Live data from Hacker News

Hackers nab $500k as Enigma is compromised weeks before its ICO

techcrunch.com

21–30 of 249 posts

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#21
post #7

Can we get the title fixed? The editorialized title is misleading/inaccurate. (edit: Thanks, it's fixed now.)

In what way? The company's website, email lists and other property was compromised and investors lost 500k, seems pretty clear to me.

Original title was something like "Enigma's ICO hacked, $500,000 stolen. CEO reused password. No 2FA."

For one, my understanding is that the Enigma's "website, email lists and other property" was compromised, not it's "ICO". Second, the $500,000 was scammed out of users/investors rather than directly stolen in the "hack". I think for crypto-coins this is an important distinction.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#22
post #19
post #14

I wish that passwords like this stopped being the main form of authentication. I guess I'm not sure what's a better way (I like the physical object + pin of my credit card but that's probably not practical for all Web authentication) but it seems pretty obvious that passwords are broken in their current form unless you use a password manager, which can be a hassle

This is where two factor authentication comes into play. Then you can have something you know (eg password) and something you own (eg phone). I quite like using Google Authenticator for my 2FA.

There are also problems with that: https://news.ycombinator.com/item?id=15068567

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#23

As with most things security, people tend to be the weakest link in the chain. This type of issue could be solved in a lot of ways. I think a solution wherein: 1. ICOs use a standard 'escrow' contract wherein ether and coin get held by the contract for 7 days or so before either party can withdraw the opposite pair (where either can back out). 2. Building some standard 'ether address' widget that verifies the type of…

That wouldn't solve this problem. Did you read the article? The ICO investors were tricked.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#24
post #14

I wish that passwords like this stopped being the main form of authentication. I guess I'm not sure what's a better way (I like the physical object + pin of my credit card but that's probably not practical for all Web authentication) but it seems pretty obvious that passwords are broken in their current form unless you use a password manager, which can be a hassle

There is no security mechanism that is safe against gross negligence.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#25

Earlier quoted context omitted.

The problem is that most people tricked into "investing" in such platforms probably don't make anything like a software engineer at Google. This loss hurts them a lot.

Even knowledgeable people can fall victim to attacks like this.

You make it sound like I claimed that people not working at google are less intelligent. My point was that if you are already making good money you are not looking for lottery tickets to buy.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#27
post #14

I wish that passwords like this stopped being the main form of authentication. I guess I'm not sure what's a better way (I like the physical object + pin of my credit card but that's probably not practical for all Web authentication) but it seems pretty obvious that passwords are broken in their current form unless you use a password manager, which can be a hassle

How about authentication with public keys? You can store them encrypted in a smartcard, on your computer, on your phone, or even write them down.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#28

Another ICO, another scam. I am not sure I feel bad for people who are gullible enough to send their hard earned money to these "companies". They have one PDF whitepaper and a generic Wordpress template website with some buzzwords, based in Cayman islands or some other tax haven for money laundering. And expecting to get rich from that.

I am unconvinced that hard earned money is 'invested' in those companies. The target demographic is not hard working class.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#29

As with most things security, people tend to be the weakest link in the chain. This type of issue could be solved in a lot of ways. I think a solution wherein: 1. ICOs use a standard 'escrow' contract wherein ether and coin get held by the contract for 7 days or so before either party can withdraw the opposite pair (where either can back out). 2. Building some standard 'ether address' widget that verifies the type of…

That wouldn't solve this problem. Did you read the article? The ICO investors were tricked.

The user wallet vs contract distinction might help, but that means tooling and education.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#30

So what, just a couple of years worth of work at Google as a SWE.

The problem is that most people tricked into "investing" in such platforms probably don't make anything like a software engineer at Google. This loss hurts them a lot.

My feeling is that most people are investing profits from another virtual currency. So it's not "real money" (in the sense of doing a deposit of USD and sending that to the ICO), but an existing paper profit that they want to try multiply further by putting it into another speculative asset.
Post reply on HN