Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

101–110 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#101

Earlier quoted context omitted.

Have you never trolled the r/debatereligion circuit?

Oh, you have got the right guy then. :) but I don't know why you said james_d.

Somehow I always thought your middle name (or initial) was d.

It's nice to see you.

Re: Inputs.io hacked – 4100 BTC stolen

#102

Earlier quoted context omitted.

It depends on what you mean by 'traced.' All bitcoin transactions are 'traced,' but you can just set up a few thousand wallets, transfer some money to all of them, send them between each other, trade some away to other people for things... it's not clear simply from the transaction log who actually took them, and who is just receiving BTC from an anonymous buyer for some sort of service.

From my understanding of bitcoin, doing this would be trivially easy to track also. However, I haven't studied this in great detail, so what is said here may be incorrect. *simplified view Wallet 1 stores 50 bitcoin for(i = 1; i At this point, wallet 100000 contains exactly 1 bitcoin, that every transaction can be traced back to wallet 0. I understand that you would include more wallets, varying values, etc. But the…

> The only way to make this behavior viable that I can see, is to have intermediate services that mix up funds.

They're called 'mixers.'

> Again, I want to re-iterate, my knowledge of bitcoin is somewhat superficial, so don't take this as an authoritative post on the subject.

You've got your head on straight. Here's one small aspect you're missing: there's no connection between a person and a wallet, and there's no transaction costs, so just make a million wallets and send random amounts to each one, and then send them through a mixer, and then to each other some more, and then to a mixer....

Re: Inputs.io hacked – 4100 BTC stolen

#103
post #8

Which begs the question, how can one determine the veracity of the security claims of website operators? Bitcoins are a convertible currency but are not regulated, insured or guaranteed by any authority. I guess even modern fiat currencies had their teething problems with theft and counterfeiting, so this is not too surprising.

I wouldn't be surprised (or disappointed) if some enterprising company developed a security certification (a la PCI) for Bitcoin-related providers. You wouldn't _have_ to offer it, but the market might favor those that had subjected themselves to that scrutiny.

Re: Inputs.io hacked – 4100 BTC stolen

#104
post #40

Earlier quoted context omitted.

This is exactly why everyone SHOULD learn how to code and be a developer. They were negligent.

Who will bake my bread and pump my gas?

"Everyone should learn to code" != "everyone should have a job as a programmer."

"Everyone should learn to write" does not mean that everyone is an author.

Re: Inputs.io hacked – 4100 BTC stolen

#105
post #46

Anybody wondering how long it will take for Bitcoin to gain enough respectability for the FBI or Secret Service to get involved after hacks like this? If the same amount of money was stolen from a normal bank, it'd likely be covered by every news outlet.

Banks losing $1 million to hackers are not exactly science fiction. Typical outcomes including authorities not catching the thief, insurance paying out or the bank self-insuring, reiterating NDAs to employees who became aware of the theft, and absolutely no media coverage. [Edit to add: For avoidance of ambiguity, I'm really, really, REALLY not suggesting that "Since banks are equally insecure, bitcoins are a great i…

> I'm really, really, REALLY not suggesting that "Since banks are equally insecure

That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hacks against us.

We aren't perfect, of course. But these monkeys are barely on the same planet, never mind in the ballpark.

Re: Inputs.io hacked – 4100 BTC stolen

#106
post #70

Earlier quoted context omitted.

You fail to point out that cash has all the same drawbacks: You can permanently lose cash if destroyed in a fire. Your cash or bank account can be confiscated easily by the government. Etc. Of course, unlike cash, Bitcoin has advantages because it offers the option to prevent these losses: you can back up a Bitcoin wallet. You can avoid government confiscation (password-protected wallet). Etc.

I'm always astounded by comparisons of bitcoin to paper cash - in 10 years we probably won't even be using paper cash and it is hardly ever used for large transactions now in advanced countries - paper cash is history. I think I've done about 5% at most of my spending in paper in the last month. How about digital cash? Also, Bitcoin can be confiscated by the government, along with the computer/server it sits on (see…

> Also, Bitcoin can be confiscated by the government

Not if you specifically want to prevent this. A bitcoin private key is 256-bit ECDSA, which provides 128 bits of security. If you can remember a 10 word randomly generated diceware phrase[1], you can securely store bitcoins in your brain.

[1] calculating the private key as a SHA256(phrase) for example

Re: Inputs.io hacked – 4100 BTC stolen

#107
post #89
post #79

Earlier quoted context omitted.

[deleted]

Wait a few years for the Bitcoin ecosystem to mature, and all the security mechanisms developed by banks (and more advanced ones that are just inapplicable to cash) will appear and be applied to Bitcoin: theft insurances, properly secured web wallets (HSM, userbased multi-sig, cold wallets, etc), tamper-proof hardware wallets, etc.

[deleted]

Re: Inputs.io hacked – 4100 BTC stolen

#108
post #60

"No regulations" sounds great up until the moment when the bank gets robbed, the police don't care, and the only proof that it wasn't an inside job is a screenshot of the banker's email[1]. (Not that I think that it was an inside job. I just think this whole situation is kinda funny.) https://bitcointalk.org/index.php?topic=283756.msg3505394#ms...

If the owner is either incapable or unwilling to refund everybody's money then it doesn't even matter whether it was an inside job or not. It's pretty telling that he's posting a screenshot that essentially says nothing instead of being open about whether or not he'll be able to fully reimburse the people who lost money. I don't think it was explicitly stated, but it seems like people are just getting whatever percen…

If that guy did not have some kind of insurance like banks do, how can he refund anyone? ( that's a question ).

And would insurances insure this kind of business ? Now are bitcoin wallets banks ? and are they subject to the same regulations ?

Is that guy a US citizen ? can he be sued by his clients ?

Re: Inputs.io hacked – 4100 BTC stolen

#109
post #89
post #79

Earlier quoted context omitted.

[deleted]

Wait a few years for the Bitcoin ecosystem to mature, and all the security mechanisms developed by banks (and more advanced ones that are just inapplicable to cash) will appear and be applied to Bitcoin: theft insurances, properly secured web wallets (HSM, userbased multi-sig, cold wallets, etc), tamper-proof hardware wallets, etc.

Unicorns!

Re: Inputs.io hacked – 4100 BTC stolen

#110
post #106

Earlier quoted context omitted.

I'm always astounded by comparisons of bitcoin to paper cash - in 10 years we probably won't even be using paper cash and it is hardly ever used for large transactions now in advanced countries - paper cash is history. I think I've done about 5% at most of my spending in paper in the last month. How about digital cash? Also, Bitcoin can be confiscated by the government, along with the computer/server it sits on (see…

> Also, Bitcoin can be confiscated by the government Not if you specifically want to prevent this. A bitcoin private key is 256-bit ECDSA, which provides 128 bits of security. If you can remember a 10 word randomly generated diceware phrase[1], you can securely store bitcoins in your brain. [1] calculating the private key as a SHA256(phrase) for example

A $5 wrench or a jail cell will deal with your encryption.
Post reply on HN