Live data from Hacker News

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

wired.com

61–69 of 69 posts

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#61
post #44

Earlier quoted context omitted.

Sounds like a problem with computers, not Bitcoin.

Yes. I believe the same sophisticated attack could be used to target banking systems. It would just need a few more sophisticated services to be in place or more inside information. But why bitcoin is targeted? Because bitcoin is an open protocol, they could target it's root, mining rigs because that's where the value is generated. In banking systems, to generate money you need to have internal access and secure cred…

Bitcoin is targeted because it's a digital asset, true digital cash. Banks don't have that. You can never really own your bank money in digital form, it always stays in the bank's computers.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#62

Earlier quoted context omitted.

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

The same thing can be said about credit cards. If there is a problem with Bitcoin (and I'm not sure that there is) it is that unlike with credit cards there is no possible recovery of stolen coins.

That's not a problem, it's a feature. It's like saying "the problem with gold is that you can't recover it". But that's precisely what gold holders want: Not letting the government "recover" it (ie. seize/steal it).

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#63
post #59

Earlier quoted context omitted.

Converting stolen CC numbers to cash actually turns out to be difficult since government and other authorities can revoke the cards, freeze fraudulent merchant accounts, and seize assets once they've hit your bank accounts. You have to mitigate all of these risks and won't always be successful. If you manage to steal Bitcoin, you can transfer it all to your personal wallet in one transaction in broad daylight and, by…

I think this is really the sticking point that makes consumer Bitcoin adoption pretty much impossible, as the level of computer security required to keep Bitcoin safe and easy to use at the same time is just not something available to your average joe. If your private key is compromised, the thief takes your entire balance, and there's nothing you can do about it. So you really want to keep it safe. Lose your private…

Exactly. Nobody is going to want to manage their own bitcoin holdings, much as I don't keep all of my savings in a safe in my house. So that gets out-sourced and insured, and somebody has to pay for that. I expect it's much less than the credit card's take, but when it's paid for by the consumer it's much different psychologically. Consumers are going to have to get a cut of the savings.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#64

Earlier quoted context omitted.

It's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.

The great thing about this is it that it puts a floor on the bounty on all network bugs. Since we know that lots of national security folks are regularly exploiting various bugs for their own purposes, this means that the internet will be significantly improved. I see it as a bonus.

I agree. I actually leverage this by leaving a couple Bitcoins unencrypted in my 1Password file and have setup an alert to let me know if any of those coins ever move. Which would be a good indication that its time to use a new password manager.

Seems like the right kind of way to do a canary.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#65
post #54
post #20

Earlier quoted context omitted.

As a Canadian, using a Canadian ISP, I would like to know as well. Not entirely surprised regarding rogue employee possibility.

There are two things at play here: attacker has to have access to one ISP to inject the route (eg. rogue employee) and there has to be another ISP that accepts such route from BGP (I would say that filtering weirdly specific routes is good and common practice). When you have access to ISP network you don't have to inject things into BGP to attack your own customers.

A /24 is not a 'weirdly specific route'. I agree, that the upstream should have been filtering things, but you can't expect them to just filter out all the /24's.

For example, Google DNS anycast would stop working: http://bgp.he.net/net/8.8.8.0/24 as would basically anyone else doing anycast.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#66

Wow. Not sure why they don't name-and-shame the ISP, but that's really ridiculous.

NANOG post from this morning has the AS path:

http://mailman.nanog.org/pipermail/nanog/2014-August/069131....

I'm unsure exactly which was originating the route.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#67
post #44

Earlier quoted context omitted.

Yes. I believe the same sophisticated attack could be used to target banking systems. It would just need a few more sophisticated services to be in place or more inside information. But why bitcoin is targeted? Because bitcoin is an open protocol, they could target it's root, mining rigs because that's where the value is generated. In banking systems, to generate money you need to have internal access and secure cred…

Bitcoin is targeted because it's a digital asset, true digital cash. Banks don't have that. You can never really own your bank money in digital form, it always stays in the bank's computers.

No I'm not talking about targeting banks directly. What about targeting consumers or ecomm sites? A consumer need to give card information, websites should make vpos operations.

These can be target vectors too.

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#68
post #44

Earlier quoted context omitted.

Yes. I believe the same sophisticated attack could be used to target banking systems. It would just need a few more sophisticated services to be in place or more inside information. But why bitcoin is targeted? Because bitcoin is an open protocol, they could target it's root, mining rigs because that's where the value is generated. In banking systems, to generate money you need to have internal access and secure cred…

Bitcoin is targeted because it's a digital asset, true digital cash. Banks don't have that. You can never really own your bank money in digital form, it always stays in the bank's computers.

[deleted]

Re: Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

#69

Earlier quoted context omitted.

Converting stolen CC numbers to cash actually turns out to be difficult since government and other authorities can revoke the cards, freeze fraudulent merchant accounts, and seize assets once they've hit your bank accounts. You have to mitigate all of these risks and won't always be successful. If you manage to steal Bitcoin, you can transfer it all to your personal wallet in one transaction in broad daylight and, by…

There is good research that indicates that the bottleneck in electronic bank theft is finding the endpoints that are irreversible (think ATMs). Doubling the amount of stolen credit cards wouldn't come anywhere close to doubling the amount of money stolen out of the system. With Bitcoin, every marginal theft adds 100% to the total Bitcoin thefts.

Could you give a citation for that? Not saying I disbelieve you, it sounds plausible, but I'd be interested to read that research.
Post reply on HN