Earlier quoted context omitted.
Those attacks would not work if everyone stopped using computers.
its almost like the NSA designed all programming languages to insure that it would be impossible to make a perfect program
Coinbase: Responding to Firefox 0-days in the wild
71–80 of 97 posts
Re: Coinbase: Responding to Firefox 0-days in the wild
#72This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...
Re: Coinbase: Responding to Firefox 0-days in the wild
#73Does it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?
Re: Coinbase: Responding to Firefox 0-days in the wild
#74Remember, not your keys, not your bitcoin. Stay off coinbase.
Re: Coinbase: Responding to Firefox 0-days in the wild
#75Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.
Given how quickly coinbase managed to respond to an advanced attacker I think they know what they're doing. Insider threat is also really difficult. Working from a point of "I don't trust my employees" is very painful for many reasons.
If you fully trust the system you're building (and that trust is well-placed, meaning you can _prove_ the lack of significant exploits/vulnerabilities) then you should have no issue allowing others to try and poke holes in it
The usual caveat is that untrusted employees with sufficient access could potentially wreak havoc, but I would argue that if you really trust your system, and define the boundaries of your system well enough (i.e. to also encapsulate the issuance and management of all permissions relating to the system), then you can effectively limit the ability of malicious actors to break things or otherwise amass control
Re: Coinbase: Responding to Firefox 0-days in the wild
#76This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...
Banking malware has existed for a while.
Re: Coinbase: Responding to Firefox 0-days in the wild
#77Earlier quoted context omitted.
That's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.
I don't hold MtGox's origins against them (plus I'm a MtG fan). But Nintendo didn't pivot from playing cards to guarded stagecoaches, they stayed in the entertainment focus and evolved over a century into electronics. The stakes were always low.
Re: Coinbase: Responding to Firefox 0-days in the wild
#78Earlier quoted context omitted.
"We're not run by idiots"?
That doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all. A similar event actually happened with another asset they offer - Ethereum Classic. https://cointelegrap…
Re: Coinbase: Responding to Firefox 0-days in the wild
#79They paid some registrar for the domain. Can police request payment details? Can someone buy domain on stolen credit card?
Re: Coinbase: Responding to Firefox 0-days in the wild
#80> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker. At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people. Here we have a researcher from Google’s Project Zero and the attacker. How do you explain these coincidences? What is the chance that some prominent resear…
Project Zero buys 0days on darknet? Google has unlimited cash, so technically possible.