Earlier quoted context omitted.
It seems more analogous to the Soviets infiltrating your small business. Which no small business owner is prepared to screen for, and which happened.
If your small business has $1.5billion in the safe then it’s not a “small business”
The $1.5B Bybit Hack
61–70 of 140 posts
Re: The $1.5B Bybit Hack
#62I really do not understand why they do not separate these into multiple separate wallets
Re: The $1.5B Bybit Hack
#63In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…
They should only use a computer that is air gapped to go online only when signing something. This is an op sec failure to not have this procedure
For that matter, I know signatures are long and human-unfriendly, but isn’t it on the order of a couple hundred bytes? Surely $1.5 billion buys transcribing the putative signature request into an isolated machine in a known state, validating/interpreting/displaying the request’s meaning on that offline machine, performing your signing there offline, copying down the result, and carrying the attestation to your secret conclave lair to combine with the others’ or whatever?
Re: The $1.5B Bybit Hack
#64Earlier quoted context omitted.
Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…
Sure, if there was an active war going on. But while NK and the USA are not exactly friendly, they're definitely not at war either. In basically any other field, the question of "what do we do when a nation state deploys hundreds of people, well funded and well trained, specifically to screw us over?" is met with some variant of "that's why we pay taxes, so the army can protect us from that". A normal bank being robb…
Routine harmful cyberattacks is a problem. You do not get to abdicate responsibility because it is too hard. If you can not handle the operational environment, then do not operate in it.
Maybe the solution is “go to war due to cyberattacks”, but that is not happening right now so their systems are inadequate for the expected operational environment (i.e. incompetent). And everybody knows this is the operational environment, everybody knows they can not deal with expected problems, and everybody does not adequately inform their customers because it would be detrimental to their bottom line.
Re: The $1.5B Bybit Hack
#65Earlier quoted context omitted.
Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…
Sure, if there was an active war going on. But while NK and the USA are not exactly friendly, they're definitely not at war either. In basically any other field, the question of "what do we do when a nation state deploys hundreds of people, well funded and well trained, specifically to screw us over?" is met with some variant of "that's why we pay taxes, so the army can protect us from that". A normal bank being robb…
Re: The $1.5B Bybit Hack
#66Earlier quoted context omitted.
Sure, if there was an active war going on. But while NK and the USA are not exactly friendly, they're definitely not at war either. In basically any other field, the question of "what do we do when a nation state deploys hundreds of people, well funded and well trained, specifically to screw us over?" is met with some variant of "that's why we pay taxes, so the army can protect us from that". A normal bank being robb…
Actually we have been at war with North Korea continously since the 1950s, we only have a cease fire with them. The Korean War ended with an armistice signed on July 27, 1953, which stopped active fighting but did not establish a formal peace treaty. https://en.m.wikipedia.org/wiki/Korean_conflict I know that soldiers stationed in South Korea get paid at the wartime rate.
Maybe the US and North Korea will sign a peace treaty in the 24th century. Captain Picard can mediate.
Re: The $1.5B Bybit Hack
#67> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Re: The $1.5B Bybit Hack
#68Earlier quoted context omitted.
Sure, if there was an active war going on. But while NK and the USA are not exactly friendly, they're definitely not at war either. In basically any other field, the question of "what do we do when a nation state deploys hundreds of people, well funded and well trained, specifically to screw us over?" is met with some variant of "that's why we pay taxes, so the army can protect us from that". A normal bank being robb…
A normal bank was robbed of $1B back in 2016, likely by North Korea, and the global reaction was pretty much a collective shrug: https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery
Re: The $1.5B Bybit Hack
#69> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Re: The $1.5B Bybit Hack
#70The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…
Russia kills people in the West with nerve-gasses or Plutonium, cuts electrical and Internet cables, blows up ammunition factories or puts incendiary devices on cargo airplanes and there are no repercussions.