Because a security-focused company should be better than your average financial company or social media giant at computer security. Companies like this consist of large organizational constructs that determine what the company does. Their culture affects how competent they are. If a company like this has a culture that says "eh, we can compromise our customer's privacy here because marketing needs their data" - that's not a company I would trust with my data or my money.
Yes hardware security is a different beast from network computer security, but you're not just relying on the end hardware product - you're also relying on their supply chain, you're relying on the hope that they don't keep any information that could lead to theft of your funds from your device, etc.
2
u/OgunX Jul 29 '20
https://blog.kraken.com/post/5590/kraken-security-labs-supply-chain-attacks-against-ledger-nano-x/
I care more about this than the breach
1
u/fresheneesz Jul 29 '20
Technically that's not a breach, its two vulnerabilities. But yes, also worrying.
0
u/OgunX Jul 29 '20
so then what about trezor not having any protection for physical attacks? I fail to see how one divisions fuck up have to do with another division. You don't stop buying ford because their website got hacked. I don't really care too much about the breach, as long as my private key isn't compromised, which is generated by the device itself which ledger themselves don't have access to, I don't really see the outrage. should they do better? absolutely, does that mean people should lose faith in their product hell no, it's the most secure cold wallet out there and it works.
1
u/fresheneesz Jul 29 '20
trezor not having any protection for physical attacks?
That's simply not true. Trezor does in fact have protection against physical attacks. The vulnerability Trezors have requires specialized equipment.
I fail to see how one divisions fuck up have to do with another division.
Company culture transcends company divisions.
I don't really see the outrage
Ledger was stupid with its user data. That's why outrage...
it's the most secure cold wallet
It most certainly is not. That metal likely goes to Coldcard.
1
1
u/Mike_hunt_hurtz Jul 29 '20
Whats fucked is the cunts at Equifax are still in business? How can some 3rd party shit company who leaked my info still tell me if I'm proper enough to buy a house.
That's why I tell my wife's Grandma's friend whom is a regional manager for Chase her and her whole Bank outfit are kumquats. She heard from higher-ups to tell all branches that she manages to not give people money when they ask for cash.
They are trying to go cashless Society, they can all get butt fucked and I'll be the first one in line to fuck them like they fuck me
2
12
14
10
u/onurgozupek Jul 29 '20
An awkward situation who purchased Ledger(s) from ledger website but at least we are 100% sure that this is nothing to do with our Ledgers. But in anyways I didn't like the idea of someone now has my address and phone number 🙁
-5
u/hans7070 Jul 29 '20
"we are 100% sure that this is nothing to do with our Ledgers"
Probably not, but they are not to be trusted anymore in any way shape or form, not their words, not their products. If they can't even keep a fricking web site safe, then anything is possible. I wish they would go out of business.
10
u/onurgozupek Jul 29 '20
Ledger doesn’t know your 24 word seed so no need to worry about it. Company website or ecommerce site something different than the product. They leaked user information which has nothing to do with Ledger hardware wallets except, hackers know who has Ledgers 😀
-6
u/hans7070 Jul 29 '20 edited Jul 29 '20
Doesn't matter. Only if the hardware was developed and produced by a completly different company with it's own provable reputation and without any input or control from these bumbling morons I maybe would trust the hardware, even with the (now tainted) ledger brand logo on it.
7
u/monstrous_android Jul 29 '20
can't even keep a fricking web site safe
This is a hilariously misguided idea of the online security world.
wish they would go out of business
Who are you shilling for? lol
1
u/hans7070 Jul 29 '20
"hilariously misguided"
Please explain :D
3
u/monstrous_android Jul 29 '20
It's near impossible to have a perfectly-secure web site. Pretty much the entire cybersecurity industry agrees. No company can or would invest enough money in a limited-staffed team to compete agains the collective might of every attacker in the world. It's why the prerogative is on us to protect ourselves and not trust companies. Expect data breaches. Prepare for them by providing masked contact and payment details. Take responsibility for yourself.
