5 ms·
> About a year and a half ago, we were alerted in the early AM of a reduction in our safe/cold wallet balances of Bitcoin and Litecoin If this happened, it mea
by sirsar 11y ago
> About a year and a half ago, we were alerted in the early AM of a reduction in our safe/cold wallet balances of Bitcoin and Litecoin
If this happened, it means what were thought of as "cold wallets" were not implemented properly. When handling millions of dollars of coins, as Cryptsy was, a deep cold wallet [1] should be used. Take an offline computer and an offline printer. Generate a bunch of (optionally multisig) addresses. Print the private keys. Copy the addresses to your server that processes transactions. Lock away the private keys (optionally in multiple places). Never connect the offline computer or printer to the internet. Send every X bitcoins to a new address from the cold wallet.
This takes a few hours and a few hundred bucks to implement. It requires human intervention to access the cold wallet (to replenish the internet-facing "hot" wallet), but that is what you want! It is a whole lot easier to manually move coins once a week than it is to check for bugs and backdoors in your whole stack. Worst case, customers suffer a delay in withdrawals and a hack causes you to lose X bitcoins.
Edit: Of course, it could also be an inside job. An "exit scam." Moving coins to a new address and then not spending them is pretty hard to get caught doing.
[1] https://en.bitcoin.it/wiki/Cold_storage https://en.bitcoin.it/wiki/Cold_storage
- datapat 11y ago>Edit: Of course, it could also be an inside job. An "exit scam." Has there ever been any real or serious evidence to demonstrate that any of these seemingly numerous Bitcoin 'hacks' have been legit and not inside jobs, which is exactly what they all look like? There are so many 'exit hacks' it seems virtually standard practice in the Bitcoin world, perhaps because nobody seems to actually go to jail for it or even face any serious legal investigations into it. If a bank announced a multi-million dollar 'hack' I'd expect the authorities would be heavily involved, immediately, and everyone with a position to have facilitated a theft would be under suspicion and investigated until ruled out. One the one hand Bitcoin is a supposedly serious, game changing currency and has billions of dollars tied up in it; on the other, it's treated as little more than internet karma points, and if people have it stolen from a wallet or someone announces yet another million dollar 'hack' at some comical 'exchange' any old clown/scammer can throw up, it seems to be simply 'tough shit' and nothing to see here. This may be the non-regulated world the fanatics want, but it's a major reason why sane people (currently almost everyone on Earth) will continue to avoid Bitcoin like the plague.
- FatalLogic 11y agoYour mode of thought, trying to divide the world into 'fanatics' and 'sane people', is not a helpful way to analyze these issues. >Has there ever been any real or serious evidence to demonstrate that any of these seemingly numerous Bitcoin 'hacks' have been legit and not inside jobs, which is exactly what they all look like? You're asking people to prove a negative[1]. It's a common logical fallacy. >nobody seems to actually go to jail for it or even face any serious legal investigations into it. Really? This claim is trivially disprovable. Numerous people have been arrested, including Mark Karpeles of Mt Gox. You've never heard of that case? $500 million allegedly stolen https://www.google.com/search?q=bitcoin+exchange+arrested https://www.google.com/search?q=bitcoin+exchange+arrested http://www.wsj.com/articles/japanese-police-arrest-mark-karpeles-of-collapsed-bitcoin-exchange-mt-gox-1438393669 http://www.wsj.com/articles/japanese-police-arrest-mark-karp... http://siliconangle.com/blog/2015/02/23/mintpal-scammer-ryan-kennedy-arrested-in-u-k-over-theft-of-3700-bitcoins/ http://siliconangle.com/blog/2015/02/23/mintpal-scammer-ryan... [1]http://rationalwiki.org/wiki/Negative_proof http://rationalwiki.org/wiki/Negative_proof
- menzoic 11y agoWhats wrong with proving a negative? There is no fallacy in that first comment you quoted. datapat isn't claiming that what he's saying is true, he's asking for a proof.
- eli 11y agoThe nature of this sort of conspiracy theory makes it impossible to disprove. For example an identified backdoor and logs pointing to an external hack is exactly what you'd expect to see planted if this were a halfway clever inside job, right? So how do you possibly rule that out?
- datapat 11y ago>The nature of this sort of conspiracy theory makes it impossible to disprove. >For example an identified backdoor and logs pointing to an external hack is exactly what you'd expect to see planted if this were a halfway clever inside job, right? So how do you possibly rule that out? If only there was an organization whose remit was to investigate and establish the facts behind fraud, robbery, hacking and other crimes.
- danmaz74 11y ago> It requires human intervention to access the cold wallet (to replenish the internet-facing "hot" wallet), but that is what you want! Am I the only one who finds it a bit amusing that an e-currency bank needs people to physically move the bullion from one vault to the other?
- tlrobinson 11y agoOn the contrary, I think it's pretty neat you can implement a variety of security schemes depending on your risk tolerance and convienence requirements. Some of the parameters you can pick from:online vs offline ("cold"), hosted vs not, SPV vs full node, multisig, dedicated hardware wallet, etc. And you can combine them in various permutations: e.x. offline + multisig is just about the most secure thing you can imagine.
- forgetsusername 11y ago>I think it's pretty neat you can implement a variety of security schemes depending on your risk tolerance and convienence requirements. Can you tell me the last time some you know had money go missing from their bank account?
- doppel 11y agoLots of people lose money because of scams, cards getting stolen/scanned/photographed, etc. - in a lot of cases, the banks just cover the cost and can rollback transactions because everyone has agreed that's how the system works. It is not because people do not have money stolen from their bank accounts due to various breaches.
- npongratz 11y agoMy understanding might be wrong, but I believe during the 2013 Cyprus bail-in, all Cypriot depositors had money missing from their bank accounts: they lost 9.9% of funds above the insurance ceiling, 6.75% of funds below the ceiling: http://www.economist.com/blogs/schumpeter/2013/03/cyprus-bail-out http://www.economist.com/blogs/schumpeter/2013/03/cyprus-bai...
- forgetsusername 11y ago>Generate a bunch of (optionally multisig) addresses. Print the private keys. Copy the addresses to your server that processes transactions. Lock away the private keys (optionally in multiple places). Never connect the offline computer or printer to the internet. Only for millions of coins? What about the savings of the average person? A loss would be devastating. Do you recommend the same security measures? If the system is insecure, it's insecure. The idea that Bitcoin is in any way ready for the mainstream is kind of funny.
- eterpstra 11y agoCash and debit cards are pretty funny, too. Anyone who grabs your cash, or gets away with a purchase on your debit card is laughing pretty hard at your expense. Maybe, if you're lucky, your bank will get around to reversing the fraudulent debit card charges, but the thief still gets away. There is nothing secure about any money system.
- sirsar 11y agoI do this, minus the "dedicated computer and printer" part. Pretty simple, really. Another option is dedicated smartcards that hold the keys. I'm genuinely curious. Can you envision any possible distributed internet currency that wouldn't require human interaction for the highest level of security? Keep in mind, the threat model here is someone gaining read access to a few kb of data. With an automated, internet-facing system, I see an airgap as the only reasonable defense against that threat. If someone gains read access to, say, your bank session cookies, they could also feasibly clean you out. The only difference is the bank might be able to reverse the transaction (undesirable a decentralized currency) or cover your losses (not a bad idea).
- ryanlol 11y agoIf you're holding your savings in cash you're doing it wrong.
- draw_down 11y agoThe proper security measures are so simple and easy. Yet this keeps happening... hmmmm.