[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 19 KB, 600x505, GayFox.jpg [View same] [iqdb] [saucenao] [google]
29099541 No.29099541 [Reply] [Original]

Alright you morons. The first step to making it is making sure your shit doesn't get stolen. Do not fool yourself, if you use Metamask in a regular browsing environment, it is just a matter of time. If you have not done something similar to this already, I suggest making a new metamask wallet and transferring everything there.

1. Enable the Windows Sandbox feature (creates a temporary virtual machine that deletes the moment it is closed)
2. Download Firefox Portable Standalone from here:
https://portableapps.com/apps/internet/firefox_portable
3. Follow this guide to configure Firefox Portable for maximum security: https://spyware.neocities.org/guides/firefox.html
4. Run Windows Sandbox, copy your Firefox Portable folder over to the desktop in there. Set a bookmark to whatever DEX exchange you use. DO NOT BROWSE ANYWHERE ELSE.
5. Install and configure Metamask in there. Get it DIRECTLY from their website links, nowhere else. https://metamask.io/
6. Install the following addons (uBlock Origin/NoScript/HTTPS Everywhere/Decentraleyes/Privacy Badger)

Once you're done, close Firefox, take the folder from Windows Sandbox and copy it back to your main machine.

Every time you want to trade, open Windows Sandbox, copy Firefox Portable folder over, initiate any trades, close Windows Sandbox.

This can also be done with a Linux USB or dual boot. Linux is the better choice over Windows Sandbox, but for the non-autistic trader, this will do.

>> No.29099952

>>29099541
thanks man

>> No.29099969

>>29099541
Thanks faggot, the panic in the other threads was getting annoying.

>> No.29100013

>>29099541
Sweet

>> No.29100058

>>29099541
Thanks anon, very nice.

>> No.29100121

>>29099541
i'm too lazy for this

I just use two laptops
1.for trading
1.for internet shit

>> No.29100318

>>29100121
Not a great idea, unless that laptop never touches the internet otherwise, has a fresh windows install with absolutely nothing else on it, and you never leave the browser open for any period of time.

But hey, let your laziness lose you your hard earned gains. Your call anon. Opsec is the name of the game with crypto.

>> No.29100417

Just buy a ledger.

>> No.29100939

>>29100417
This too, but you'll need to move shit around in a hot wallet, and metamask is your best option right now.

>> No.29101101

What about atomic wallet or exodus?

>> No.29101235

Why not use the app?

>> No.29101270

Yeah this is a great reminder that I should be using a dedicated browser for MM.

>> No.29101331

>>29101101
It'll work fine for anything that does a wallet install as long as you have your seed available. I suggest saving the seed in something like Keepass and making some massive password you can't forget to get into it.

Either way, things that use a non-portable installer will take longer than this, since you'll need to configure it every time. Still worthwhile and I 100% recommend it.

>> No.29101412

>>29101235
The app is the WORST fucking thing you could choose to do. Absolutely do not ever ever ever do crypto transactions on a smart phone.
>>29101270
Dedicated browser isn't enough unfortunately. It's a step up, but without an isolated OS you're still wide open for an interested party.

>> No.29101463

>>29101331
This, also you can even make with Keepass to in order to make the file open, to need a separate key, which you could buy a couple usb drives and put it in there too, so the only way to open it would be to physically have the usb plugged in

>> No.29101461

>>29099541
or just use coinbase wallet on your iPhone and never screenshot/type the seed words. way easier than going through all that shit each time
>inb4 normie
yeah, doing anything that isn't the most twisted, complicated way possible means you're a normie

>> No.29101616

>using Windows
ngmi. If you can use macOS or Linux use it. Much less to worry about as the security is second to none and you don’t have to constantly be worried a fucking virus is going to take your keys.

>> No.29101671

>>29101463
I do exactly this, with one added thing to it. Since that leaves you at risk for fire/flood/natural disaster locking you out forever, make a dropbox account with a new email and another password (not the keypass password). Put the key in that in case your drives get lost forever as insurance.

Also bury a few in places you know.

