Live data from Hacker News

The $1.5B Bybit Hack

blog.trailofbits.com

91–100 of 140 posts

Re: The $1.5B Bybit Hack

#92
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversible transactions is a feature for fiat money Reversible transactions would generally be a bug regarding cash & hard assets of which cryptocurrency is trying to imitate.

it can still be still hard to reverse fiat even if easier than crypto. try disputing a wire. this is why you should always use a credit card, preferably Amex, for purchases-tons of buyer protection.

Re: The $1.5B Bybit Hack

#93
post #36

Earlier quoted context omitted.

Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…

>But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. That's not really a viable strategy. It has been tried a few times - Mittelwerk and Kőbánya spring to mind - but you can't really build a self-contained factory. If your enemy can't bomb the factory, they'll bomb the roads and railways serving your factory, they'll bom…

Yes, I am aware. I was using “resistant to sustained aerial bombardment” in the general sense of all classes of mitigations, not just fortification.

But thank you for elaborating when I was too lazy to. It helps further reinforce my point that the key is mitigating the risk however you can, not specific risk mitigations somehow absolving responsibility.

Re: The $1.5B Bybit Hack

#94
post #24
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversibility is a trade-off. It's great if you are on the sending end of a transaction. It can be a nightmare on the receiving end. Irreversibility is the other way around. And both approaches have different costs and assumptions.

bank error in your favor

Re: The $1.5B Bybit Hack

#95
I hate how complexity has become the norm in the industry. Instead of having simple systems with code and modules that are simple, fit-for-purpose and fully auditable, the approach has been to have insanely complex systems and then to add some even more complex security solution on top like CrowdStrike. Seems like a bandaid patch.

Re: The $1.5B Bybit Hack

#97
post #81

Earlier quoted context omitted.

> those crypto bros, a bunch of failed morons (self-proven by all these hacks) Bankers are a bunch of idiots, too. I know this to be true because that one investment bank collapsed a bunch of years ago. In all seriousness though, ETH is just a commodity; a bearer instrument; a thing. It's similar to gold or cash in some ways. If you store it properly, you're fine. If you give it to someone untrustworthy who loses it,…

I’d be shit scared of a trad-fi institution holding crypto. I doubt they have the operational muscle, instinct, and know-how to properly safeguard it. Unless they partner with someone who does, which is what they’d likely do.

> Unless they partner with someone who does, which is what they’d likely do.

They're already doing it. Most crypto or crypto-adjacent product you'll see traditional firms is relying on a provider white-labelling crypto exposure.

Re: The $1.5B Bybit Hack

#98

My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.

The displayed information was tampered due to malware. communication would not have helped.

Re: The $1.5B Bybit Hack

#99
post #68

Earlier quoted context omitted.

A normal bank was robbed of $1B back in 2016, likely by North Korea, and the global reaction was pretty much a collective shrug: https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery

According to that page, the global reaction was to block most ($850M) of the fraudulent payments, recover a third of the remainder, add additional security to the SWIFT network and raise standards for banks, and push for penalties for the criminals who participated. That seems like more than a shrug.

Say what you want about CBDCs, but they would fix this specific failure mode of digital assets where an enemy nation-state can steal $1.5 billion worth of the token.

Re: The $1.5B Bybit Hack

#100
post #59

Earlier quoted context omitted.

This is why it is dangerous to replace people and laws with code. With laws, you eventually get to talk to a human being who has leeway in interpreting the situation. With code, it just works the way it does, regardless of circumstances. Cryptocurrencies avoid a central authority, but by doing that, they also avoid any possibility of human discretion, oversight, or recourse. There is no institution to appeal to, no c…

It does feel, doesn’t it, that the cryptocurrency crowd seems mainly to comprise the kinds of actors who correctly anticipate that the legitimate banking sector—and most humans, if asked—will say “no” to them… Which I guess the idealists would say is part of the point: “first they came for the DPRK extortionists, and I said nothing,” etc.

> correctly anticipate ... will say “no” to them

Could conceivably, under different circumstances, say no. And are uncomfortable with that state of affairs.

Or to be snarky. Doesn't it seem that the crowd that gets up in arms about unlawful search and seizure are the sort of actors who correctly anticipate that the legitimate authorities would take issue with their behavior?

Post reply on HN