Live data from Hacker News

XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

hackernoon.com

11–20 of 50 posts

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#11
I read the headline and my immediate guess was cryptocurrency. I clicked and, sure enough, there it was.

Maybe it's time to refine some of these ideas? While regular money does get stolen, maybe storing it online isn't the best method? Maybe requiring some human interaction is a good idea?

At this point, I can't really justify investing in any cryptocurrency. I'm absolutely unable to justify investing in any ICO.

If I opened a contract and my PayPal balance disappeared, I'd be pretty angry and might have some recourse. I'd absolutely have some options if it were with my credit/debit card or directly through my bank.

Good luck, folks. I'm still going to maintain the wait-and-see approach.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#14
post #11

I read the headline and my immediate guess was cryptocurrency. I clicked and, sure enough, there it was. Maybe it's time to refine some of these ideas? While regular money does get stolen, maybe storing it online isn't the best method? Maybe requiring some human interaction is a good idea? At this point, I can't really justify investing in any cryptocurrency. I'm absolutely unable to justify investing in any ICO. If…

The story is almost like the 2008 time where wall street wiz kids package the mortgages to special mortgages back securities/contacts and resell them over and over again to banks, mutual funds, etc.

Hugh hype was created.

Last time: It was safe because it was back by mortgage.

This time: It is safe because it is back by crypto algorithm.

Last time few smart insiders got billions richer and unload everything before the bubble burst.

And the time ...... (Love to see all imaginable endings to this time's story - good or bad)

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#15
post #12

Don't you also have to trust that the person running EtherDelta hasn't modified what's running on the site...?

If you use EtherDelta through MetaMask or Mist, then EtherDelta doesn't have direct access to your private keys, and you're given a prompt outside of EtherDelta's control to confirm any action you take, so you're much less vulnerable to malicious behavior from the EtherDelta admin.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#16

The smart contracts in Ethereum sounds awesome in practice and way more useful than Bitcoin mining but it seems like a giant security hole.

Kinda like a knife -- it's a very useful tool if used well and a very painful tool if mishandled.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#17
post #11

I read the headline and my immediate guess was cryptocurrency. I clicked and, sure enough, there it was. Maybe it's time to refine some of these ideas? While regular money does get stolen, maybe storing it online isn't the best method? Maybe requiring some human interaction is a good idea? At this point, I can't really justify investing in any cryptocurrency. I'm absolutely unable to justify investing in any ICO. If…

> Maybe requiring some human interaction is a good idea?

What's the fun in that?

Did Samy say "Maybe I should ask the user if they want to friend me"? NO! He said "People want to friend me" and "LOL MYSPACE XSS", then became the most popular person on the network overnight.

After Tom, of course, who cheated.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#18
post #14
post #11

I read the headline and my immediate guess was cryptocurrency. I clicked and, sure enough, there it was. Maybe it's time to refine some of these ideas? While regular money does get stolen, maybe storing it online isn't the best method? Maybe requiring some human interaction is a good idea? At this point, I can't really justify investing in any cryptocurrency. I'm absolutely unable to justify investing in any ICO. If…

The story is almost like the 2008 time where wall street wiz kids package the mortgages to special mortgages back securities/contacts and resell them over and over again to banks, mutual funds, etc. Hugh hype was created. Last time: It was safe because it was back by mortgage. This time: It is safe because it is back by crypto algorithm. Last time few smart insiders got billions richer and unload everything before th…

In 2007, I sold my business. In 2008, I put a bunch into the stock market and property. It was comparatively dirt cheap. I made a killing.

I'd do the same with cryptocurrency, but I can't figure out how. My 2008 investments were pretty risk-free. Of course the economy was going to recover. It always does.

I've no idea how to do that with cryptocurrency.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#20
post #3

> I want to make one point clear: I believe that EtherDelta, in concept, is safer and more “trustworthy” than a traditional exchange. Everything about how EtherDelta functions is transparent and verifiable by users.... The attack detailed in this piece could have been identified by anyone before it was exploited, and if there had been a security review protocol in place, it would have been easily prevented. Even "in…

This blows my mind. These programmers can implement quite complex contacts-financial-exchanges on top of a quite complex distributed system, but then fail to sanitize user input in their web interface. It makes no sense.
Post reply on HN