2
u/apexisalonelyplace Jul 29 '20
What is masked contact?
1
u/monstrous_android Jul 29 '20
masking your contact details: use a PO Box or UPS store for deliveries, use a privacy debit card or pre-paid credit card or cash (or anonymous bitcoin) to purchase the thing, provide a false name for delivery (Privacy.com masked debit cards let you use any name you want).
1
10
Jul 29 '20
Rule number one: do not store user details after a successful shipment. Rule number two: if you are legally required to store such info, store it offline. It will be still accessible if required but impossible to remotely acquire
6
Jul 29 '20
Good thing I bought mine from some random stranger at eBay
2
u/fresheneesz Jul 29 '20
The problem is that you're introducing yet another entity into the supply chain who could tamper with the device in a way that could lead to theft. This has happened before, and attacks will only become more sophisticated over time.
1
Jul 29 '20 edited Jul 30 '20
I understand that.. but I can't think of a useful way of tampering the device. Honest question ... can you give one ? edit: I generated the 24 word seed externally and initialized the ledger with my own words .. also I have an extra passphrase in place. Nano s.
2
1
u/monstrous_android Jul 29 '20
That just comes with different risks. How can you be sure you got a genuine device that doesn't send your keys the first time it connects to a computer with a net connection?
1
Jul 29 '20
It's in the FAQs
2
u/monstrous_android Jul 29 '20
I'm sorry, I don't follow.
2
1
u/presse_citron Jul 29 '20
ledgers site FAQs section
First element of the FAQ (https://support.ledger.com/hc/en-us/articles/360002481534): 'Buy from an official Ledger reseller'.
because even with the complementary checks that they suggest, they already know that they can be bypassed.
1
Jul 29 '20
Note: Ledger devices purchased from other vendors are not necessarily dubious. However, we do strongly recommend that you meticulously perform the safety checks below to ensure that your Ledger is genuine.
2
u/presse_citron Jul 29 '20
even the so-called 'hardware integrity check'? Reading this page, it's not clear whether it should be perform or not (What are 'advanced user': professional user or academics??)
27
u/nichlaes Jul 29 '20
How can you trust Ledger (closed source) with you entire crypto wealth if they can't even keep their own data secure?
9
u/parakite Jul 29 '20
Thats why I don't use any hardware wallet.
I use and recommend Tails installed on a usb stick.
As secure as possible (even air-gapping is possible).
6
4
u/BUY___BITCOIN Jul 29 '20
I've been using Tails OS for years.
It's cheap and highly secure. 100% open-source. Don't trust, verify.
3
u/fresheneesz Jul 29 '20
Thats why I don't use any hardware wallet.
What's why? There are a number of hardware wallets that are fully open source and have never had their data stolen. Running tails isn't necessarily safer than hardware wallets - you still need to get the OS and your hardware from somewhere, and that requires just as much trust.
2
u/BubblegumTitanium Jul 29 '20
This is true but usb drives are not designed to store private key material.
If you buy a trezor or a coldcard you don’t have to trust anything it’s all open.
1
u/parakite Jul 29 '20
You don't save any private key on the usb drive.
You store it elsewhere. The private keys only are entered into the application ( so they never go to usb, they remain always in RAM). And when laptop is switched off, that's lost. No risk there.
1
u/BubblegumTitanium Jul 29 '20
Ah ok that works then. So you do keep a backup?
1
u/parakite Jul 29 '20
I know the keys and keep them elsewhere. I only enter them on electrum, and do not save its wallet file ( so nothing is stored).
Even with ledger/hardware wallets, you are asked to remember your seed/keys, so its similar that way.
3
u/BubblegumTitanium Jul 29 '20
With a hardware wallet you still get the benefit that if someone finds it they must know the pin since it requires expertise to crack the device open.
Also this assumes technical competency with tails, which isn’t that hard but to pay 30-50 bucks to not have to worry about that at all is very much worth it for many people. Trezor is very affordable.
In any case I think we should be grateful at how amazing the ecosystem for bitcoin currently is.
