Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

101–110 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#101

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

> There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition.

I think Uber and Airbnb stand on different ground here. The building codes issue is a red herring; Airbnb faces more severe problems. I can think of plenty of "traveler protection", "hotel protection", "tenant protection" and "landlord protection" stories. Real stories detailing Airbnb's failure to answer these issues are already circulating the internet:

http://www.google.com/search?q=airbnb+nightmare

(to be fair, these stories seem to focus exclusively on bad tenants, while I can see bad landlords being an issue as well)

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#104

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

A decent observation, but it's also true that sometimes complexity becomes an end in itself. It cyclically begets more complexity until it collapses and a new, simpler form emerges.

This Tetris-like complexity-collapse model is very common in biological evolution.

When it works well, the new simpler system will still solve the problems that the old complex system solved. It will just solve them more elegantly.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#105
Imagine that a thief breaks and enters into a warehouse which is holding physical gold for its customers, and the thief steals all their gold. The warehouse and/or its customers will suffer losses, but every single ounce of the gold stolen by the thief will continue to be as valuable as any other ounce of gold. In other words, gold will continue to be the same exact commodity.

Essentially the same thing has happened here, but in the digital realm. A thief (or thieves) broke into the backend systems of an exchange which was holding bitcoins for its customers, and the thief stole all their bitcoins. The exchange and/or its customers have suffered losses, but every single bitcoin stolen by the thief will continue to be as valuable as any other bitcoin. In other words, Bitcoin will continue to be the same exact commodity -- its integrity has NOT been compromised.

The moral of this story: if you own bitcoins, make sure they are stored in a truly secure system. Many Bitcoin exchanges claim to be -- but really aren't -- truly secure!

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#106

Earlier quoted context omitted.

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

I think it's important to use language that's fair and reasonable when arguing your point. When you say "There is no plausible 'consumer protection' story for preventing licensed (sic) livery cab drivers from picking up curb hails" (I think you meant unlicensed) it's easy to dispute that point. Here is the first hit on Google for "cab rider ripoff": http://www.nypost.com/p/news/local/taxis_taking_wBtAr13EzaKS... - "A…

That type of legal solution is not possible if taxi drivers are unlicensed.

The original comment was very specifically worded to only cover licensed livery drivers, not random unlicensed drivers.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#107
post #51

Earlier quoted context omitted.

As a Rails developer myself, it is really embarrassing to admit that all Rails apps in the last few years have been completely and totally vulnerable. The good point that it was discovered by security researchers without a known exploit is good, but we don't know if it was previously exploited without anyone's knowledge. Maybe there were smart pen testers who were routinely getting in to Rails apps without anyone's k…

I completely agree: It's a stupid bug that lingered long in the codebase, probably because it was hidden in an obscure feature that nobody knew about or used. It's embarrassing, but I bet that pretty much every larger framework out there had a remote code execution bug[1]. Still, it's wrong to point at it and say "that's an engineering or QA bug that's symptomatic for the rails bunch." I'm not a rails friend, but the…

I bet that pretty much every larger framework out there had a remote code execution bug[1].

I would gladly take the other side of that bet.

A decade ago I was working on a site using Perl/Mason/Apache. When we were bought by eBay, we were put through a thorough pen test. The ONLY security hole they identified as needing fixing was a redirect that could redirect to any URL anywhere. (The people testing us were shocked - they had never before seen that few problems.)

To the best of my knowledge, no holes have been discovered in that architecture in the following decade either. (Looking through Apache vulnerabilities, there have been a couple of remote code exploits. But not on all platforms, and we turned off every feature we didn't need.)

If you take the attitude up front that you won't have magic, this kind of bug doesn't tend to slip in. If you take the attitude that there will be a lot of magic, then this kind of bug does slip in.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#108
post #99

Earlier quoted context omitted.

Claiming hotel regulation has no benefit to consumers is simply not true. Consider the perspective of a resident of San Francisco (like me). SF has a very limited amount of housing. We can debate all day about ways to fix that and impediments to building more (and more affordable) housing, but the simple facts right now are that there are a LOT more people who want to live in SF than there are housing units. Addition…

You may value that prioritization, but that isn't strange as you are a renter and so prefer things aligned as close as possible to your personal benefit. That is simple egoism, don't coat it in nice language.

Um, in exactly the same way that tourists prefering their interests to be prioritized is also 'egoism', right? Or property owners preferring their incomes to be maximized, just like renters preferring their rents to be minimized. So?

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#109
post #82

Earlier quoted context omitted.

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

Legitimate banks don't get hacked? Is that true?

You don't hear of any high-profile bank disclosures, which I imagine is probably because they have security teams that keep up with everything religiously. Most old brick banks have internal systems architected in ways that a younger intruder in the Anonymous mold wouldn't know anything about, as well; you're starting to get into big iron Cobol land.

That said, I don't think it's an impossible task (is anything?), and I'm sure some day there will be a large disclosure through some means, internally-assisted or otherwise.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#110

Earlier quoted context omitted.

Even given I must admit that this was a spectacularly stupid hole[1], I don't think your point is valid. It's not like other frameworks in other languages don't have similar issues [2]. Rails is for what it does well engineered, well tested and using it for what it's intended is usually a solid choice. Rails enables and pushes testing on all levels, thus improving quality of all rails apps that follow the lead. You c…

I don't think "Rails generation" means only Rails. I think the idea is that we're so dependent on frameworks these days, there are massive pieces of our application that we have no clue how they work, and worse, we trust the framework authors implicitly. More and more we're seeing the downfalls of this. As Rails is essentially the best known and most deployed, hence the name. Think about it: for most apps, probably 9…

> If ASP.NET WebForms had the same level of security holes in the past years as Rails ... just wow.

That's a joke, right?

https://www.google.ca/search?q=asp.net+remote+code&oq=as...

>we trust the framework authors implicitly

You want to export your common web app code to a framework for all the same reasons you don't want to write your own crypto libraries - the more people look at it the safer it is.

Far more damage has been done to the web from people not using a good ORM or a toolkit that escapes your view layer against XSS, or forgot to add request forgery protection.

Post reply on HN