10 ms·
Compromised Linode, thousands of BitCoins stolen
- plasma 15y agoIt's quite possible that the attacker has been using the support admin login details for much longer against Linode, without being noticed, until now. What sort of defenses can developers put in place to protect against admin panels? I've used these sorts of techniques in the past: 1) Separate username/password system compared to the regular website 2) IP whitelist of who may even access the admin panel 3) Failed login attempts send an e-mail alert with a log entry Any other recommendations or suggestions?
- sgornick 15y agoForum thread regarding this: https://bitcointalk.org/index.php?topic=66916.40;all https://bitcointalk.org/index.php?topic=66916.40;all
- mindslight 15y agoThe comments calling for 'tainting' of stolen bitcoins and blocking their exchange will be the end of bitcoin. The anonymity of bitcoin is only due to general laziness. What happens when the market figures that out? Bitcoin's byzantine agreement is novel, but its crypto is crap.
- nbpoole 15y agoSo, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being notified and with minimal logging?
- stevenbrianhall 15y agoRegarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."
- mmaunder 15y agoI'm a Linode fanboy, but we need maximum transparency on what occurred and what's being done. What support interface? How compromised? Who's credentials, etc.
- ErneX 15y agoMe too, I've been recommending them a lot and really like their service. I just checked our 2 boxes uptimes just in case.
- redthrowaway 15y agoHopefully they're working on it, and will give a post mortem once they get it sorted out. I'm inclined to show patience and not demand they do anything other than ascertain the scale of the breach, alert those affected, and secure their systems at this point. Later, they can get into what happened and how they will avoid it in the future.
- marshray 15y agoWe can't wait for a full postmortem before Linode says anything. Linode can't just leave us all wondering about our own security while pouring over over someone else's Pastebins.
- lawnchair_larry 15y agoWhere are you reading this? The status page and the blog have no mention of the incident.
- ErneX 15y ago
- nwmcsween 15y agoReading the ticket slush posted it shows no password change logs, if linode was compromised either the whole infrastructure was compromised (unlikely) or a rouge admin or a admin comprimised account accessed the vps and stole the $, as per the bitcoin forums. Total stolen is roughly $16,000 USD
- dissident 15y ago> if linode was compromised either the whole infrastructure was compromised (unlikely) That's funny. I know from experience in the script kiddie part of the Internet that it was sometimes exceptionally easier to hack entire datacenters (even ones worth millions of dollars) just to get into a few of their customers, especially if those customers secured themselves. Hosting companies have very sophisticated websites sometimes, meaning that they're almost always vulnerable to something. I know of an SQL injection in an very large U.S. datacenter's administration panel which has been there for at least six years. Six years and it has not been fixed, and maybe a dozen people have independently discovered it. The deeper you delve, the more you realize that at least a handful of people also have access to important upstreams/backbones. It's a lot bigger of a mess than anybody realizes. A bit of advice: if you say you're secure, you're either lying or colocating.
- mahmud 15y agoLinode will send you a confirmation email if you access the admin panel from a "new" IP. This guy must have had his email address compromised as well. Looks like a class spear-attack.
- redegg 15y agoSo far there are 3 people who've reported their Linodes compromised. They all had popular Bitcoin services running on their Linode. 3 compromised emails? Very unlikely. They are all major contributors to Bitcoin, I think they know a little more than using the same password everywhere. Linode will only send you a confirmation email if you enable the feature, otherwise tough luck. It's also been confirmed by the vice president of Linode to be a fault on their side.
- mahmud 15y agoFair enough. I stand corrected. More plausible to have broken web UI security than an entire bitcoin-community-wide targetting.
- Legion 15y ago> Linode will send you a confirmation email if you access the admin panel from a "new" IP. IF you have the IP whitelisting feature enabled on your account. It is not by default.
- ceejayoz 15y ago> Linode will send you a confirmation email if you access the admin panel from a "new" IP. This guy must have had his email address compromised as well. The attack was not via the consumer facing admin panel. It was the internal Linode customer service interface.
- jaredstenquist 15y agoSince my $1,000 worth of bitcoins dropped in value to $150 over a period of weeks, I've become significantly less interested in using it as a currency.
- sgornick 15y agoYou mean less interested in using it as a way to profit from speculation. As a currency it is not as critical that the value only goes up. A person or merchant receiving bitcoins can easily convert them out to USDs and still lose less in fees than the same transaction would cost compared to accepting a credit card or debit card payment. For example, BTC -> USD at most exchanges is around half a percent.
