Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

201–210 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#201
post #93

Earlier quoted context omitted.

where do you keep the key to the crypto fs?

Written on a scrap of paper in your wallet. only the password and no other info should be on the scrap. If you can memorize it, it is a bad password.

https://www.xkcd.com/936/

Re: Compromised Linode, thousands of BitCoins stolen

#202
post #165

Earlier quoted context omitted.

What would you recommend? Would you say the same thing if he'd been colocating and a data center employee had stolen his bitcoins? Because that seems far more analogous than any restaurant analogy, and I don't see any reasonable way for somebody who's not a huge corporation to avoid this kind of risk. You have to trust somebody at some point unless you're keeping the server locked in your own closet. It seems really…

Then he should Colo with a hosting provider with a contract provision that specifically holds them liable for any losses related to problems caused by the host, and enumerates those possible losses beforehand.

Simply not going to happen at any reasonable rate.

There's a saying in many businesses with different variations:

"Price, quality, speed" pick any two.

So this would be:

"Price, security, bandwidth" pick any two.

People pick on price and bandwidth security is taken for granted to be commercially acceptable. The colo can easily figure out price and bandwidth they are clearly defined. Losses from a security breach not as easy - to many variables. Same reason insurance companies love to write life insurance but hate to write disability insurance. Life insurance is absolute (you know when someone is dead and tables exist to compute probabilities on when they will die). Disability is open to interpretation, fraud and other things. It's not black and white.

Re: Compromised Linode, thousands of BitCoins stolen

#203

Earlier quoted context omitted.

"it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider." Really? (I'm reading that as saying you think it _is_ a reasonable thing to store $13k worth of effectively-cash-value in a $19.95/month vps account?) Does anyone know what regulations like HIPPA or PCI have to say about the security of data stored on managed-by-3rd-party servers like VPS…

First of all, yes, I think it's reasonable. Second, where are you getting $19.95/month from, anyway? I haven't seen the plan in question mentioned, and even if this particular VPS happened to be Linode's lowest-end, the last time I looked (a while back, granted), slush had multiple large VPSs with Linode. Third, really, what does the price of the VPS have to do with it? You think as the cost of the VPS goes down, we'…

Linode plans (like those of other hosting/vps providers) are differentiated on storage/memory/bandwidth. Security isn't a factor. Compare that to an auto where "security" is definitely mentioned and part of the selling proposition and what you pay (they mention theft devices, crash stuff, airbags etc.)

Re: Compromised Linode, thousands of BitCoins stolen

#204
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

"please think for a second what liability you would want for any mistakes that you make with your web startup or idea" It seems to me that bitcoin wallets are a relatively new and not well enough understood risk. There are very few other "files" like them, in that an attacker copying them can deprive you of their value in a way that you cant protect with backups. I feel a big part of current "internet security best p…

Don't store your money on servers you don't own. Don't have a web interface. Don't allow anyone to connect. Don't use passwords, use public key encryption. These are the basics.

Re: Compromised Linode, thousands of BitCoins stolen

#205
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

"please think for a second what liability you would want for any mistakes that you make with your web startup or idea" It seems to me that bitcoin wallets are a relatively new and not well enough understood risk. There are very few other "files" like them, in that an attacker copying them can deprive you of their value in a way that you cant protect with backups. I feel a big part of current "internet security best p…

An interesting point is that for receiving coins and for long-term storage, bitcoin wallets do not need to be online, and in fact do not need to ever have touched a machine that has been online. While slush "just" lost his "hot wallet", another user lost 200k. When will it become common best practice to store high-value accounts entirely off computers? You can print out a bitcoin wallet and put it in a safe deposit box for storage, and still add money to it.

Re: Compromised Linode, thousands of BitCoins stolen

#206
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

"please think for a second what liability you would want for any mistakes that you make with your web startup or idea" It seems to me that bitcoin wallets are a relatively new and not well enough understood risk. There are very few other "files" like them, in that an attacker copying them can deprive you of their value in a way that you cant protect with backups. I feel a big part of current "internet security best p…

I don't see what's so conceptually new about bitcoin wallets. They're just plain text that you don't want people getting access to. It's no different than storing passwords in plain text: if someone copies them, they're completely compromised (until the user changes them). The solution is pretty simple: encrypt your own bitcoins with your own password (or more ideally, your private key). Then, if someone hacks your server, they don't get anything.

Re: Compromised Linode, thousands of BitCoins stolen

#208

Earlier quoted context omitted.

Simplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it…

Sorry, there is just no way that this is the case. Please don't throw such a serious allegation out there without any evidence. To even suggest that this is technically possible for an employee to do is a serious allegation, let alone suggesting that someone did it maliciously. This spreads all kinds of FUD. I'll happily eat my words if that turns out to be what happened, but it is definitely not the simplest answer.

Up-vote to the original comment because it's not stupid or impossible, just unlikely.

We can only speculate at this point.

The simplest answer is probably that one of the staff was subject to a targeted hack and a 3rd party gained external access to the CSR tools.

Possibly for an extended period of time. It's relatively unlikely an internal staff member would do something this dumb (but, not impossible. we've had this happen _here_ where I work, with credit card numbers, but obviously the person responsible was caught almost immediately).

Re: Compromised Linode, thousands of BitCoins stolen

#209
post #88

Earlier quoted context omitted.

All Bitcoin transactions are publicly logged, but they aren't reversible. So you can see who stole your money but you can't do anything about it.

There is a bunch of violent people who would disagree.

Only if those violent people can locate the thief's physical location, which they can't.

Re: Compromised Linode, thousands of BitCoins stolen

#210
post #206

Earlier quoted context omitted.

"please think for a second what liability you would want for any mistakes that you make with your web startup or idea" It seems to me that bitcoin wallets are a relatively new and not well enough understood risk. There are very few other "files" like them, in that an attacker copying them can deprive you of their value in a way that you cant protect with backups. I feel a big part of current "internet security best p…

I don't see what's so conceptually new about bitcoin wallets. They're just plain text that you don't want people getting access to. It's no different than storing passwords in plain text: if someone copies them, they're completely compromised (until the user changes them). The solution is pretty simple: encrypt your own bitcoins with your own password (or more ideally, your private key). Then, if someone hacks your s…

Keys normally grant access so worst case once they're compromised you can take the server offline physically. Even private signing keys can be revoked though some damage may have been done.

With Bitcoin, once it's copied, you can consider it gone forever, irrevocably, in totality.

Post reply on HN