Live data from Hacker News

The Looting of ShapeShift

news.bitcoin.com

21–30 of 95 posts

Re: The Looting of ShapeShift

#21
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

> Are there any best practices guides on this?

I'm not aware of any, but we did have quite a lot of procedures meant to mitigate this sort of things when I worked in banking. For one, none of the developers had any sort of access to production machines.

Re: The Looting of ShapeShift

#22

We learn some more things. Bob has prior police records in Florida, where he’s from. So they didn't even do a background check before hiring "Bob"? For a position where he would have access to systems that handled financial data? That's just grossly incompetent, in my book. I've worked for 5-man startups and Fortune 500 companies. In every case, the offer letter has stated that the offer is conditional on the success…

They don't do the background check.

They do- one company found a warrant on me that I didn't know I had for an unpaid traffic ticket.

Re: The Looting of ShapeShift

#23

Man, calling a social security number a "social serfdom number" is really dumb and off putting. So is the continual reference to 'fiat money' constantly. I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.

You might appreciate

http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...

Re: The Looting of ShapeShift

#24
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

I am not sure why those who essentially believe in utopia through an organized "war of all against all" wouldn't expect that anyone in position of trust wouldn't try to rip them off as much as possible.

"Damn you, you've betrayed our trust and prevented us from building a world where we didn't have to trust people..."

Re: The Looting of ShapeShift

#25
post #18

Earlier quoted context omitted.

Are you suggesting that the criminal should not be blamed for his criminal actions or the losses that he knowingly and willingly incurred?

Not quite. I suggest that a CEO should assume his responsibilities. He is quick to trash Bob[1] several times, but I see assumption of any responsibility at all. [1] Despite our note to all employees to come into the office urgently, Bob, our head IT guy, the one responsible for security and infrastructure, arrives at 11:30am. Soon after, Bob decides it’s time for his lunch break, and we don’t see him for an hour, du…

It's the difference between heroic responsibility and actual causality.

"Of course it's my fault. There's no-one else here who could possibly be responsible for anything".

The whole subtext of this was "Here's how I fucked up in leading this company", but then the actual text is causality. It is his responsibility to make sure employees are trustworth? Yes. Is he the cause of employees abusing trust? No.

He then also determined that his responsibility was to let people know what had happened, so that's what he did. He told us the things they used to figure out what happened in order to attempt (and fail, and then attempt again...) to prevent it from recurring.

Re: The Looting of ShapeShift

#26

Earlier quoted context omitted.

That's sort of boilerplate though, isn't it? They reserve the right to do all sorts of terrible shit, but because most of that shit costs money they don't actually do it.

There are few positions that merit a hiring background check more than ones directly involving the financial transactions of a company. Even if it costs a lot of money, it is absolutely money well spent.

Background checks definitely do not cost a lot of money. I think it's in the $15 range.

Re: The Looting of ShapeShift

#28

Man, calling a social security number a "social serfdom number" is really dumb and off putting. So is the continual reference to 'fiat money' constantly. I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.

You might appreciate http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...

http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...

Re: The Looting of ShapeShift

#29
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

Well the traditional banks have been dealing with exactly this kind of threat for a long time.

There's a load of practices that are designed to stop this kind of problem in that world.

Things like :-

- Enforced holidays. Frauds are hard to maintain when you're not there to keep cooking the books. - Audit reviews. an independant function with the ability and authority to review key processes - split authority. Key actions need multiple people to complete (statistically fraud incidence drops a lot when you need multiple people involved) - Strong background checking. When I worked at a bank they went back 10 years of employment history and required accounting for any gaps. + credit checking + criminal record checking etc.

It's all possible, just quite expensive...

Re: The Looting of ShapeShift

#30

Man, calling a social security number a "social serfdom number" is really dumb and off putting. So is the continual reference to 'fiat money' constantly. I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.

You might appreciate http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...

I was thinking more along these lines: http://www.theatlantic.com/politics/archive/2014/04/dont-swe...
Post reply on HN