- georgemcbay 15y ago"As a currency it is not as critical that the value only goes up." True, but to be a practical currency it is critical that the value remains relatively stable. A currency capable of dropping from $1000 USD to $150 USD in a very short time is clearly not stable.
- codexon 15y agoThis is unfortunately untrue. Bitcoin has been subject to huge 30% swings in a matter of minutes.
- deleted 15y ago[deleted]
- KaeseEs 15y agoWell, no. Currencies as we know them are not only for exchange, but also are supposed to be reasonable stores of value. If a currency loses 85% of its worth in a period of weeks, it has failed at this fundamental task. Now, for merchants this might not seem to matter, as they might be able to always convert bitcoins to a real currency immediately and never hold them long enough for depreciation to matter, but if the currency is excessively volatile there will never be a buyer at the exchange besides speculators, which prevents the currency from ever being really useful.
- klodolph 15y agoI'm not really sure why people are trying to store bitcoins on a VPS in the first place. You can't process credit cards on a VPS and be PCI compliant (it's against the rules), but any moron can do what they want with bitcoins.
- mvanveen 15y agoThis strikes me as a really good point. The onus for proof of merit is on the decentralized currency. Simply put, people trust Visa and MasterCard to safely manage transactions, for better or for worse. Regulation like PCI helps ensure that this trust is sound. The Bitcoin community at large could really benefit from a set of published best practices for managing transactions. Anybody possessing an insecure wallet is ultimately a liability to the credibility of the currency.
- gravitronic 15y agoBut all that regulation is evil and it's the freedom of bitcoin that gives it the power* *for hackers to get away with the entertaining virtual train robberies we've seen in the last year
- kiba 15y agoTo be fair, websites were all continuously compromised last years, many of which have nothing to do with bitcoin. Even so, bitcoin seems to attract every shark in a one thousand mile radius.
- lhnn 15y agoIt'd be worth it if more people used Bitcoins. No, we don't NEED regulation. We need competence and standards, which can come about without incompetent government intervention.
- icebraining 15y agoNobody said anything about government intervention. PCI DSS is private regulation.
- 15y ago
- luser001 15y agoHmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers take note of this incident. This is a very interesting incident.
- ceejayoz 15y ago> customer service can access your account only if you read them your hardware token's code At the very least, I'd hope Linode implements two-factor authentication for their own logins. A customer-provided OTP would be great but you'd need a customer service reset tool for that when people forget, which would put you back where you started...
- ajross 15y agoNot necessarily if the reset tool is manually driven and audited. The vulnerability we're worried about here is an automated attack against many customers of a single hosting provider. There will always be ways to human-engineer your way into any single host. Having a hosting provider just increases the attack surface a little.
- ceejayoz 15y ago> The vulnerability we're worried about here is an automated attack against many customers of a single hosting provider. This was an attack against Linode's customer service systems, which allow their support reps to reset root passwords. There's no reason for that system not to be protected by two factor authentication on top of heavy logging.
- RLG_RLG 15y agoYou obviously have never worked for a retail ISP.
- 15y ago
- DiabloD3 15y agoThe writeup of this is rather suspect. What happened is someone guessed slush's Linode account password, and used the root password reset feature from there. What I don't understand is why does such a feature exist, why doesn't Linode require >16 character length passwords that are sufficiently random (or eschew password auth altogether), and why does slush (apparently from what I can tell) allow password auth for ssh AND allow root to login on ssh.
- pavel_lishin 15y ago> why doesn't Linode require >16 character length passwords that are sufficiently random Well, depending on how they got Marek's password, it might not matter. If someone went to his apartment and saw it written down on a post-it...
- megamark16 15y agoIf they had guessed his password then their login would have shown up in the activity logs for his account, which he indicated was not the case.
- doublec 15y agoThe response from linode says that it was a "a customer support interface" that was used to access the account. This seems to indicate an error in their support system rather than someone guessing slush's password.
- darklajid 15y agoYes, the writing is a little incoherent. Maybe that's the reason that caused you to miss that, in fact, someone used Linode's 'Customer Service Representative' interface to get access to his account. Don't stop reading and comment with 'I call bullshit'.