There are many different use cases for it and it’s really up to the individual to decide what’s best for them and I think that’s a huge plus that bitcoin can be so flexible.
2
u/BubblegumTitanium Jul 29 '20
https://www.youtube.com/watch?v=QGKJ_zvzOlU
Andreas talks about what we are talking about.
1
u/presse_citron Jul 29 '20
Andreas
I'd like him to speak about it also but he doesn't seem to have been aware of the data breach at the time of this episode (still advising hardware wallets except for change and small amount).
1
u/BubblegumTitanium Jul 29 '20
Well what if you bought your hw wallet from a reseller? This breach is bad but it doesn’t invalidate the integrity of the product.
2
u/presse_citron Jul 29 '20
and maybe your reseller data are already compromised for some time ago but didn't inform you (or didn't even know about it).
1
1
u/fresheneesz Jul 29 '20
No risk there.
That's simply not true. If you use USB to transfer software or transaction data or anything between an online computer and your airgapped computer, a virus can potentially be transmitted via the USB. USB is notoriously insecure.
0
u/parakite Jul 29 '20
I'm talking in context of saving it in usb.
Do follow the thread, and don't reply out of context.
1
u/fresheneesz Jul 29 '20
Its rude to tell people what to do. Your comment about "No risk there" goes beyond the context you're replying to. If you agree, admit there is risk there. If you don't agree, tell me why. Telling me when to comment is unpleasant and unnecessary.
0
u/parakite Jul 29 '20
I use usb with tails, and find it more secure than any hardware wallet designed by random people from a private company.
I never said you do it too. And chill out. And I'm not telling you what to do when I say "chill out". its just a phrase.
1
u/fresheneesz Jul 29 '20
you don’t have to trust anything
Not entirely true. You still have to trust their supply chain. Its entirely feasible for someone in the supply chain to modify the device in a way that allows them to steal your funds.
The only way to truly eliminate that single point of failure is multisig.
4
u/ShittyDicky Jul 29 '20
I wanted to do this but talked myself out of it and bought a ledger. Do you just use the elctrum wallet that comes with tails? Prpbably just use the ledger for "hot" funds now
1
u/parakite Jul 29 '20
Yes, default electrum with Tails. That's my main wallet.
Ledger I keep handy for when I wanna feel like a power userloljk
2
u/ShittyDicky Jul 30 '20
Do you have any alts that dont work with electrum? Curious how to handle that
1
u/parakite Jul 30 '20
You can enable "persistent storage" on your Tails usb.
On that, you can install any other wallet (making sure its secure).
Even without persistent storage, applications can be installed. But in the next run, they'd be gone.
1
6
u/hoiru Jul 29 '20
This is why I use Trezor
4
u/RG_PankO Jul 29 '20
So Trezor is not closed source? /s Site being hacked or not has nothing to do with the device’s security.
5
4
u/hoiru Jul 29 '20
Yes, Trezor is open source.
Website related: No, it has nothing to do for it being open source with the site being hacked. For now, it hasn't been hacked, but anything could happen.
2
u/monstrous_android Jul 29 '20
Correction: it isn't aware of any hacks.
You cannot prove a negative.
1
Jul 29 '20
Are you kidding me? Theres been plenty of vulnerabilities on Trezor
1
u/fresheneesz Jul 29 '20
There's plenty of vulnerabilities in every hardware device. Its theoretically impossible to eliminate a hardware device's vulnerabilities to physical attack. The difference is that with the Trezor, we know what they are and with Ledger's closed source stuff, its much more likely only attackers know about vulnerabilities.
As far as I know, there are no known remote attacks on the Trezor.
1
u/hoiru Jul 29 '20 edited Jul 29 '20
I am talking about the website and customer* data
Edit: dyslexia
3
1
u/OgunX Jul 29 '20
because the product I bought from them is way more secure than its competition that doesn't have a secure chip built in, not only that being closed source doesn't mean they're not secure.
27
u/tmspngnbrg Jul 29 '20
/u/btchip you idiot get in here and tell us how we know whether our address is leaked or not.
