Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.
Inputs.io hacked – 4100 BTC stolen
161–170 of 193 posts
Re: Inputs.io hacked – 4100 BTC stolen
#162Re: Inputs.io hacked – 4100 BTC stolen
#163They seem to be using Google Apps for the e-mail. And they claim: > The attacker was able to bypass 2FA due to a flaw on the server host side Which flaw is this? Is it a known issue for Google? I would like to know more details.
Re: Inputs.io hacked – 4100 BTC stolen
#164Earlier quoted context omitted.
> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…
Serious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?
Re: Inputs.io hacked – 4100 BTC stolen
#165Earlier quoted context omitted.
Not sure about that. Also, I read somewhere that the going rate of solving bank robberies is around 75-80% and many robbers are only caught because a) they do something stupid like not wear a mask or do anything to conceal their identity, or b) continuing robbing banks until their caught. Considering hacks like this take time and a fairly high level of sophistication, not sure the FBI would want to employ the amount…
The inputs.io hack required zero sophistication. Did you read TradeFortress' explanation? The hacker merely used the password reset feature on an email account, and then reset the Linode Manager password from the email.
Re: Inputs.io hacked – 4100 BTC stolen
#166Earlier quoted context omitted.
If that guy did not have some kind of insurance like banks do, how can he refund anyone? ( that's a question ). And would insurances insure this kind of business ? Now are bitcoin wallets banks ? and are they subject to the same regulations ? Is that guy a US citizen ? can he be sued by his clients ?
> If that guy did not have some kind of insurance like banks do, how can he refund anyone? Bitcoin is a relatively new thing, would not be surprised to start seeing bitcoin insurance for these types of services. > Is that guy a US citizen ? can he be sued by his clients ? I think it would depend if his clients have contracts, otherwise its a caveat emptor deal, especially when dealing with bitcoin.
(A large part of the Euro crisis was the Euro central bank refusing to backstop banks itself, delegating that to national central banks which can't print money and can therefore run out themselves)
Re: Inputs.io hacked – 4100 BTC stolen
#167Bitcoin's digital fungibility, which will always be a curse to some, will always be its greatest virtue. Distrust is one of its most valuable effects. Respect it or don't respect it. That's up to you.
Re: Inputs.io hacked – 4100 BTC stolen
#168Earlier quoted context omitted.
This is exactly why everyone SHOULD learn how to code and be a developer. They were negligent.
Who will bake my bread and pump my gas?
Re: Inputs.io hacked – 4100 BTC stolen
#169Earlier quoted context omitted.
> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…
Serious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?
What I mean is, if they implement a new whiz-bang feature, the best case is that people complain a bit less. But if their new feature opens up an attack vector or social engineering opportunity, they may suffer serious financial loss and very bad press.
Re: Inputs.io hacked – 4100 BTC stolen
#170Earlier quoted context omitted.
Nobody is forcing you to use it OR help its development. Why do you even care?
I care because the stories are spamming up HN. You can't downvote stories, and flagging them would probably be considered inappropriate.