Tokens and Bitcoins

One of my team’s responsibilities at the United Nations was taking care of the systems that provided remote access, our VPN-like systems. We used Citrix appliances that offered a kind of web-based VPN. The system wasn’t the best, but it met our needs.
To ensure more secure authentication, we used a second authentication factor based on RSA tokens. They were small devices, similar to key fobs, with a display that showed numbers that changed every minute. To access the system, the user had to provide their username, password, and the code shown on the token. Its operation was based on synchronization with the server, which validated whether the number provided was the one expected at that moment. It was a model very similar to what apps like Google Authenticator do today, but it required the use of a physical device, which brought considerable logistical challenges. With thousands of users, we had to distribute the tokens, deal with losses and malfunctions, and maintain a continuous replacement process.
Even though my team wasn’t directly responsible for distributing the tokens, we would end up involved whenever there were problems: synchronization, configuration, or device failures. When I arrived at the UN, the system already existed, but it was outdated. So I started working on migrating to a more recent version. I managed to convince my boss it would be better to hire RSA itself to do the installation and migration, since it was a complex system that was not well understood internally. We hired the service and a consultant came to help us. We opted to run the system on Linux, which wasn’t the most common choice at the time, so much so that the consultant himself wasn’t all that familiar with that environment.
Our servers team prepared the machine and started the installation with the consultant’s help. After that, he would handle the migration and configuration. The person responsible for keeping an eye on the server was my friend Gabriel, who was on the UN’s Linux infrastructure team. When he analyzed the installation instructions, he was surprised: the procedure suggested disabling several security features of the operating system. His reaction was immediate: it made no sense for a security solution to require that kind of configuration.
The consultant tried to help and even put us in touch with RSA’s engineering team, but that didn’t fix the problem. In the end, it was Gabriel who solved the issue: he installed the system, did several rounds of trial-and-error adjustments to the security configuration, and managed to keep most of the operating system’s security mechanisms enabled. It was careful and very well-executed work. The result was so good that the consultant himself ended up inviting him to come work with them. Luckily for the UN, he didn’t accept.
One of the big new features of the new version was the option of using soft tokens, which ran as apps on phones or computers. The concept was the same as with physical tokens, but without the need for hardware distribution. I found that interesting because, when the consultant talked about this new possibility, he mentioned that the soft token did the initial synchronization with the server via a zero-knowledge protocol, which I had studied quite a bit during my time at Unicamp.
When I presented this new feature to the CISO, highlighting the logistical gain, he liked the idea. To test it, we initially decided to release the virtual tokens only to users outside New York, who were precisely the hardest to serve with physical devices. In those cases, tokens had to be sent by mail and activated over the phone, which involved costs, delays, and some security limitations. The pilot worked well and, later, we expanded the use of virtual tokens to all users.
It was around that time that I started hearing about something still little known: Bitcoin. I talked to some colleagues who had also heard about it, but no one had hands-on experience. After reading a lot about it, I decided to try. Back then, buying bitcoins was much more complicated than it is today. At the time, we didn’t know about cryptocurrency exchanges like Coinbase, which were still very niche. We had to find someone willing to sell and negotiate directly. In my case, I negotiated over email and sent the payment via Western Union. After that, I waited a few days to see if the bitcoins would actually show up in my wallet. I bought two, at about 100 dollars each. It was enough to learn how everything worked.
In conversations with my brother, he also became interested in the topic and ended up getting even more involved than I did. Over time, he started to follow cryptocurrency communities closely. In one of our conversations, he mentioned a USB-stick-sized device used for Bitcoin mining. I bought two: one for me and another for him. I had an old computer at the office that was practically unused. I plugged in the device and left it running to mine. The result was minimal — something like a tiny fraction of a bitcoin — but it helped me understand the process better.
Over time, Bitcoin began to gain popularity and the price went up. It reached about 1,000 dollars, ten times what I had paid. As often happens in such cycles, the price later began to fall. That’s when I decided to sell and ended up getting about 900 dollars for each bitcoin. It was a good profit, though much smaller than it would have been if I had kept the assets until they reached much higher values in the following years.