Live data from Hacker News

How I Stole a User's Siacoin

mtlynch.io

31–40 of 73 posts

Re: How I Stole a User's Siacoin

#31

I used to mine Bitcoin back in 2011 and I lost my wallet.dat file (through several stupid moves on my part). It's got approx 103 BTC in it, anyone is welcome to it, I've given up trying. https://blockchain.info/address/166BuLPWHUjqoqiYp5rGE3B5r5Am...

My brother accidentally deleted his wallet.dat from Dropbox a few years ago - he had given it a random filename and encrypted it with GPG so it was unrecognizable to hackers (and apparently him as well).

It had 1,000 BTC in it! He had received them from a generous Bitcoin contributor in the early days who said "here you go, hold on to it, it will be worth something someday."

I still give him a hard time about his $3 million USD mistake...

Re: How I Stole a User's Siacoin

#32
post #30

Earlier quoted context omitted.

Would CFAA really apply here? He's not accessing any computer illegitimately, the blockchain is public record, the key was posted to a public website. He's accessing the public siacoin network, posting transactions that anyone has permission to.

I'm not convinced that "posting to a public network" gets you out of the sketch. Sections 5-7 seem at least partially relevant, but then I'm neither in the US nor am I a lawyer anywhere else. Posting data to a remote system, with the clear intent of taking a thing of value from another person without permission. Perhaps it falls between the cracks, but I'd be reasonably surprised if it doesn't come under this or anot…

Well, have a look at United States v. Kane, it basically indicates that if you don't exceed authorized access you're in the clear. It's hard to say that posting a cryptographic signature to a network design to accept them from anyone exceeds authorized access if pushing buttons to trigger an exploit on a poker machine doesn't.

I'm sure you could have a pretty good argument in court if they went after you using CFAA. Other theft and fraud laws might cover it without issue though, just saying CFAA might not be the right choice here.

Re: How I Stole a User's Siacoin

#33

I used to mine Bitcoin back in 2011 and I lost my wallet.dat file (through several stupid moves on my part). It's got approx 103 BTC in it, anyone is welcome to it, I've given up trying. https://blockchain.info/address/166BuLPWHUjqoqiYp5rGE3B5r5Am...

My brother accidentally deleted his wallet.dat from Dropbox a few years ago - he had given it a random filename and encrypted it with GPG so it was unrecognizable to hackers (and apparently him as well). It had 1,000 BTC in it! He had received them from a generous Bitcoin contributor in the early days who said "here you go, hold on to it, it will be worth something someday." I still give him a hard time about his $3…

Did he try Dropbox support to see if they have a backup?

Re: How I Stole a User's Siacoin

#34
post #24

So I can overlook the misdemeanor pocketing of a few bucks with the intent on giving it back, but you basically admit and brag about breaking the Computer Fraud and Abuse Act as some kind of exercise of how clever you are for doing a dictionary attack against a weak and exposed key? Good luck sir.

Imagine you were the person who decides whether or not to bring charges against Mr. Lynch. Would you?

Alternatively: imagine you were selected to sit as a juror in such a case. Would you nullify?

Re: How I Stole a User's Siacoin

#35
post #30

Earlier quoted context omitted.

I'm not convinced that "posting to a public network" gets you out of the sketch. Sections 5-7 seem at least partially relevant, but then I'm neither in the US nor am I a lawyer anywhere else. Posting data to a remote system, with the clear intent of taking a thing of value from another person without permission. Perhaps it falls between the cracks, but I'd be reasonably surprised if it doesn't come under this or anot…

Well, have a look at United States v. Kane, it basically indicates that if you don't exceed authorized access you're in the clear. It's hard to say that posting a cryptographic signature to a network design to accept them from anyone exceeds authorized access if pushing buttons to trigger an exploit on a poker machine doesn't. I'm sure you could have a pretty good argument in court if they went after you using CFAA.…

Perhaps, again I'm not a lawyer. However, one of the things brought up is that they didn't do something with a computer “which is used in or affecting interstate or foreign commerce or communication”.

I don't know about the additional "unauthorised access" but I'd be surprised if someone can't make a case from cracking a password to do something on a network you know shouldn't be possible unless you were the person who owned the address.

Re: How I Stole a User's Siacoin

#36
post #30

Earlier quoted context omitted.

Would CFAA really apply here? He's not accessing any computer illegitimately, the blockchain is public record, the key was posted to a public website. He's accessing the public siacoin network, posting transactions that anyone has permission to.

I'm not convinced that "posting to a public network" gets you out of the sketch. Sections 5-7 seem at least partially relevant, but then I'm neither in the US nor am I a lawyer anywhere else. Posting data to a remote system, with the clear intent of taking a thing of value from another person without permission. Perhaps it falls between the cracks, but I'd be reasonably surprised if it doesn't come under this or anot…

He didn't just post the passphrase, he also posted this:

"If someone figures it out, I will send you free sias"

I'd call that a clear invitation/authorization for anyone to try to crack his passphrase.

Re: How I Stole a User's Siacoin

#37
post #30

Earlier quoted context omitted.

I'm not convinced that "posting to a public network" gets you out of the sketch. Sections 5-7 seem at least partially relevant, but then I'm neither in the US nor am I a lawyer anywhere else. Posting data to a remote system, with the clear intent of taking a thing of value from another person without permission. Perhaps it falls between the cracks, but I'd be reasonably surprised if it doesn't come under this or anot…

He didn't just post the passphrase, he also posted this: "If someone figures it out, I will send you free sias" I'd call that a clear invitation/authorization for anyone to try to crack his passphrase.

Reasonable, but not an invitation to transfer the entire amount then setup an automated process to transfer any remaining amount to your own address.

Re: How I Stole a User's Siacoin

#38

I often wish that password entry for things fully under your control (i.e. when there are no retry limits aside from brute computational power) would come with limited brute forcing support. Such password dialogs could just let you type your best effort, and they could use the things you type to inform the guessing process; you could fat-finger a character or two, and it would just take a moment longer to log in as i…

Some people (e.g. Facebook) do this already. And it turns out that this doesn't really impact security all that much!

Here's a recent research paper on the topic: pASSWORD tYPOS and How to Correct them Securely - http://www.ieee-security.org/TC/SP2016/papers/0824a799.pdf

Re: How I Stole a User's Siacoin

#39

Earlier quoted context omitted.

Wow. That's like, "I know I bought a house a few years ago. It was a decent house, I think, but I lost the address and can't seem to remember where it was or how to find it again." (except that with Bitcoin, it's like, "the house is somewhere in this galaxy, but I can't remember which solar system")

It's more like: "I bought a painting for 20$ at flea market. 6 years later I learned it was from Van Gogh but sadly I don't know where it is now."

My dad actually bought a painting for $25 at a flea market in Amsterdam and it turned out to be a Paul Citroen, we ate pretty good for a couple of years because of that. Not quite a Van Gogh but still, a good catch.

Re: How I Stole a User's Siacoin

#40

So what are both "ionic" and "tonic" in the same dictionary for a human readable entropy library?

Good question. I'm the author of that library and I can say I just borrowed the word list from another project.

Luckily, that library only cares that you get the first three letters of each word correct, so we can update the word to 'tonsil' or 'tongue' without breaking compatibility.

Post reply on HN