Live data from Hacker News

Bitcoin exchange hacked via Rails exploit, funds stolen

bitcointalk.org

221–230 of 279 posts

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#221
post #8

I can't get to the article at the moment, but I'd love to know why they failed to update their app especially since it handles financial transactions. I had several apps to update and the process took very little time and effort.

This vulnerability went from disclosure to exploit extremely quickly. The CVE was published on the 8th. I can't speak for them, but in the process of trying to update, we ran in to some issues with therubyracer (a core component of the Rails asset pipeline) and libv8 (the library that therubyracer uses to embed the V8 engine). It was extraordinarily bad timing, and it slowed down our update process by almost a day wh…

Depends on what you do in your app.

But if it was somewhat important, kill the application servers until you can be sure to have upgraded properly.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#222
post #203

Earlier quoted context omitted.

Note how free market works great in this case: the organization costs people their lost money and will most likely go out of business. Unlike big banks. That sounds horrible. If a bank gets hacked and "loses" my money, they owe me that money . Federal and state law requires them to put that money back into my bank account, at the bank's expense. (Note, this is not the same as FDIC insurance, which applies in the even…

> The free market still applies: on top of getting their money back, customers can take their money to more secure banks. Unless the bank goes bankrupt. Basically, if the bank plays fast and loose with customers' money the customers shoulder the risks whilst the bank owners get the rewards - and there's no way customers can tell whether this is happening, since they neither have access to the bank's internal records…

FDIC insurance applies if the bank goes bankrupt (and has since the 1930s), ergo, I would still get my money back. It is not a matter of arbitration; banks have gone bust frequently enough that there is a settled procedure for issuing insurance proceeds to depositors of a failed bank.

Banks pay for FDIC insurance coverage as part of their capital requirements for being a bank.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#223

Earlier quoted context omitted.

Building codes (construction codes; how you must build), not zoning (what you're allowed to build).

I agree with the general sentiment, I think many of these regulations exist as protection for existing industry, but isn't the risk of a hotel burning down much greater than a home burning down? The potential loss of life in a single incident is far higher. I imagine the rules about what safety equipment a small ocean-going yacht and an ocean liner must have are pretty different too, for similar reasons.

Your talking about multi-occupancy vs single occupancy, not temporary vs permanent structures. Not sure to which one the OP meant, though.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#224
post #200

Earlier quoted context omitted.

> its integrity has NOT been compromised Shesh. A Bitcoin has no inherent value. If such incidents become common enough, nobody will be willing to buy bitcoins for dollars or accept bitcoins as payments for goods,which means that the thieves will sit on a bunch of useless bits.

Gold does not have that much of inherent value either.

Gold is inherently useful as a tangible object with exploitable physical properties. Gold, for example, has good conductivity and is used to plate electrical connections. Gold is also useful for its rust-resistance.

Thus, on this basis, like all useable physical goods, gold has some inherent value as a commodity.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#225
post #219

Earlier quoted context omitted.

Would you invest time in a framework where the developers knowingly lie about security vulnerabilities and provide fixes that are intentionally complicated? That seems like something that would ruin any future credibility of the project. No further security vulnerabilities could be trusted as being accurate (and any further patches would just be begging for additional scrutiny).

That "concern" is absurd. You're making no sense.

If a Linux distro released a kernel patch for a super-critical security vulnerability that lied about its nature, AND downplayed its importance, users would go apeshit (justifiably).

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#226
post #61

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

Except that regulating things is not the same as holding a monopoly on regulations. If government is so completely confident that its currency is much more superior and stable, well, allow the competition! Make it legal to receive whatever I want to receive as a payment. Let businesses regulate the currency market and determine what currency is reliable. Oh wait, except that then government cannot tax you, of course.…

> Oh wait, except that then government cannot tax you, of course.

There are actually some voices saying that Bitcoin needs a taxation protocol.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#227

So where's DHH's long blog post? Last I checked, he was still in charge. He's quick to talk about hypermedia, or his latest Le Mans effort, or how profitable Rails apps are.

I wondered this myself, but I think the reason is that there is a lot of eyes on 37signals and DHH. I think they downplay it a bit till the storm rides over and people get patched up.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#228
post #219

Earlier quoted context omitted.

That "concern" is absurd. You're making no sense.

If a Linux distro released a kernel patch for a super-critical security vulnerability that lied about its nature, AND downplayed its importance, users would go apeshit (justifiably).

You're still making no sense. Various large projects, including the kernel, have seen silent security patches (yes, even by Linus himself).

Also there is no "downplaying" in declaring any kind of problem as a remote SQL injection vulnerability. That is still obviously urgent enough for everyone to patch immediately. Yet it doesn't attract blackhats in the same way as blarting "remote code injection".

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#229
post #213

Earlier quoted context omitted.

So you're advocating releasing a "decoy" patch that's intentionally obtuse and doesn't actually fix the issue? And then downplaying the severity by not encouraging developers to take the follow-up patch seriously? That's a flat out terrible idea.

No. I was advocating to release a patch that fixes the issue in an obfuscated, non-obvious way. And labeling it as a boring-yet-important follow-up to the previous SQL-injection vulnerability, rather than yelling "LOOK, REMOTE CODE INJECTION HERE -->.<-- !!" on all available news-channels.

How much time do you think that would have bought? At least a few minutes, but definitely not days. And at what cost would it be?

I'm all in favor of giving people more time to upgrade, but this issue was very unusual. Multiple groups were all finding it at the same time and who knows when the first "full disclosure is always the right answer" group would have started singing? Like it or not, full-disclosure people exist in the world, and responsible-disclosure people need to be aware of their existence.

If just one person/group had found this, RoR could have done a better "get ready to upgrade next Tuesday at 6am" followed by a "here is the patch, details to follow tomorrow" on Tuesday at 6am.

Re: Bitcoin exchange hacked via Rails exploit, funds stolen

#230

There seems to be a pattern emerging in all of these 'disruptive' business models, whether it be Bitcoin (banking), AirBnb (hotels), or Uber (cabs). We look around and see these industries burdened by regulation, which tends to create entrenched players and which seem to us to be inefficient. So we create similar peer-to-peer equivalents, only to start rediscovering the reasons for all those regulations in the first…

Much of the regulation was created for good reason but it is hard to argue that there aren't a lot of regulation that is merely special interest to prevent competition or grant special favor.

Rather than more regulation, perhaps more transparency is a better solution. 3rd party certification would do a much better job at security than a government regulation. And have much less abuse and overhead.

Post reply on HN