Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

101–110 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#102
post #74

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit.

It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied.

AFAIK, the US works the other way around.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#104
post #74

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit.

Additionally, you need to have a direct debit agreement with your bank to be able to initiate a direct debit. You need to show at least some legitimate banking history (and a government-issued ID) to get one, and they come with limits on how many and how much you can debit per period, and your bank will terminate the agreement if your reversal rate is higher than normal.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#105
post #74

Earlier quoted context omitted.

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied. AFAIK, the US works the other way around.

> By default, those requests are denied.

This depends on your bank, mine allows them by default.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#106

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

You think that is bad, every doctors office I have ever dealt with over the phone has just asked for my name, and birthdate. Think of all the friends on social media I can impersonate!

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#107
post #74

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

This does have a minor drawback on the service provider side as allowing people to sign up for a service with direct debit is hard to get right, so many services prefer to offer credit card payment even if it is more expensive. There is no way for you to verify that a person signing up is actually the account holder save for doing the "we debited 1c on your account" thing, which takes a few days.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#108
post #22

Earlier quoted context omitted.

One thinks about crypto as a clownworld only until one had to work with or inside the real financial system. Techincally, it is in no way better than crypto. The only difference is that in real financial system there is a strong legal cover for all the technical and security fuckups. Like, stealing from bank by exploiting their 10-years old Windows XP ATM connected to the internet is 10-years-in-jail offence, while s…

> while stealing crypto may be hard or impossible to prosecute in many jurisdictions. This is one of the inherent contradictions of crypto. If the ultimate goal of crypto is to create a financial system that is free of government control, then that system must also be free of the justice system because that's the government too. Asking people whose salaries are paid for with tax dollars to help you recover stolen cry…

If your goal is to avoid taxes, you're better off using cash than crypto. And not everyone using crypto is a diehard libertarian.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#109

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Credit card numbers are similarly a private number used as a public number, and printed on plaintext on the card.

I have an Apple Card. The only text on the card is my name. I think a lot of bank cards are starting to do similar stuff.

It isn't foolproof, though. Someone somehow was able to charge against the card, a couple of months ago.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#110
post #87

This sounds like your standard startup-y security stack. Bonus points for trying to use your cloud provider's hardware key storage and keeping secrets in 1password. It ain't great but you could do worse. (I've worked at startups and we did better. No access to the cloud provider without a time-based escalation. Secrets in secrets managers. Passwords rotated regularly. Mandatory 2FA. Signed commits. But it would proba…

What's particularly astounding about the case of FTX is that it was rolling in cash (unlike many startups), and yet never cared enough to throw money at hiring tons of security-minded staff and engineers

Yeah have often thought the same but presumably they wouldn’t have been able to keep pulling all these shenanigans/fraud if they had proper security staff.
Post reply on HN