Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

71–80 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#71
post #57

Earlier quoted context omitted.

But all that regulation is evil and it's the freedom of bitcoin that gives it the power* *for hackers to get away with the entertaining virtual train robberies we've seen in the last year

It'd be worth it if more people used Bitcoins. No, we don't NEED regulation. We need competence and standards, which can come about without incompetent government intervention.

Nobody said anything about government intervention. PCI DSS is private regulation.

Re: Compromised Linode, thousands of BitCoins stolen

#73
post #31
post #8

Earlier quoted context omitted.

> customer service can access your account only if you read them your hardware token's code At the very least, I'd hope Linode implements two-factor authentication for their own logins. A customer-provided OTP would be great but you'd need a customer service reset tool for that when people forget, which would put you back where you started...

Not necessarily if the reset tool is manually driven and audited. The vulnerability we're worried about here is an automated attack against many customers of a single hosting provider. There will always be ways to human-engineer your way into any single host. Having a hosting provider just increases the attack surface a little.

> The vulnerability we're worried about here is an automated attack against many customers of a single hosting provider.

This was an attack against Linode's customer service systems, which allow their support reps to reset root passwords. There's no reason for that system not to be protected by two factor authentication on top of heavy logging.

Re: Compromised Linode, thousands of BitCoins stolen

#74
post #33

Earlier quoted context omitted.

Are you sure? I think that you may be mistaken. The bar is just set higher in a "virtualized environment"... "In a public cloud environment, additional controls must be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder da…

Amazon getting a PCI compliance pass was a big deal. The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised.

> The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised.

None of that should be particularly difficult for a VPS provider as large as Linode.

Re: Compromised Linode, thousands of BitCoins stolen

#75

The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…

This is why insurance exists.

I wonder if there are any insurance providers who'd be willing to provider coverage for this sort of event.

Re: Compromised Linode, thousands of BitCoins stolen

#76

Earlier quoted context omitted.

Show me your wallet with a good amount of cash and leave the room for a while. Afterwards, let's talk about your comparison. Is 'can be stolen' really something that the state can protect you against? Let's discuss it over dinner. Depending on the contents of the wallet I'd pay. On a more serious note: Your mockery, while amusing, is unrelated to the problem at hand. 'Stealing amounts of $currency from private person…

What state? PCI DSS is private regulation.

I believe some states have laws requiring parts of PCI DSS to be implemented.

Re: Compromised Linode, thousands of BitCoins stolen

#77

i think bitcoin could use another layer of authentication to verify the person is indeed the owner of bitcoins.

In this case, there's no one to authenticate - it's an automated system that transfers bitcoins. If the application is able to send bitcoins, so is anyone with root over the machine running it.

Re: Compromised Linode, thousands of BitCoins stolen

#78
post #64
post #42

Earlier quoted context omitted.

Has anyone solved the liquidity mess? Say I want to buy a car and have to unload $20k of bitcoins. Can I do that? With a latency of less than 24 hours? Without getting my PayPal account frozen?

Yes you can, but not in 24h. (Hopefully buying a $20k car is not an impulse buy you make in a day, ahem...) Sell the BTC on MtGox and withdraw the USD via Dwolla directly to your bank account. No need to use Paypal! MtGox's withdrawal limit can be raised to $10k per day if you provide a notarized government ID copy (IIRC). Dwolla's limit is $5k per transfer with as many txfer per day. So it would take 2 days for comp…

thank the legacy financial system for these unexplainable delays

I understand your feelings on this. But the fact remains that the using the "legacy financial system" I can move my money between investments on my etrade account with a latency of minutes. I can buy that car on a credit card or with a personal check with zero latency. Bitcoins aren't remotely there yet.

There may be some privacy or social justice reasons behind pushing bitcoins. They may be fun (I'm sure they're more fun for a hacker to play with than mutual funds). But they're not a serious option for someone looking to "invest" their money, and claiming they are is doing the people you're trying to sell on the idea a disservice.

Re: Compromised Linode, thousands of BitCoins stolen

#79
post #6

Hmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers ta…

Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.

Re: Compromised Linode, thousands of BitCoins stolen

#80
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

I'd argue this isn't about bitcoins. A (popular) VPS provider, according to that article, had a security problem that allowed some idividuals to access the VPS management interface for any machine they cared for. They could've defaced your site in high traffic times. They could've logged in and delete your projects on the VPS. Depending on your setup (they had root) they could've searched for your backups. They could…

It's not about "don't put anything on a VPS", it's about "don't put money on a VPS."
Post reply on HN