Live data from Hacker News

Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

coindesk.com

31–40 of 63 posts

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#31
post #19

Ugh. There are much better solutions than keeping user funds in the hot wallet (fully cold storage with manual withdrawals, multi-signature wallets), but many "reputable" businesses STILL uses them. I don't understand why. If you want to store your customers funds online, do it the right way, or don't do it at all.

You cannot automate a cold-wallet scheme. Any automated website or tool will require a "hot wallet" of some kind. The more funds in the hot wallet, the longer the website / BTC Bank can go automatically. Customers like having funds available to them immediately... among other things.

> You cannot automate a cold-wallet scheme.

Yes, you can. You can have the hot wallet only deal with multi-signature outputs, and have these approved by separately locked down servers running behind TOR, for example, using out-of-band mechanisms for approving transactions.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#32
post #30

Earlier quoted context omitted.

You cannot automate a cold-wallet scheme. Any automated website or tool will require a "hot wallet" of some kind. The more funds in the hot wallet, the longer the website / BTC Bank can go automatically. Customers like having funds available to them immediately... among other things.

> You cannot automate a cold-wallet scheme. That's why I said that it would be manual. Actually, it could be semi-automatic - a script could generate all relevant transactions, and a human operator could simply confirm them few times a day by signing the transaction with his password protected private key. > Customers like having funds available to them immediately... among other things. Either security or convenienc…

Any wallet that has been exposed to a computer connected to the Internet, or is sitting on one, is a "hot wallet".

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#33
post #9
post #7

Earlier quoted context omitted.

>Do people still think the irrevocability of BTC transactions is a good thing? Yes. Third parties will provide escrow/insurance services if there is demand for them. Transactions been irreversible "by default" is a core benefit of bitcoin and merchants may preffer that over chargebacks at 18€.

I've heard that this type of insurance is expensive and a large part of banks' transaction fees. I can only imagine how expensive an insurance service like that for Bitcoin would be.

However unlike the existing system there will be a transparent, competitive market for such insurance mechanisms, and they will be available to consumers/businesses directly.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#34
post #30

Earlier quoted context omitted.

You cannot automate a cold-wallet scheme. Any automated website or tool will require a "hot wallet" of some kind. The more funds in the hot wallet, the longer the website / BTC Bank can go automatically. Customers like having funds available to them immediately... among other things.

> You cannot automate a cold-wallet scheme. That's why I said that it would be manual. Actually, it could be semi-automatic - a script could generate all relevant transactions, and a human operator could simply confirm them few times a day by signing the transaction with his password protected private key. > Customers like having funds available to them immediately... among other things. Either security or convenienc…

> and a human operator could simply confirm them few times a day by signing the transaction with his password protected private key.

It's a payment system. This would be unacceptable.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#36
I'm not a bitcoin expert, so I may end up off base, but...

The US government seemed surprisingly warm to bitcoin in the senate hearing. I suspect that if governments end up getting involved in bitcoin, each merchant will require some form of ID for each wallet that they interact with. This will mean that tracking down crimes like this will be fairly easy, since there's a record of each transaction. Trace down the chain, find the people involved, and if an anonymous wallet shows up, you investigate the people that it transferred to or from.

Sure, it erodes privacy, but bitcoin has the potential to make things much easier for law enforcement (and anyone else interested in money transfers) by causing registration of endpoints, giving very strong leads to investigators.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#37
post #31

Earlier quoted context omitted.

You cannot automate a cold-wallet scheme. Any automated website or tool will require a "hot wallet" of some kind. The more funds in the hot wallet, the longer the website / BTC Bank can go automatically. Customers like having funds available to them immediately... among other things.

> You cannot automate a cold-wallet scheme. Yes, you can. You can have the hot wallet only deal with multi-signature outputs, and have these approved by separately locked down servers running behind TOR, for example, using out-of-band mechanisms for approving transactions.

You can do anything if you allow massive handwaving. ("out-of-band mechanisms for approving transactions")

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#38
post #31

Earlier quoted context omitted.

You cannot automate a cold-wallet scheme. Any automated website or tool will require a "hot wallet" of some kind. The more funds in the hot wallet, the longer the website / BTC Bank can go automatically. Customers like having funds available to them immediately... among other things.

> You cannot automate a cold-wallet scheme. Yes, you can. You can have the hot wallet only deal with multi-signature outputs, and have these approved by separately locked down servers running behind TOR, for example, using out-of-band mechanisms for approving transactions.

>You can have the hot wallet only deal with multi-signature outputs

Then you don't have a cold-wallet scheme. You have a hot wallet scheme.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#39
If you are new to bitcoin-related sites, you might find this story legitimate. But anyone that reads the article will see there is a basic flaw: DDoS attacks do not give access to the server, they just make the service inaccessible. If you read past (paid) articles about this very same service, you will see claims about how secure the system is, and how expert everyone that developed it is. The same was claimed by inputs.io, I'm sure you have read about that story earlier.

The thing is, if you want to use bitcoin, you cannot trust third parties to hold your coins for you. If you want to support bitcoin in your business, you cannot trust other sites to handle the payment for you. Yes, it is not convenient. But you have everything available to handle this yourself and, yes, you will need someone competent to do that for you if you are not into it. Bitcoin is not meant for the average user or the unaware merchant and it might never be, people need to start accepting this fact.

Re: Bitcoin Payment Processor BIPS Attacked, Over $1M Stolen

#40
post #35
post #13

Can we get a break from all these Bitcoin posts please?

Why did you click on it? Just ignore or downvote next time. Bitcoin is a hot topic these days, tons of people are interested in what's going on.

This isn't reddit. There's no downvote on stories for (most) users on HN.
Post reply on HN