Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

151–160 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#151
post #107

Earlier quoted context omitted.

I bet that pretty much every larger framework out there had a remote code execution bug[1]. I would gladly take the other side of that bet. A decade ago I was working on a site using Perl/Mason/Apache. When we were bought by eBay, we were put through a thorough pen test. The ONLY security hole they identified as needing fixing was a redirect that could redirect to any URL anywhere. (The people testing us were shocked…

> I would gladly take the other side of that bet. You admit that the framework you used had a couple of exploits and you were not affected because you turned of all features that you didn't need. The current rails vulnerability does not affect you if you turned off all features you didn't need. Same argument. So we have a hole in Mason, I already cited one in Spring, someone else cited one in .NET http://news.ycombin…

Not the framework, the Apache webserver. I am not aware that there has ever been a hole in Mason, and I would be surprised if there was.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#152

Earlier quoted context omitted.

I don't think "Rails generation" means only Rails. I think the idea is that we're so dependent on frameworks these days, there are massive pieces of our application that we have no clue how they work, and worse, we trust the framework authors implicitly. More and more we're seeing the downfalls of this. As Rails is essentially the best known and most deployed, hence the name. Think about it: for most apps, probably 9…

> If ASP.NET WebForms had the same level of security holes in the past years as Rails ... just wow. That's a joke, right? https://www.google.ca/search?q=asp.net+remote+code&oq=as... >we trust the framework authors implicitly You want to export your common web app code to a framework for all the same reasons you don't want to write your own crypto libraries - the more people look at it the safer it is. Far more damage…

Read the damn vulnerability description. I've actually just finishing the QA cycle on our app for this and its a very niche issue.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#153
post #89

Earlier quoted context omitted.

That is an absolutely terrible lesson to draw from this episode. First and most importantly, Airbnb and Uber are not disrupting industries burdened primarily by consumer safety regulations; they are disrupting industries burdened primarily by barriers to entrance that are designed to direct economic rents to politically favored actors. Huge difference. There is no plausible 'consumer protection' story for preventing…

There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition. This is not a very thoughtful comment. There are obvious reasons why properties zones for permanent residence aren't appropriate for transient residence; the latter type of occu…

Is there any evidence that apartments rented out with AirBnB are more prone to crime and abuse of non-tenants than apartments not rented out with AirBnB?

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#154

Earlier quoted context omitted.

Claiming hotel regulation has no benefit to consumers is simply not true. Consider the perspective of a resident of San Francisco (like me). SF has a very limited amount of housing. We can debate all day about ways to fix that and impediments to building more (and more affordable) housing, but the simple facts right now are that there are a LOT more people who want to live in SF than there are housing units. Addition…

Thank god they aren't building more housing in SF - a temporary fix (b/c eventually you'll run out of housing again) to a non-problem. The NewYorkification of San Francisco would ruin the city. I talked about it more here http://news.ycombinator.com/item?id=4815087 http://news.ycombinator.com/item?id=4815247 http://news.ycombinator.com/item?id=4815537

You are literally arguing for the destruction of the planet when you argue against density. More people living in a smaller space is much more efficient, and therefore less polluting energy.

San Francisco might be "ruined" by your definition, but how is it any of your right to tell people what they can and can not build on their land?

Zoning is central planning at it's worst.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#155
post #89

Earlier quoted context omitted.

There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition. This is not a very thoughtful comment. There are obvious reasons why properties zones for permanent residence aren't appropriate for transient residence; the latter type of occu…

Is there any evidence that apartments rented out with AirBnB are more prone to crime and abuse of non-tenants than apartments not rented out with AirBnB?

You're effectively asking whether apartments rented to unchecked strangers for days at a time are more prone to abuse than apartments rented months or years at a time.

There is a reason hotels require "special use" zoning exceptions in cities, and it's not because Mariott and Hyatt have captured the city council; it's often the residents who create uproars when those exceptions are granted.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#156
post #116

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

You have a point, but you're taking it too far. I agree that companies need to take a look at how their industry is regulated and what purpose those regulations serve. But the fact that companies can come into these types of industries, openly skirt the regulations, and still be massively successful shows that the existing laws aren't meeting the needs of the people who use these services. And how exactly has governm…

I'm not sure what problems you're talking about in the first place.

