Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

131–140 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#131
post #61

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

Except that regulating things is not the same as holding a monopoly on regulations. If government is so completely confident that its currency is much more superior and stable, well, allow the competition! Make it legal to receive whatever I want to receive as a payment. Let businesses regulate the currency market and determine what currency is reliable. Oh wait, except that then government cannot tax you, of course.…

Note how free market works great in this case: the organization costs people their lost money and will most likely go out of business. Unlike big banks.

That sounds horrible. If a bank gets hacked and "loses" my money, they owe me that money. Federal and state law requires them to put that money back into my bank account, at the bank's expense. (Note, this is not the same as FDIC insurance, which applies in the event of a bank failure.) The free market still applies: on top of getting their money back, customers can take their money to more secure banks.

Make it legal to receive whatever I want to receive as a payment. Let businesses regulate the currency market and determine what currency is reliable. Oh wait, except that then government cannot tax you, of course.

You can receive whatever you want to receive as payment; this has been a basic principle of English-based law for hundreds of years. The currency requirement is merely that any debt obligation must be satisfiable through the use of currency equivalent to the value of the debt. Also note that the government reserves the right to tax you regardless of the currency you use. This has been basic law in some form or the other for hundreds of years, and is explicitly stated in I.R.C. section 61.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#132
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

"I'd love to know why they failed to update their app especially since it handles financial transactions"

Because these exchanges focus more on promoting the "world changing" ideology than they do on taking their users' money seriously.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#133
post #72

Earlier quoted context omitted.

This has everything to do with regulating bit coins and the exchanges. No bank in the US would ever dare run a stock rails site, I would bet they would be rightfully sued. On top of that, funds in a bank are insured to a point so if someone at a bank messes up, the innocent people who lost their money won't lose everything they own. The free market is cruel and so are it's proponents, we've advanced past this "fuck y…

> No bank in the US would ever dare run a stock rails site, I would bet they would be rightfully sued. Why so? Even banking websites build on frameworks and if you'd have chosen Spring for example, there was a Remote Code Execution vulnerability in 2010. And even if you roll your own framework, you're just as likely to introduce a critical flaw. The Dutch governmental DigiD service runs rails [1]. The critical differ…

Because, as you're aware, "build on frameworks" is not necessarily "stock rails".

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#134

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

It's great to see that this post has triggered so much discussion. Let me add that I'm not saying the status quo shouldn't be challenged, or that there aren't efficiencies to be had, only that if a business model looks too good to be true ("hey, I can rent a whole house for the cost of a hotel room and have 10 people stay for the price of 1!"), it probably is. Neighbors (who also qualify as consumers, I believe) are raising serious objections to AirBnb. At least one Bitcoin exchange has qualified itself as a bank---presumably raising its costs and requiring it to charge more fees than its competitors in return for the security it offers. Meet the new boss, same as the old boss.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#135
post #87

Earlier quoted context omitted.

Or, you know, why their wallet is compromised just because the web interface is. It's like a CA that creates the certificates in PHP right there.

This is a remote code exploit. For the web interface to do its job, it needs to be able to manipulate the wallet. They can stare at the code that does that, write their own, and do whatever they want.

Why does a web interface need to directly manipulate the wallet? It needs to store the transactions somewhere where the machine that executes them (using the wallet) can find them.

You need the seperation and you need to closely monitor and control the transactions requested from the web interface to detect any fraud or misuse.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#136
post #67

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

This argument seems to beg the question (in the actual meaning of that phrase), at least w.r.t Uber and AirBNB. All the problems they've had have come from the regulatory authorities, except for those one or two bad incidents on AirBNB which are pretty much unavoidable in a business like that. So is the argument that regulation is good because it's hard to cope with the regulators? I just don't buy into the abrogatio…

All the problems they've had have come from the regulatory authorities, except for those one or two bad incidents on AirBNB which are pretty much unavoidable in a business like that.

Atlantic, Wired, the NY Times, Chicago Tribune, and the L.A. Times have variously run horror stories for renters who made the mistake of using AirBNB to book rooms (see, e.g., Toshi hotels and their variants). The whole point of hotel regulations is to protect the guests, not the hotelier.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#137
post #115

Earlier quoted context omitted.

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

"There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition." As an apartment owner in a multi-unit apartment building, I don't want the neighboring apartments being used as short-term rental properties - and the building regulations for…

Why do you need to government to require that? How about you only rent from land lords that disallow tenants from renting out their apartment. Maybe some people don't mind this and would like to have that as an option.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#138

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

It's not always about the direct users. Having Airbnb people show up next door and have a 3 day party impacts people. Or from a health and safety standpoint, bedbugs easily spread though apartment buildings.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#139
post #67

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

This argument seems to beg the question (in the actual meaning of that phrase), at least w.r.t Uber and AirBNB. All the problems they've had have come from the regulatory authorities, except for those one or two bad incidents on AirBNB which are pretty much unavoidable in a business like that. So is the argument that regulation is good because it's hard to cope with the regulators? I just don't buy into the abrogatio…

All the problems they've had have come from the regulatory authorities...

I'm not sure about Uber, but this is most definitely not true of AirBnb, which has come under fire from many neighborhood associations. It's not just your quality of life that gets reduced when you rent your house to bad apples, it's your neighbors' as well.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#140
post #125

Disclaimer: I know virtually nothing about bitcoin past what I've read on HN. Bitcoin are uniquely identifiable by nature. Has there been any attempt to create and maintain a manifest of "tainted" (i.e., stolen) bc that could be referenced during transactions? If a receiver of bc knows that they are tainted, and that the next receiver might refuse them, then they might refuse them as well. I understand that I'm hand-…

That is possible, but the problem is the time it takes to disseminate the knowledge of the crime is longer than the time to trade the bitcoins. So if the thief immediately exchanged them with some merchant right after the robbery, then sometime later, the coins were marked as tainted, the merchant would suffer as well, since they're now holding the coins.

This would create a chilling effect on trade since now you have to worry about the legitimacy of the other party, which brings us right back to the problems we have with credit cards, etc.

Post reply on HN