Live data from Hacker News

Is Bitcoin security worth $1B?

blockcypher.com

11–20 of 33 posts

Re: Is Bitcoin security worth $1B?

#11
post #5

> Multiple signature (multisig) transactions would have prevented all of it. Yeah, no, there's still a need for hot wallets which can be spent automatically by a server and these were basically the only ones stolen. You actually have to keep the keys separate for it to make a difference. Also their api is borderline retarded. The server passes back a hash to sign and the client is just supposed to blindly sign it. Su…

This is incorrect. You can have servers using multisig too, it increases the overall security of the transactions, especially if the different private keys are stored in different environments (different datacenters, different OS, etc.).

Regarding the blind signature: yes, you can check it and in most cases it's just checking a series of bytes at a given position in an array. One line of code. Building a multisig transaction locally? Good-luck doing that.

Also I've heard many times arguments along the lines of "my security is better than yours, I don't trust you". It's reminiscent of those arguments about cloud providers like AWS, "my outages are better than yours". The point is we are focusing solely on block chain infrastructure: the security, performance,and reliability. It's our expertise. Is it yours?

Re: Is Bitcoin security worth $1B?

#12

Yes, multi-signature transactions can greatly improve security. But this idea of using a third party to write your transactions for you is a very, very bad idea. It introduces an additional point of failure for security: someone can break into their server, and make it start generating transactions that send coins somewhere other than where you said. Writing software that uses this API would be negligence.

Someone can also break into your servers and manipulate your transactions. It's our business to run a secure and reliable service. Bitcoin infrastructure is fairly complex and so the probably that you'll miss something are pretty high. Isn't it better to focus on your own business rather that spend all your time and money building and maintaining the backend piece?

Re: Is Bitcoin security worth $1B?

#13
post #7

Earlier quoted context omitted.

It is kind of ironic that people who are using a currency dependent on the security of crypto operations created an API that commits a fundamental mistake: trusting the data you receive.

You don't have to trust our data - you can check it against the multitude of block explorers available in the market. However, if you use blockchain.info to check, be aware that they do not support pay-to-script transactions and will not show the transaction until it's confirmed. And you can easily check the received data. The security of our APIs lies in the fact we don't store private keys - the user signs their ow…

the user signs their own transaction.

If I understand it right then that is a lie.

In reality you ask the user to sign a transaction that you create for him.

This is extremely dangerous for the user (pretty close to signing a blank cheque) and I don't like how you try to downplay this flaw.

Your API is broken by design and puts anyone who is naive enough to use it at great risk. You should take it offline.

Re: Is Bitcoin security worth $1B?

#16
post #11
post #5

> Multiple signature (multisig) transactions would have prevented all of it. Yeah, no, there's still a need for hot wallets which can be spent automatically by a server and these were basically the only ones stolen. You actually have to keep the keys separate for it to make a difference. Also their api is borderline retarded. The server passes back a hash to sign and the client is just supposed to blindly sign it. Su…

This is incorrect. You can have servers using multisig too, it increases the overall security of the transactions, especially if the different private keys are stored in different environments (different datacenters, different OS, etc.). Regarding the blind signature: yes, you can check it and in most cases it's just checking a series of bytes at a given position in an array. One line of code. Building a multisig tra…

Also I've heard many times arguments along the lines of "my security is better than yours, I don't trust you". It's reminiscent of those arguments about cloud providers like AWS, "my outages are better than yours".

I guess this is where sufficiently advanced incompetence becomes indistinguishable from malice.

In either case, I strongly advise everyone to refrain from ever using any bitcoin service that you may be involved with.

Re: Is Bitcoin security worth $1B?

#17

We already spend a total of $15 million dollars per day in energy costs[1] making secure transactions in Bitcoin, so I think in a way we're already spending more than $5 billion on Bitcoin security. [1]: http://www.forbes.com/sites/timworstall/2013/12/03/fascinati...

I ran the numbers on newer mining rigs a few weeks ago and came up with a PH/s needing about 1 semi tractor trailer engine to run. The network is currently doing about 130PH/s, so that's about 130 semis engines running. Not anything to sneeze about, but also definitely not $15M a day.

Re: Is Bitcoin security worth $1B?

#18
post #13

Earlier quoted context omitted.

You don't have to trust our data - you can check it against the multitude of block explorers available in the market. However, if you use blockchain.info to check, be aware that they do not support pay-to-script transactions and will not show the transaction until it's confirmed. And you can easily check the received data. The security of our APIs lies in the fact we don't store private keys - the user signs their ow…

the user signs their own transaction. If I understand it right then that is a lie. In reality you ask the user to sign a transaction that you create for him . This is extremely dangerous for the user (pretty close to signing a blank cheque) and I don't like how you try to downplay this flaw. Your API is broken by design and puts anyone who is naive enough to use it at great risk. You should take it offline.

Seems more like signing a check someone else filled out for you. You can still verify the amount and refuse if it's wrong. Or am I wrong? Doesn't the transaction have to include all the relevant details before it's signed?

Re: Is Bitcoin security worth $1B?

#19
post #18
post #13

Earlier quoted context omitted.

the user signs their own transaction. If I understand it right then that is a lie. In reality you ask the user to sign a transaction that you create for him . This is extremely dangerous for the user (pretty close to signing a blank cheque) and I don't like how you try to downplay this flaw. Your API is broken by design and puts anyone who is naive enough to use it at great risk. You should take it offline.

Seems more like signing a check someone else filled out for you. You can still verify the amount and refuse if it's wrong. Or am I wrong? Doesn't the transaction have to include all the relevant details before it's signed?

Yes, technically the transaction body does include all details.

However, decoding and verifying a complex transaction takes about the same amount of work as generating it yourself to begin with...

Their documentation clearly expects you to blindly sign whatever tx they make up for you. There's not a word on verifying the transaction locally before signing it.

http://dev.blockcypher.com/#signing_sending

Re: Is Bitcoin security worth $1B?

#20
post #18
post #13

Earlier quoted context omitted.

the user signs their own transaction. If I understand it right then that is a lie. In reality you ask the user to sign a transaction that you create for him . This is extremely dangerous for the user (pretty close to signing a blank cheque) and I don't like how you try to downplay this flaw. Your API is broken by design and puts anyone who is naive enough to use it at great risk. You should take it offline.

Seems more like signing a check someone else filled out for you. You can still verify the amount and refuse if it's wrong. Or am I wrong? Doesn't the transaction have to include all the relevant details before it's signed?

Indeed, you are correct.
Post reply on HN