Live data from Hacker News

Bitcoin payment processor BIPS compromised, 1295 BTC stolen

bitcointalk.org

31–40 of 70 posts

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#31
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

if you could get such a thing in place, couldn't everyone just roll back transactions?

I feel like having such a system in place would probably end up breaking a lot of the legitimacy (since you'd need over half of miners to agree to it, in which case some sort of "central" entity would exist)

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#32
post #17

Earlier quoted context omitted.

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…

Is it just me, or is some excited "Look we encrypt everything, and look, we even use good algorithms and look at those key sizes!" becoming a red flag about the security of a service? Most of the times it seems to be someone being excited about using state of the art encryption and forgetting that encryption is only as hard as the system and the humans surrounding it.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#33
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

http://www.reddit.com/r/Bitcoin/comments/1qomqt/what_a_landm...

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#34
post #17

Earlier quoted context omitted.

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…

Double salted?

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#35
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

Someone is already into it http://www.forbes.com/sites/kashmirhill/2013/11/13/sanitizin...

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#36
post #31

Earlier quoted context omitted.

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

if you could get such a thing in place, couldn't everyone just roll back transactions? I feel like having such a system in place would probably end up breaking a lot of the legitimacy (since you'd need over half of miners to agree to it, in which case some sort of "central" entity would exist)

You could to a point, but you would need a lot of mining power and the ability to act quickly.

BIPS didn't announce that they'd been compromised until over a week since the funds were sent out, so it's completely impossible at this point. If you wanted to get a transaction with one confirmation reversed, you would need to convince the two largest pools (ghash.io and btcguild) to mine a fork that doesn't contain your blacklisted transaction in under 10 minutes, and even then they'd create a very noticeable reorganisation. You'd also then have to race to get your funds out, as you know your keys have been compromised.

It's fairly impossible really.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#37
post #16
post #15

Earlier quoted context omitted.

@fleitz A million dollars difference, seems to me.

You mean in addition to being technically incompetent the team was also too stupid to buy insurance?

Do they have insurance for being stupid?

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#38
post #13
post #12

Earlier quoted context omitted.

That seems infinitely better than catastrophic loss of customer funds.

There's no difference as if you shut your site down everytime someone DDoS then you'll have no customers anyway.

"If we keep closing our retail store every time there's a riot inside of it, we'll never have any customers."

No, you shut the thing down, you post a page that explains what is going on and what you're doing about it, then you open again when it's clear.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#39
post #27
post #13

Earlier quoted context omitted.

There's no difference as if you shut your site down everytime someone DDoS then you'll have no customers anyway.

mmm i think at this point in the Bitcoin community, stating that practice on your homepage would actually get you more customers. "In the event of an obvious attack, we disconnect from the network and begin diagnostics after __ minutes of sustained activity."

ddos can run over a rather long period of time and come and go fairly quick. cutting the internet connection just is no viable solution for an online service.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#40
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

Who decides the addresses to add here? What if a government demands the assets of a political dissident be frozen?
Post reply on HN