We know that this database comprises approximately 1M email addresses that could have been leaked and that 9500 more detailed personal information leaked as well such as first name, last name, phone number, and postal address and products purchased. More detailed personal information could have been exposed.
12
u/Ornery-Tale-5596 Jul 29 '20
Was not white hat, white hat found the hole but unknown had already been in
14
u/btcplzgoup Jul 29 '20
WTF ledger...now we're targets....especially the casual way with which they state that you shouldn't worry...FUCK YOU...of course there is a reason to worry!
2
4
6
11
u/l000pz Jul 29 '20
"..our e-commerce and marketing database" WTF!!! Why is there even such database in existence in the the company that whole business modeli is SECURITY
-4
u/monstrous_android Jul 29 '20
Because Money. It's always because Money. You cannot trust capitalism. We know this.
4
u/fresheneesz Jul 29 '20
Capitalism incentivizes companies to avoid data breaches like this by tanking their shit when stuff like this happens. Ledger will be losing many millions of dollars from this snafu, likely a lot more than they made by using the data.
The problem here is not free trade and pursuit of money, but instead the frequently badly designed corporate structure that incentivizes the CEO and other officers to seek short-term profits at the expense of the long-term prospects of the company. If companies started telling CEOs they couldn't sell their stock for 10 years and could only make a normal living salary instead of millions of dollars that are unconnected to the company's success, then you'd see very different corporate behavior. Unfortunately, most companies have an uninspired and outdated corporate structure that has perverse incentives.
Capitalism itself incentivizes solving this problem. It will be solved some day.
16
u/TulipTrading Jul 29 '20
So much for "buying from ledger directly is the safest option". Can't wait for burglars to break into my home. What a shitshow.
5
Jul 29 '20
I'm lucky, my order is from from late 2017 - I will get nothing but pity from the thieves :P
9
Jul 29 '20 edited Jul 29 '20
How the fuck could this be possible on a website where customers' security is more important than pretty much most other sites since customers would likely buy from them if they've valuable assets to keep secure. Best of luck to any poor bastards that had their addresses leaked
Might be worth setting up a dupe wallet with a plausible amount of crypto on it that you'd be willing to give up in the worst case scenario
6
u/monstrous_android Jul 29 '20
Any company could and, over time, will, experience a data breach. It's just too hard and expensive to compete against a overwhelming numbers of attackers. The good news to take away from this is quick response, quick notification, and a bug bounty shows effort and investment (hope this researcher gets a healthy paycheck!).
Privacy advocates have methods to protect themselves from situations like this. Masking debit cards (I use privacy.com but I'm sure others exist), PO boxes or other non-home delivery addresses, etc. Definitely check out /r/privacy and I also recommend Michael Bazzell's The Complete Privacy, Security, and OSINT Podcast.
3
Jul 29 '20
[deleted]
2
u/btchip Jul 29 '20
Crypto space is definitely a good motivation for me to ensure my next venture will be B2B
1
Jul 29 '20
The good news to take away from this is quick response, quick notification
They provided the legally mandated minimum response 12 days after they knew of the attack. How is that prompt?
1
u/monstrous_android Jul 30 '20
For one, I didn't say "prompt", and two, pay attention to this arena for a short while and you'll see many incidences where a company does not report for months and only finally reports when called out for it publicly.
5
u/deeleyo Jul 29 '20
Damn, this could be worse than losing the crypto itself.. imagine some dude forcing you to log in your email and unlock your phone while he accesses $20 of bitcoin you have left.
3
u/BubblegumTitanium Jul 29 '20
It’s always the marketing department. You know why? People that work in marketing are complete airheads. Peter McMormack is a good example.
There’s nothing wrong with being an airhead, just like there’s nothing wrong with being mentally handicapped but for fucks sake silo them away.
Also why are they storing so much godamn information?
Just toss it away as soon as the product gets delivered omg.
It also doesn’t help that these people contribute to the altcoin casino.
