Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

131–140 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#131
post #93

Earlier quoted context omitted.

where do you keep the key to the crypto fs?

Written on a scrap of paper in your wallet. only the password and no other info should be on the scrap. If you can memorize it, it is a bad password.

That's not strictly true. If you're careful and imaginative, with moderate effort you can commit a fair amount of highly random data to memory. You just can't expect to change it every month.

This may be oversimplified, but it's the correct horse battery staple.

Re: Compromised Linode, thousands of BitCoins stolen

#132
post #78
post #64

Earlier quoted context omitted.

Yes you can, but not in 24h. (Hopefully buying a $20k car is not an impulse buy you make in a day, ahem...) Sell the BTC on MtGox and withdraw the USD via Dwolla directly to your bank account. No need to use Paypal! MtGox's withdrawal limit can be raised to $10k per day if you provide a notarized government ID copy (IIRC). Dwolla's limit is $5k per transfer with as many txfer per day. So it would take 2 days for comp…

thank the legacy financial system for these unexplainable delays I understand your feelings on this. But the fact remains that the using the "legacy financial system" I can move my money between investments on my etrade account with a latency of minutes. I can buy that car on a credit card or with a personal check with zero latency. Bitcoins aren't remotely there yet. There may be some privacy or social justice reaso…

My understanding of when they move money around in minutes is that they're basically giving you a short-term, interest-free loan in exchange for using their service. In reality, it still takes a day or two for things to clear.

Re: Compromised Linode, thousands of BitCoins stolen

#133
post #126

Earlier quoted context omitted.

By using your public key. http://www.debian-administration.org/articles/152 You can also require a password AND a cert.

Yes, but will that help you if the attacker trojans whatever it is that is doing the decryption? I mean, I'm very clearly not a crypto expert, but I do believe that this would be quite a lot like what Bruce Schnier calls 'the evil maid' attack. Instead of having a bootloader, you have a minimal Linux install, then you get a key to that minimal linux install, and that minimal linux install uses that key to decrypt you…

I advise you seek the services of a professional sys admin to secure systems.

Re: Compromised Linode, thousands of BitCoins stolen

#134
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

It's certainly a grey area, but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked? Say this happened to Amazon and it affected a company like Heroku or dropbox, both users of AWS? Regardless of what terms of service says, I'll bet there's some liability somewhere. And if there's a cut off, maybe linode should advertise that? "Hey, we're cheap, but you get what you pay for!" rather than "You're getting ripped off if you go with amazon over linode!"

If a bank gets robbed, I'm not liable for the cash they steal. But how about if I've got cash in a safe deposit box and someone uses a fake id to get into it, and the bank doesn't recognize the fraud? That's trickier. And if someone robs my house and I've got a bunch of cash under my mattress, that's another story too. I know the analogy doesn't quite hold up because it's kind of like a bank and a customer engineering a safe together (eg both could be at fault for a break in), but there's got to be some responsibility on Linode's part.

Re: Compromised Linode, thousands of BitCoins stolen

#135
post #106

Earlier quoted context omitted.

Sigh. Please give me a definition of 'scam' that fits with bitcoin and not e.g. Apple or Google shares. Hint: In a scam, there's deceit. The bitcoin devs never deceived anyone. The whole system is transparent, so if there's anyone who bought without understanding the risks, they have no one to blame but themselves. (Note: No, I don't own any bitcoins).

Perhaps I am just cynical. I did not mean to suggest the devs were scammers. But I still believe the ecosystem as a whole reeks of pyramids and other scams and I am sick of reading about it. I also think Scientology and MLM are scams but there are people who think they are not and we can't all agree. But then I also think casinos and lotteries are scams so I am kind of outside mainstream opinion on a few things I gue…

I was probably too harsh, but frankly, just as you're sick of reading about it, I'm sick of every single thread on bitcoin having that inaccuracy. What can I say, I'm literal minded - the misuse of words annoys me.

But I still believe the ecosystem as a whole reeks of pyramids and other scams

Oh, sure, that's kind of inevitable, it's a result of the lack of constraints and oversight. But personally, it's a part of why I like reading about it - it still has that feeling of a "wild west", populated by pioneers and thieves. Kinda like the Internet as a whole a few decades ago. Of course, it also means I wouldn't trust it with my money.

I am sick of reading about it.

Sorry, but then... why not just skip the link? There are a few topics I'm kinda sick of too, but I just ignore them.

But then I also think casinos and lotteries are scams so I am kind of outside mainstream opinion on a few things I guess.

Again, my literal mind jumps when I read that ; ) I can completely understand that you consider them immoral and/or predatory, but there's no need to call them a scam particularly - FSM knows there are plenty of other immoral acts.

Re: Compromised Linode, thousands of BitCoins stolen

#136
post #115
post #62

Earlier quoted context omitted.

It's from his e-mail conversation with Linode support: http://pastebin.com/UW7iT5fj

So hardly "from linode" More accurately "according to somebody at linode"

er no, either. ITYM "according to an alleged discussion with a Linode employee".

Re: Compromised Linode, thousands of BitCoins stolen

#137
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

It's certainly a grey area, but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked? Say this happened to Amazon and it affected a company like Heroku or dropbox, both users of AWS? Regardless of what terms of service says, I'll bet there's some liability somewhere. And if there's a cut off, maybe linode should advertise that? "Hey, we're cheap, but you get what…

> but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked

If you co-locate your hardware at a data center and your staff competently secures your systems.

Re: Compromised Linode, thousands of BitCoins stolen

#138
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

It's certainly a grey area, but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked? Say this happened to Amazon and it affected a company like Heroku or dropbox, both users of AWS? Regardless of what terms of service says, I'll bet there's some liability somewhere. And if there's a cut off, maybe linode should advertise that? "Hey, we're cheap, but you get what…

I'd say this is more akin to stashing a bunch of money in a self-storage unit instead of a bank account. One explicitly insures against theft, the other does not. The onus is on you as a customer to decide what to go with.

Re: Compromised Linode, thousands of BitCoins stolen

#140

Earlier quoted context omitted.

Oh, FFS. I meant "what state?" as in, "why are you talking about the state?", since you said: (...) something that the state can protect (...) and since the PCI (which was what we were talking about) is private , it doesn't make sense to talk about the State. US-centered mindset The fuck? Firstly, I'm European. Secondly, I assumed you were talking about the State[1], not a particular state. [1]: https://en.wikipedia.…

First and foremost: I'm sorry. We clearly didn't talk about the same thing and I misunderstood what you wrote. My take: Someone was mocking Bitcoins with "But all that regulation is evil and it's the freedom of bitcoin that gives it the power" and I tried to make a point saying that _no regulation is involved here_ (laws? certainly). This is a wallet, it got stolen. Your credit cards are protected, your cash is gone…

Well, I'm sorry for the confrontational reaction.

I invoked PCI because of the thread: the original post was from klodolph, who said:

(...) You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

And to that gravitronic replied:

But all that regulation is evil and it's the freedom of bitcoin that gives it the power(...)

"All that regulation" only makes sense if gravitronic is talking about PCI, which was the only regulation cited by klodolph.

Post reply on HN