6 ms·
Bitcointalk Server Compromised
- CyberShadow 11y ago> Somehow, the attacker got KVM access credentials for the server. [...] After he got KVM access, the attacker convinced NFOrce that he was me (using his KVM access as part of his evidence) and said that he had locked himself out of the server. So NFOrce reset the server's root password for him, giving him complete access to the server and bypassing most of our carefully-designed security measures... Ugh. We need to remember that social engineering your ISP, hosting provider, etc. is a very real attack vector. Do not trust them. Reminds me of the "N" twitter username story: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
- h1fra 11y agoStrangely, the N username now look likes a legit account. Or is it the same guy? https://twitter.com/n https://twitter.com/n
- jimlei 11y agoHe got it back like a month later. Just browse back in N's twitter feed (late february 2014)
- nadams 11y ago> convinced NFOrce that he was me > So NFOrce reset the server's root password for him So a couple of things: I do my hosting with gandi (moving away from self hosting as Comcast business is...well anyways...). I had setup TOTP with their service and my phone died and I lost my OTP key (lesson learned - always backup OTP keys - hint gitlab developers...). I had submitted a ticket and they called the number that was on the account and had me answer a few questions. I don't remember what the questions were - but they weren't certainly "can you reboot this server?". The simple fact that the company used that as verification should be a red flag. Here is another red flag - why does the hosting provider have the ability to reset a VM's root password? Gandi states that in their FAQ that they won't reset the root password - though they give you instructions on how to do that. Though if he had access to KVM (through virtsh or virt-manager ?) he could have easily reset it himself (which would require a reboot). Perhaps he wanted to be discrete as possible?
- sytse 11y agoGitLab CEO here, I don't understand the hint, when you set up 2FA on GitLab we give you backup codes to recover, but that might not be what you mean.
- ah- 11y agoWhat's the best way nowadays to protect yourself as a user against this? You certainly can't trust anyone to store your password securely, so you're forced to have a strong password per site, and it's impossible to memorize that many passwords. I'm currently using Password Hasher (https://chrome.google.com/webstore/detail/password-hasher-plus-pass/glopbmohkffbnplcjbbbfmmimfhfnhgd https://chrome.google.com/webstore/detail/password-hasher-pl...), but that only works well because I mostly use just one machine.
- yuvadam 11y agoUse a password manager. KeepassX is a good choice if you only trust yourself (and your backups). LastPass and 1Password are good choices if you don't care about letting others host your (supposedly encrypted) passwords.
- imrehg 11y agoThumbs up for KeePassX too! Also, there's Mitro, encrypted password manager living inside a Chrome extension: https://www.mitro.co/ https://www.mitro.co/
- mannkind 11y ago> LastPass and 1Password are good choices if you don't care about letting others host your (supposedly encrypted) passwords. That statement doesn't apply to 1Password; AgileBits does not host your data.
- becausecomputer 11y ago1Password works with Dropbox, unless you manage the storage and backup manually.
- tetrep 11y ago> 1Password works with Dropbox... Because it has the amazing feature of storing all your passwords in a file. It's nothing like the features offered by lastpass with respect to serving you your passwords from a remote host and if you can't trust your password manager to KDF & encrypt then you really shouldn't be using it as it's doubtful it's properly generating secure passwords.
- tedunangst 11y ago> The forum will pay up to 15 XAU Somewhat interesting that the bounty is not priced in terms of Bitcoin.
- colinbartlett 11y agoXAU is ounces of gold so the price of 15 ounces is about 18,000 USD at the moment.
- weinzierl 11y agoIf it would be priced in terms of Bitcoin it would make the bounty less attractive for a lot of people. Bitcoin is highly volatile and not everyone believes it will rise. 15 XAU is by the way currently around USD 18000.
- firethief 11y agoThe bounty is to be paid in Bitcoin anyway; I don't see how your attractiveness explanation is applicable. The problem with setting the price in Bitcoin is the volatility: someone with information could attempt to time their contact with Theymos to maximize their bounty. This could significantly delay revealing the information, if the bounty claimant felt the price were temporarily in a slump, and could cost Theymos a lot more than expected if they got lucky.
