Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

31–40 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#31
post #8
post #6

Hmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers ta…

> customer service can access your account only if you read them your hardware token's code At the very least, I'd hope Linode implements two-factor authentication for their own logins. A customer-provided OTP would be great but you'd need a customer service reset tool for that when people forget, which would put you back where you started...

Not necessarily if the reset tool is manually driven and audited. The vulnerability we're worried about here is an automated attack against many customers of a single hosting provider.

There will always be ways to human-engineer your way into any single host. Having a hosting provider just increases the attack surface a little.

Re: Compromised Linode, thousands of BitCoins stolen

#32

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

Simplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it…

Pretty sure there is a default port that accepts connections as part of bitcoind, so you can just portscan for it.

Re: Compromised Linode, thousands of BitCoins stolen

#33
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

Are you sure? I think that you may be mistaken. The bar is just set higher in a "virtualized environment"...

"In a public cloud environment, additional controls must be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder data environment. More stringent preventive, detective, and corrective controls are required to offset the additional risk that a public cloud, or similar environment, could introduce to an entity’s CDE.

These challenges may make it impossible for some cloud-based services to operate in a PCI DSS compliant manner. Consequently, the burden for providing proof of PCI DSS compliance for a cloud-based service falls heavily on the cloud provider, and such proof should be accepted only based on rigorous evidence of adequate controls."

From: https://www.pcisecuritystandards.org/documents/Virtualizatio...

Amazon:

http://aws.amazon.com/security/

Re: Compromised Linode, thousands of BitCoins stolen

#34

Since my $1,000 worth of bitcoins dropped in value to $150 over a period of weeks, I've become significantly less interested in using it as a currency.

You were gullible and invested at the peak of the bubble at $30/BTC (now worth $5/BTC). Any bubble would have crushed you, eg the dotcom stock market frenzy. Your fault.

Bitcoin is up 400% over the last year (from $1 to $5/BTC), which has made it an excellent investment for other (smarter) investors not swayed by a bubble.

Re: Compromised Linode, thousands of BitCoins stolen

#35

i think bitcoin could use another layer of authentication to verify the person is indeed the owner of bitcoins.

One of the features of the next release of the bitcoin protocol is to allow things like multi-factor authentication (e.g. require a signature from the private key on your computer and your mobile phone before the bitcoins can be spent)

Re: Compromised Linode, thousands of BitCoins stolen

#36

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

Simplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it…

I'd be very surprised (and suspicious) if they were running any kind of diangostics over their customer's data without an explicit signed contract. The liability worry there alone is scary.

Re: Compromised Linode, thousands of BitCoins stolen

#37

Earlier quoted context omitted.

Regarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."

I'm a Linode fanboy, but we need maximum transparency on what occurred and what's being done. What support interface? How compromised? Who's credentials, etc.

Me too, I've been recommending them a lot and really like their service. I just checked our 2 boxes uptimes just in case.

Re: Compromised Linode, thousands of BitCoins stolen

#38
post #9

Since my $1,000 worth of bitcoins dropped in value to $150 over a period of weeks, I've become significantly less interested in using it as a currency.

You mean less interested in using it as a way to profit from speculation. As a currency it is not as critical that the value only goes up. A person or merchant receiving bitcoins can easily convert them out to USDs and still lose less in fees than the same transaction would cost compared to accepting a credit card or debit card payment. For example, BTC -> USD at most exchanges is around half a percent.

It sounds like Bitcoin is doing much better in the "Medium of Exchange" side of the money coin than the "Store of Value" side.

Re: Compromised Linode, thousands of BitCoins stolen

#39
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

I'd argue this isn't about bitcoins. A (popular) VPS provider, according to that article, had a security problem that allowed some idividuals to access the VPS management interface for any machine they cared for.

They could've defaced your site in high traffic times. They could've logged in and delete your projects on the VPS. Depending on your setup (they had root) they could've searched for your backups. They could've read your mail, if that machine is your infrastructure service - and continue from there (password reset, amazon, buy expensive stuff. password reset, twitter, damage your reputation).

In this case the bits modified were part of a virtual currency and had a more or less clear value. I'd say there could've been worse results of that security hole though and 'don't put anything on a vps' is not a solution.

Re: Compromised Linode, thousands of BitCoins stolen

#40
post #3

So, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being no…

Reading the ticket slush posted it shows no password change logs, if linode was compromised either the whole infrastructure was compromised (unlikely) or a rouge admin or a admin comprimised account accessed the vps and stole the $, as per the bitcoin forums. Total stolen is roughly $16,000 USD
Post reply on HN