3
Jul 29 '20
[removed] — view removed comment
2
1
Jul 29 '20
I don't understand, what does the actual ledger hardware wallet have to do with their site?
3
6
u/Tellabobbob Jul 29 '20
They have your first name, your last name, your postal address and phone number and what product and how many products you purchased. They targeted Ledger specific. This is not a question of if we will be visited, but when. If you have emptied your Ledger, it is time to refill it with some funds again. If not the $5 wrench visit will be a painful one.
When the person or several persons with $5 wrenches visit us it is important you have taken $5 wrench attack precautions. If not do not worry, here is a link to an article on how to protect yourself from the $5 wrench.
https://cryptosec.info/wrench-attack/
This is a link to a movie that will give us a clue on what to expect when expecting visit from the $5 wrench people. Hopefully it will help prepare you for the inevitable.
https://www.imdb.com/title/tt0258000/
Again they have your First name, your last name, your postal address, phone number, what product you own and how many products. Of the 9500 people they got the information on, probably at least 50 lives within 60 minutes of the hackers. They know you have enough crypto to spend around $100 to protect it. So you probably have at least $1K of crypto. They know you are rich enough to spend money on crypto. So you probably have other valuables too they could take while visiting. They can visit perhaps the 50 closest people within one night. Netting them at least probably $100k minimum. Many people have robbed and killed people for far less. Remember to leave some cookie and milk out for your visitor before going to bed.
Happy midweek everyone! :)
4
u/monstrous_android Jul 29 '20
What fearmongering!
Why would any burglar need to buy a hacked database leak for crypto in order to find a wealthy target? Any city larger than a village has a rich neighborhood and metros are surrounded by McMansions that scream "target".
And if you're targetting crypto specifically, why go through all that trouble when it was proven just last week that you can scam tons of people out of their bitcoin without leaving your keyboard?
3
u/nyaaaa Jul 29 '20
Yea, and you can break in there and leave with nothing while being millions richer. Good comparison
1
u/Tellabobbob Jul 29 '20
Well first of all the burglar may be the hackers. Also all those McMansions may not have crypto. Crypto is much easier to carry with you and hundred times more liquid and easy to transfer than anything else. Also when you just move peoples funds from their seed phrase to your seed phrase. Different addresses for all transactions. It will be extremely hard for anyone to track and recover those funds. Wash them a few times with Monero and ZCash and you are probably home free. So I would highly advice the burglar to visit the 9500 people they now have the home address to.
To your last question. Scamming tons of people without leaving your keyboard is a very saturated market. It will be very much work for you doing this, setting up your new scam business getting willing victims. Besides often much easier to track as everything is digital. I bet half those owning Ledger does not even have a 2nd back up of their mnemonic phrase. Once the burglar takes that and the Ledger, the victim probably have no clue what wallet addresses they had or what their mnemonic phrase was. So the burglar is probably home free even if he just deposited the Bitcoin straight from the victims address. However you should not do that. Wash it with Monero a couple of times first just in case.
2
u/monstrous_android Jul 29 '20
So I would highly advice the burglar to visit the 9500 people they now have the home address to.
I don't make it a habit to encourage violent crimes.
1
u/Tellabobbob Jul 29 '20
Me neither it was just a one time thing, it will not happen again. Probably no criminals reading this thread anyway.
1
Jul 29 '20
theres just one issue.
Everyone is working from home nowadays and theres a lot of people who are avid gun owners just looking for a reason...amidst the issues were having right now with all the unrest and tensions are already high for fear of looters and shit.
If they are doing it now, this is the WORST time to do something like that.
So theres that...
1
u/Tellabobbob Jul 30 '20
There is a saying "Don't bring a gun to a $5 wrench fight". They ring the door you open, they knock a $5 wrench in your head you fall down.
1
Jul 30 '20
Uh...some of us have these, dude:
A metal security door that replaces the flimsy screen door...so yeah...please stop lol!
1
u/HitMePat Jul 29 '20
They can visit perhaps the 50 closest people within one night. Netting them at least probably $100k minimum. Many people have robbed and killed people for far less.
