Live data from Hacker News

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

wired.com

21–30 of 69 posts

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#21
The lack of auth and encryption is only part of the problem with Stratum's implementation. At Toorcamp 2014 I presented about the vulnerabilities discovered when looking into common miners and their impact on the network. More details available in the associated white paper:

http://www.dejavusecurity.com/blog/2014/7/15/bitcoin-researc...

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#22
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

That there is this level of investment is not particularly surprising when the item is fungible for cash (even at a fractional rate to market). There is the added kicker that often the failure/loss will go unreported if the victim has more to lose than the attacker (see early Mt Gox moves at 'covering' the fact that bitcoins were stolen).

It is difficult for me to imagine a better way to incentivize the creation and deployment of malware than Bitcoin today.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#23
post #12

Earlier quoted context omitted.

> I like to see it as ISPs and butt providers increasing their security and patching vulnerabilities thanks to Bitcoin's growing adoption :) They'd have every reason already to increase their security. So I'll take the other approach, and continue to enjoy popcorn when I read about yet another one of these heists.

What are you using to replace "cloud" with "butt" :)

https://chrome.google.com/webstore/detail/cloud-to-butt-plus...

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#24

Wow. Not sure why they don't name-and-shame the ISP, but that's really ridiculous.

"the CTU research team provided the BGP evidence to the upstream ISP closest to the origin of the malicious activity."

I think this likely means it's a smaller ISP.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#26

Earlier quoted context omitted.

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#27
It's mind boggling to me that this wasn't done a year or two ago.

If bitcoin were genuinely anonymous (it isn't, because it's highly linkable, even if essentially pseudonymous), it would probably be vastly more dangerous in this way -- there would be billions of dollars spent on exploiting security outside bitcoin++ to steal bitcoin++.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#28
I know a number of people who got hit by this type of reconnect attack. I suspect I may have been hit by it for short periods of time. Most of the big altcoin pools were targeted. Soon after most miner software was modified to disable this Stratum feature but there are still plenty of other issues with the Stratum protocol as highlighted by other comments.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#29
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

That there is this level of investment is not particularly surprising when the item is fungible for cash (even at a fractional rate to market). There is the added kicker that often the failure/loss will go unreported if the victim has more to lose than the attacker (see early Mt Gox moves at 'covering' the fact that bitcoins were stolen). It is difficult for me to imagine a better way to incentivize the creation and…

Well given how long Target and others sit on massive CC data breaches you'd have to say the same incentives exist for CC attacks and bitcoin.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#30

Earlier quoted context omitted.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

Barely 0.01% of the world population uses Bitcoin and we already see a technology on the market that is expected to significantly improve security, and this was the result of 1+ year of engineering effort from teams of engineers: hardware wallets like http://www.bitcointrezor.com So security isn't great overall right now, but clearly it is improving way ahead of time with respect to a potential mainstream adoption of Bitcoin.
Post reply on HN