Live data from Hacker News

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

wired.com

41–50 of 69 posts

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#41
post #39
post #31

Earlier quoted context omitted.

Lots of money has been lost in other security breaches, oftentimes with much worse consequences because the data is centralized. This hasn't stopped people from shopping at Target for instance. The nice thing is, security breaches in a decentralized network like bitcoin serve to make the entire network anti-fragile. There's a huge incentive for people with bitcoin to secure their own bitcoins against known exploits a…

The difference is that with the Target breach, people knew that they would get their credit card $$ back.

There are externalities to this "you don't have to worry at all about the security of your credit card info" feature.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#43
post #39
post #31

Earlier quoted context omitted.

Lots of money has been lost in other security breaches, oftentimes with much worse consequences because the data is centralized. This hasn't stopped people from shopping at Target for instance. The nice thing is, security breaches in a decentralized network like bitcoin serve to make the entire network anti-fragile. There's a huge incentive for people with bitcoin to secure their own bitcoins against known exploits a…

The difference is that with the Target breach, people knew that they would get their credit card $$ back.

But the way this is implemented is "credit card companies will take 3% of every transaction they perform, and then give back a very small portion of that to counteract fraud". The power we give these organizations - basically a 3% tax on every transaction - is mind boggling.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#44

Earlier quoted context omitted.

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

Sounds like a problem with computers, not Bitcoin.

Yes. I believe the same sophisticated attack could be used to target banking systems. It would just need a few more sophisticated services to be in place or more inside information.

But why bitcoin is targeted?

Because bitcoin is an open protocol, they could target it's root, mining rigs because that's where the value is generated. In banking systems, to generate money you need to have internal access and secure credits .

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#45
post #4

I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://www.theregiste…

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

At the same time, it hugely incentivizes improvements in computer security. After all, it's "our" fault for still using crappy and buggy Linux, Windows and Mac OSes, written in crappy and error-prone languages such as C and C++. Mind you, this crappy software is responsible for a lot more thefts than just bitcoin (e.g. China hacking and stealing trade secrets), but with bitcoin, you can put a definitive (if volatile) dollar price on the hacking.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#46

Nobody has pointed it out so far. Since it is an attack on IP routing, it could be prevented by using SSL for the Stratum protocol used by mining pools.

Would it? With this sophistication and latest exposures of CAs security I'm not fully sure that TLS MITM is a remote probability.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#47
post #38

Earlier quoted context omitted.

Actually, based on the numbers in the article I do find the level of investment surprising. > Though each redirection lasted just 30 second or so, the thief was able to perform the attack 22 times, each time hijacking and gaining control of the processing power of a group of bitcoin miners > At its peak, according to the researchers’ measurements, the hacker’s scam was pocketing a flow of bitcoins and other digital c…

The half minute window was only required to reprogram mining pools to mine into the attackers pool. The effects of the attack last much longer than the time needed to execute the attack.

People were mining for him for weeks at a time without realising anything was amiss.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#48
post #39

Earlier quoted context omitted.

The difference is that with the Target breach, people knew that they would get their credit card $$ back.

But the way this is implemented is "credit card companies will take 3% of every transaction they perform, and then give back a very small portion of that to counteract fraud". The power we give these organizations - basically a 3% tax on every transaction - is mind boggling.

Compared to the spread and inconvenience on $ -> bitcoin -> $ transactions, that's quite cheap.

Keeping bitcoin online enough for convenient transactions carries the small but important risk of losing your entire wallet.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#49
post #39

Earlier quoted context omitted.

The difference is that with the Target breach, people knew that they would get their credit card $$ back.

But the way this is implemented is "credit card companies will take 3% of every transaction they perform, and then give back a very small portion of that to counteract fraud". The power we give these organizations - basically a 3% tax on every transaction - is mind boggling.

But then that tax gets selectively reimbursed via dividend to shareholders. Upward redistribution.
Post reply on HN