Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

41–50 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#42
post #34

Since my $1,000 worth of bitcoins dropped in value to $150 over a period of weeks, I've become significantly less interested in using it as a currency.

You were gullible and invested at the peak of the bubble at $30/BTC (now worth $5/BTC). Any bubble would have crushed you, eg the dotcom stock market frenzy. Your fault. Bitcoin is up 400% over the last year (from $1 to $5/BTC), which has made it an excellent investment for other (smarter) investors not swayed by a bubble.

Has anyone solved the liquidity mess? Say I want to buy a car and have to unload $20k of bitcoins. Can I do that? With a latency of less than 24 hours? Without getting my PayPal account frozen?

Re: Compromised Linode, thousands of BitCoins stolen

#44

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

Simplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it…

Sorry, there is just no way that this is the case. Please don't throw such a serious allegation out there without any evidence. To even suggest that this is technically possible for an employee to do is a serious allegation, let alone suggesting that someone did it maliciously. This spreads all kinds of FUD.

I'll happily eat my words if that turns out to be what happened, but it is definitely not the simplest answer.

Re: Compromised Linode, thousands of BitCoins stolen

#46
post #36

Earlier quoted context omitted.

Simplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it…

I'd be very surprised (and suspicious) if they were running any kind of diangostics over their customer's data without an explicit signed contract. The liability worry there alone is scary.

you do realize that in this theory, the same person then went and stole thousands of dollars in bitcoins, right? I don't think they were worrying about liability...

Re: Compromised Linode, thousands of BitCoins stolen

#47
post #42
post #34

Earlier quoted context omitted.

You were gullible and invested at the peak of the bubble at $30/BTC (now worth $5/BTC). Any bubble would have crushed you, eg the dotcom stock market frenzy. Your fault. Bitcoin is up 400% over the last year (from $1 to $5/BTC), which has made it an excellent investment for other (smarter) investors not swayed by a bubble.

Has anyone solved the liquidity mess? Say I want to buy a car and have to unload $20k of bitcoins. Can I do that? With a latency of less than 24 hours? Without getting my PayPal account frozen?

What does PayPal have to do with Bitcoins? Trying to buy or sell Bitcoins with PayPal is foolish.

Re: Compromised Linode, thousands of BitCoins stolen

#48
post #3

So, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being no…

Regarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."

Where are you reading this? The status page and the blog have no mention of the incident.

Re: Compromised Linode, thousands of BitCoins stolen

#50
post #3

So, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being no…

Regarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."

That update had already been released when I made my original comment (hence why I said "a customer service interface was compromised via stolen credentials"). It doesn't reveal how the credentials were compromised, nor how the attacker managed to use them to log in.
Post reply on HN