>> No.29101759

>>29101461
Based, they use cold storage custody. Check out Blockfi for extra gains

>> No.29101781

>>29101616
Sweet sweet friend, if you think your shit is safe on MacOS, you are horribly mistaken.

Linux is definitely a step up, but again, if you're running the browsers needed for Metamask, the risk is still there. Vectors for attack go for the weakest link, and the weakest link is the browser and scripts running within it.

>> No.29101804

Why not just buy a trezor ???

>> No.29101840

>>29101461
Again, if you trade crypto on your phone on a regular basis, you're going to lose your shit eventually. Only the normiest of normies think that apple operating systems are safe.

>> No.29101848

>>29099541
Security is great but you guys wrote down your seed phrase right Anon

>> No.29101900

>>29101461
Do you need an account with coinbase for this? I dont want to give them my info

>> No.29101910

>>29101616
>MacOS

fuck off normie, MacOS is the most unsafest shit OS out there, Win 10 is even more secure than the shit Apple gives you, Linux + VM is problably the safest you can get

>> No.29101965

>>29100939
you know that you can send things around with your ledger right? that's kind of the point

>> No.29101969

>>29101840
What if I execute zero trades on my phone? I appreciate the OP but it's a bit complicated for me

>> No.29101979

>>29101910
This guy gets it.

>> No.29101999

>>29101848
Stamped on a piece of stainless steel, not written down on a piece of paper like a fool

>> No.29102019
File: 15 KB, 415x368, OptionalFeatures_2021_02_18_23_45_44.png [View same] [iqdb] [saucenao] [google]
29102019

>>29099541
>>29101840
i only use my phone for transferring crypto between exchanges, and looking at my metamask every now and again
i looked at your guide and i dont see windows sandbox feature. is this something you need to install somewhere? i can figure out everything else posted there

>> No.29102050

>>29101900
No

>> No.29102155

>>29101900
No you don’t need an account. It’s literally the same as MetaMask. You can stake and trade on dexes with it

>> No.29102181

>>29101331
by wallet install you mean add specific coins to it?

>> No.29102191

>>29101616
I use Mac for making music other than that it’s totally shit. I literally am thinking about getting a cheap hp laptop + virtual machine + vpn just to execute sales and hold my money. Honestly hate going on the internet cause risks of spyware but got to

>> No.29102216

What are the best browser extensions to protect myself besides uBlock Origin?

>> No.29102215

>>29101412
What's wrong with crypto transactions on up to date ios?

cold storage for holds obviously

>> No.29102259
File: 36 KB, 225x350, Msyu.jpg [View same] [iqdb] [saucenao] [google]
29102259

>>29099541
Thank you anon!

So Firefox Portable folder will have metamask seed, addons, and bookmarks, right?

Where would you save the seed if someone steal your PC?

>> No.29102272

>>29102216
Decentraleyes, Cookie Autodelete, HTTPS Everywhere

>> No.29102296

>>29099541
Just use a extremely random password utilizing every acceptable type of key/symbol and you should be good

>> No.29102341

>>29101840
Fud, this is beyond retarded. If you follow the instructions
>don’t screen or type out your seed words anywhere
>don’t visit any websites on the wallet browser except app.uniswap.com
There’s literally zero chance of getting your shit stolen. Never happened (prove me wrong) and never will happen

>> No.29102361

>>29101969
If it involves importing your wallet via a seed phrase to your phone, you've opened yourself up to the risk. Phones store typed data in various ways, not including the million different ways applications can keylog you after the fact.

Plus it has the biggest flaw of all, giving physical access to a multitude of people on a regular basis. Tons of those wallets allow you to get into them with just a biometric scan. Absolutely trivial to bypass.

>>29102019
What version of windows are you on? It is relatively new, I think 1909 or later.

>> No.29102369

>>29102272
cheers

>> No.29102504

>>29102259
Follow info here
>>29101331
>>29101463
>>29101671

>> No.29102536

>>29102191
>I use Mac for making music
What genre?

