I lost my keys :( - don't be like me.

in Hive.IO Community3 months ago (edited)

$1

You might have read some of my blog posts on the importance of keeping your private keys safe. I wrote a detailed explanation of what they are here: understanding Hive keys. One of my main recommendations is to keep your keys off your computer.

How to keep your HIVE keys safe
As you might have seen in another video I made on how to use Trust Wallet, I'm a firm believer that you should not keep your keys stored on your computer. As soon as you receive your keys, you should make two copies:
One digital copy on a cold device (one that is not connected to the internet). I use a text file on a simple USB stick like this one and keep it in a fire-proof safe.
Another copy should be in a different location, ideally in a non-digital format like good old pen and paper.

Here is my first copy:

As recommended, they are not stored on any device, only nice and protected inside a fire-proof safe.

Nothing could go wrong, right?

Wrong.

My USB stick is still with me, but became severely corrupted and unable to mount on any computer.

The second problem is I didn't write down the second copy in good ol' low tech pen & paper because I was going to to it later when I found a typewriter to type my keys and passwords to avoid mistakes 😔.

Thanks Murphy.

I tried repairing via Terminal using diskutil repairVolume /dev/disk6s2
I tried mounting in read-only mode using sudo mkdir -p /Volumes/mount sudo mount -t hfs -o rdonly /dev/disk6s2 /Volumes/mount

I eventually got a invalid B-tree node size error which menas that the core filesystem structure (the catalog B-tree, which stores file/folder records) is corrupted in a way that fsck_hfs cannot fix. This is why the system won’t mount it — even read-only.

So I then tried PhotoRec to scan the raw partition for files.

This was awesome, because I felt like a hacker, lol (j/k) and also gave me a bit of hope as it did recover some of my files on the drive. Unfortunately, they were not the text files I was looking for.

I haven't given up hope on recovering my keys as there is this piece of software called Disk Drill that has already identified the text files I am looking for.

The only problem is I have to buy the paid version of the software that costs $100 that I don't want to spend right now.

Disk Drill guy.png


So, where am I at?

I still have all my keys for this account, so there's no problem there, but I don't have the master password for my business accounts:

@recording-box
@yellowcherry
@hivefunded

So I wouldn't be able to change my keys. I do have them set to a recovery account, so I could recover them if they ever become compromised, but I think I'm going to move my funds out of those wallets and into new wallet instead.
I still have the keys in @keychain on several devices, so I will still be able to post from them and export them to new devices, but I won't hold funds there for security reasons.

I've also written down my keys in a small notebook which I keep in my fire-proof safe that is bolted to the ground.

$1

I guess you can say I've learned my lesson in self-custody.

Sort:  

Dang, sorry to hear that. Good luck with moving all value over to new accounts!

Not all is lost thankfully and I believe I learned a valuable lesson. I'm still here and will be for a long time :)

Oops. I really ought to review my backup strategy as things can go wrong. You never know if a backup is good until you try to use it. Good luck with getting your keys back.

I do wonder how many people used Hive and then lost their keys. I've heard of a few cases. Some leaked them to crooks too.

!BEER

Yes. Review your backup strategy and learn from dummies like me.

I've been very careful about not leaving them on my computer or phone, but didn't take the extra step to have a backup for my backup. Fortunately, they have not been compromised and I still have them on Keychain so I can still post, send encrypted messages and money from my beloved @recording-box account which I started back in the day during the hostile takeover. That account means a lot to me. I don't want to keep my funds there though.

Damn! I hope you can recover them.

I guess you don't have the Owner Key either? With that one, you can create a new set of keys and even a new Master Password.

I have my full set of keys on several devices, but I also have to check my backups and make new ones.

No, I made sure to never save my keys to any device; Only this USB stick. I am hopeful that I'll be able to recover them using Disk Drill, but to be honest, maybe managing my funds from a different account is a healthy practice too.

Yeah, makes sense. Sometimes, too much safety can cause this. This happened to a friend, and she lost access to her original Discord account.

For some time, I was using a cold wallet for accounts where I kept liquid assets, but I stopped after a year or two because it was too much of a hassle. I'll see if I can use it again in the future.

I keep mine on a similar USB stick, but in my case.. I have 2 of them.

I should have made at least 2 AND copied them to paper.
Next time I'm going to make 6 like Dr Robert Neville in I am Legend.

I m legend External drives.jpg

Quite terrifying to lose your keys. They are embedded into KeyChain, as a last resort.. all but the master ones.

Yeah Backing up your keys is very important, I learned this firsthand.

Todo estará bien tocayo.
!PIZZA
!PIMP

Si, yo creo que todo estará bien. Mas bien me parece buena idea administrar mis HIVE desde otra cuenta donde tenga todas mis copias desde un principio; quizás le pueda poner multisig también. De cualquier manera, prefiero esto a estar llorando porque me sucedió una tragedia, sabes?

I'm very sorry to hear that, man. Good luck with the keys :/ Unfortunately, the new generation of USBs break very quickly. I bought one the other day and it was broken, then I bought another one and that one was broken too. Only the third time did I manage to find a working one.

I thought USBs were indestructible. I actually don't remember one ever failing on me. It HAD to be this one 😄. Anyway, I can still use my business accounts because I have imported the keys to Keychain, but I can't change those keys until I recover the master password. Not all is lost.

Oh dear, maybe that $100 is the best $100 you will be spending. Good luck

That will definitely be the case :). I'm optimistic I'll recover the files, I just want to wait a bit just in case I need some emergency chocolate.

All the best for this process, Alex. Sucks. 🫣

Thanks Thomas!

Nothing has been lost thankfully. I'll just manage my funds from another account. I still have the possibility of recovering my master passwords once I run the Disk Drill utility, but I have to have an extra $100 to try; not going to do that right now.

Ah ok. 👍🏻

Safe unless compromised then :) And a lesson learned, I see :)

Damn that is a sad experience. I hope that your keys will be safe in the future and this will not happen again.

Yeah, made several copies on paper and they are in a fire-proof safe :) Hopefully it won't happen again.


Hey @alex-rourke, here is a little bit of BEER from @steevc for you. Enjoy it!

Did you know that <a href='https://dcity.io/cityyou can use BEER at dCity game to buy cards to rule the world.

And I keep wondering why your posts haven't appeared in my feed for so long. Paper, it's good when the information (slightly encrypted) is on good old paper.

Yeah, I've also been a bit busy focusing on fiat-mining and other IRL activities. I'm not gone, I was just laying low for a bit.

PIZZA!

$PIZZA slices delivered:
@gr33nm4ster(2/15) tipped @alex-rourke

Come get MOONed!