Live data from Hacker News

Bitcoin payment processor BIPS compromised, 1295 BTC stolen

bitcointalk.org

21–30 of 70 posts

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#21
post #17

Earlier quoted context omitted.

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…

Appearing to be incompetent in some circumstances may be a pretty good cover. If you are a security guard at an art museum, and buddies with some art thieves, then it might be in your best interest to get yourself a reputation for sleeping on the job.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#22
post #17

Earlier quoted context omitted.

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

I don't think they're suggesting that, more just gross incompetence on the part of the developer, and a little bit of liberty about how "secure" the systems they have created actually are. It's a lot like inputs.io, a web wallet compromised because the developer used Linode to protect millions of dollars. The developer of that particular service paid back about the half the funds then disappeared. > BIPS was built by…

So if he gotten over 50% of stolen funds as his `fee` he could end up ahead? But yeah, given that he paid back half of stolen funds this angle does look weak.

Is it possible to launder stolen bitcoins on Chinese exchange?

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#23

Earlier quoted context omitted.

If you are new to bitcoin-related sites, you might find this story close to legitimate. But anyone that reads the article will see there is this "basic" flaw mentioning that DDoS attacks gave access to the server. If you read past (paid) articles about this very same service, you will see claims about how secure the system is, and how expert everyone that developed it is. The same was claimed by inputs.io, I'm sure y…

Reading between the lines you are suggesting that this vector of attack had to come internally from BIPS? Given how much bitcoin price soared it is not unreasonable to question whether one of the engineers there had his price named.

Just to clarify, yes, I meant exactly that (and that is why I love this place, people actually get it).

And the inputs.io guy is not even close to paying half to what was "stolen". The inputs.io guy was also running coinlender and other services, which are all gone -- including himself.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#25
post #4

That technical explanation sounds almost like word salad. How did a DDoS hit your SAN in the first place and how did your SAN blowing up allow a compromise?

I've heard of DDoS attacks used to divert the admins attention while a real attack is occurring. Also I know packet flooding can cause some network hardware to switch into a lower security mode in an attempt to handle the load. I'm not sure if either of those apply in this case, though. I definitely am not a network or security expert.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#26
post #4

That technical explanation sounds almost like word salad. How did a DDoS hit your SAN in the first place and how did your SAN blowing up allow a compromise?

I've heard of DDoS attacks used to divert the admins attention while a real attack is occurring. Also I know packet flooding can cause some network hardware to switch into a lower security mode in an attempt to handle the load. I'm not sure if either of those apply in this case, though. I definitely am not a network or security expert.

Right, they're used as distractions fairly often. The rest of the explanation makes no sense though; that is, I don't see how the DDoS would then "make the system vulnerable" to Bitcoin theft. Unless it was something like where the attackers already had access, but most everything was kept in cold storage and they wanted to force them to move a lot of BTC into their live wallets.

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#27
post #13
post #12

Earlier quoted context omitted.

That seems infinitely better than catastrophic loss of customer funds.

There's no difference as if you shut your site down everytime someone DDoS then you'll have no customers anyway.

mmm i think at this point in the Bitcoin community, stating that practice on your homepage would actually get you more customers.

"In the event of an obvious attack, we disconnect from the network and begin diagnostics after __ minutes of sustained activity."

Re: Bitcoin payment processor BIPS compromised, 1295 BTC stolen

#29
post #3

Address of the stolen funds: https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj...

Since every bitcoin transaction is in public, why don't we build a public blacklist for these addresses with stolen coins (and all addresses these bitcoins further transferred to)? such that the hackers cannot get too much from their actions
Post reply on HN