Live data from Hacker News

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

wired.com

31–40 of 69 posts

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#31

Earlier quoted context omitted.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

Lots of money has been lost in other security breaches, oftentimes with much worse consequences because the data is centralized. This hasn't stopped people from shopping at Target for instance.

The nice thing is, security breaches in a decentralized network like bitcoin serve to make the entire network anti-fragile. There's a huge incentive for people with bitcoin to secure their own bitcoins against known exploits and hence make that exploit null while inevitably protecting against similar class exploits.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#32

Earlier quoted context omitted.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

It seems to be a transitional period where people must trade security for freedom, while the industry figures out the security part.

Much like early immigrants to North America who had leaving the stability and safety of UK/European banks for an emerging market and/or the Wild West.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#33
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

Nothing fundamental with bitcoin, same thing happens with online banking. In general, people will try to steal anything of value.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#34

Earlier quoted context omitted.

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

The same thing can be said about credit cards. If there is a problem with Bitcoin (and I'm not sure that there is) it is that unlike with credit cards there is no possible recovery of stolen coins.

Converting stolen CC numbers to cash actually turns out to be difficult since government and other authorities can revoke the cards, freeze fraudulent merchant accounts, and seize assets once they've hit your bank accounts. You have to mitigate all of these risks and won't always be successful.

If you manage to steal Bitcoin, you can transfer it all to your personal wallet in one transaction in broad daylight and, by design, no one can stop you or reverse the transaction once it's discovered to be fraudulent. Maybe run it through a darknet tumbler for good measure, but you're basically home free the second you get the private keys.

Stealing $100m worth of Bitcoin would be massively more valuable than stealing CC numbers with access to $500m in credit because you can actually cash out all of it. So much larger R&D budgets and more sophisticated attacks make financial sense.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#35

Earlier quoted context omitted.

That there is this level of investment is not particularly surprising when the item is fungible for cash (even at a fractional rate to market). There is the added kicker that often the failure/loss will go unreported if the victim has more to lose than the attacker (see early Mt Gox moves at 'covering' the fact that bitcoins were stolen). It is difficult for me to imagine a better way to incentivize the creation and…

Well given how long Target and others sit on massive CC data breaches you'd have to say the same incentives exist for CC attacks and bitcoin.

That is true, but as we've seen in both the Krebsonline posts and elsewhere converting a stolen credit card into cash has more risk than converting bitcoin into cash. Some of the things that make bitcoin useful (its cash like behaviors) also make it a juicier target I think.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#36
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

That there is this level of investment is not particularly surprising when the item is fungible for cash (even at a fractional rate to market). There is the added kicker that often the failure/loss will go unreported if the victim has more to lose than the attacker (see early Mt Gox moves at 'covering' the fact that bitcoins were stolen). It is difficult for me to imagine a better way to incentivize the creation and…

Actually, based on the numbers in the article I do find the level of investment surprising.

> Though each redirection lasted just 30 second or so, the thief was able to perform the attack 22 times, each time hijacking and gaining control of the processing power of a group of bitcoin miners

> At its peak, according to the researchers’ measurements, the hacker’s scam was pocketing a flow of bitcoins and other digital currencies including dogecoin and worldcoin worth close to $9,000 a day.

An estimated 22 half-minute episodes of hijacking a flow worth $9000 / day. There are 1440 minutes in a day, so $9000*11/1440 = $68.75 . The means here are much more impressive than the ends.

edit: forget what I said, the article later says that $83,000 of currency was taken.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#38

Earlier quoted context omitted.

That there is this level of investment is not particularly surprising when the item is fungible for cash (even at a fractional rate to market). There is the added kicker that often the failure/loss will go unreported if the victim has more to lose than the attacker (see early Mt Gox moves at 'covering' the fact that bitcoins were stolen). It is difficult for me to imagine a better way to incentivize the creation and…

Actually, based on the numbers in the article I do find the level of investment surprising. > Though each redirection lasted just 30 second or so, the thief was able to perform the attack 22 times, each time hijacking and gaining control of the processing power of a group of bitcoin miners > At its peak, according to the researchers’ measurements, the hacker’s scam was pocketing a flow of bitcoins and other digital c…

The half minute window was only required to reprogram mining pools to mine into the attackers pool. The effects of the attack last much longer than the time needed to execute the attack.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#39
post #31

Earlier quoted context omitted.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

Lots of money has been lost in other security breaches, oftentimes with much worse consequences because the data is centralized. This hasn't stopped people from shopping at Target for instance. The nice thing is, security breaches in a decentralized network like bitcoin serve to make the entire network anti-fragile. There's a huge incentive for people with bitcoin to secure their own bitcoins against known exploits a…

The difference is that with the Target breach, people knew that they would get their credit card $$ back.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#40

Earlier quoted context omitted.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

The unfortunate thing about this is a lot of people are going to lose a lot of money before either 1. Mainstream web security catches up to the cleverness of the bitcoin hackers or 2. People lose faith in bitcoin because the internet is generally not secure enough to support it.

You should not "invest" in bitcoin if you cannot afford losing it. So I would not shed a single tear.
Post reply on HN