Live data from Hacker News

Coinbase: Responding to Firefox 0-days in the wild

blog.coinbase.com

41–50 of 97 posts

Re: Coinbase: Responding to Firefox 0-days in the wild

#41
post #17

Those attacks would not work if they did not enable JavaScript on every website by default.

Those attacks would not work if everyone stopped using computers.

its almost like the NSA designed all programming languages to insure that it would be impossible to make a perfect program

Re: Coinbase: Responding to Firefox 0-days in the wild

#42

Earlier quoted context omitted.

Yeah, they could have moved processes before execing the shell. Detecting "Firefox + Shell" is quite easy and standard, even in existing SIEMs. Detecting "arbitrary program + shell" is at least moderately more difficult. It's the attacker's dilemma though. They only need to trip one alarm to trigger IR.

The biggest fail here was that 32 bit program warning, which probably alerted the employee. Notice that they didn't actually have an alert for Firefox+Shell, they detected that later by inspecting the audit logs.

> We detected the attacker at this stage, based on a number of behaviors (e.g. Firefox shouldn’t spawn a shell).

They explicitly state it was one of the behaviors they detected as suspicious.

Re: Coinbase: Responding to Firefox 0-days in the wild

#43

Remember, not your keys, not your bitcoin. Stay off coinbase.

For the average person, using Coinbase with 2FA is going to be better than managing their own private key. Even if their hot storage was penetrated, which is unlikely, they have insurance and other means of making sure that customer deposits are unaffected.

Re: Coinbase: Responding to Firefox 0-days in the wild

#44
post #5
post #4

This is among the critical differences between MtGox and Coinbase.

"We're not run by idiots"?

That doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all.

A similar event actually happened with another asset they offer - Ethereum Classic.

https://cointelegraph.com/news/ethereum-classic-51-attack-th...

Re: Coinbase: Responding to Firefox 0-days in the wild

#45

Remember, not your keys, not your bitcoin. Stay off coinbase.

> A criminal gang operating in India kidnapped and tortured cryptocurrency traders in recent weeks before demanding 80 bitcoins as ransom, police say. Three men had been held captive for 15 days inside a high-rise building and were beaten or tortured... Not even their family members were aware of the abduction. The victims had lost all hope because they had no access to anyone https://www.newsweek.com/cryptocurrency-…

Im confused why this is a response to the parent.

Re: Coinbase: Responding to Firefox 0-days in the wild

#46
post #44
post #5

Earlier quoted context omitted.

"We're not run by idiots"?

That doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all. A similar event actually happened with another asset they offer - Ethereum Classic. https://cointelegrap…

Huh, I would've thought that since people will pay over 300 usd for one Bitcoin Cash coin (according to 3 web sites I just sampled), there would always be plenty of miners competing for them.

Re: Coinbase: Responding to Firefox 0-days in the wild

#47
post #9

Does it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?

One of the benefits to ex. firejail is precisely that a Firefox exploit does not compromise ex. ~/.ssh

Re: Coinbase: Responding to Firefox 0-days in the wild

#48

This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...

> This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...

Why would that be the case when it is not illegal to sell exploits?

Re: Coinbase: Responding to Firefox 0-days in the wild

#50
post #44

Earlier quoted context omitted.

That doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all. A similar event actually happened with another asset they offer - Ethereum Classic. https://cointelegrap…

Huh, I would've thought that since people will pay over 300 usd for one Bitcoin Cash coin (according to 3 web sites I just sampled), there would always be plenty of miners competing for them.

BCH is and will be mined proportionately to its price; since its price is far lower than BTC it also has far lower security.
Post reply on HN