"We had changed almost everything, but hadn’t scrapped our personal computers used while Bob had been part of the team. Would that have been the paranoid thing to do? Yes." At my humble and refreshingly drama-free place of work we have standard client images. Anything weird and the techies re-image the client. Assuming 'Bob' wasn't in charge of the images, would such a procedure have sorted the rdp?
Maybe. The larger question was why did Bob have root access to people's individual laptops? He could have done a "snowden", grabbed their SSH keys including passphrases. That would have been much harder to detect.
The Looting of ShapeShift
51–60 of 95 posts
Re: The Looting of ShapeShift
#52Earlier quoted context omitted.
There are few positions that merit a hiring background check more than ones directly involving the financial transactions of a company. Even if it costs a lot of money, it is absolutely money well spent.
Background checks definitely do not cost a lot of money. I think it's in the $15 range.
Re: The Looting of ShapeShift
#53Man, calling a social security number a "social serfdom number" is really dumb and off putting. So is the continual reference to 'fiat money' constantly. I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.
Would you call a communist a hypocrite for buying food at a grocery store?
Re: The Looting of ShapeShift
#54This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…
Re: The Looting of ShapeShift
#55Earlier quoted context omitted.
The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.
One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…
If you don't want to trust your hosting provider with anything, you have to own the hardware.
Re: The Looting of ShapeShift
#56Earlier quoted context omitted.
The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.
One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…
Because they control the hypervisor, they control everything. That means they have as much access and authority as the code that you are running on their servers have. So the only way to protect yourself from them is to limit what your servers (deployed on their cloud) can actually do.
So for instance you could have a secure backend server on a dedicated host in a trusted environment, with the cloud servers using an API to the backend server. If the API is suitably secure then the cloud servers could be compromised without allowing them to directly issue invalid commands in the same way the backend server could. Then you could use the cloud to scale out your web frontend without compromising yourself.
The same is true of hardware on the dedicated host (such as the "Trusted Computing" Module) that you do not control. If that (or the BIOS) gets compromised you might not even know that your host is no longer secure.
Re: The Looting of ShapeShift
#57Earlier quoted context omitted.
The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.
One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…
Re: The Looting of ShapeShift
#58Earlier quoted context omitted.
http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...
While I think both of these are great, it still doesn't explain calling it "social serfdom number".
Re: The Looting of ShapeShift
#59Earlier quoted context omitted.
http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...
While I think both of these are great, it still doesn't explain calling it "social serfdom number".
He was the first to [nominally] move a bitcoin business out of New York when the bitlicense was enacted.