Live data from Hacker News

The Looting of ShapeShift

news.bitcoin.com

51–60 of 95 posts

Re: The Looting of ShapeShift

#51
post #46

"We had changed almost everything, but hadn’t scrapped our personal computers used while Bob had been part of the team. Would that have been the paranoid thing to do? Yes." At my humble and refreshingly drama-free place of work we have standard client images. Anything weird and the techies re-image the client. Assuming 'Bob' wasn't in charge of the images, would such a procedure have sorted the rdp?

Maybe. The larger question was why did Bob have root access to people's individual laptops? He could have done a "snowden", grabbed their SSH keys including passphrases. That would have been much harder to detect.

That attack would have been prevented by their immediate SSH key rotation after the initial attack.

Re: The Looting of ShapeShift

#52

Earlier quoted context omitted.

There are few positions that merit a hiring background check more than ones directly involving the financial transactions of a company. Even if it costs a lot of money, it is absolutely money well spent.

Background checks definitely do not cost a lot of money. I think it's in the $15 range.

Yeah, $15 in FIAT MONEY!!!!!!

Re: The Looting of ShapeShift

#53

Man, calling a social security number a "social serfdom number" is really dumb and off putting. So is the continual reference to 'fiat money' constantly. I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.

Would you call a communist a hypocrite for buying food at a grocery store?

Nope, but some people would!

https://twitter.com/edroso/status/721760775530876928

Re: The Looting of ShapeShift

#54
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

Step one is to properly vetting the person in charge of all your security.

Re: The Looting of ShapeShift

#55

Earlier quoted context omitted.

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…

It's not just hard to do, it's impossible. For a cloud provider anyway. Given that your software has to be capable of executing Bitcoin transactions itself, and the VM manager sits at a higher level and controls allocation and access to your VM's memory (to isolate it from other VMs), you are at the very least trusting that (1) when your cloud provider says they are using VMware or whatever standard software they aren't lying, and (2) that VMware itself is securely designed to limit its own access (and access of its own operators) to the underlying VMs.

If you don't want to trust your hosting provider with anything, you have to own the hardware.

Re: The Looting of ShapeShift

#56

Earlier quoted context omitted.

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…

Encryption won't protect you - the cloud provider has access to executables (in ram and perhaps on disc), your keys (ram and disc) and the data both pre and post encryption (in ram).

Because they control the hypervisor, they control everything. That means they have as much access and authority as the code that you are running on their servers have. So the only way to protect yourself from them is to limit what your servers (deployed on their cloud) can actually do.

So for instance you could have a secure backend server on a dedicated host in a trusted environment, with the cloud servers using an API to the backend server. If the API is suitably secure then the cloud servers could be compromised without allowing them to directly issue invalid commands in the same way the backend server could. Then you could use the cloud to scale out your web frontend without compromising yourself.

The same is true of hardware on the dedicated host (such as the "Trusted Computing" Module) that you do not control. If that (or the BIOS) gets compromised you might not even know that your host is no longer secure.

Re: The Looting of ShapeShift

#57

Earlier quoted context omitted.

The article seemed pretty open about major mistakes that ShapeShift made and lessons learned. It's a good postmortem to learn from, and far more open than most would have posted.

One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…

IMHO if you're doing anything financial and don't own the bare metal hardware that the hypervisor runs on and 100% control physical access to it, and run your own network gear (right up to your border with transit providers), you're doing something fundamentally wrong.

Re: The Looting of ShapeShift

#58
post #45
post #28

Earlier quoted context omitted.

http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...

While I think both of these are great, it still doesn't explain calling it "social serfdom number".

it's a blunt dog whistle for "hey libertarian gold hoarders we are your sort of people"

Re: The Looting of ShapeShift

#59
post #45
post #28

Earlier quoted context omitted.

http://www.theatlantic.com/politics/archive/2014/04/nlpd-non...

While I think both of these are great, it still doesn't explain calling it "social serfdom number".

Erik Voorhees is like that.

He was the first to [nominally] move a bitcoin business out of New York when the bitlicense was enacted.

Post reply on HN