- liquidsnake 15y agoThe OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscriber for services during the period damages occurred. In no event shall Linode.com be liable for any special or consequential damages, loss or injury. This also provides an interesting dilemma when it comes to such events. In this case the damage is relatively easily quantifiable, he got X bitcoins stolen so the damage is X times the bitcoin value at that time. Still, it could have easily been user personal data or credit card information, which would have made an evaluation harder to make. One of the risks of using such a platform I guess and something that anyone who does it should consider.
- eli 15y agoThis is somewhat off topic, but just because the TOS says something doesn't necessarily make it true.
- clarkmoody 15y agoThat is very interesting indeed. Holding Bitcoins in a wallet on your server is the equivalent of having actual cash on your server. When someone takes it, there is a definite value of the damages vs. ID theft where the damage could be drawn out over a period of time. As I consider launching my own Bitcoin business, I have wondered about where to host the bitcoind that serves as my business bank account. This event certainly makes me reconsider just any VPS.
- mindstab 15y agoThis especially seems hard to certify. Bitcoin aims to be quasi anonymous. Users could just log into their own systems and transfer coins to another anonymous wallet elsewhere and then try and claim robbery. Or be rooted (by say script kiddies) and then take advantage of that, transfer coins, and try and claim for them. They end result is something like bitcoin would seem nearly impossible to insure for in any reasonable way. Isn't this akin a bit to storing a bag with $12K in a storage locker in a public space and then asking to reimbursed after robbers broke into the locker and stole the bag. I think the author is hoping for way too much. The world doesn't work that way, nor probably can or should it.
- mindstab 15y agoHow did the attackers know what they were looking for. I'm going to assume that it's a small minority of linode users who have bitcoins on their machines. How were just these users targeted so accurately? What tied together knowledge they used bitcoins to those VMs and their linode accounts? Also, was the nature of the attack just that the were able to login to your linode admin panel and from their root the machines and then loot your wallets?
- 3pt14159 15y agoSimplest answer is probably the right one in this case: Someone at Linode did it. Ran a script to see how many bitcoin files there were on all the machines (they probably do these types of queries for anti-virus/whatever anyways) and took a customer support password to log in and get the coins. If he did it right he still might be working there, as it is easy to get credentials from friends/coworkers (even though it should be really really hard).
- trotsky 15y agoPretty sure there is a default port that accepts connections as part of bitcoind, so you can just portscan for it.
- ajross 15y agoI'd be very surprised (and suspicious) if they were running any kind of diangostics over their customer's data without an explicit signed contract. The liability worry there alone is scary.
- gravitronic 15y agoyou do realize that in this theory, the same person then went and stole thousands of dollars in bitcoins, right? I don't think they were worrying about liability...
- ajross 15y agoYou misunderstand. Not the thief's liability, Linodes. If someone, say, engages in insider trading because of something they saw in Linode's own analysis system, Linode can be sued for failing to protect that information. If they have a policy of never reading customer data (and can prove it) that becomes much harder. The posited "anti virus checker" would throw that promise out the window.
- jaequery 15y agoi think bitcoin could use another layer of authentication to verify the person is indeed the owner of bitcoins.
- kirian 15y agoOne of the features of the next release of the bitcoin protocol is to allow things like multi-factor authentication (e.g. require a signature from the private key on your computer and your mobile phone before the bitcoins can be spent)
- icebraining 15y agoIn this case, there's no one to authenticate - it's an automated system that transfers bitcoins. If the application is able to send bitcoins, so is anyone with root over the machine running it.
- tantalor 15y agoIf this was sensitive data why was it not encrypted? Replace "bitcoin wallet" with "medical history" or "credit card numbers".
- regularfry 15y agoIt had to be decrypted to be used. It was in use. Ergo...
- singlow 15y agoIt had to be rebooted to reset the root password. I see no good reason not to have a decryption key held in memory and require you to log in and enter the key upon reboot for something this important.
- ben0x539 15y ago> Although passwords are stored using SHA1 with a salt, Where's the bcrypt/scrypt/whatever police in this comments thread?
- aidenn0 15y agoI already asked in the comments of the original article how many rounds of sha1 are used. SHA-1 still isn't the best, since it yields to FPGA attacks, but a single round can brute-force all 8 character passwords in less than 2 days on a GPU. My guess is that 10k rounds of sha-1 would probably not be feasible for non-dictionary attacks without specialized hardware.
- clarkmoody 15y agoThe article mentions salted SHA-1, which is much more resistant to attack. Obviously, more rounds and unique salts per user would yield better results, regardless of the hashing scheme employed.