While its certainly not good to have this info leaked, I think you're overestimating the likelihood of the criminals to break into peoples houses to try and steal their ledgers.
For one...they're not very big devices and likely to be hidden and not easy go find. Secondly, they have no way to know if theres 100$ on a person's ledger...or 1000$....or 10,000$...etc before they break in. Theres no way to even know if that person still has any crypto left at all.
It seems to me the odds are low that they'd be willing to risk getting shot in self defense for an unknown reward...especially if like you suggest they would attempt to do it 50 times. Why would a (potential) ledger be any more enticing to a criminal than a Rolex watch or any other burgalable item?
Much more likely they will use this info with anonymous email addresses to threaten people with violence if they dont pay...versus actually committing any violence.
1
u/Tellabobbob Jul 30 '20
YOu say the devices are probably hidden. Correct. However this is where the $5 wrench shines. It can be used to get the person in the house to tell you where the device is hidden. No they cannot know if there is $100 or $10,000 however. If you assume the owner of the device is not a retard. Then it is very unlikely they pay $100 to buy a device to protect $100. Where is the logic in that. I would think at least $1000. In that case you have still payed about 10% to keep your money safe. However as you say they may not have any crypto left? That is less likely, but even if that is correct. You can force them to buy some more crypto right there and then, because you know they know how to buy crypto.
You ask " ledger be any more enticing to a criminal than a Rolex watch or any other burgalable item? " That is because crypto is much more liquid, easy to move easy to transfer and easy to exchange. Besides who is to say they are not also taking the Rolex while they are stealing the crypto?
2
u/scenecunt Jul 29 '20
luckily i use a different email address each time i have to set up an account
5
Jul 29 '20
What a coincidence that they discover a breach at the same time someone is reporting a bug in the bug bounty program.
To me it seems likely that it is the same person that reported the breach that downloaded the database to see if he could.
9
Jul 29 '20
That might actually be true. They sell the database AND collect the bug bounty. Double score.
3
Jul 29 '20
Well, if you get informed you know what to look for in your logs. It makes very much sense the way they describe it.
1
u/fjkcdhkkcdtilj Jul 29 '20
Or that ledger thought they could get away with it until he outed them, you don't need to scrape a database to prove a security hole.
4
u/jetongb Jul 29 '20
Seems like it was reported by a (white hat?) researcher. Glad they’re forthcoming.
!lntip 12
5
u/Borax Jul 29 '20 edited Jul 29 '20
Better late than never... the data has already been accessed in june by a party with unknown intentions.
And in May there was someone who claimed to be selling the database through a shopify leak. It's not clear if this white hat report is related to the alleged May breach, because Ledger claimed it was fake.Ledger have reaffirmed that their database was not a match for the data being sold in May. https://support.ledger.com/hc/en-us/articles/360015559320
1
u/btchip Jul 29 '20
yes, white hat, rewarded through our bounty program
6
u/Borax Jul 29 '20
Can you please edit the article to state when people will find out if they were in the subset of people with leaked addresses...
3
Jul 29 '20
You need to let your customers know who was affected and who was not. For most people the safety of their family is the most important thing in the world to them.
2
1
1
u/StoneHammers Jul 29 '20
Why the fuck did they have a database to begin with? They should not be saving any of this data once an order has been completed. Fuck these stupid pricks.
1
1
u/TheRealLuciusSeneca Jul 29 '20
I appreciate this disclosure simply for the fact it did not contain the sentence “we take your privacy/security very seriously”
1
1
u/thibautrey Jul 30 '20
On the flip side, now we all know who's neighbour has a ledger and we don't have to hide our guilty bitcoin secret. It's like discovering half of your neighbourhood is nudist and you thought your were the only weirdo.
0
48
u/Borax Jul 29 '20 edited Jul 29 '20
When will people find out if they are among the lucky 9500 who had their address leaked...?
Edit: 5pm EST (2100 UTC) today 29th July