Live data from Hacker News

The $1.5B Bybit Hack

blog.trailofbits.com

21–30 of 140 posts

Re: The $1.5B Bybit Hack

#21
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Is cash silly? It has the same property (non-reversibility)

Keeping $1.5 billion in cash is silly.

Re: The $1.5B Bybit Hack

#22
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversible transactions is a feature for fiat money Reversible transactions would generally be a bug regarding cash & hard assets of which cryptocurrency is trying to imitate.

1.5 billion in cash would not disappear this easy. You would need trucks to even transport it.

Re: The $1.5B Bybit Hack

#23

Taking a step back from this attack, it looks like the new crypto-reality is far far far immature security-wise & compliance-wise ("compliance to what??" you can ask me). While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals…

I'm not sure how you'd do compliance, though. At least not universally. You could (which I suppose is your point) implement compliance requirements for crypto companies operating facilities on your soil. That doesn't really do anything for decentralized systems though

Re: The $1.5B Bybit Hack

#24
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversibility is a trade-off. It's great if you are on the sending end of a transaction. It can be a nightmare on the receiving end. Irreversibility is the other way around. And both approaches have different costs and assumptions.

Re: The $1.5B Bybit Hack

#25
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

It seems more analogous to the Soviets infiltrating your small business. Which no small business owner is prepared to screen for, and which happened.

Re: The $1.5B Bybit Hack

#26
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

The state of online security hasn't changed much.

What has changed is that there is an digital (as opposed to gold) international form of money whose transactions cannot be reversed or stopped. Bybit and those holders of large crypto are operating with a fundamentally different threat model where its worthwhile for an attacker to invest millions of dollars of effort (for the Bybit payout even tens or hundreds of millions) attacking them. Everyone else just needs to worry about getting ransomed for a much smaller amount.

Re: The $1.5B Bybit Hack

#27
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

That’s a really good point. If a nation state bombed a private oil rig with $1.5B in damages all hell would break loose. But if it’s a cyber attack no one cares and we blame the victim.

I think it really boils down to plausible deniability, and the fact that it’s convenient for the governments on the receiving end to ignore the damages done to private citizens when there’s no physical harm and clear responsibility.

No president is going to bomb NK because they attacked a crypro exchange. Maybe they should, but it’s not something the public will support. So it’s easy to say “oh well we don’t really know for sure who did it” and call it a day. It’s our own fault.

I also agree that private citizens have a responsibility to secure ourselves, but where do you draw the line? If I don’t have an AA gun on my roof, am I responsible for enemy warplanes bombing my business? Isn’t this partially why I pay taxes?

Re: The $1.5B Bybit Hack

#28

Earlier quoted context omitted.

Reversible transactions is a feature for fiat money Reversible transactions would generally be a bug regarding cash & hard assets of which cryptocurrency is trying to imitate.

Crypto has reversible transactions when both parties agree to use that functionality in advance (well, the reasonably programmable ones do, anyway) It's not a bug if both parties give consent, which sounds like a wonderful way to transact, to me!

But, when you REALLY want reversibility is when the transaction is done without your consent — when stuff is stolen and you want it back.

Thieves will not tend to consent to reversible transactions.

Re: The $1.5B Bybit Hack

#29
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

At a certain scale nation-state-level actors have to be part of your threat model, there's no excuse.

But yeah, it's quite baffling how in a couple years we seemingly went from stealing email addresses to credit cards to straight up billions of dollars.

If we can expect that everything shifts online eventually, where will this end? Clicked on the wrong link? Guess your house is gone... tough luck.

Post reply on HN