That's the point. :-) A number of them have been enumerated above: protecting banking customers from loss in the event of theft; regulating the location and safety of hotels; providing some means of recourse against a dishonest cabbie.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#157
post #115

Earlier quoted context omitted.

"There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition." As an apartment owner in a multi-unit apartment building, I don't want the neighboring apartments being used as short-term rental properties - and the building regulations for…

Why do you need to government to require that? How about you only rent from land lords that disallow tenants from renting out their apartment. Maybe some people don't mind this and would like to have that as an option.

I don't rent - I own my apartment. I've invested in a property and a neighborhood zoned for a specific purpose. Cities are generally configured with zoning laws designed to preserve a certain standard of living for the larger community that extends beyond just a single apartment or building. It helps to preserve the intended use of those properties for people that choose to buy in those neighborhoods.

For instance it gives property owners in a residential neighborhood an assurance that a neighboring building can't decide to convert their rooftop to a nightclub potentially disturbing the neighboring buildings with noise, foot-traffic, car traffic, drunks, trash, fights, etc. If you gave individual landlords the right to make these decisions without wider oversight, you'd run into a lot more issues like these. Sure - today they can petition to override existing zoning regulations and that sometimes happens, but residential issues are larger than just an individual apartment or building.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#158
post #124

Well, with a Bitcoin bank, at least as a customer you have a chance of not being robbed. By contrast, if you keep your money with an FDIC bank in USD, you are having your funds diluted away every day (the latest proposal is to print a $1 trillion coin).

Trillion dollar coin or no coin, the debt ceiling attempts to regulate (in part) expenditures already authorized by Congress and signed into law. It's a tempest in a teapot for one party in Congress to argue that it's irresponsible to conduct authorized expenditures, because in fact, Congress did authorize the expenditures.

The two transactions, debt providing cash to the government, and seigniorage (difference in value from the metal in the coin and the fiat value asserted) providing cash to the government for the coin issuance are approximately equally inflationary, over time, assuming that the debt remains outstanding. If such a coin were undertaken, in all probability, it would be repurchased by the Treasury and retired, and debt would be issued. Indeed, the a return of the coin to the Treasury could be via issuance of debt directly to the Federal Reserve.

A little perspective on Federal Reserve Bank's process to create cash:

Federal Reserve Balance Sheet - by James Hamilton on Econobrowser

http://www.econbrowser.com/archives/2008/12/federal_reserve_...

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#159
post #50

After the Rails exploit was announced I was jokingly mentioning to a friend that this will hit a few Bitcoin exchanges. Seems there are still exchange operators that haven't learned anything about the previous exploits.

An exchange operator that operates both the exchange its self and its web-facing front end from the same server(s). You really have to wonder what they were thinking?

While a front end compromise is always going to be bad, splitting the two gives you more options and more ability to spot when the front end is acting unusually.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#160
post #115

Earlier quoted context omitted.

"There is no plausible 'consumer protection' story that would explain why building codes for permanent residence are not good enough for temporary residence as well. The law is there to protect hotel operators from vacation rental competition." As an apartment owner in a multi-unit apartment building, I don't want the neighboring apartments being used as short-term rental properties - and the building regulations for…

Why do you need to government to require that? How about you only rent from land lords that disallow tenants from renting out their apartment. Maybe some people don't mind this and would like to have that as an option.

Because that's not always an available option in the housing market. There are some cities (for example, present day San Francisco) where city wide apartment vacancy is so low that tenants basically have to take what they can get. Tenants are at a serious disadvantage to the whim landlords in this kind of market. Thus laws exist that restrict what landlords are allowed to provide, which serves to protect the tenants.

You can make an argument about not restricting the free market, but shelter is such a basic human need that I think it merits a healthy amount of regulation.

Post reply on HN