Live data from Hacker News

Hackers nab $500k as Enigma is compromised weeks before its ICO

techcrunch.com

41–50 of 249 posts

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#41
post #22
post #19

Earlier quoted context omitted.

This is where two factor authentication comes into play. Then you can have something you know (eg password) and something you own (eg phone). I quite like using Google Authenticator for my 2FA.

There are also problems with that: https://news.ycombinator.com/item?id=15068567

That's not Authy/Google Authenticator. That's social engineering their way into getting a persons text messages for SMS 2FA.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#42
Cryptocurrency is probably doomed because the makers of cryptocurrencies have a fundamental conceptual disconnect with money: what it is, why it works and what it represents. Money only works when you have a powerful state actor enforcing the legality of the transaction. When you try to escape that, you get at best a parallel system that still goes back to the state for help in keeping functioning or a system prone to failure, fraud and speculation. To whit yet another one of these incidents.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#43

As with most things security, people tend to be the weakest link in the chain. This type of issue could be solved in a lot of ways. I think a solution wherein: 1. ICOs use a standard 'escrow' contract wherein ether and coin get held by the contract for 7 days or so before either party can withdraw the opposite pair (where either can back out). 2. Building some standard 'ether address' widget that verifies the type of…

That wouldn't solve this problem. Did you read the article? The ICO investors were tricked.

[deleted]

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#44

Cryptocurrency is probably doomed because the makers of cryptocurrencies have a fundamental conceptual disconnect with money: what it is, why it works and what it represents. Money only works when you have a powerful state actor enforcing the legality of the transaction. When you try to escape that, you get at best a parallel system that still goes back to the state for help in keeping functioning or a system prone t…

maybe, but this particular incident was more along the lines of phishing and little to do with the cryptocurrency itself

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#46

Earlier quoted context omitted.

That wouldn't solve this problem. Did you read the article? The ICO investors were tricked.

And how wouldn't it solve the problem? (1) would act as a more safe instrument for sending money to addresses you don't regularly interact with, (2) would attempt to make the address type much more apparent to the user so they don't send to addresses they aren't familiar with.

Just because you invent a special type of escrow contract that makes it harder to steal money doesn't mean an attacker would use it... he would just instruct users to send money to his own contract and bypass all of the protections you've invented.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#47
post #28

Another ICO, another scam. I am not sure I feel bad for people who are gullible enough to send their hard earned money to these "companies". They have one PDF whitepaper and a generic Wordpress template website with some buzzwords, based in Cayman islands or some other tax haven for money laundering. And expecting to get rich from that.

I am unconvinced that hard earned money is 'invested' in those companies. The target demographic is not hard working class.

CNBC has been talking about Bitcoin, Ethereum, Ethereum Lite and a slew of recent ICOs in the last month or so. Whether those viewers count as "hard working class" is up for debate

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#48
post #22

Earlier quoted context omitted.

There are also problems with that: https://news.ycombinator.com/item?id=15068567

That's not Authy/Google Authenticator. That's social engineering their way into getting a persons text messages for SMS 2FA.

If you can compromise the iCloud account of an iOS user (pretty sure iOS 2fa is only SMS based), then you can install google authenticator on your own device.

I'm sure it's more complicated than that in reality, but if you have SMS access, you only need to find one weak link in the chain including iCloud/google, email provider, app provider, etc.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#49
post #28

Another ICO, another scam. I am not sure I feel bad for people who are gullible enough to send their hard earned money to these "companies". They have one PDF whitepaper and a generic Wordpress template website with some buzzwords, based in Cayman islands or some other tax haven for money laundering. And expecting to get rich from that.

I am unconvinced that hard earned money is 'invested' in those companies. The target demographic is not hard working class.

You would be surprised. People know nothing about Bitcoin but have a friend, uncle or acquaintance who has dropped a few thousands in BTC and raves about the price going from 580 usd to 4000 usd in just a year. People lose their minds and they won't even have shitty tulips to show for it.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#50

As a Russian proverb goes, "a thief stolen a thief's hat"

That's an interesting concept but I can't find anything about it.

I found this : http://kv-journal.su/content/vor-u-vora-ukral

"the thief stole from the thief"

I can't find anything hat related, though I wish I could

Post reply on HN