Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

91–100 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#91

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

>Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines and then loot your wallets?

The way I understand it the attackers were able to get access to the admin panel and invoked some kind of 'change root password' emergency stuff. The machines were rebooted it seems, which makes sense: The interface of Linode has probably/hopefully no access to the root password. Maybe this 'Reset my root' feature (now I'm guessing) reboots the machine in single user mode or passes init=/bin/sh to the kernel to reset the password once and reboots again afterwards.

Only THEN the attacker had access. But yes, he had root. The good (if you want to call it that) part of it is that this procedure rings every alarm possible. The real owner doesn't have the password anymore, as he'll soon figure out. It's everything but sneaky.

I DO wonder why root is allowed to log in at all, though..

Re: Compromised Linode, thousands of BitCoins stolen

#92
post #78
post #64

Earlier quoted context omitted.

Yes you can, but not in 24h. (Hopefully buying a $20k car is not an impulse buy you make in a day, ahem...) Sell the BTC on MtGox and withdraw the USD via Dwolla directly to your bank account. No need to use Paypal! MtGox's withdrawal limit can be raised to $10k per day if you provide a notarized government ID copy (IIRC). Dwolla's limit is $5k per transfer with as many txfer per day. So it would take 2 days for comp…

thank the legacy financial system for these unexplainable delays I understand your feelings on this. But the fact remains that the using the "legacy financial system" I can move my money between investments on my etrade account with a latency of minutes. I can buy that car on a credit card or with a personal check with zero latency. Bitcoins aren't remotely there yet. There may be some privacy or social justice reaso…

This latency is not a pb inherent to Bitcoin. It happens whenever you hold currency X and need currency Y, for any value of X != Y. You are going to waste time exchanging one for the other. This is one of the reason why I expect Bitcoin's adoption to take off for international trade where the 2 parties of a transaction use different currencies to begin with.

Also I doubt you can sell stocks on Etrade and withdraw dollars to your bank in minutes. When I do this with my stockbroker (TD ameritrade) it takes at least 2-3 days because the transfer is made by ACH which takes a while to clear.

This latency is perfectly acceptable for stock market investors, therefore I see no reason why it would not be acceptable for Bitcoin investors...

Re: Compromised Linode, thousands of BitCoins stolen

#93
post #79
post #6

Hmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers ta…

Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.

where do you keep the key to the crypto fs?

Re: Compromised Linode, thousands of BitCoins stolen

#94
This reminds me of a situation when I first signed up for linode... my password on my account inexplicably changed one day(I use lastpass so no I did not type the randomly generated password wrong). I contacted support and they fixed it, but I still remember questioning why or how...

Re: Compromised Linode, thousands of BitCoins stolen

#95

Earlier quoted context omitted.

I'd argue this isn't about bitcoins. A (popular) VPS provider, according to that article, had a security problem that allowed some idividuals to access the VPS management interface for any machine they cared for. They could've defaced your site in high traffic times. They could've logged in and delete your projects on the VPS. Depending on your setup (they had root) they could've searched for your backups. They could…

It's not about "don't put anything on a VPS", it's about "don't put money on a VPS."

I'm sorry, but you just said the same thing again that I was arguing against. 'Money' is not as clear cut as you'd like it to be.

Bitcoins are no real recognized currency. So you can trade them for USD -> Don't store it?

What about this great project I'm working on? All my stuff on the VPS, because that's convenient and accessible from everywhere. I spent a double digit number of days on it. I have a daily rate for working as a programmer. Don't store it?

You totally ignored (so hard, that I think you didn't read it fully) my post about issues that are harder to value even. Access to your mail can be devastating. Even if you don't store 'money' on that VPS. Putting a dent into your online reputation by messing with your life on the net is hard to value, but certainly damaging. Again, no 'money' stored.

Bottom line: You ignored my point or didn't read my post at all. You picked a line out of context and refuted it with a pointer to the argument _I explicitly tried to prove wrong_.

Re: Compromised Linode, thousands of BitCoins stolen

#96
post #5

I'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.

They were coins of a mining pool (slush pool - mining.bitcoin.cz - one of the largest three). And they were only the 'hot coins' left on-line for user withdrawals. The majority of the coins are kept offline/cold, as a common security measure for any bitcoin service.

Re: Compromised Linode, thousands of BitCoins stolen

#97

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

>Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines and then loot your wallets? The way I understand it the attackers were able to get access to the admin panel and invoked some kind of 'change root password' emergency stuff. The machines were rebooted it seems, which makes sense: The interface of Linode has probably/hopefully no access to t…

"The real owner doesn't have the password anymore, as he'll soon figure out."

He won't figure it out until he tries to login though.

Re: Compromised Linode, thousands of BitCoins stolen

#98
This is obviously an unacceptable incident. I don't understand how the author can write:

Especially upsetting is that I went to great pains to keep everything as secure as possible.

When that's plainly not true. Surely having a wallet stored on a VPS is a really bad idea, what with admins potentially having full access to hard drive contents? Wouldn't a PGP'd local copy be a better solution, or am I missing a trick?

Re: Compromised Linode, thousands of BitCoins stolen

#99
post #75

The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…

This is why insurance exists. I wonder if there are any insurance providers who'd be willing to provider coverage for this sort of event.

Insurance won't insure for what they don't understand and build a risk model for. I can assure they won't understand something like this for a very long time.

Re: Compromised Linode, thousands of BitCoins stolen

#100

How did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines…

>Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines and then loot your wallets? The way I understand it the attackers were able to get access to the admin panel and invoked some kind of 'change root password' emergency stuff. The machines were rebooted it seems, which makes sense: The interface of Linode has probably/hopefully no access to t…

I disabled root login when I was setting up the server. Could my server be affected too?

Also admins that only log with ssh keys and don't use root won't be able to notice that, will they?

Post reply on HN