Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

161–170 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#161

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

The FBI would probably come knocking with a warrant demanding that all Bitcoins that has passed thru Silk Road should be added to the list, because thus founds comes from illegal activities.

Re: Inputs.io hacked – 4100 BTC stolen

#163

They seem to be using Google Apps for the e-mail. And they claim: > The attacker was able to bypass 2FA due to a flaw on the server host side Which flaw is this? Is it a known issue for Google? I would like to know more details.

As a Linode & GApps customer that uses DFA I'm curious about this as well... Are they talking about Google, Linode or their own app?

Re: Inputs.io hacked – 4100 BTC stolen

#164
post #159

Earlier quoted context omitted.

> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…

Serious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?

Usually because they have to support IE6

Re: Inputs.io hacked – 4100 BTC stolen

#165
post #52

Earlier quoted context omitted.

Not sure about that. Also, I read somewhere that the going rate of solving bank robberies is around 75-80% and many robbers are only caught because a) they do something stupid like not wear a mask or do anything to conceal their identity, or b) continuing robbing banks until their caught. Considering hacks like this take time and a fairly high level of sophistication, not sure the FBI would want to employ the amount…

The inputs.io hack required zero sophistication. Did you read TradeFortress' explanation? The hacker merely used the password reset feature on an email account, and then reset the Linode Manager password from the email.

They had to get access to the email account first though; I thought it was a Google mail account with 2FA [can't be bothered checking back].

Re: Inputs.io hacked – 4100 BTC stolen

#166
post #129
post #108

Earlier quoted context omitted.

If that guy did not have some kind of insurance like banks do, how can he refund anyone? ( that's a question ). And would insurances insure this kind of business ? Now are bitcoin wallets banks ? and are they subject to the same regulations ? Is that guy a US citizen ? can he be sued by his clients ?

> If that guy did not have some kind of insurance like banks do, how can he refund anyone? Bitcoin is a relatively new thing, would not be surprised to start seeing bitcoin insurance for these types of services. > Is that guy a US citizen ? can he be sued by his clients ? I think it would depend if his clients have contracts, otherwise its a caveat emptor deal, especially when dealing with bitcoin.

Normal bank insurance is done by the central bank, which can lend unlimited money to cover this kind of hole.

(A large part of the Euro crisis was the Euro central bank refusing to backstop banks itself, delegating that to national central banks which can't print money and can therefore run out themselves)

Re: Inputs.io hacked – 4100 BTC stolen

#167
People who don't understand the importance of storing their own bitcoins spread across plenty of cold addresses -- generated from fresh, never-connected boxes and enough entropy -- are begging for loss. Given the attitude people have with security and the nature of viruses alone, 99%+ of people aren't 'ready' to use bitcoin beyond small amounts. It's inherently risky for any considerable amount. I never recommend bitcoin to most other people. It's recommended as worthy in and of itself, though.

Bitcoin's digital fungibility, which will always be a curse to some, will always be its greatest virtue. Distrust is one of its most valuable effects. Respect it or don't respect it. That's up to you.

Re: Inputs.io hacked – 4100 BTC stolen

#168
post #40

Earlier quoted context omitted.

This is exactly why everyone SHOULD learn how to code and be a developer. They were negligent.

Who will bake my bread and pump my gas?

bread will be made by robots (well actually already is.) and it will be delivered by automated drones, and your car is going to be electric and it's going to be charged just by parking it over a wireless charger.

Re: Inputs.io hacked – 4100 BTC stolen

#169
post #159

Earlier quoted context omitted.

> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…

Serious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?

I suspect this because, every time there is competition between innovative features that are nice for users, and ensuring security/limiting exposure and attack surface, the latter concern wins with little discussion.

What I mean is, if they implement a new whiz-bang feature, the best case is that people complain a bit less. But if their new feature opens up an attack vector or social engineering opportunity, they may suffer serious financial loss and very bad press.

Re: Inputs.io hacked – 4100 BTC stolen

#170
post #158

Earlier quoted context omitted.

Nobody is forcing you to use it OR help its development. Why do you even care?

I care because the stories are spamming up HN. You can't downvote stories, and flagging them would probably be considered inappropriate.

Can't you just... like... not read them? On every visit to HN I click 3-4 links tops, but you don't see me complaining in the comments section of the other 26 :)
Post reply on HN