Live data from Hacker News

The Looting of ShapeShift

news.bitcoin.com

81–90 of 95 posts

Re: The Looting of ShapeShift

#81
post #2

This is certainly the worst case scenario - your security officer installing remote access software on developers machines, stealing bitcoins from production, then selling the company source code, access credentials and access to the internal network to a Russian hacker. Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best pr…

It's extremely expensive. Many banks and companies in the finance industry (hedge funds) do this: Hire at least 2 or 3 people for every job. Have them watch each other whenever touching systems that connect to production or deploying code to production. Never trust any one of them with the private keys or passwords to anything - they can only get half of a secret and their co-worker gets the other half. To do this ef…

> Hire at least 2 or 3 people for every job.

This is actually the key one - the more people who need to be corrupt, the harder it is to get away with being a crook. A surprising amount of internal fraud can be completed simply by requiring people to take solid blocks (2 weeks plus) of leave every year.

That "inefficiency" the "lean 10x disruptors" congratulate themselves over does not always end well.

Re: The Looting of ShapeShift

#82
Let's not lose sight of the fact that their cold wallet was untouched and all they lost was on the order of a hour's worth of turnover. That's more than can be said for a lot of the other bitcoin hacks.

Re: The Looting of ShapeShift

#83
post #11

Am I the only one to think that all this narrative to blame Bob is pathetic ? This is pure and simple Mr. Voorhees (CEO) incompetency. After all, Bob is a criminal and he was just doing his "job".

Are you really saying that criminals can't be blamed because "thieves gonna thieve"? Sure ShapeShift can take some blame for bad security, which he readily admits in the post, but the bulk of the blame is owed to the person who did the crime.

Eh, when CEOs lay off tens of thousands of people to pocket a sweet bonus, they're "just doing their job", regardless of whether it ruins their ex-employees lives. I think it's a bit of a reach, but "just doing my job" seems to be a modern get-out-of-jail card for pretty much any action that harms others.

Re: The Looting of ShapeShift

#84
post #81

Earlier quoted context omitted.

It's extremely expensive. Many banks and companies in the finance industry (hedge funds) do this: Hire at least 2 or 3 people for every job. Have them watch each other whenever touching systems that connect to production or deploying code to production. Never trust any one of them with the private keys or passwords to anything - they can only get half of a secret and their co-worker gets the other half. To do this ef…

> Hire at least 2 or 3 people for every job. This is actually the key one - the more people who need to be corrupt, the harder it is to get away with being a crook. A surprising amount of internal fraud can be completed simply by requiring people to take solid blocks (2 weeks plus) of leave every year. That "inefficiency" the "lean 10x disruptors" congratulate themselves over does not always end well.

I've kinda thought about this in the context of relatively complex technical jobs. One side of my family tree worked a bunch in the consumer banking (non-investment) industry, and I remember hearing story after story of someone being caught after their mandatory leave.

But at a job where the ideal is automation, rather than manual verification and analysis, I wonder what additional obstacles must be placed in a potential attacker's way? Rotating keys based on employee schedules? I'm sure there are many well-studied ways to do this, but it's interesting to armchair analyze.

Re: The Looting of ShapeShift

#85
post #81

Earlier quoted context omitted.

It's extremely expensive. Many banks and companies in the finance industry (hedge funds) do this: Hire at least 2 or 3 people for every job. Have them watch each other whenever touching systems that connect to production or deploying code to production. Never trust any one of them with the private keys or passwords to anything - they can only get half of a secret and their co-worker gets the other half. To do this ef…

> Hire at least 2 or 3 people for every job. This is actually the key one - the more people who need to be corrupt, the harder it is to get away with being a crook. A surprising amount of internal fraud can be completed simply by requiring people to take solid blocks (2 weeks plus) of leave every year. That "inefficiency" the "lean 10x disruptors" congratulate themselves over does not always end well.

> solid blocks (2 weeks plus) of leave

I've heard that's because a lot of those scams/tricks fall apart without constant gradual intervention, so an important part of it is that the employee is prevented from accessing most work-resources during that time.

Re: The Looting of ShapeShift

#86
"Very quickly, we realize he is pretty much useless. "

When you hire IT people, have no clue how distinguish between a good one and a fake one, in other words have no clue, this happens.

Also not enough oversight and auditing admins when money is involved is a bad sign.

Re: The Looting of ShapeShift

#88

Earlier quoted context omitted.

They do- one company found a warrant on me that I didn't know I had for an unpaid traffic ticket.

Do you know where one would go to perform an accurate background check on oneself?

John Oliver covered this recently. Many background check agencies won't let you run a background check on yourself.

https://www.youtube.com/watch?v=aRrDsbUdY_k

Re: The Looting of ShapeShift

#89

Earlier quoted context omitted.

You might appreciate http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...

Idk, I'm so tired of NewYorker-style liberal's attempt at humor about other political groups. It's disrespectful because they don't show that they've attempted to actually think about the issues, they're just knee-jerking with their emotions. Their treatment of Trump is similarly ridiculous. They're just waving their blueTribe flag as hard as they can. And when liberals talk about Ayn Rand? It's like she's the worst…

The author of that article seems willing to be sarcastic about anything.

http://www.newyorker.com/humor/daily-shouts/switched-standin...

I have to say I quite enjoy that writing style.

Re: The Looting of ShapeShift

#90
post #70
post #40

Earlier quoted context omitted.

Criminal background checks are actually surprisingly hard to do. There are cheap ones that will search a subset, but doing it thoroughly actually requires physically going to courthouses in the county for all prior addresses. Even then, you can miss records if they are in counties where the person doesn't live.

This surprises me about America. Other countries have national criminal record databases. Is it that America hasn't spent the money to build one, or that counties/states/police stations don't want to share information, or that they're not allowed to share information?

But access to those databases is not necessarily available to all. In the UK we have the 'Disclosure and Barring Service' (which used to be the 'Criminal Records Bureau', but there are now a bunch of non crime (or non conviction) reasons you might be on the barred list) which will perform a background check which discloses any convictions and any allegations of sexual abuse. All this for the bargain price of £59.

As that last suggests, however, only certain roles are eligible for the checks, those being primarily roles that involve working with children or vulnerable adults, though the full list [0] is quite interesting.

[0] https://www.gov.uk/government/uploads/system/uploads/attachm...

Post reply on HN