- scanr 11y agoAnyone know what this table means: 1 word 0 2 words 0 3 words 0 4 words 3m 5 words 19d 6 words 405y 7 words 3My Does it mean that if your password contains only 4 words, it 3 minutes to crack regardless of the words? Is https://xkcd.com/936/ https://xkcd.com/936/ bad advice?
- desantis 11y agoThis threw me off as well, I think you are suppose to use the first chart if your password was generated randomly and the second chart if you used words. I am not 100 percent sure though.
- TheLoneWolfling 11y agoThat XKCD comic is good advice. But use a long enough passphrase. Also, he's being (very) conservative. In other words, he's assuming a very fast password cracker. Roughly speaking, he has a wordlist of ~8070 words, which works out to ~13 bits of entropy / word. Which implies at 3My to crack 7 words he's assuming ~26 trillion (!) password hashes per second. That's potentially realistic if you're using a fast hash - but you should be using something that's slow (and memory-constrained) for a password hash.
- DanBlake 11y agoDoesnt the english language consist of 500,000-1,000,000 words? * http://www.merriam-webster.com/help/faq/total_words.htm http://www.merriam-webster.com/help/faq/total_words.htm
- TheLoneWolfling 11y agoYes. But most of them are far too close to each other to remember easily. Or relatively not used words. It's (generally) easier to just use a longer passphrase and a shorter wordlist of only relatively common words.
- deleted 11y ago[deleted]
- hobarrera 11y agoI've had Digital Ocean reset a VM on a different account (a client's) just by asking politely from my own account (not impersonation or anything alike on my part). While it was helpful on that occasion, it should probably go completely against policy to do stuff like this.
- cpach 11y agoOuch. That makes me wary of using DO.
- mzjs 11y agoThis is an issue with all providers, though. It's not specific to just DO.
- toxicFork 11y agoOf course. The weakest link seems to be customer support when it comes to security.
- cpach 11y agoYep. That’s why it’s so crucial that these companies try to adapt solid guidelines in order to minizime the risks of social engineering attempts.
- nadams 11y agoI wouldn't say all - but many. However, there is always more than one way to skin a cat. Gandi states that they won't reset it - but offers instructions on how to do it [1]. Which, presumably if you are spinning up VMs the owner of the account should get an email notification. [1] - https://wiki.gandi.net/en/hosting/gandi-expert/change-root-passwd-in-expert-mode https://wiki.gandi.net/en/hosting/gandi-expert/change-root-p...
- grubles 11y agoYou literally only asked politely? I feel like there was at least /some/ sort of info you had to provide.
- crobertsbmw 11y agoInteresting that he says, "If your password is not completely random (ie. generated with the help of dice or a computer random number generator), then you should assume that your password is already broken." 1) When he says "dice" is he talking about physical dice or something, or is there some protocol called dice that I am not aware of? 2) I feel like even though a computer generated random string isn't completely random, that it could still be effective. Could someone elaborate on this a little bit more? What if you do tricky things like concatenate multiple random strings together? What about functions like urandom (I'm pretty sure that is truly random.)?
- imaginenore 11y agoYes, he is talking about real dice. He comes from Bitcoin security point of view: don't trust anything. Dice, being physical objects outside of computer networks can be trusted to a pretty good degree. When it comes to creating something random on a computer, it's actually incredibly hard to guarantee randomness. Most RNGs are black boxes or are so non-transparent that they might as well be black boxes. You might have an idea how your *nix /dev/random works, but can you actually guarantee your OS is not compromised? Can your guarantee your BIOS is not compromised? Can you guarantee that your hardware is not compromised? That's why if you want a truly secure Bitcoin cold storage, you generate a wallet offline using something like dice or coinflips (dice are quicker).
- Dylan16807 11y agoI don't quite follow your logic. You still need an airgapped computer to turn those random bits into a working address, don't you? Is there a way to do that by hand? Is it more likely that the RNG is compromised than the bitcoin software?
- imaginenore 11y agoYes, but you have eliminated one vector of attack - a faulty or compromised RNG. > Is it more likely that the RNG is compromised than the bitcoin software? 1) That's a weird question. It's not like they are mutually exclusive. Both are possible. Dice allows you to eliminate the RNG problems. 2) http://en.wikipedia.org/wiki/Random_number_generator_attack#Prominent_examples http://en.wikipedia.org/wiki/Random_number_generator_attack#...