Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

11–20 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#11

The writeup of this is rather suspect. What happened is someone guessed slush's Linode account password, and used the root password reset feature from there. What I don't understand is why does such a feature exist, why doesn't Linode require >16 character length passwords that are sufficiently random (or eschew password auth altogether), and why does slush (apparently from what I can tell) allow password auth for ss…

> why doesn't Linode require >16 character length passwords that are sufficiently random

Well, depending on how they got Marek's password, it might not matter. If someone went to his apartment and saw it written down on a post-it...

Re: Compromised Linode, thousands of BitCoins stolen

#12
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

This strikes me as a really good point. The onus for proof of merit is on the decentralized currency.

Simply put, people trust Visa and MasterCard to safely manage transactions, for better or for worse. Regulation like PCI helps ensure that this trust is sound.

The Bitcoin community at large could really benefit from a set of published best practices for managing transactions. Anybody possessing an insecure wallet is ultimately a liability to the credibility of the currency.

Re: Compromised Linode, thousands of BitCoins stolen

#13
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

But all that regulation is evil and it's the freedom of bitcoin that gives it the power*

*for hackers to get away with the entertaining virtual train robberies we've seen in the last year

Re: Compromised Linode, thousands of BitCoins stolen

#14
The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscriber for services during the period damages occurred. In no event shall Linode.com be liable for any special or consequential damages, loss or injury.

This also provides an interesting dilemma when it comes to such events. In this case the damage is relatively easily quantifiable, he got X bitcoins stolen so the damage is X times the bitcoin value at that time. Still, it could have easily been user personal data or credit card information, which would have made an evaluation harder to make.

One of the risks of using such a platform I guess and something that anyone who does it should consider.

Re: Compromised Linode, thousands of BitCoins stolen

#15

The writeup of this is rather suspect. What happened is someone guessed slush's Linode account password, and used the root password reset feature from there. What I don't understand is why does such a feature exist, why doesn't Linode require >16 character length passwords that are sufficiently random (or eschew password auth altogether), and why does slush (apparently from what I can tell) allow password auth for ss…

If they had guessed his password then their login would have shown up in the activity logs for his account, which he indicated was not the case.

Re: Compromised Linode, thousands of BitCoins stolen

#16
How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts?

Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines and then loot your wallets?

Re: Compromised Linode, thousands of BitCoins stolen

#17

The writeup of this is rather suspect. What happened is someone guessed slush's Linode account password, and used the root password reset feature from there. What I don't understand is why does such a feature exist, why doesn't Linode require >16 character length passwords that are sufficiently random (or eschew password auth altogether), and why does slush (apparently from what I can tell) allow password auth for ss…

The response from linode says that it was a "a customer support interface" that was used to access the account. This seems to indicate an error in their support system rather than someone guessing slush's password.

Re: Compromised Linode, thousands of BitCoins stolen

#18
post #9

Since my $1,000 worth of bitcoins dropped in value to $150 over a period of weeks, I've become significantly less interested in using it as a currency.

You mean less interested in using it as a way to profit from speculation. As a currency it is not as critical that the value only goes up. A person or merchant receiving bitcoins can easily convert them out to USDs and still lose less in fees than the same transaction would cost compared to accepting a credit card or debit card payment. For example, BTC -> USD at most exchanges is around half a percent.

"As a currency it is not as critical that the value only goes up."

True, but to be a practical currency it is critical that the value remains relatively stable. A currency capable of dropping from $1000 USD to $150 USD in a very short time is clearly not stable.

Re: Compromised Linode, thousands of BitCoins stolen

#19

The writeup of this is rather suspect. What happened is someone guessed slush's Linode account password, and used the root password reset feature from there. What I don't understand is why does such a feature exist, why doesn't Linode require >16 character length passwords that are sufficiently random (or eschew password auth altogether), and why does slush (apparently from what I can tell) allow password auth for ss…

Yes, the writing is a little incoherent. Maybe that's the reason that caused you to miss that, in fact, someone used Linode's 'Customer Service Representative' interface to get access to his account.

Don't stop reading and comment with 'I call bullshit'.

Post reply on HN