Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

181–190 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#181

Earlier quoted context omitted.

You know exactly what input transactions contains tainted coins, so you know the amount, and thus how many untainted coins there are.

But when you transfer BTC out, even if it's in the exact amount of the tainted coins transferred in, how do you decide whether the outgoing coins represent the tainted ones or the untainted ones? Say there's a 50 BTC untainted wallet, and tainted 1 BTC is transferred in, then 1 BTC is transferred out. How do you decide whether that outgoing 1 BTC was drawn on the tainted portion or the untainted portion of the accoun…

Always regards the last bitcoins as the tainted ones. Local wallets could simply treat tainted bitcoins as not existing, thus removing that annoyance too.

Re: Inputs.io hacked – 4100 BTC stolen

#182

Earlier quoted context omitted.

You know exactly what input transactions contains tainted coins, so you know the amount, and thus how many untainted coins there are.

But when you transfer BTC out, even if it's in the exact amount of the tainted coins transferred in, how do you decide whether the outgoing coins represent the tainted ones or the untainted ones? Say there's a 50 BTC untainted wallet, and tainted 1 BTC is transferred in, then 1 BTC is transferred out. How do you decide whether that outgoing 1 BTC was drawn on the tainted portion or the untainted portion of the accoun…

Always regards the last bitcoins as the tainted ones. Local wallets could simply treat tainted bitcoins as not existing, thus removing that annoyance too.

Re: Inputs.io hacked – 4100 BTC stolen

#183

Earlier quoted context omitted.

You know exactly what input transactions contains tainted coins, so you know the amount, and thus how many untainted coins there are.

But when you transfer BTC out, even if it's in the exact amount of the tainted coins transferred in, how do you decide whether the outgoing coins represent the tainted ones or the untainted ones? Say there's a 50 BTC untainted wallet, and tainted 1 BTC is transferred in, then 1 BTC is transferred out. How do you decide whether that outgoing 1 BTC was drawn on the tainted portion or the untainted portion of the accoun…

Always regards the last bitcoins as the tainted ones. Local wallets could simply treat tainted bitcoins as not existing, thus removing that annoyance too.

Re: Inputs.io hacked – 4100 BTC stolen

#184

These coins were stored on a VPS? On Linode? All it took to steal 1 million USD was to hack an email account ? Insanity.

BitCoin is security amateur hour. That's why the BitCoin protocol and client hasn't been attacked too much. It's just easier to hack some exchange.

Re: Inputs.io hacked – 4100 BTC stolen

#185
post #148

Earlier quoted context omitted.

I don't know, $1.1M is a lot of money. If someone stole a million dollars from my company, I don't know if I'd be rushing to reimburse it with personal funds (assuming I even could), however bad I felt for the users. That said, if I recall correctly, one case where the corporate veil can potentially be pierced in a lawsuit is negligence. IANAL, but maybe users would have a legitimate case against personal funds, assu…

Well, the site owner apparently promised to reimburse any deposit losses with his own funds back when he was trying to convince people to deposit money on the site: https://bitcointalk.org/index.php?topic=283756.msg3505423#ms...

Ah, that's a bit different then. Thanks.

Re: Inputs.io hacked – 4100 BTC stolen

#186
post #64

Earlier quoted context omitted.

[deleted]

Meh, he provided a bunch of useful and relevant info, and subtly (but not misleadingly) plugged his business. I don't mind.

I wish the [Deleted] thing didn't blend in so well with the post above. Always ends up confusing me for a second.

Re: Inputs.io hacked – 4100 BTC stolen

#188
post #159

Earlier quoted context omitted.

> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…

Serious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?

Programmers don't decide the UX. And any decent-sized bank will be pulled in different directions by:

1. The standard "enterprise problems": strategic partnerships dictating toolsets and so on.

2. The standard "big company problems": many business units acting as fiefdoms who will be arguing over how much real estate they need on customer-facing channels.

3. Tensions between customers who are scared of "money" and "online" and want everything locked down vs customers who want the latest whizz-bang everything.

4. Regulations.

5. Customers spanning a range from high-value rural farmers with vast sums of agribusiness who are stranded on dialup (yes, they exist), customers who do their banking on whatever their work PC is (XP and IE6 is still a thing - out biggest surge of the day is the 9 am rush when people log in from work to do their banking), through to customers who want the latest and greatest HTML5 webbery.

Saying, "fuck it we only support WebKit and high speed internet" is not really an option.

Re: Inputs.io hacked – 4100 BTC stolen

#189
post #173

Earlier quoted context omitted.

I suspect this because, every time there is competition between innovative features that are nice for users, and ensuring security/limiting exposure and attack surface, the latter concern wins with little discussion. What I mean is, if they implement a new whiz-bang feature, the best case is that people complain a bit less. But if their new feature opens up an attack vector or social engineering opportunity, they may…

I'm not asking for whizz-bang features, just a lack of the busy, overengineered sort we tend to see. Heck, First Direct is one of the better banks in this country, but their website popups deliberately hide browser chrome including the address bar , which is just obviously terrible for security. But that's something that must have been deliberately added.

I have had poo-flinging contests (in banking) with external "security experts" (i.e. grads with a 3 ring binder from accountancy firms) who think ripping out the chrome is a todo on the required security checklist.

Re: Inputs.io hacked – 4100 BTC stolen

#190
post #171

Earlier quoted context omitted.

Can't you just... like... not read them? On every visit to HN I click 3-4 links tops, but you don't see me complaining in the comments section of the other 26 :)

Yes I can, but if I do then the site will only get worse. http://lesswrong.com/lw/c1/wellkept_gardens_die_by_pacifism/

Interesting link, thank you!

But I don't see how it's relevant - this is a site about start-up news and Bitcoin is exactly where the opportunities for start-ups are. It's not like they're posting porn or something - probably the next PayPal will come from someone reading these links and comments here.

Although I admit that sometimes there are too many links about politics on HN, but you can say politics is also kind of relevant to the start-up world, especially when it concerns policy decisions about technology.

In conclusion, I'm yet to see an irrelevant link on HN. The algorithm works as advertised IMHO.

Post reply on HN