8 ms·
Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins
- 0x0 12y agoCould this be prevented by adding some TLS to the mining control channels?
- Filligree 12y agoYes. It's both hilarious and ironic that they didn't.
- smutticus 12y agoHere is the link to the original research. http://www.secureworks.com/cyber-threat-intelligence/threats/bgp-hijacking-for-cryptocurrency-profit/ http://www.secureworks.com/cyber-threat-intelligence/threats...
- cgjaro 12y agoUpvote the parent!
- mrb 12y agoI work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don't even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: http://blog.zorinaq.com/?e=67 http://blog.zorinaq.com/?e=67 http://www.theregister.co.uk/2012/03/02/linode_bitcoin_heist/ http://www.theregister.co.uk/2012/03/02/linode_bitcoin_heist... This means attackers had effectively root access to any Linode's customers' VM! When was the last time you saw an entire cloud provider environment being compromised? I like to see it as ISPs and cloud providers increasing their security and patching vulnerabilities thanks to Bitcoin's growing adoption :)
- blazespin 12y agoIt's a fundamental problem with bitcoin in that it hugely incentivizes computer hacking. The more widespread bitcoin and blockchain becomes, the greater the incentive. There will be a lot of collateral damage from all this.
- onewaystreet 12y agoThe same thing can be said about credit cards. If there is a problem with Bitcoin (and I'm not sure that there is) it is that unlike with credit cards there is no possible recovery of stolen coins.
- superuser2 12y agoConverting stolen CC numbers to cash actually turns out to be difficult since government and other authorities can revoke the cards, freeze fraudulent merchant accounts, and seize assets once they've hit your bank accounts. You have to mitigate all of these risks and won't always be successful. If you manage to steal Bitcoin, you can transfer it all to your personal wallet in one transaction in broad daylight and, by design, no one can stop you or reverse the transaction once it's discovered to be fraudulent. Maybe run it through a darknet tumbler for good measure, but you're basically home free the second you get the private keys. Stealing $100m worth of Bitcoin would be massively more valuable than stealing CC numbers with access to $500m in credit because you can actually cash out all of it. So much larger R&D budgets and more sophisticated attacks make financial sense.
- danielweber 12y agoThere is good research that indicates that the bottleneck in electronic bank theft is finding the endpoints that are irreversible (think ATMs). Doubling the amount of stolen credit cards wouldn't come anywhere close to doubling the amount of money stolen out of the system. With Bitcoin, every marginal theft adds 100% to the total Bitcoin thefts.
- 12y ago
- nchelluri 12y agoLink is a 404 for me.
- deleted 12y ago[deleted]
- kmod 12y agoThe finger-pointing at BGP is red herring: the problem is that the stratum protocol has zero authentication. If you can intercept those streams, you can trivially ask anyone to start mining for you instead. This could also have been done using DNS poisoning, ISP-side intercepts, or anything else in the standard bag of tricks. http://blog.kevmod.com/category/bitcoin/ http://blog.kevmod.com/category/bitcoin/
- bdamm 12y agoIndeed, for bitcoin it's a solvable problem, however let's not let that distract us from the monumental revelation that BGP hacking is so easy to do that someone motivated by a relatively paltry reward can pull it off. This is one aspect of bitcoin that I really like, it shows us where the weaknesses are.
- marcosdumay 12y agoYou're certainly not looking, because BGP insecurity is very old news.
- scott_karana 12y agoWow. Not sure why they don't name-and-shame the ISP, but that's really ridiculous.
- sergers 12y agoAs a Canadian, using a Canadian ISP, I would like to know as well. Not entirely surprised regarding rogue employee possibility.
- dfox 12y agoThere are two things at play here: attacker has to have access to one ISP to inject the route (eg. rogue employee) and there has to be another ISP that accepts such route from BGP (I would say that filtering weirdly specific routes is good and common practice). When you have access to ISP network you don't have to inject things into BGP to attack your own customers.
- devicenull 12y agoA /24 is not a 'weirdly specific route'. I agree, that the upstream should have been filtering things, but you can't expect them to just filter out all the /24's. For example, Google DNS anycast would stop working: http://bgp.he.net/net/8.8.8.0/24 http://bgp.he.net/net/8.8.8.0/24 as would basically anyone else doing anycast.
- tacoman 12y ago"the CTU research team provided the BGP evidence to the upstream ISP closest to the origin of the malicious activity." I think this likely means it's a smaller ISP.
- tbarbugli 12y agoJack Bauer will take good care of this issue
- deleted 12y ago[deleted]
- mickayz 12y agoThe lack of auth and encryption is only part of the problem with Stratum's implementation. At Toorcamp 2014 I presented about the vulnerabilities discovered when looking into common miners and their impact on the network. More details available in the associated white paper: http://www.dejavusecurity.com/blog/2014/7/15/bitcoin-research-whitepaper-announcement http://www.dejavusecurity.com/blog/2014/7/15/bitcoin-researc...
- rdl 12y agoIt's mind boggling to me that this wasn't done a year or two ago. If bitcoin were genuinely anonymous (it isn't, because it's highly linkable, even if essentially pseudonymous), it would probably be vastly more dangerous in this way -- there would be billions of dollars spent on exploiting security outside bitcoin++ to steal bitcoin++.
- runeks 12y ago> It's mind boggling to me that this wasn't done a year or two ago. Two years ago, obtaining the same amount of bitcoins as this attack did would net you 1/100th the profit in dollars (bitcoins were around $6 a piece two years ago). I think it's likely that attackers started considering this scheme around a year ago, when the bitcoin price shot up to $100, and the potential rewards became sizable.
- driverdan 12y agoI know a number of people who got hit by this type of reconnect attack. I suspect I may have been hit by it for short periods of time. Most of the big altcoin pools were targeted. Soon after most miner software was modified to disable this Stratum feature but there are still plenty of other issues with the Stratum protocol as highlighted by other comments.
- gluczywo 12y agoNobody has pointed it out so far. Since it is an attack on IP routing, it could be prevented by using SSL for the Stratum protocol used by mining pools.
- fsniper 12y agoWould it? With this sophistication and latest exposures of CAs security I'm not fully sure that TLS MITM is a remote probability.