Live data from Hacker News

The Looting of ShapeShift

news.bitcoin.com

31–40 of 95 posts

Re: The Looting of ShapeShift

#31

Earlier quoted context omitted.

They don't do the background check.

They do- one company found a warrant on me that I didn't know I had for an unpaid traffic ticket.

Do you know where one would go to perform an accurate background check on oneself?

Re: The Looting of ShapeShift

#33
post #11

Am I the only one to think that all this narrative to blame Bob is pathetic ? This is pure and simple Mr. Voorhees (CEO) incompetency. After all, Bob is a criminal and he was just doing his "job".

No. There are Bobs everywhere. Do your job, and Bob doesn't rip you off. Leave Bob to the courts - blaming Bob is like blaming your dog for stealing your lunch, or a wave for soaking you on the shore. You will not hurt Bob's feelings.

edit: Bob didn't betray you. Your friends and family betray you. Bob stole from you.

Re: The Looting of ShapeShift

#34
post #11

Am I the only one to think that all this narrative to blame Bob is pathetic ? This is pure and simple Mr. Voorhees (CEO) incompetency. After all, Bob is a criminal and he was just doing his "job".

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

Their fundamental business model didn't account for and compensate for the incredible amount of risk involved in handling large amounts of money.

Re: The Looting of ShapeShift

#35
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

It's extremely expensive. Many banks and companies in the finance industry (hedge funds) do this:

Hire at least 2 or 3 people for every job. Have them watch each other whenever touching systems that connect to production or deploying code to production. Never trust any one of them with the private keys or passwords to anything - they can only get half of a secret and their co-worker gets the other half.

To do this effectively, you have to build a zero trust environment, and rely on surveillance to ensure that nobody is a bad actor. It really makes CIA/NSA level security look somewhat weak.

It's also very expensive, as you can imagine.

Re: The Looting of ShapeShift

#36

Earlier quoted context omitted.

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

Their fundamental business model didn't account for and compensate for the incredible amount of risk involved in handling large amounts of money.

To the contrary - their business model depended on it. Spending money on security and procedures would make them unprofitable. It's gambling. And losing.

Re: The Looting of ShapeShift

#37
post #11

Am I the only one to think that all this narrative to blame Bob is pathetic ? This is pure and simple Mr. Voorhees (CEO) incompetency. After all, Bob is a criminal and he was just doing his "job".

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything.

Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I know this is hard to do, but it's mandatory when you're handling digital currency.

Re: The Looting of ShapeShift

#38
"We had changed almost everything, but hadn’t scrapped our personal computers used while Bob had been part of the team. Would that have been the paranoid thing to do? Yes."

At my humble and refreshingly drama-free place of work we have standard client images. Anything weird and the techies re-image the client. Assuming 'Bob' wasn't in charge of the images, would such a procedure have sorted the rdp?

Re: The Looting of ShapeShift

#39
post #28

Earlier quoted context omitted.

You might appreciate http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...

http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...

One of these is sad and one is funny. They're both great for completely different reasons.

Re: The Looting of ShapeShift

#40

Earlier quoted context omitted.

There are few positions that merit a hiring background check more than ones directly involving the financial transactions of a company. Even if it costs a lot of money, it is absolutely money well spent.

Background checks definitely do not cost a lot of money. I think it's in the $15 range.

Criminal background checks are actually surprisingly hard to do. There are cheap ones that will search a subset, but doing it thoroughly actually requires physically going to courthouses in the county for all prior addresses. Even then, you can miss records if they are in counties where the person doesn't live.
Post reply on HN