- pork 15y agoYou can salt all you want, but an 8 character password with a single round is going to fall very, very fast. Salt, being public, has nothing to do with it.
- mappu 15y agoIt does however mean you have to spend two days per password, rather than two days for the entire user base, or ten minutes with a pre-existing lookup table.
- getsat 15y agoNo, consumer GPUs can do almost a billion SHA1 hashes per second now. We're talking seconds to minutes for "complex" passwords, not days. http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/
- opendomain 15y agoI know that bit pin is supposed to be annonomous but is there any way to get these back? I mean is there some logs or if they were signed by his account or anything?
- wmf 15y agoAll Bitcoin transactions are publicly logged, but they aren't reversible. So you can see who stole your money but you can't do anything about it.
- jQueryIsAwesome 15y agoThere is a bunch of violent people who would disagree.
- kijin 15y agoOnly if those violent people can locate the thief's physical location, which they can't.
- sdrinf 15y agoAs a Linode customer, I'm really looking forward to hearing out their side on this issue
- thisduck 15y agoThe title reads like a title one would expect from the future.
- shirro 15y agoLinode compromised! That is important news that concerns me. If the headline didn't mention the BitCoin scam that HN is always pumping would it have made it to the front page? Certainly haven't heard anything from Linode :-(
- icebraining 15y agoSigh. Please give me a definition of 'scam' that fits with bitcoin and not e.g. Apple or Google shares. Hint: In a scam, there's deceit. The bitcoin devs never deceived anyone. The whole system is transparent, so if there's anyone who bought without understanding the risks, they have no one to blame but themselves. (Note: No, I don't own any bitcoins).
- shirro 15y agoPerhaps I am just cynical. I did not mean to suggest the devs were scammers. But I still believe the ecosystem as a whole reeks of pyramids and other scams and I am sick of reading about it. I also think Scientology and MLM are scams but there are people who think they are not and we can't all agree. But then I also think casinos and lotteries are scams so I am kind of outside mainstream opinion on a few things I guess.
- icebraining 15y agoI was probably too harsh, but frankly, just as you're sick of reading about it, I'm sick of every single thread on bitcoin having that inaccuracy. What can I say, I'm literal minded - the misuse of words annoys me. But I still believe the ecosystem as a whole reeks of pyramids and other scams Oh, sure, that's kind of inevitable, it's a result of the lack of constraints and oversight. But personally, it's a part of why I like reading about it - it still has that feeling of a "wild west", populated by pioneers and thieves. Kinda like the Internet as a whole a few decades ago. Of course, it also means I wouldn't trust it with my money. I am sick of reading about it. Sorry, but then... why not just skip the link? There are a few topics I'm kinda sick of too, but I just ignore them. But then I also think casinos and lotteries are scams so I am kind of outside mainstream opinion on a few things I guess. Again, my literal mind jumps when I read that ; ) I can completely understand that you consider them immoral and/or predatory, but there's no need to call them a scam particularly - FSM knows there are plenty of other immoral acts.
- javascriptlol 15y agoThe attitude that Linode should refund the loss is a fragilising attitude. The more trust you keep pushing onto the provider the bigger everything is going to blow up when something goes wrong.
- Pent 15y agoThis reminds me of a situation when I first signed up for linode... my password on my account inexplicably changed one day(I use lastpass so no I did not type the randomly generated password wrong). I contacted support and they fixed it, but I still remember questioning why or how...
- mootothemax 15y agoThis is obviously an unacceptable incident. I don't understand how the author can write: Especially upsetting is that I went to great pains to keep everything as secure as possible. When that's plainly not true. Surely having a wallet stored on a VPS is a really bad idea, what with admins potentially having full access to hard drive contents? Wouldn't a PGP'd local copy be a better solution, or am I missing a trick?
- larrys 15y ago"As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation." "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operations" you need a more secure solution and process which will cost you more money. Under no circumstances can a hosting provider assume the liability for something like this. The tradeoff you make for the low cost you pay is that you might have an issue like this because someone screws up. You pay more for a safe to store your money (and for a safe deposit box to store your valuables) because it's important and you understand the risk involved in not doing that. If you have valuable jewelry many times the insurance company will only insure if you keep it in the safe when you are not wearing it and even the amount of days is specified when it can be out of the safe. It's unreasonable to expect (and linode's contract clearly states as other's have mentioned) a hosting provider to have a liability over what you are paying them. Edit Add: Unless you specifically have an agreement in advance or that is what they promised or charged you for. Before anyone reacts to this with any harsh criticism please think for a second what liability you would want for any mistakes that you make with your web startup or idea. You could either be charging zero or charging a small $5 to $20 per month charge. You might make a mistake. Are you willing to accept and even be able to insure for thousands or even millions in liability for those mistakes?
