Bitcoin Forum
November 18, 2024, 12:47:16 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Losing my Bitcoins  (Read 3048 times)
goakley (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
May 20, 2011, 05:10:49 PM
 #1

I have a laptop, which I use to do all my bitcoin-relating activities.  If my laptop were to get stolen, or if the HDD died, I would lose all of my bitcoins, wouldn't I?  Is there a way I can prevent this?
Drifter
Sr. Member
****
Offline Offline

Activity: 364
Merit: 252


View Profile
May 20, 2011, 05:12:32 PM
 #2

Copy, and preferably encrypt, your wallet.dat to another hard drive/usb/cloud/etc

Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 20, 2011, 05:12:41 PM
 #3

Backup your wallet every now and then, copy wallet.dat and store it somewhere safe
eturnerx
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
May 20, 2011, 05:13:53 PM
 #4

Backup you wallet.dat file - that's the thing you need to prove your coins. If you lose your laptop then you can install bitcoin software someplace else, copy your wallet.dat into the right place and you're good to go again. Encrypt your backup!
goakley (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
May 20, 2011, 05:17:02 PM
 #5

Thank you all very much for your help.

Would it be wise to backup the entire data directory, in addition to wallet.dat?  It seems like that would save me having to re-download the older blocks if I lost my installation.
eturnerx
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
May 20, 2011, 05:22:38 PM
 #6

I would say you a bit of time and internet bandwidth to backup the whole data directory. *shrugs* I don't bother personally, but you could.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 20, 2011, 05:26:00 PM
 #7

One word of warning: do regular backups OR use a different "savings account" type setup, there can be issues if you try to restore an old backup directly.

Ideal setup is to have a wallet.dat with a single address generated offline, backup and encrypt it then send any spare bitcoins there. Your day-to-day stuff should be backed up roughly every 10 transactions.
bencoder
Member
**
Offline Offline

Activity: 90
Merit: 10


View Profile
May 20, 2011, 05:39:19 PM
 #8

This does make me think of a scenario - the bitcoin aware thief, who steals your laptop and transfers your coins before you had a chance to recover your wallet, download the blockchain and send them on to a new address (one that also isn't in your wallet already).

This is quite interesting - perhaps there should be an option in the client to make a new address that hasn't been seen already, for this possible situation where your wallet has been compromised.

Another thing I'd like to see is a secure and heavily backed up service where you can upload an encrypted wallet.dat - if your laptop gets stolen you can send the service a decryption key(kept on a usb stick with you all the time perhaps) to have the coins sent to a new address immediately, and just hope that the thief hasn't had the chance to send them on to another address yet. The service can take a small percentage of the recovered coins (after decrypting the wallet) as payment for holding it.

I wonder how long it will be until this becomes an actual issue?
Yurock
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
May 20, 2011, 05:44:53 PM
 #9

This is quite interesting - perhaps there should be an option in the client to make a new address that hasn't been seen already, for this possible situation where your wallet has been compromised.
After recovery of lost wallet.dat, transfer all the coins to an address from another, secure wallet. Don't forget about transaction fee when sending BTC.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 20, 2011, 05:48:04 PM
 #10

This does make me think of a scenario - the bitcoin aware thief, who steals your laptop and transfers your coins before you had a chance to recover your wallet, download the blockchain and send them on to a new address (one that also isn't in your wallet already).
The only solution is to encrypt your harddrive with a key that is stored only in your brain

Quote
This is quite interesting - perhaps there should be an option in the client to make a new address that hasn't been seen already, for this possible situation where your wallet has been compromised.
How does that help the above situation?
Anyway, generate a new address, write it down, generate a new address again - it'll never get mentioned on the network.

Quote
Another thing I'd like to see is a secure and heavily backed up service where you can upload an encrypted wallet.dat - if your laptop gets stolen you can send the service a decryption key(kept on a usb stick with you all the time perhaps) to have the coins sent to a new address immediately, and just hope that the thief hasn't had the chance to send them on to another address yet. The service can take a small percentage of the recovered coins (after decrypting the wallet) as payment for holding it.
A monthly fee for hosting is more likely - otherwise the service provider never breaks even unless some theft occurs. Plus you'd want to avoid adding incentives for theft such as giving a percentage of recovered coins.

I'd happily run such a service myself without the % of recovered coins aspect - you encrypt your wallet, send it to me and i'll store it in a secure fashion for 2BTC/month. I might do just that if there's sufficient interest, seems like a nice business plan.
bencoder
Member
**
Offline Offline

Activity: 90
Merit: 10


View Profile
May 21, 2011, 01:29:21 AM
 #11

Quote
This is quite interesting - perhaps there should be an option in the client to make a new address that hasn't been seen already, for this possible situation where your wallet has been compromised.
How does that help the above situation?
Anyway, generate a new address, write it down, generate a new address again - it'll never get mentioned on the network.

