Live data from Hacker News

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

wired.com

11–20 of 69 posts

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#11
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

[deleted]

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#12
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

> I like to see it as ISPs and butt providers increasing their security and patching vulnerabilities thanks to Bitcoin's growing adoption :)

They'd have every reason already to increase their security. So I'll take the other approach, and continue to enjoy popcorn when I read about yet another one of these heists.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#13
The finger-pointing at BGP is red herring: the problem is that the stratum protocol has zero authentication. If you can intercept those streams, you can trivially ask anyone to start mining for you instead. This could also have been done using DNS poisoning, ISP-side intercepts, or anything else in the standard bag of tricks. http://blog.kevmod.com/category/bitcoin/

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#14
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#16
post #12
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

> I like to see it as ISPs and butt providers increasing their security and patching vulnerabilities thanks to Bitcoin's growing adoption :) They'd have every reason already to increase their security. So I'll take the other approach, and continue to enjoy popcorn when I read about yet another one of these heists.

What are you using to replace "cloud" with "butt" :)

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#17
post #13

The finger-pointing at BGP is red herring: the problem is that the stratum protocol has zero authentication. If you can intercept those streams, you can trivially ask anyone to start mining for you instead. This could also have been done using DNS poisoning, ISP-side intercepts, or anything else in the standard bag of tricks. http://blog.kevmod.com/category/bitcoin/

Indeed, for bitcoin it's a solvable problem, however let's not let that distract us from the monumental revelation that BGP hacking is so easy to do that someone motivated by a relatively paltry reward can pull it off.

This is one aspect of bitcoin that I really like, it shows us where the weaknesses are.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#18
post #12

Earlier quoted context omitted.

> I like to see it as ISPs and butt providers increasing their security and patching vulnerabilities thanks to Bitcoin's growing adoption :) They'd have every reason already to increase their security. So I'll take the other approach, and continue to enjoy popcorn when I read about yet another one of these heists.

What are you using to replace "cloud" with "butt" :)

The infamous Cloud2Butt browser extension strikes again.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#19
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

Sounds like a problem with computers, not Bitcoin.
Post reply on HN