Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

201–210 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#201
post #71

Imagine if you were an employee at this company with access to these keys. They're so disorganized, you could have stolen tens or millions of dollars in crypto and even right now after auditors have gone through everything, still no one would know you had done it. That anyone had done it. How ethical are you really? Could you actually resist that temptation? Do you think all your co-workers could too? What a fiasco.

That's most probably what occurred during the "hack" that FTX experienced shortly after entering bankruptcy.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#202
post #74

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

At least with my bank, and I think most banks here in Sweden, I need to approve people before they can make direct debits.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#203
post #149

Earlier quoted context omitted.

Do you mean that if I know a German bank account number I can just withdraw money for me? Be right back, asking some German friends for their bank account numbers. Jokes aside, you're probably wrong. There's NO way I can just pull money from their bank account just by knowing their bank account number.

As a person you can only send them money. As a business you can initiate a direct debit which withdraws money. However you are attesting that they signed a direct debit agreement with you and provided their account number and agreed on the amount to pay. This is the same as a credit card - you can charge any card with just the number and a couple of basic details, however if there's a complaint "I found these CC deta…

That is usually not how credit cards work anymore. Sure, you can try to charge any card but if it is issued by a European bank it will very likely be denied and you will be asked to do a Strong Customer Authentication.

Same applies to SEPA direct debit. Here in Sweden most (all?) banks requires the customer to sign digitally before any direct debit mandate is created.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#204
post #196

Earlier quoted context omitted.

I don't believe that. Let's say I have account number 1234 and my name is John Doe. You're telling me that, no strings attached, no repercussion, Mike Hacker can set up a large recurring payment from my account, without my approval? I'd need solid proof of how that would work.

Yes. That is a thing that can be done, here’s Stripe’s documentation on how to set up a Direct Debit mandate: https://stripe.com/docs/payments/payment-methods/bacs-debit?... The thing that’s being missed here is that direct debits can be disputed in the same way a credit card payment can, and by default the customer wins. Their money will be refunded immediately by the bank, who will then go after you to get it back.

Yes and no. Swedish banks for example will just deny direct debits unless the customer has explicitly agreed to let their accounts be charged. So direct debit works differently per country and per bank.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#205

Earlier quoted context omitted.

This is mostly unique to the US. Where I'm from, we don't use our SSNs as passwords , bank checks and direct debit are simply not a thing, and credit cards have two-factor authentication for online purchases.

2FA for online purchases is, at least in Germany, is not always a thing. I don't know how it's decided, but I'd say only about 50% -70% of online purchases trigger the 2fa of my bank.

It is virtually always a thing here in Sweden. The only exception I have encountered the last like 5 years is Paypal.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#206

Earlier quoted context omitted.

> I wouldn't want the government to control jeans manufacturing Of course you do. You want asbestos to be banned in the clothes you buy. You want labelling of material to not be lies. You want child labour banned. You want slavery banned. You want trademark protection. You want the factory to not dump toxic waste in the nearby river. And you say "well, of course I want that , but not... I dunno..." and give some hypo…

I literally said the laws should apply to all kinds of property equally - yet you think I "want to get rid of all financial regulation"? I hope you enjoyed building that strawman and then tearing it down

I mean, you did say you wouldn’t want the government regulating jeans manufacturing.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#207

Earlier quoted context omitted.

> I wouldn't want the government to control jeans manufacturing Of course you do. You want asbestos to be banned in the clothes you buy. You want labelling of material to not be lies. You want child labour banned. You want slavery banned. You want trademark protection. You want the factory to not dump toxic waste in the nearby river. And you say "well, of course I want that , but not... I dunno..." and give some hypo…

I literally said the laws should apply to all kinds of property equally - yet you think I "want to get rid of all financial regulation"? I hope you enjoyed building that strawman and then tearing it down

So what did you mean by saying jeans manufacturing should not be regulated, and only (?) jeans (and other goods) ownership should be regulated?

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#208
post #180

Earlier quoted context omitted.

> People who want financial system free of government control and people who want government to prosecute for crypto crimes are mostly different people. Are they? I'm not so sure. Could you elaborate? The whole selling point of cryptocurrencies seems to be to start from scratch, without those pesky KYC/AML and tax laws. Traditional banking is not a natural law. It's man-made. The benefits cryptocurrencies have over t…

> Could you elaborate? The whole selling point of cryptocurrencies seems to be to start from scratch, without those pesky KYC/AML and tax laws. > The set of people who like cryptocurrency is not small. There are two sets of people who like cryptocurrency. First ones like crypto because of better yields than traditional bank accounts or investments. But they want to live in a miracle pinky unicorn world where they can…

I see what you mean. I guess in my mind "people who like cryptocurrency" like it for reasons other than its bigger-fool value proposition.

Yes, I agree that there are many many people out there who don't care one bit for e.g. bitcoin itself, but would be perfectly happy buying a regulated ETF that tracked the price of bitcoin.

I implicitly did not count these people as "liking cryptocurrencies". What they like is money, in particular fiat money.

> These people don't care much about yields, they cannot transfer money via traditional ways for various reasons, and they want governments to stay away from crypto as long as possible.

These are the people I was referring to, who want "no regulation" when they want to do something fine, but "full regulation" if and when they get screwed.

They want insurance only when things go poorly, and see insurance as a waste of money the days when they don't have accidents.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#209
post #202
post #74

Earlier quoted context omitted.

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelanc…

At least with my bank, and I think most banks here in Sweden, I need to approve people before they can make direct debits.

How do you approve a payee with your bank? At the time you grant them permission to debit your account, or at the time of the first payment?

There is no technical channel for the former within the SEPA Direct Debit framework (i.e. the first time the payer's bank learns about a mandate is with the first direct debit), so I'm wondering if this is a different/domestic direct debit scheme.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#210

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

I can't echo the general point here strongly enough.

It's tempting to make this all "about crypto."

But crypto's just a technology. Maybe it ends up being a thing, maybe it doesn't. The fundamentals remain, and one of the present fundamentals is that (along with good old fashioned grift) stupid and terrible cybersec practices run rampant still.

Post reply on HN