Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

61–70 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#61
post #54

> Although passwords are stored using SHA1 with a salt, Where's the bcrypt/scrypt/whatever police in this comments thread?

I already asked in the comments of the original article how many rounds of sha1 are used. SHA-1 still isn't the best, since it yields to FPGA attacks, but a single round can brute-force all 8 character passwords in less than 2 days on a GPU. My guess is that 10k rounds of sha-1 would probably not be feasible for non-dictionary attacks without specialized hardware.

The article mentions salted SHA-1, which is much more resistant to attack.

Obviously, more rounds and unique salts per user would yield better results, regardless of the hashing scheme employed.

Re: Compromised Linode, thousands of BitCoins stolen

#62

Earlier quoted context omitted.

Regarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."

Where are you reading this? The status page and the blog have no mention of the incident.

It's from his e-mail conversation with Linode support: http://pastebin.com/UW7iT5fj

Re: Compromised Linode, thousands of BitCoins stolen

#64
post #42
post #34

Earlier quoted context omitted.

You were gullible and invested at the peak of the bubble at $30/BTC (now worth $5/BTC). Any bubble would have crushed you, eg the dotcom stock market frenzy. Your fault. Bitcoin is up 400% over the last year (from $1 to $5/BTC), which has made it an excellent investment for other (smarter) investors not swayed by a bubble.

Has anyone solved the liquidity mess? Say I want to buy a car and have to unload $20k of bitcoins. Can I do that? With a latency of less than 24 hours? Without getting my PayPal account frozen?

Yes you can, but not in 24h. (Hopefully buying a $20k car is not an impulse buy you make in a day, ahem...)

Sell the BTC on MtGox and withdraw the USD via Dwolla directly to your bank account. No need to use Paypal!

MtGox's withdrawal limit can be raised to $10k per day if you provide a notarized government ID copy (IIRC). Dwolla's limit is $5k per transfer with as many txfer per day. So it would take 2 days for completing the withdrawal, plus a few days for your bank to actually post the transaction (thank the legacy financial system for these unexplainable delays).

Of course the very best way to do it is to actually buy a car in bitcoins... see the Bitcoin Market subforum and find a seller. I remember last year someone was happy to announce he was the first person ever to buy a used car with bitcoins.

Re: Compromised Linode, thousands of BitCoins stolen

#65
post #2

Forum thread regarding this: https://bitcointalk.org/index.php?topic=66916.40;all

The comments calling for 'tainting' of stolen bitcoins and blocking their exchange will be the end of bitcoin. The anonymity of bitcoin is only due to general laziness. What happens when the market figures that out? Bitcoin's byzantine agreement is novel, but its crypto is crap.

Re: Compromised Linode, thousands of BitCoins stolen

#66

Earlier quoted context omitted.

But all that regulation is evil and it's the freedom of bitcoin that gives it the power* *for hackers to get away with the entertaining virtual train robberies we've seen in the last year

Show me your wallet with a good amount of cash and leave the room for a while. Afterwards, let's talk about your comparison. Is 'can be stolen' really something that the state can protect you against? Let's discuss it over dinner. Depending on the contents of the wallet I'd pay. On a more serious note: Your mockery, while amusing, is unrelated to the problem at hand. 'Stealing amounts of $currency from private person…

[deleted]

Re: Compromised Linode, thousands of BitCoins stolen

#67
post #54

Earlier quoted context omitted.

I already asked in the comments of the original article how many rounds of sha1 are used. SHA-1 still isn't the best, since it yields to FPGA attacks, but a single round can brute-force all 8 character passwords in less than 2 days on a GPU. My guess is that 10k rounds of sha-1 would probably not be feasible for non-dictionary attacks without specialized hardware.

The article mentions salted SHA-1, which is much more resistant to attack. Obviously, more rounds and unique salts per user would yield better results, regardless of the hashing scheme employed.

You can salt all you want, but an 8 character password with a single round is going to fall very, very fast. Salt, being public, has nothing to do with it.

Re: Compromised Linode, thousands of BitCoins stolen

#68
post #33
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

Are you sure? I think that you may be mistaken. The bar is just set higher in a "virtualized environment"... "In a public cloud environment, additional controls must be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder da…

Amazon getting a PCI compliance pass was a big deal. The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised.

Re: Compromised Linode, thousands of BitCoins stolen

#69

If this was sensitive data why was it not encrypted? Replace "bitcoin wallet" with "medical history" or "credit card numbers".

It had to be decrypted to be used. It was in use. Ergo...

It had to be rebooted to reset the root password. I see no good reason not to have a decryption key held in memory and require you to log in and enter the key upon reboot for something this important.

Re: Compromised Linode, thousands of BitCoins stolen

#70

Earlier quoted context omitted.

But all that regulation is evil and it's the freedom of bitcoin that gives it the power* *for hackers to get away with the entertaining virtual train robberies we've seen in the last year

Show me your wallet with a good amount of cash and leave the room for a while. Afterwards, let's talk about your comparison. Is 'can be stolen' really something that the state can protect you against? Let's discuss it over dinner. Depending on the contents of the wallet I'd pay. On a more serious note: Your mockery, while amusing, is unrelated to the problem at hand. 'Stealing amounts of $currency from private person…

What state? PCI DSS is private regulation.
Post reply on HN