- dave_sullivan 15y agoIt's certainly a grey area, but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked? Say this happened to Amazon and it affected a company like Heroku or dropbox, both users of AWS? Regardless of what terms of service says, I'll bet there's some liability somewhere. And if there's a cut off, maybe linode should advertise that? "Hey, we're cheap, but you get what you pay for!" rather than "You're getting ripped off if you go with amazon over linode!" If a bank gets robbed, I'm not liable for the cash they steal. But how about if I've got cash in a safe deposit box and someone uses a fake id to get into it, and the bank doesn't recognize the fraud? That's trickier. And if someone robs my house and I've got a bunch of cash under my mattress, that's another story too. I know the analogy doesn't quite hold up because it's kind of like a bank and a customer engineering a safe together (eg both could be at fault for a break in), but there's got to be some responsibility on Linode's part.
- RLG_RLG 15y agoPlease people (not corporations w/ staffs), do not run critical systems in the cloud. Get a dedicated server (not cheapest you can find) and secure it with: (install in this order) APF - http://www.rfxn.com/projects/advanced-policy-firewall/ http://www.rfxn.com/projects/advanced-policy-firewall/ BFD - http://www.rfxn.com/projects/brute-force-detection/ http://www.rfxn.com/projects/brute-force-detection/ rkhunter Ideally, install rkhunter on fresh system, right after updates, APF, & BFD. Then update the binary check-sums with this command, if you know server is secure: Update file properties: # rkhunter --propupd --sk Run a system check to make sure it is known clean: # rkhunter --check --sk Lastly, sign up for the security alert mailing list for your version of linux on your server. If you want maximum security, be sure to password protect your boot loader and use an encrypted file system. This will make it very difficult for ISP to work on your server however!
- bigiain 15y agoAnd, I'd add "if any of this is news to you, you should _seriously_ question whether you're skilled/competent enough to be admin-ing publicly accessable servers with files (like bitcoin wallets) that can be valued in the thousands (or tens or hundreds of thousands or more)".
- ceejayoz 15y agoShipping syslog offsite is a good step, too.
- shirro 15y agoI am off to store some cash in my car and put all my important docs in a bus locker. BRB.
- nazgulnarsil 15y agonot having your wallet separately encrypted means you're asking to be robbed.
- dedward 15y agoWithout passing too much judgement........ it's common sense that as your revenue goes up, the time and effort put into ensuring you are on an appropriate platform should go up as well. Because sh*t happens...... whether we like it or not. Even if the technical requirements are light and it runs fine on a tiny linode, that might not be the right place from a security or integrity point of view, depending on the value of the app. (for me, a digital wallet worth that much, I'd want at my home..... where I can control it)
- beedogs 15y agoLOL, bitcoin.
- ropable 15y agoFor those of us late to the Bitcoin idea, how does one "steal" Bitcoins? Is it the equivalent of copying someones private key and then deleting all their copies of the key?
- wmf 15y agoGenerally the thief copies the wallet (private keys) and transfers the BTC to his own account. It's not necessary to delete anything.
- marshray 15y agoOr just copying the key and "spending" it before anyone else can.
- mckoss 15y agoNo, you use a stolen private key to transfer the Bitcoins to a new public key whose private key is only known to the thief.
- dale-ssc 15y agoWe install a little script that runs at boot up to page us if /.expected-reboot isn't present (or removes it if it is). Then, to reboot systems, we run expected-reboot, which is a tiny script that touches /.expected-reboot before calling shutdown. Wouldn't have prevented this but would likely have paged this unfortunate soul when his machine rebooted unexpectedly.
- sgornick 15y agoBitcoinica just reported losing 10K BTC (worth $50K USD) in this same incident. - http://bitcointalk.org/index.php?topic=66961.msg778254#msg778254 http://bitcointalk.org/index.php?topic=66961.msg778254#msg77...
- SkyMarshal 15y agoSaw that too. In past discussions on HN, Zhoutong said he hosted it at Heroku, but apparently they keep the 'hot wallet' alone on Linode instead for some reason, and use that to enable instant withdrawals. At least Bitcoinica is eating the loss, it's not client money that was directly stolen.
