Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

11–20 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#11
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

Cache: https://webcache.googleusercontent.com/search?q=cache%3Ahttp... .

It's a forum post without any details - your question is raised, but has (so far) not been answered.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#12
post #7
post #6

Earlier quoted context omitted.

The banking system was already very sophisticated pre-1930s.

In the US, at least, people still got famous for being bank robbers back then. The FDIC, which provides limited insurance for bank deposits, started their insurance on January 1, 1934. So, sophistication aside, it's an interesting question what happened to depositors after a bank robbery.

FDIC doesn't insure against robberies.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#13

I guess this is still the Wild Wild West era of Bitcoin; I'd wager plenty of banks got knocked off by bandits back in the day, too. What happened to a bank's customer's funds if it got robbed prior to 1933?

Banks don't keep all of their assets in cash in the safe. In its very simplest form, a bank takes money from depositors and pays a small "savings" rate. It then lends this money to borrowers at a higher rate. Every dollar in the safe is a dollar that isn't out earning interest, so the bank wants to only keep enough on hand to cover what customers will need for withdrawals.

I met an ex bank robber once. He and his "gang" attempted to rob a branch that was near a factory. The factory employed a number of immigrants who were fond of cashing their entire paycheques on pay day, so it would bring in a lot of extra cash every pay day. They timed their robbery for when the payroll money was present.

Unfortunately for them, the scheme had been rumbled, so the payroll delivery was fake and the police were waiting in plain clothes for them. He was shot in the neck but survived and learned to play bridge in prison, and in the fullness of time was released, where I met him and heard his story.

Any ways... It seems quite possible to me that a bank could be robbed but remain solvent.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#16
post #7
post #6

Earlier quoted context omitted.

The banking system was already very sophisticated pre-1930s.

In the US, at least, people still got famous for being bank robbers back then. The FDIC, which provides limited insurance for bank deposits, started their insurance on January 1, 1934. So, sophistication aside, it's an interesting question what happened to depositors after a bank robbery.

The FDIC doesn't cover bank robberies. https://www.fdic.gov/consumers/consumer/information/fdiciorn...

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#18
post #6

Earlier quoted context omitted.

The banking system was already very sophisticated pre-1930s.

My question was, specifically: It's 1903, you deposit your life savings into your local bank, and a week alter it gets robbed. Do you get any of that money back? Or are you now broke?

How would the bank know whose money got stolen? It's basically a bad question. If the bank fails because of the robbery, then you lose all your money in 1903 (or at least most of it). Otherwise, things just keep on trucking as normal.

Edit: See the response from raganwald

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#20
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

It's not excusable really, but I'm not too surprised.

It was only a day or so from when a patch was available to when a public exploit was everywhere. Maybe they were on vacation, maybe the site was built by contractors who have since moved on, maybe they don't read hackernews or other programming news sources. I expect to see similar stories in the coming weeks.

Post reply on HN