Earlier quoted context omitted.
The FDIC doesn't cover bank robberies. https://www.fdic.gov/consumers/consumer/information/fdiciorn...
Though I believe they've got another form of insurance for this.
Bitcoin exchange hacked via Rails exploit, funds stolen
31–40 of 279 posts
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#32Then worse, you have tons of internet criminals coming up with clever strategies to part people with their Bitcoin. Will these guys reimburse their users or end up giving an excuse and disappearing into the ether? Only time will tell.
That said, Bitcoin itself remains strong and probably one of technologies with the biggest potential in quite a long time. These issues will continue to occur and spawn drama for the foreseeable future. At some point the good Bitcoin news will drown out the bad Bitcoin business news. But that's not going to happen anytime soon. So let's get used to it.
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#33Earlier quoted context omitted.
In the US, at least, people still got famous for being bank robbers back then. The FDIC, which provides limited insurance for bank deposits, started their insurance on January 1, 1934. So, sophistication aside, it's an interesting question what happened to depositors after a bank robbery.
FDIC doesn't insure against robberies.
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#34I guess this is still the Wild Wild West era of Bitcoin; I'd wager plenty of banks got knocked off by bandits back in the day, too. What happened to a bank's customer's funds if it got robbed prior to 1933?
Banks don't keep all of their assets in cash in the safe. In its very simplest form, a bank takes money from depositors and pays a small "savings" rate. It then lends this money to borrowers at a higher rate. Every dollar in the safe is a dollar that isn't out earning interest, so the bank wants to only keep enough on hand to cover what customers will need for withdrawals. I met an ex bank robber once. He and his "ga…
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#35I guess this is still the Wild Wild West era of Bitcoin; I'd wager plenty of banks got knocked off by bandits back in the day, too. What happened to a bank's customer's funds if it got robbed prior to 1933?
Banks don't keep all of their assets in cash in the safe. In its very simplest form, a bank takes money from depositors and pays a small "savings" rate. It then lends this money to borrowers at a higher rate. Every dollar in the safe is a dollar that isn't out earning interest, so the bank wants to only keep enough on hand to cover what customers will need for withdrawals. I met an ex bank robber once. He and his "ga…
The nearly immortal protagonist often ends up being the banker in a small frontier towns. He routinely has to deal with mobs of people who attempt to "nationalize the bank" and are dumbfounded to discover that the bank does have all of the money in a safe.
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#36If it's that easy to steal, you're probably doing it wrong. The front-end server should never have direct access to the bitcoin RPC server, since the front-end is likely to be vulnerable. Instead, it should contact a robust back end server, which then talks to the RPC.
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#37Is there a Best Current Practice for all steps in BitCoin - for people wanting to buy or sell bitcoins; for people wanting to trade goods for bitcoin; for people wanting to run bitcoin financial services or exchanges?
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#38I guess this is still the Wild Wild West era of Bitcoin; I'd wager plenty of banks got knocked off by bandits back in the day, too. What happened to a bank's customer's funds if it got robbed prior to 1933?
A lot of banks get knocked off today http://www.fbi.gov/stats-services/publications/bank-crime-st...
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#39Well that's not really a surprise. Perhaps the "Rails generation" will gain some engineering, product selection and QA skills now. There's a big reason banks operate the way they do with the kit they do.
[1] Auto-Unmarshalling yaml in xml, seriously? Who wants yaml in xml?
[2] I'm sorry to single out spring here, but this is a nice example since it's the same kind of attack: Instatiation of an arbitrary class, in this case by modifying the class loader and loading the class from a remote server: http://support.springsource.com/security/cve-2010-1622
Re: Bitcoin exchange hacked via Rails exploit, funds stolen
#40If it's that easy to steal, you're probably doing it wrong. The front-end server should never have direct access to the bitcoin RPC server, since the front-end is likely to be vulnerable. Instead, it should contact a robust back end server, which then talks to the RPC.
Bitcoin bank developers commonly "do it wrong."