- kylebrown 15y agoUpdate: the Linode compromise first reported was that of the "slush" mining pool (mining.bitcoin.cz), reporting a loss of 3094 BTC. Second report was the donation-funded bitcoin faucet, reporting a loss of all of its 5 BTC. Third report is the biggest, Bitcoinica.com which is arguably the second-largest exchange. Their main site is hosted at rackspace, but their 'hot wallet' was hosted at Linode, and contained 10,000 BTC which were stolen.[1] 1: https://www.bitcoinica.com/posts/warning-please-do-not-re-use-and-old-bitcoin-deposit-addresses https://www.bitcoinica.com/posts/warning-please-do-not-re-us... EDIT: Those not following this incident on the bitcoin forums might be amused that the attacker used the stolen bitcoins to form a transaction with a size of 1337 bytes. That's probably not a coincidence, since the size of bitcoin transactions are usually under 1kb. http://blockchain.info/tx-index/2893660/d9804de366aa4c2a01565c3a3c8aa2ea20baafc276dc875f80b9044841205333 http://blockchain.info/tx-index/2893660/d9804de366aa4c2a0156...
- brandoncordell 15y agoIt sucks that money was lost but I can't help but to shake my head at someone keeping something like that on a cheap VPS. It's just stupid to think that was at all safe. That's something you should do on your personal computer where you can assure your security. I'm not really sure if the author of the article expects to be compensated but if so, he's dreaming. Just read through their terms. Next time he won't be so ignorant as to put something so sensitive on a server like this.
- rubypay 15y agoCould this have been a vulnerability in Lish, which can be run from a browser using Linode's AJAX console? http://library.linode.com/troubleshooting/using-lish-the-linode-shell http://library.linode.com/troubleshooting/using-lish-the-lin... I've completely ruined networking and disabled root logins on a Linode VPS, but could still access that same VPS as root using Lish.
- cpt1138 15y agoUpdate from linode: http://status.linode.com/ http://status.linode.com/
- bbit 15y agoWow, Bitcoinica lost 43,554 BTC from Linode compromise! - https://bitcointalk.org/index.php?topic=66979.0 https://bitcointalk.org/index.php?topic=66979.0
- ianloic 15y agoWhy the fuck are people putting their bitcoins on servers that they don't control? That's just stupid.
- motters 15y agoThe lesson repeatedly not being learned seems to be that it's not a good idea to keep wallet files on other people's servers, where you have no control over their security process.
- cookiecaper 15y agoHow many times does something like this have to happen before people learn to encrypt? Any serious business or financial data should be encrypted, period. Almost all of the major hacks we read about could have been minimized if not entirely avoided if the data was encrypted. I just read the release from Bitcoinica where they explained that the server accessed contained _only_ Bitcoinica's "hot wallet", and that no code, services, customer data, or other wallets were stored on the server. If this was the case, why couldn't every access to that wallet, which, assuming the above is true, necessarily occurs on other servers, run a decryption on the file first? Even if you keep the passphrase and/or secret key in plaintext on the machines that run the code, the separation should prevent this kind of rogue access as long as the intrusion is isolated as these people claim. There is really no excuse just to have a plaintext wallet sitting around anywhere anymore (the official bitcoin client now supports symmetrical encryption). Like credit card numbers, when a wallet is accessed it should be decrypted in ethereal storage like RAM and promptly discarded; it should never hit disk as plaintext. At least the same practices used for PCI compliance and credit card data should be used for btc wallets; preferably better since there is no recourse if your btc wallet is compromised.
- pavelkaroukin 15y agoI do not believe implementing something like you describe is viable right now. Although, AFAIK, bitcoin 0.5+ support keys encryption. I am not sure if this available only through GUI or through API as well, but even if it is not available through API, it might be good idea to implement.
- cbs 15y ago>If this was the case, why couldn't every access to that wallet, which, assuming the above is true, necessarily occurs on other servers From the sounds of it, this was that other server. All it did was operate on the wallet. And if they used other servers, then those would have been the target of the attack. And, no matter how much damn encryption they have, they rooted the box that operates on the decrypted data, thats game over. The only attacker you would be able to thwart with more encryption would be the one who is able to root a linnode VPS, but unable to extract the key or decrypted wallet from from software running on that box. Sure, there is probably some number of attackers in that space, but security is a game of diminishing returns, and there are different security measures to take that are a much better investment of time than stopping that small slice of people.