Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

31–40 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#32
post #20

Earlier quoted context omitted.

I mean FTX had over 300 million dollars moved out of company funds, without company authorization, by parties unknown, and with insufficient monitoring to even know it happened until third parties let them know. So kind of depends on your definition of hacked, I guess.

Sounds like really nice plausible deniability for whomever came up with such a blatant wrong way of storing secrets/value

Nov. 11 — Friday: SBF resigns, FTX goes bankrupt

Nov. 12 — Saturday: FTX hacked for most of its remaining crypto

Y'all be the judge.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#33
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

> That crosses the line and goes deep into "willful negligence" territory, in my view. A lot of people are making the assumption that gross incompetence reigned supreme with FTX, and that does seem like the likeliest explanation, but another potential explanation is deeply devious criminal activity. They could have preplanned this behavior. If they were ever caught doing anything really bad, they had "plausible denia…

While I agree with most of this, keeping a small number of things secure for yourself is far easier than doing it for thousands/millions of accounts in an automated way. That's true of almost everything in software. For instance, just because I know how to use a password manager doesn't mean it's easy to get my whole family using a password manager. They were clearly dysfunctional and there may be some of this at play but Occam's Razor says it was just easier to store less securely.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#34

Earlier quoted context omitted.

> That crosses the line and goes deep into "willful negligence" territory, in my view. Er, that's the thing that pushed you over the line? Not all the fraud and crime?

i was okay with the fraud and the crime. it was the hierarchical polyamory that pushed me over the line.

> the hierarchical polyamory that pushed me over the line.

Really. At that point one should have the decency to declare your outfit a religion, and stop paying taxes.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#35

Earlier quoted context omitted.

> That crosses the line and goes deep into "willful negligence" territory, in my view. Er, that's the thing that pushed you over the line? Not all the fraud and crime?

i was okay with the fraud and the crime. it was the hierarchical polyamory that pushed me over the line.

That was just ironic I am sure

Just like the “very easy math” that they all touted that was all that was needed to manage the entire thing

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#36

While this is flatout insane, it does not speak toward crypto's security directly. If you personally decide that you want a company to hold your crypto that's your decision and a poor one at that. You have the ability to create your own wallet and hold your funds in it securely. Some exchanges like Coinbase even have wallet apps so the transition is super easy to make.

And then there are the M of N keys schemes where one can have multiple parties holding the keys. Example: Three keys, any two can sign transactions. You have one somewhere safe(in a safe) and one on your hardware wallet. And the bank has one for your account. The bank can't do anything without you also signing the transaction. You can always sign transactions on your own with both your keys.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#37
It wasn't/isn't just them. It wasn't a massive secret either.

https://news.ycombinator.com/item?id=32077583

The test of all these security exploits are in the exploiting. In practice, you can run wild and nothing will happen. My HN password was 000000 for years.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#38
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

> Wait, what? ... WTF? ... Unbelievable.

You sound shocked! shocked! to find gross incompetence going on in a place where the accounting system is an Excel spreadsheet manually maintained by the CEO himself, with entries like "Hidden, poorly internally labled fiat@ account" (sic) purportedly worth $8 billion.

Private keys in plaintext in the shared Google Drive that the entire company has access to? That is the least surprising news I've heard today.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#40
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

> That crosses the line and goes deep into "willful negligence" territory, in my view. Er, that's the thing that pushed you over the line? Not all the fraud and crime?

Both are bad. Crime is bad, but this is an argument for making software engineering more like a medical doctor's guild. Some things simply should not be done. There is an expectation of competence for some things like finance and medicine.
Post reply on HN