Live data from Hacker News

Bitcoin payment processor BIPS compromised, 1295 BTC stolen

bitcointalk.org

61–70 of 70 posts

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#61

Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…

>This fairly unique combination of properties quite possibly make Bitcoin the ideal target for thieves Or someone who runs an online wallet service with a privacy policy, who can pretend to have their hands tied when people ask where the money went.

The best thieves are the ones who get their victims to hand over their valuables willingly ...

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#62

Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…

"It isn't recognized as currency by any jurisdiction on the planet as far as I can tell"

Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#63
post #44

Here's their security page: https://bips.me/security -- "industry-leading security" .. "BIPS ... does not store bitcoin on its servers". Is it time for a PCI-like consortium that will validate your bitcoin storage security procedures? (Not that PCI is guarantee of anything, but at least following it prevents you from having full credit card data lying around in files). I.e. analyze your fail-safes (which seem to be l…

Bitcoin advocates talk about lack of regulations a feature, not a bug, so I'd wonder how well it'd go over. I think it's important and will have to happen eventually.

Could see if voluntary adoption works out.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#64
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions

The moment we start maintaining a list of blacklisted/tainted/marked coins that are not accepted everywhere is when bitcoin will start failing. The list will start off innocent enough but when(not if) it starts being abused, it'll be all over. It'll start with blatant thefts like this, but the blacklist-maintainers, whoever they are, will eventually attract the attention of the law enforcement. The definition of theft will expand and expand. Eventually these blacklist-maintainers and/or GOV will decide which coins are valid are which are not. Coins will be seized just because of some random political agenda and bitcoin will just be a mess. The only way to stay off the blacklist will be to register with some authority and basically bitcoin will be no different from a regular bank. Then everyone will abandon it and go to Litecoin.

Seriously, the moment I hear about a blacklist of coins on bitcoin is the same day I buy $5,000USD of Litecoin. I'll be a millionaire within 8 months.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#65
> It is imperative to understand that everything was wiped out from our servers and getting functionality back is priority #1. The wallet part of BIPS was a free service to make payments easier for users. Web Wallets are like a regular wallet that you carry cash in and not meant to keep large amounts in. Hence we offered a paper wallet as a cold storage alternative for those who wanted a safe storage solution.

"Oh, we never said that our food is screened against infection - if you wanted that you should have checked out the premium section!"

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#66

Earlier quoted context omitted.

The idea that airgapping during DDoS attacks will prevent intrusions is laughable.

For those of us who aren't laughing, how does the intruder bridge the air gap?

How would an attacker exploit a service while it was inaccessible because they're DDoSing it? Why would someone draw attention to themselves like that?

Maybe the attacker stole the coins and then DDoS'd the site?

It's all speculation, we're pretty light on details, but the whole DDoS-as-a-distraction thing seems a little out there to me.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#67
post #62

Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…

"It isn't recognized as currency by any jurisdiction on the planet as far as I can tell" Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...

Wow that is a the saddest ponzi scheme I've come across so far... it really makes you wonder how bad our educational system is if our ponzi schemes are getting so poorly designed and managed.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#68
post #62

Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…

"It isn't recognized as currency by any jurisdiction on the planet as far as I can tell" Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...

Thanks for the link, the reasoning from the ruling [1] is a bit more precise however. For the purposes of establishing standing the SEC to prosecute. The judge reasoned to that in part with this:

"First, the Court must determine whether the BTCST investments constitute an investment of money. It is clear that Bitcoin can be used as money. It can be used to purchase goods or services, and as Shavers stated, used to pay for individual living expenses. The only limitation of Bitcoin is that it is limited to those places that accept it as currency. However, it can also be exchanged for conventional currencies, such as the U.S. dollar, Euro, Yen, and Yuan. Therefore, Bitcoin is a currency or form of money, and investors wishing to invest in BTCST provided an investment of money."

The key here is that the judge is trying to understand if the transactions involved met the standard of being an 'investment of money.' Which he reasons to by establishing that you can convert currency to and from BTC and you can buy products with BTC. He doesn't address the question of people who create BTC out of the act of 'mining' it. Let's say Van Gough was alive today, you could use his paintings as "money" in exactly the same way, except Van Gough could make new money just by painting something. Which makes other things more complicated (are bottles of tide "money" if you can trade them for drugs? [2]) It sounds like this ruling simply allowed the SEC to move forward with their case, but I'll be interested to watch it to see if it gets appealed (the ruling). Clearly ruling to overly broad here would put the onus on people with collectibles to follow FinCen rules when trading them, which to date they have largely avoided.

[1] http://www.courthousenews.com/2013/08/06/Bitcoin.pdf

[2] http://www.theatlantic.com/business/archive/2012/03/why-are-...

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#69
post #17

Earlier quoted context omitted.

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…

There's a lot of incompetence on display in that technical description.

"Our private server facilities" sounds like they were trying to run their own facility for some misbegotten reason.

"A double salted SHA-512 hashing algorithm" sounds like a weak homegrown password hash. I'm guessing it was something along the lines of SHA512(salt1 + SHA512(salt2 + password)), which is pitifully weak compared to any sort of iterated hash (bcrypt, scrypt, PBKDF2, etc). It could also mean SHA512(salt1 + password + salt2), which would be even worse in a kind of sad, hilarious way.

"AES RIJNDAEL 256 encryption" is a perfectly normal SSL cipher. Referring to it as "RIJNDAEL" is a bit of a tipoff, though: Rijndael is not an acronym, so it shouldn't be capitalized, and it's simply an older name for AES, so it's entirely redundant in this phrase.

"2048-bit, highest assurance Extended Validation SSL certificate" is something you can get from any number of vendors. It isn't actually any more secure than any other SSL certificate.

"Industry-leading security and fraud protection" probably means nothing. Or, at most, possibly that they're using an off-the-shelf fraud detection service like Maxmind - which would have done little to nothing to protect them from a determined fraudster, let alone an attacker.

"Tape backups" just make it sound like they're using equipment from the 90s.

"Secure Card and Google Authenticator" are both decent features to implement, but suggesting that they result in "up to 3 levels of authentication" is amusing. Multiple possession factors ("something you have", like a security token or a cell phone with Authenticator) don't add together; to have three factors, you'd need a knowledge factor (a password), a possession factor, and a biometric factor. And they definitely don't have the last one.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#70
post #16
post #15

Earlier quoted context omitted.

@fleitz A million dollars difference, seems to me.

You mean in addition to being technically incompetent the team was also too stupid to buy insurance?

What company sells insurance against bitcoin being stolen?

Its so easy to steal your own bitcoin from yourself. How could a company profit from insuring against that?

Post reply on HN