>> No.29102553

>>29101616
Lots of mac shit talk from poorfags. I'm a SWE and half the time i can't even figure out how to run my own programs because of macOS security shit. I am not worried about pajeet limewire porno viruses

>> No.29102635
File: 16 KB, 460x423, winver_2021_02_18_23_57_03.png [View same] [iqdb] [saucenao] [google]
29102635

>>29102361
might be a little bit outdated for that then, guess ill have to update my computer sometime later tonight

>> No.29102680

just use malwarebytes once a day

>> No.29102696

>>29102259
Place seed words into a small titanium capsule and then insert it into the deepest, darkest alleysways of your anus

>> No.29102748

>>29102635
Quick search got me this.
https://www.ghacks.net/2019/04/26/install-the-windows-sandbox-in-windows-10-home/

Make sure you meet the requirements or follow the guide to get it working on home.

>> No.29102761

thanks for the airdrop

>> No.29102931

Are you retards really getting your metamask wallets hacked? How common is this?

>> No.29102957

>>29101671
Mmmm... But do not save it in .txt, encryp the file or .rar with password!

>> No.29103103

>>29102957
The file itself can be encrypted, yes. It doesn't really matter though, since you still need the password AND the key to get in. So if you only keep copies of the key files in physical USB drives, it requires someone trying to steal your shit to have physical access to your machine and also know the keepass password.

>> No.29103137

>>29101412
oh god what is going to happen to me I do half my trades on Metamask in iOS

>> No.29103220

>>29102931
It's not a common thing yet, but with the growing popularity and money flooding into the alt markets via Metamask, it makes it a massive target. Just like CEX is a huge target for those interested, and why so many exchanges have been fucked over the years from bad actors in the organizations or hacks.

>> No.29103385

>>29102931
theres been like 10 threads in the last 24 hours and the last dude said he didnt do anything but click the first result on google for pancakeswap

>> No.29103508

>>29103137
Nothing, just stop while you're ahead. Transfer your stuff to a new wallet with a new seed phrase made like the guide above.

This takes 20-30 minutes to set up, and only adds maybe 2-3 minutes of extra steps compared to normal trading when it is done. It's worth it.

>> No.29103753

>>29103385
>shitcakeswap
Good.

>> No.29103876
File: 8 KB, 300x165, 8091DF3A-9FB4-4BE2-BD17-691AC17824C8.jpg [View same] [iqdb] [saucenao] [google]
29103876

Just use Brave Browser wallet hooked in to a Trezor.

I only use metamask on my mobile to ape into swaps when I’m not at home.

>> No.29103930

if you don't keep a physical notebook and airgapped encrypted usbs you're doing it wrong

>> No.29103978
File: 30 KB, 667x670, 1569437304722.jpg [View same] [iqdb] [saucenao] [google]
29103978

>>29103753
>zit boy yo

>> No.29104261

>>29103385
he was bullshitting you moron

>> No.29104325

>>29103876
I don't have the time or will to explain to you why that isn't enough (or why brave isn't secure at all). Just know a stranger on the internet is telling you. That's not enough.

>> No.29104376

>>29099541
or just use a ledger. It's alot easier

>> No.29104625

>>29104325
Link?

>> No.29105802

>>29104261
he posted his wallet tho and all his eth went to some phishing address and it said his address was compromised or some shit on etherscan

>> No.29106189

>>29104325
I know what you're talking about anon.
In reality though, gold is the safest asset to hold if you really want to get technical. You can make your own hardware and operating system and wallet but ultimately, gold hidden somewhere is safer than your bitcoins

>> No.29106267
File: 558 KB, 540x540, 1612190243944.gif [View same] [iqdb] [saucenao] [google]
29106267

>>29103385
>>29104261
>>29105802
>Just went on the first link to ps to see if there was an airdrop
>read this
>check the twitter account to see if the links are the same
Fucking scared me

>> No.29106287

>>29099541
Alllll that gay shit
Or literally just link a hardware wallet and keep enjoying shady porn sites because we all know that's where the good shit gets posted.

>> No.29106303

>>29099541
jfc. i dont have to any of this for my brokerage account. kys. circle jerk this much for 'security' then send buy transfer coins, paying absurd fees for pnd scams.

>> No.29106312

>>29099541
Or spend $100 for a trezor. Best investment youll ever make.

