Live data from Hacker News

Bitcoin payment processor BIPS compromised, 1295 BTC stolen

bitcointalk.org

11–20 of 70 posts

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#11
post #5
post #4

That technical explanation sounds almost like word salad. How did a DDoS hit your SAN in the first place and how did your SAN blowing up allow a compromise?

iSCSI san, so attached via ethernet or similar, taking network devices offline would take san offline. The rest is pure magic.

Re: pure magic: perhaps the SAN is willing to talk to whoever sends it packets, and/or to be administered by whoever can enter admin:admin into a poorly-secured web interface as soon as it loses the appropriate connection/reboots due to overload/..?

I agree with my sibling comment that this seems an odd way to install a SAN.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#12
post #10

Hey, how about just disconnecting the critical machines from the network when under such an attack?

Our DDOS recovery plan is to just shut everything off and admit defeat. Brilliant.

That seems infinitely better than catastrophic loss of customer funds.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#13
post #12
post #10

Earlier quoted context omitted.

Our DDOS recovery plan is to just shut everything off and admit defeat. Brilliant.

That seems infinitely better than catastrophic loss of customer funds.

There's no difference as if you shut your site down everytime someone DDoS then you'll have no customers anyway.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#14
post #4

That technical explanation sounds almost like word salad. How did a DDoS hit your SAN in the first place and how did your SAN blowing up allow a compromise?

If you are new to bitcoin-related sites, you might find this story close to legitimate. But anyone that reads the article will see there is this "basic" flaw mentioning that DDoS attacks gave access to the server. If you read past (paid) articles about this very same service, you will see claims about how secure the system is, and how expert everyone that developed it is. The same was claimed by inputs.io, I'm sure y…

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#15
post #12
post #10

Earlier quoted context omitted.

Our DDOS recovery plan is to just shut everything off and admit defeat. Brilliant.

That seems infinitely better than catastrophic loss of customer funds.

@fleitz A million dollars difference, seems to me.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#16
post #15
post #12

Earlier quoted context omitted.

That seems infinitely better than catastrophic loss of customer funds.

@fleitz A million dollars difference, seems to me.

You mean in addition to being technically incompetent the team was also too stupid to buy insurance?

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#17

Earlier quoted context omitted.

If you are new to bitcoin-related sites, you might find this story close to legitimate. But anyone that reads the article will see there is this "basic" flaw mentioning that DDoS attacks gave access to the server. If you read past (paid) articles about this very same service, you will see claims about how secure the system is, and how expert everyone that developed it is. The same was claimed by inputs.io, I'm sure y…

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared.

> BIPS was built by passionate bitcoiners and talented developers. BIPS is hosted in our private server facilities. Passwords are stored with a double salted SHA-512 hashing algorithm. Our entire website is protected with AES RIJNDAEL 256 encryption and we have encryption of data traffic with 2048-bit, highest assurance Extended Validation SSL certificate, with 99.9% Browser Recognition.

> BIPS protects your payment information with industry-leading security and fraud protection. On top of this, our server/database is regularly stored on tape backups. For added security you can also enable Secure Card and Google Authenticator at any time for up to 3 levels of authentication.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#18
post #16
post #15

Earlier quoted context omitted.

@fleitz A million dollars difference, seems to me.

You mean in addition to being technically incompetent the team was also too stupid to buy insurance?

I would imagine insurance for an online bitcoin wallet is somewhere between "prohibitively expensive" and "not possible to buy"
Post reply on HN