Live data from Hacker News

The Looting of ShapeShift

news.bitcoin.com

91–95 of 95 posts

Re: The Looting of ShapeShift

#91

When being accused of bigotry, it's never a good sign to use "social serfdom number" in your post mortem.

That's just some shit that ancaps like to say. Also note the constant references to fiat currency. I don't think he was actually being racist with that.

Re: The Looting of ShapeShift

#92

When being accused of bigotry, it's never a good sign to use "social serfdom number" in your post mortem.

That's just some shit that ancaps like to say. Also note the constant references to fiat currency. I don't think he was actually being racist with that.

I agree, I don't think "serfdom" is racist, but it doesn't shine a good light on you to use, and erodes the trust people put in you by default.

Re: The Looting of ShapeShift

#93

Earlier quoted context omitted.

That's just some shit that ancaps like to say. Also note the constant references to fiat currency. I don't think he was actually being racist with that.

I agree, I don't think "serfdom" is racist, but it doesn't shine a good light on you to use, and erodes the trust people put in you by default.

Agreed.

Re: The Looting of ShapeShift

#94
post #56

Earlier quoted context omitted.

One of the striking things in this article was when he said they might have been compromised by their "CloudCo" (Cloud Provider). If I'm going to build any systems that handle money or bitcoin in a cloud provider, I will make damn sure I don't trust the cloud provider with anything. Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I…

Encryption won't protect you - the cloud provider has access to executables (in ram and perhaps on disc), your keys (ram and disc) and the data both pre and post encryption (in ram). Because they control the hypervisor, they control everything. That means they have as much access and authority as the code that you are running on their servers have. So the only way to protect yourself from them is to limit what your s…

You can use hardware security modules in datacenter space you physically control to store the private keys used to encrypt your data at "CloudCo". Amazon even offers this service and calls it Cloud HSM.

There's always the in-memory vulnerability, which is harder to mitigate, but requires an attacker with physical access to the hypervisor, so it's much more difficult to execute (as most meat-space hacks are).

Re: The Looting of ShapeShift

#95
This reads like a case study in pure incompetance at every possible level. Lack of vetting, no third party auditing, poor segregation of customer funds. It's a total shit show. This should permanently damage their business and reputation, but the Bitcoin community has always been forgiving of people who lose their money. Fool me once...
Post reply on HN