Live data from Hacker News

Coinbase: Responding to Firefox 0-days in the wild

blog.coinbase.com

71–80 of 97 posts

Re: Coinbase: Responding to Firefox 0-days in the wild

#71
post #41
post #17

Earlier quoted context omitted.

Those attacks would not work if everyone stopped using computers.

its almost like the NSA designed all programming languages to insure that it would be impossible to make a perfect program

I find the explanation of "to err is human" far more likely.

Re: Coinbase: Responding to Firefox 0-days in the wild

#72

This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...

Banking malware has existed for a while.

Re: Coinbase: Responding to Firefox 0-days in the wild

#73
post #9

Does it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?

Docker is not intended as or very useful for security isolation - especially for GUI applications. I would suggest a VM if you want to isolate your browser.

Re: Coinbase: Responding to Firefox 0-days in the wild

#75

Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

Given how quickly coinbase managed to respond to an advanced attacker I think they know what they're doing. Insider threat is also really difficult. Working from a point of "I don't trust my employees" is very painful for many reasons.

To me it shouldn't be a question of whether you trust your employees - obviously it makes for a better working relationship if you do, but I think there's a more fundamental issue here, which is "I don't trust my system"

If you fully trust the system you're building (and that trust is well-placed, meaning you can _prove_ the lack of significant exploits/vulnerabilities) then you should have no issue allowing others to try and poke holes in it

The usual caveat is that untrusted employees with sufficient access could potentially wreak havoc, but I would argue that if you really trust your system, and define the boundaries of your system well enough (i.e. to also encapsulate the issuance and management of all permissions relating to the system), then you can effectively limit the ability of malicious actors to break things or otherwise amass control

Re: Coinbase: Responding to Firefox 0-days in the wild

#76

This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...

Banking malware has existed for a while.

Banking has insurance against fraud and transactions are generally reversible.

Re: Coinbase: Responding to Firefox 0-days in the wild

#77

Earlier quoted context omitted.

That's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.

I don't hold MtGox's origins against them (plus I'm a MtG fan). But Nintendo didn't pivot from playing cards to guarded stagecoaches, they stayed in the entertainment focus and evolved over a century into electronics. The stakes were always low.

Pretty low bar honestly, even if they had pivoted to stagecoaches it’s hard to knock them if they’d been successful. The ends are more important. Gox was really stupid though.

Re: Coinbase: Responding to Firefox 0-days in the wild

#78
post #44
post #5

Earlier quoted context omitted.

"We're not run by idiots"?

That doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all. A similar event actually happened with another asset they offer - Ethereum Classic. https://cointelegrap…

The infrastructure to carry out that attack against BCH would cost around a billion dollars in mining equipment and power. Not exactly what you would call a small miner. BCH also has rolling 10 block checkpoints so max you could reorg would be 10 blocks or In reality there is nowhere you could rent this hashpower and miners that do have it would never risk the legal, social and monetary consequences to rollback 2 hours of transactions.

Re: Coinbase: Responding to Firefox 0-days in the wild

#80

> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker. At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people. Here we have a researcher from Google’s Project Zero and the attacker. How do you explain these coincidences? What is the chance that some prominent resear…

> Project Zero and the attacker. How do you explain these coincidences?

Project Zero buys 0days on darknet? Google has unlimited cash, so technically possible.

Post reply on HN