Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…
>This fairly unique combination of properties quite possibly make Bitcoin the ideal target for thieves Or someone who runs an online wallet service with a privacy policy, who can pretend to have their hands tied when people ask where the money went.
Bitcoin payment processor BIPS compromised, 1295 BTC stolen
61–70 of 70 posts
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#62Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…
Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#63Here's their security page: https://bips.me/security -- "industry-leading security" .. "BIPS ... does not store bitcoin on its servers". Is it time for a PCI-like consortium that will validate your bitcoin storage security procedures? (Not that PCI is guarantee of anything, but at least following it prevents you from having full credit card data lying around in files). I.e. analyze your fail-safes (which seem to be l…
Bitcoin advocates talk about lack of regulations a feature, not a bug, so I'd wonder how well it'd go over. I think it's important and will have to happen eventually.
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#64Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...
Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions
Seriously, the moment I hear about a blacklist of coins on bitcoin is the same day I buy $5,000USD of Litecoin. I'll be a millionaire within 8 months.
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#65"Oh, we never said that our food is screened against infection - if you wanted that you should have checked out the premium section!"
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#66Earlier quoted context omitted.
The idea that airgapping during DDoS attacks will prevent intrusions is laughable.
For those of us who aren't laughing, how does the intruder bridge the air gap?
Maybe the attacker stole the coins and then DDoS'd the site?
It's all speculation, we're pretty light on details, but the whole DDoS-as-a-distraction thing seems a little out there to me.
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#67Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…
"It isn't recognized as currency by any jurisdiction on the planet as far as I can tell" Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#68Pretty sad, especially for folks who lost coin. The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew whe…
"It isn't recognized as currency by any jurisdiction on the planet as far as I can tell" Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...
"First, the Court must determine whether the BTCST investments constitute an investment of money. It is clear that Bitcoin can be used as money. It can be used to purchase goods or services, and as Shavers stated, used to pay for individual living expenses. The only limitation of Bitcoin is that it is limited to those places that accept it as currency. However, it can also be exchanged for conventional currencies, such as the U.S. dollar, Euro, Yen, and Yuan. Therefore, Bitcoin is a currency or form of money, and investors wishing to invest in BTCST provided an investment of money."
The key here is that the judge is trying to understand if the transactions involved met the standard of being an 'investment of money.' Which he reasons to by establishing that you can convert currency to and from BTC and you can buy products with BTC. He doesn't address the question of people who create BTC out of the act of 'mining' it. Let's say Van Gough was alive today, you could use his paintings as "money" in exactly the same way, except Van Gough could make new money just by painting something. Which makes other things more complicated (are bottles of tide "money" if you can trade them for drugs? [2]) It sounds like this ruling simply allowed the SEC to move forward with their case, but I'll be interested to watch it to see if it gets appealed (the ruling). Clearly ruling to overly broad here would put the onus on people with collectibles to follow FinCen rules when trading them, which to date they have largely avoided.
[1] http://www.courthousenews.com/2013/08/06/Bitcoin.pdf
[2] http://www.theatlantic.com/business/archive/2012/03/why-are-...
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#69Earlier quoted context omitted.
Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.
I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…
"Our private server facilities" sounds like they were trying to run their own facility for some misbegotten reason.
"A double salted SHA-512 hashing algorithm" sounds like a weak homegrown password hash. I'm guessing it was something along the lines of SHA512(salt1 + SHA512(salt2 + password)), which is pitifully weak compared to any sort of iterated hash (bcrypt, scrypt, PBKDF2, etc). It could also mean SHA512(salt1 + password + salt2), which would be even worse in a kind of sad, hilarious way.
"AES RIJNDAEL 256 encryption" is a perfectly normal SSL cipher. Referring to it as "RIJNDAEL" is a bit of a tipoff, though: Rijndael is not an acronym, so it shouldn't be capitalized, and it's simply an older name for AES, so it's entirely redundant in this phrase.
"2048-bit, highest assurance Extended Validation SSL certificate" is something you can get from any number of vendors. It isn't actually any more secure than any other SSL certificate.
"Industry-leading security and fraud protection" probably means nothing. Or, at most, possibly that they're using an off-the-shelf fraud detection service like Maxmind - which would have done little to nothing to protect them from a determined fraudster, let alone an attacker.
"Tape backups" just make it sound like they're using equipment from the 90s.
"Secure Card and Google Authenticator" are both decent features to implement, but suggesting that they result in "up to 3 levels of authentication" is amusing. Multiple possession factors ("something you have", like a security token or a cell phone with Authenticator) don't add together; to have three factors, you'd need a knowledge factor (a password), a possession factor, and a biometric factor. And they definitely don't have the last one.
Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen
#70Earlier quoted context omitted.
@fleitz A million dollars difference, seems to me.
You mean in addition to being technically incompetent the team was also too stupid to buy insurance?
Its so easy to steal your own bitcoin from yourself. How could a company profit from insuring against that?