Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

41–50 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#41
post #22

When reading crypto clownworld stories like this, it is easy and fun to observe that cryptocurrency is a satire of the real (or "fiat", if you prefer) financial system. Less fun, but far more important, is to note how incredibly (infinitely?) subtle this satire is: https://news.ycombinator.com/item?id=22352840

One thinks about crypto as a clownworld only until one had to work with or inside the real financial system. Techincally, it is in no way better than crypto. The only difference is that in real financial system there is a strong legal cover for all the technical and security fuckups. Like, stealing from bank by exploiting their 10-years old Windows XP ATM connected to the internet is 10-years-in-jail offence, while s…

That only difference is an extremely important difference

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#42
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

"Sufficiently advanced incompetence is indistinguishable from malice."

I don't recall who said it, but it seems to fit.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#43
post #32
post #20

Earlier quoted context omitted.

Sounds like really nice plausible deniability for whomever came up with such a blatant wrong way of storing secrets/value

Nov. 11 — Friday: SBF resigns, FTX goes bankrupt Nov. 12 — Saturday: FTX hacked for most of its remaining crypto Y'all be the judge.

Let's hope he doesn't buy the judge with the stolen funds...

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#45
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

> That crosses the line and goes deep into "willful negligence" territory, in my view. A lot of people are making the assumption that gross incompetence reigned supreme with FTX, and that does seem like the likeliest explanation, but another potential explanation is deeply devious criminal activity. They could have preplanned this behavior. If they were ever caught doing anything really bad, they had "plausible denia…

> A lot of people are making the assumption that gross incompetence reigned supreme with FTX, and that does seem like the likeliest explanation, but another potential explanation is deeply devious criminal activity.

Former FTX US President Reportedly Quit After ‘Protracted Disagreement’ With Bankman-Fried - https://www.coindesk.com/business/2023/04/09/former-ftx-us-p...

> ...

> According to the report, another employee in the exchange’s legal department was “summarily terminated after expressing concerns about Alameda’s lack of corporate controls, capable leadership and risk management.”

> Alameda wasn’t even clear on what its own positions were, “let alone hedging or accounting for them,” Ray's document reads. A June 2022 portfolio summary, which was supposed to show Alameda’s makeup of crypto positions, was reportedly fabricated after employees were allegedly instructed by an unnamed higher-up to “come up with some numbers? Idk.”

> At one point, according to the report, Bankman-Fried told employees:

> “Alameda is unauditable. I don’t mean this in the sense of ‘a major accounting firm would have reservations about auditing it’; I mean this in the sense of ‘we are only able to ballpark what its balances are, let alone something like a comprehensive transaction history.’ We sometimes find $50m of assets lying around that we lost track of; such is life.”

---

I'm not sure "devious" is the right word choice. Criminal activity - yes. I suspect they knew they were criminals to some degree but were grossly incompetent when it came to managing it.

It feels more like a constant stream of lies to support the ongoing fraud rather than devious.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#46

Earlier quoted context omitted.

> That crosses the line and goes deep into "willful negligence" territory, in my view. Er, that's the thing that pushed you over the line? Not all the fraud and crime?

i was okay with the fraud and the crime. it was the hierarchical polyamory that pushed me over the line.

Hierarchical polyamory? I thought they meant spreadsheets, not spreading the sheets.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#48

Earlier quoted context omitted.

> That crosses the line and goes deep into "willful negligence" territory, in my view. Er, that's the thing that pushed you over the line? Not all the fraud and crime?

Both are bad. Crime is bad, but this is an argument for making software engineering more like a medical doctor's guild. Some things simply should not be done. There is an expectation of competence for some things like finance and medicine.

Their finance scheme was like benefits fraud. Plaintext keys is malpractice. Is that close to what you mean?

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#49

It wasn't/isn't just them. It wasn't a massive secret either. https://news.ycombinator.com/item?id=32077583 The test of all these security exploits are in the exploiting. In practice, you can run wild and nothing will happen. My HN password was 000000 for years.

I mean I have a yahoo chess account with a password of like abc123, that's not the point.

Your HN password doesn't provide access to your money, never mind other people's money.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#50
post #22

When reading crypto clownworld stories like this, it is easy and fun to observe that cryptocurrency is a satire of the real (or "fiat", if you prefer) financial system. Less fun, but far more important, is to note how incredibly (infinitely?) subtle this satire is: https://news.ycombinator.com/item?id=22352840

One thinks about crypto as a clownworld only until one had to work with or inside the real financial system. Techincally, it is in no way better than crypto. The only difference is that in real financial system there is a strong legal cover for all the technical and security fuckups. Like, stealing from bank by exploiting their 10-years old Windows XP ATM connected to the internet is 10-years-in-jail offence, while s…

My impression is that there is a lot more auditing going on in the conventional financial system. Not to say that it's not bad, but there are at least some (legit) outside eyeballs on your system.
Post reply on HN