Live data from Hacker News

The $1.5B Bybit Hack

blog.trailofbits.com

41–50 of 140 posts

Re: The $1.5B Bybit Hack

#41
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

At a certain scale nation-state-level actors have to be part of your threat model, there's no excuse. But yeah, it's quite baffling how in a couple years we seemingly went from stealing email addresses to credit cards to straight up billions of dollars. If we can expect that everything shifts online eventually, where will this end? Clicked on the wrong link? Guess your house is gone... tough luck.

This is why it is dangerous to replace people and laws with code. With laws, you eventually get to talk to a human being who has leeway in interpreting the situation. With code, it just works the way it does, regardless of circumstances.

Cryptocurrencies avoid a central authority, but by doing that, they also avoid any possibility of human discretion, oversight, or recourse. There is no institution to appeal to, no customer service to call, and no regulator to enforce fairness.

Re: The $1.5B Bybit Hack

#42
post #36
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…

I suspect the truth lies between the two - we are under constant attack, but we aren’t as a society reacting as if we were.

It’s like a building occasionally gets hit by a shell and we dont get on a war footing.

The closest analogy I can come up with is England in the 1600s and early 1700s. Fairly regularly ships would be attacked by pirates from North Africa, and sometimes an actual land raid woukd occur- pirates from North Africa would take slaves from small seaside towns.

It was not till Englands navy grew strong enough that the threat was eliminated - and perhaps that’s the real issue here - we know it’s happening, we cannot turn the Wild West into urban peace, so we just have to keep taking the licks and keep building more secure and stronger

Re: The $1.5B Bybit Hack

#43
post #24
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversibility is a trade-off. It's great if you are on the sending end of a transaction. It can be a nightmare on the receiving end. Irreversibility is the other way around. And both approaches have different costs and assumptions.

I think it’s less about reversibility itself and more the larger system within which it works. Banking works because the companies agree to follow rules so there’s a social context where if I make a mistake you will help fix it because the odds are fair that you will make a mistake at some point, too. In contrast, cryptocurrency is a political movement so the ideological “trust less” purity test matters more than whether the system is actually used. There is no technical reason why a system couldn’t have something like a settlement period to allow fraud reversal.

Re: The $1.5B Bybit Hack

#44
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Is cash silly? It has the same property (non-reversibility)

It’s also impossible to steal from afar and transactions of $100/$1000000/$1000000000 each look very different.

Re: The $1.5B Bybit Hack

#45
post #36
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…

Sure, if there was an active war going on. But while NK and the USA are not exactly friendly, they're definitely not at war either. In basically any other field, the question of "what do we do when a nation state deploys hundreds of people, well funded and well trained, specifically to screw us over?" is met with some variant of "that's why we pay taxes, so the army can protect us from that".

A normal bank being robbed for 1.5 billion, ESPECIALLY by a pariah country like North Korea, would absolutely not be met with "oh that was definitely your own fault" as many of the sibling comments seem to imply.

Re: The $1.5B Bybit Hack

#46
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Is cash silly? It has the same property (non-reversibility)

Orders of magnitude matter, and you have to look at the overall system. You can’t move $1.5B in cash without a fleet of trucks and a lot of time, and serious banking has lots of safeguards around it to prevent thefts by requiring more people to cooperate on an insider theft.

Cryptocurrency was designed as a political statement rather than a serious banking system so you effectively have the same level of precaution for both large and small amounts, akin to a bank keeping a billion dollars in the teller’s tray.

Re: The $1.5B Bybit Hack

#47
post #27
post #13

The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…

That’s a really good point. If a nation state bombed a private oil rig with $1.5B in damages all hell would break loose. But if it’s a cyber attack no one cares and we blame the victim. I think it really boils down to plausible deniability, and the fact that it’s convenient for the governments on the receiving end to ignore the damages done to private citizens when there’s no physical harm and clear responsibility. N…

Well, there's a couple of airliner shootdowns that kind of go in this category. MH17, PS752, AHY8243... That's at least $0.5B in damage plus many hundreds of civilian lives.

Re: The $1.5B Bybit Hack

#48
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Is cash silly? It has the same property (non-reversibility)

> Is cash silly?

No, of course not.

Adjusting your comment for the situation: > Is $100.00 in cash silly? It has the same property (non-reversibility)

No, not silly if that's what I am comfortable to keep on me (wallet, mattress, etc) and I'm mugged/robbed most people will recover. (Especially if you're also able to afford the inherent risk of crypto.)

> Is $1,500,000,000.00 in cash silly? It has the same property (non-reversibility)

YES! And probably a challenge for most humans even if you're able to get that cash in the limited US $100,000.00 bill [1] - that's 15,000 green slips of paper. (I'm making a bold assumption that this link [2] is reasonably actually for the physical scale, though this apparently only shows 13,000 not the 15,000 needed.)

They effectively treated the $1.5B like a pile of cash in a fence with a few (easily pickable apparently) locks keeping it shut.

That SHOULD have been in a 100% offline, air gapped system with multiple levels of 2+ person approvals to access.

But this failure implies to me that even THEY didn't really consider the crypto assets they were holding as something with a real value either.

1- https://en.m.wikipedia.org/wiki/United_States_one-hundred-th...

2- https://www.reddit.com/r/pics/s/GHNABiJh6A

Re: The $1.5B Bybit Hack

#49
post #36

Earlier quoted context omitted.

Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…

I suspect the truth lies between the two - we are under constant attack, but we aren’t as a society reacting as if we were. It’s like a building occasionally gets hit by a shell and we dont get on a war footing. The closest analogy I can come up with is England in the 1600s and early 1700s. Fairly regularly ships would be attacked by pirates from North Africa, and sometimes an actual land raid woukd occur- pirates fr…

> The closest analogy I can come up with is England in the 1600s and early 1700s.

I like your point, but that it a hell of an analogy. 1600 is when they formed the East India company, which was basically a state sponsored bunch of pirates, looting the wider world with its hundreds of thousands of soldiers. https://en.m.wikipedia.org/wiki/East_India_Company

Re: The $1.5B Bybit Hack

#50

Taking a step back from this attack, it looks like the new crypto-reality is far far far immature security-wise & compliance-wise ("compliance to what??" you can ask me). While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals…

> those crypto bros, a bunch of failed morons (self-proven by all these hacks)

Bankers are a bunch of idiots, too. I know this to be true because that one investment bank collapsed a bunch of years ago.

In all seriousness though, ETH is just a commodity; a bearer instrument; a thing. It's similar to gold or cash in some ways. If you store it properly, you're fine. If you give it to someone untrustworthy who loses it, of course that's a problem.

Well-regulated banks can start holding crypto on behalf of customers as soon as they're given the regulatory go-ahead. They've stored gold in vaults for thousands of years; they can store crypto in digital vaults too.

Post reply on HN