3 ms·
Andreas is the CSO of Blockchain.info, a site which takes client security seriously enough that they never touch their client's private keys, rather than "handi
by Adlai 13y ago
Andreas is the CSO of Blockchain.info, a site which takes client security seriously enough that they never touch their client's private keys, rather than "handing out IOUs to their users"; maybe we'll see a rise in adoption of this approach.
- olalonde 13y agoBlockchain is just a wallet though. Many use cases (e.g. exchanges) require a trusted third party to be in control of the coins. I agree that there is no reason to hold coins if your use case doesn't absolutely require it.
- maaku 13y agoThey've had some pretty horrible mistakes with respect to security though (before Andreas' time though, so no reflection on him), and the basic model of a web wallet is inherently broken...
- nwh 13y ago20 rounds of PBKDF2, there's tears in my eyes.
- novaleaf 13y agowhat's so wrong with 20 rounds of pbkdf2? I don't know of any attacks that can defeat it in realistic time spans.
- nwh 13y agoA KDF is meant to slow down dictionary attacks by introducing a lot of computation. Normal values might be in the hundreds of thousands, even millions to bring the computation time down to less than a few a second on extremely high powered GPUs. 20 rounds has so little impact it's astonishing they even bothered to load the KDF library. Attacking encrypted files like this would be very fast for a motivated person, and when we know there's magic internet money involved there's a lot of motivated people.
- novaleaf 13y agodoing 20 rounds in a browser represents a non-trivial amount of work. that's much better than nothing, as it helps defeat existing rainbow tables. iirc, 1000 rounds will take a however as you suggest, on the server side, I would expect them to use a much higher 10k or so round count.
- sillysaurus3 13y agoMay I ask, what are some examples of the security mistakes?
- nwh 13y agoThey left people's wallets with "aliases" open to be cracked by anybody who found them for years, messed up their RNG and revealed some users private keys, a few XSS mishaps, and their support reset 2FA keys for hackers with social engineering.
- nerveband 13y agoa.k.a. they made mistakes and then remedied the problem quickly without much controversy. Sounds like the opposite of another trading firm that just collapsed. These sound like mistakes that many beginner companies can easily make when trying to craft them. Why is there a demand for perfection out of the gate? And why are offers to remedy the situation not given the same kudos?