>> No.29106360

>>29099541
Go back to plebbit. My 2k link has been on metamask for YEARS

>> No.29106475

>>29099541
Why the fuck would i do this? You're paranoid bro

>> No.29106484

>>29101463
I'm a pentester and all it takes to break into a keepass database file is
keepass2john key.kdb > hashfile
hashcat hashfile wordlist
Within 5 minutes I have your master password and can access the rest of your passwords
To everyone out there do yourself a favor and put spaces in your passwords when you can. "dog cat fish" is much harder for a gpu to crack than "!dogCat1fish8".
>>29102019
delete system 32

>> No.29106495

>>29106303
You don't need any of this for exchanges, which are like you brokerage account. Self custody of private keys is like holding gold bullion, banknotes and bearer instruments. Only they're digital and can be stolen through that medium. Too many people are doing the equivalent of walking around with a $10,000 wad in their pocket and then acting surprised when they get robbed.

>> No.29106758

>>29106495
Centralized exchanges are where the most shit has been stolen from people to date in crypto. What the fuck are you smoking anon?

>> No.29107048

>>29106484
>put spaces in your passwords
many sites dont allow spaces

>> No.29107050

>>29099541
I just use metamask to trade, keep ~0.5 ETH for gas and transfer my holdings into a coinbase wallet

>> No.29107246

>>29106287
>>29106312
>>29106360
>>29106475
Not my problem if you don't take the most basic of Opsec with your assets. A hardware wallet is a valuable tool, but it is not at all the end all be all. Especially if you're trading out of it through their software. A hardware wallet by definition is intended to be cold storage and air gapped from the internet. This just makes it another hot wallet.
>>29106484
Good advice all around. Storing your master password in a key without a separate remembered password is fucking stupid.

>> No.29107304

>>29107246
Youre not even using the term hot wallet correctly.

>> No.29107325

>>29107246
>Not my problem if you don't take the most basic of Opsec with your assets
You're not explain how this prevents any hacking or anything. /g/ fag here telling you you're full of shit

>> No.29107398

>>29106484
>dog cat fish" is much harder for a gpu to crack than "!dogCat1fish8".
No its not
>Within 5 minutes I have your master password
No you won't, i use a key too. Granted you need access to my system

>> No.29107458

>>29100318
>Putting your crypto on a windows machine
WHY would you do this.

>> No.29107835

>>29107304
OK bruv
>>29107325
Because frankly I don't know them. If I did, I'd be swimming in your shit coins right now rather than shit posting on /biz/. Again, basic Opsec is applicable for many situations, and this is one of them. Isolating your trade platform as much as possible from your primary device and common vectors of attack is the bare minimum.
>>29107458
A guide for normies that don't want to bother with Linux, because the moment they read it their eyes glaze over.

>> No.29108049

>>29107835
>Because frankly I don't know them
So youre a retard full of shit
>Isolating your trade platform as much as possible from your primary device and common vectors of attack is the bare minimum
Pretty fucking retarded and paranoid anon. First of all never trade on windows because windows is shit. I don't know why any retard would isolate like you said. I keep my personal stuff on waterfox, trading on librewolf more for organization. You can't prove or even speculate how the hack would work so fuck off fag

>> No.29108141

>>29107835
>want to bother with Linux,
Good security would be using linux. Do not use windows if you're worried about security period

>> No.29108160

cant you just setup the trezor or ledger with metamask
do u have to make a new address for this

>> No.29108179

>>29106758
>cryptos go into a big pot
>wow a lot got stolen
This metamask shit happens like every other month dude. It's the same thread over and over. The take is just smaller.
Mtgox literally one time. It was never even designed to be a crypto exchange.

>> No.29108182
File: 86 KB, 720x1480, Screenshot_20210219-124602_MetaMask.jpg [View same] [iqdb] [saucenao] [google]
29108182

>>29099541
It did not work!!?? All my crypo got stolen anyways

>> No.29108264

By the way. If you're gonna do this at least be smart about it. Having a browser extension with the ability to sign transactions is clearly a bad idea

>> No.29108760

>>29108182
F. So sorry. This literally happens to everyone who uses metamask though. Can't say we didn't warn you