The bitcoin wallet stores 100 addresses that have not yet been "generated". That means when you generate a new address and send coins to it, the thief will also see those coins because he has the same extra addresses in the wallet.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 21, 2011, 01:33:16 AM
 #12

Quote
This is quite interesting - perhaps there should be an option in the client to make a new address that hasn't been seen already, for this possible situation where your wallet has been compromised.
How does that help the above situation?
Anyway, generate a new address, write it down, generate a new address again - it'll never get mentioned on the network.

The bitcoin wallet stores 100 addresses that have not yet been "generated". That means when you generate a new address and send coins to it, the thief will also see those coins because he has the same extra addresses in the wallet.

So generate a new address on a totally new client and send all your coins to it
bencoder
Member
**
Offline Offline

Activity: 90
Merit: 10


View Profile
May 21, 2011, 01:36:38 AM
 #13

So generate a new address on a totally new client and send all your coins to it

Sure but you have to do that before the thief does it himself and it's not always going to be simple (imagine if you only had 1 computer and that got stolen). That's my point, which is why I want a service where I can log in (from my phone if need be) and quickly get my wallet decrypted and my coins sent to a new separate address that the thief will have no access to.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 21, 2011, 01:41:46 AM
 #14

So generate a new address on a totally new client and send all your coins to it

Sure but you have to do that before the thief does it himself and it's not always going to be simple (imagine if you only had 1 computer and that got stolen). That's my point, which is why I want a service where I can log in (from my phone if need be) and quickly get my wallet decrypted and my coins sent to a new separate address that the thief will have no access to.

Makes sense Smiley
Of course you then need to have total trust in the service holding your wallet for decryption AND you need to update them all the time. What if the service decides to rip you off too?
Yurock
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
May 21, 2011, 05:42:29 AM
 #15

Service that receives payments from its users has more trust than thieves. Under normal circumstances, encryption key is unknown to the backup service, so it does not have access to your bitcoins. The only time when it has the access (and chance to appropriate bicoins) is when your wallet is already stolen. If your wallet gets damaged, but not stolen, you can download the encrypted walled and decrypt it locally.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 21, 2011, 05:47:13 AM
 #16

Service that receives payments from its users has more trust than thieves. Under normal circumstances, encryption key is unknown to the backup service, so it does not have access to your bitcoins. The only time when it has the access (and chance to appropriate bicoins) is when your wallet is already stolen. If your wallet gets damaged, but not stolen, you can download the encrypted walled and decrypt it locally.

If I was a scammer this is what I would do:

(This is of course pure speculation, but it is also the reason why if I did run such a service I would not WANT the decryption keys in order to avoid this possibility):
First, setup a service with a small monthly fee offering to store encrypted wallets and as you suggest decrypt and send the coins elsewhere on demand.
Then I sit and wait.
One of my clients has a theft occur, they call me and I decrypt their wallet. I send all the coins to myself. Then I tell the client "Sorry, the thief got there first".
I would be unlikely to get caught and the incentives are quite huge.

What would prevent this?
Yurock
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
May 21, 2011, 05:56:49 AM
 #17

What would prevent this?
Time of transaction is recorded. If transaction occurred  before revealing the key, we assume, it was thief. If transaction occurred  after revealing the key, we assume, it was dishonest service. You or someone trusted has to watch transactions in order to detect this.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 21, 2011, 05:59:06 AM
 #18

Ok, now the service provider is honest but the thief is very clever and waits for that window between you giving the key to the service provider and them running the transaction - this window could be hours if it's a manual process, or seconds if it's automated, but if it's automated the window can be made longer through careful use of a DoS attack.
Yurock
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
May 21, 2011, 06:37:46 AM
 #19

the thief is very clever and waits for that window between you giving the key to the service provider and them running the transaction
Clever thief normally performs the transaction ASAP to outstrip the victim with her backup service.
Gareth Nelson
Hero Member
*****
Offline Offline

Activity: 721
Merit: 503


View Profile
May 21, 2011, 06:48:38 AM
 #20

the thief is very clever and waits for that window between you giving the key to the service provider and them running the transaction
Clever thief normally performs the transaction ASAP to outstrip the victim with her backup service.

Clever thief wants to lead any investigations away from him and onto the innocent 3rd party Wink
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!