Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

81–90 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#82

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

Legitimate banks don't get hacked? Is that true?

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#83
post #61

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

Except that regulating things is not the same as holding a monopoly on regulations. If government is so completely confident that its currency is much more superior and stable, well, allow the competition! Make it legal to receive whatever I want to receive as a payment. Let businesses regulate the currency market and determine what currency is reliable. Oh wait, except that then government cannot tax you, of course.…

Make it legal to receive whatever I want to receive as a payment.

This is already. You can legally trade things for other things. There is no law saying that you have to use Euro (or your local government issued money)( for everything.

The only think you have to use it for, is taxes or paying fines.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#84

Basically all the comments points to how amateurish that exchange was run compared to a real online banking website. Now how many real banks do run their website using Rails? Ruby? You guys certainly aren't as stupid as to believe this is the latest major 0-day Rails exploit to create havoc right? And now comes the answers containing the logical fallacy: "All languages/frameworks have security issues" . Which is rubb…

Most languages are inappropriate for highly sensitive information or other critical systems. You don't see the the aerospace industry putting Ruby hardware controllers into planes, nor do you see the defense industry putting classified information behind Ruby web servers.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#85
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

The simple, and harsh reason is because they are incompetent.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#86

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

Claiming hotel regulation has no benefit to consumers is simply not true. Consider the perspective of a resident of San Francisco (like me). SF has a very limited amount of housing. We can debate all day about ways to fix that and impediments to building more (and more affordable) housing, but the simple facts right now are that there are a LOT more people who want to live in SF than there are housing units.

Additionally, there are a lot of tourists that visit SF. Those two demands for places to sleep, from tourists and residents, are at odds. The price you can charge for a hotel room in SF is substantially greater than what you can charge on a nightly basis in stable rent.

So what we're seeing happen in SF is people who have rental units that would normally be on the rental market are now pulling those off the rental market and putting them on the AirBnB market, which serves tourists instead of residents. Because frankly, why wouldn't you? If you can rent your place for $200/night to tourists you can make a hell of a lot more money than you can renting to someone for a year.

The hotel regulations aren't only to help hotel consumers, they're to help the renters too. Now, you could argue the natural market economics should just play out and the city should allow as many hotels to exist as the market will support. But that's not a city I want to live in. I value prioritizing housing for residents instead of tourists.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#87
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

Or, you know, why their wallet is compromised just because the web interface is. It's like a CA that creates the certificates in PHP right there.

This is a remote code exploit. For the web interface to do its job, it needs to be able to manipulate the wallet. They can stare at the code that does that, write their own, and do whatever they want.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#88
post #78

Earlier quoted context omitted.

I'm building a new site from scratch soon, and was considering what language, and decided against RoR because of this. Perhaps not rationally, but it's been 5 years since I last did RoR, and I know there's a lot I don't know that's changed in that time. So better to stick with devils I know.

I wouldn't call this an informed decision...

It's a decision about how uninformed I am. While I could certainly learn to become an expert in RoR security, I shouldn't do it on this specific project.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#89

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition.

This is not a very thoughtful comment. There are obvious reasons why properties zones for permanent residence aren't appropriate for transient residence; the latter type of occupancy is accompanied by crime and abuse.

You seem to be falling into the trap of considering "consumer protection" only from the perspective of the tenant.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#90
And this is why I would NEVER in 10,000 years trust an anonymous form of money that can't be recovered or tracked to a group of average developers who in this case are obviously are amateur and don't even respond to massive critical security updates. I'm sure all the rest are like that to some degree as well. No thanks, I'll stick with cash under my matress before ever using that.

I feel bad for anyone that actually got screwed because of this.

Post reply on HN