The Looting of ShapeShift
news.bitcoin.com
news.bitcoin.com
Building a security system to handle this level of attack is a whole level beyond stopping even determined external attackers. Are there any best practices guides on this?
One thing that the article showed is the importance of external security review to deal with the threat of internal incompetence or evil.
Despite all the theoretical advantages of blockchain over conventional banking protocols, they are not doing categorically better than banks at avoiding major losses. Although, the numbers at http://www.risk.net/operational-risk-and-regulation/opinion/... are shocking.
I'm not aware of any, but we did have quite a lot of procedures meant to mitigate this sort of things when I worked in banking. For one, none of the developers had any sort of access to production machines.
"Damn you, you've betrayed our trust and prevented us from building a world where we didn't have to trust people..."
There's a load of practices that are designed to stop this kind of problem in that world.
Things like :-
- Enforced holidays. Frauds are hard to maintain when you're not there to keep cooking the books. - Audit reviews. an independant function with the ability and authority to review key processes - split authority. Key actions need multiple people to complete (statistically fraud incidence drops a lot when you need multiple people involved) - Strong background checking. When I worked at a bank they went back 10 years of employment history and required accounting for any gaps. + credit checking + criminal record checking etc.
It's all possible, just quite expensive...
Hire at least 2 or 3 people for every job. Have them watch each other whenever touching systems that connect to production or deploying code to production. Never trust any one of them with the private keys or passwords to anything - they can only get half of a secret and their co-worker gets the other half.
To do this effectively, you have to build a zero trust environment, and rely on surveillance to ensure that nobody is a bad actor. It really makes CIA/NSA level security look somewhat weak.
It's also very expensive, as you can imagine.
This is actually the key one - the more people who need to be corrupt, the harder it is to get away with being a crook. A surprising amount of internal fraud can be completed simply by requiring people to take solid blocks (2 weeks plus) of leave every year.
That "inefficiency" the "lean 10x disruptors" congratulate themselves over does not always end well.
But at a job where the ideal is automation, rather than manual verification and analysis, I wonder what additional obstacles must be placed in a potential attacker's way? Rotating keys based on employee schedules? I'm sure there are many well-studied ways to do this, but it's interesting to armchair analyze.
I've heard that's because a lot of those scams/tricks fall apart without constant gradual intervention, so an important part of it is that the employee is prevented from accessing most work-resources during that time.
We learn some more things. Bob has prior police records in Florida, where he’s from.
So they didn't even do a background check before hiring "Bob"? For a position where he would have access to systems that handled financial data? That's just grossly incompetent, in my book. I've worked for 5-man startups and Fortune 500 companies. In every case, the offer letter has stated that the offer is conditional on the successful completion of a background check, and none of the positions I've held have been remotely as sensitive as the position that Bob was hired for.As that last suggests, however, only certain roles are eligible for the checks, those being primarily roles that involve working with children or vulnerable adults, though the full list [0] is quite interesting.
[0] https://www.gov.uk/government/uploads/system/uploads/attachm...
Since Bob hasn't been criminally charged with anything, "outing" him is legally "libel". He could sue, and win.
Let me guess, YANAL? In USA, it ain't libel unless it's provably false. If "Bob" could prove that, why did he run?
At my humble and refreshingly drama-free place of work we have standard client images. Anything weird and the techies re-image the client. Assuming 'Bob' wasn't in charge of the images, would such a procedure have sorted the rdp?
The larger question was why did Bob have root access to people's individual laptops? He could have done a "snowden", grabbed their SSH keys including passphrases. That would have been much harder to detect.
Bob sucks.
When you hire IT people, have no clue how distinguish between a good one and a fake one, in other words have no clue, this happens.
Also not enough oversight and auditing admins when money is involved is a bad sign.
I always love the irony of people so against the basic social contract are always so quick to turn to authorities when things predictably go wrong.
http://www.newyorker.com/humor/daily-shouts/l-p-d-libertaria...
He was the first to [nominally] move a bitcoin business out of New York when the bitlicense was enacted.
And when liberals talk about Ayn Rand? It's like she's the worst depraved demon ever. But if you read some of her quotes, they're kind of motivational. Sure it can be a little too selfish, but I know a lot of people who would benefit if they internalized that THEY are the main driver in their own lives, rather than playing victim their whole life. http://www.goodreads.com/author/quotes/432.Ayn_Rand “If you don't know, the thing to do is not to get scared, but to learn.”
I've been watching the Rubin Report b/c Dave Rubin is a liberal that will actually fucking sit down and talk it out with someone on the otherside. Great show. https://www.youtube.com/user/RubinReport
Too soon?
From Rubin's wikipedia page https://en.wikipedia.org/wiki/Dave_Rubin
"regressive left"
The regressive what? According to Rubin, there's a bunch of liberals defending atrocities done in the name of Islam.
I'm just about the most left-wing person I know, very involved in politics, and no one I've met is an apologist for haters.
Edit: Okay. I had to watch a Rubin episode, just in case. Because you know, he might not be a whackjob. Chosen randomly:
Julie Lenarz and Dave Rubin: Brussels, Terrorism, Immigration Crisis (Full Interview) https://www.youtube.com/watch?v=bLfxJPJDzMo
I stopped at 1:20 when he stated that many on the far-left endorse terrorism. Which is apparently the intellectual equivalent of when conservatives paint all Muslims as terrorists.
No worries. Just added Rubin to my ever growing twit filter. Thanks for the tip.
http://www.newyorker.com/humor/daily-shouts/switched-standin...
I have to say I quite enjoy that writing style.
BTW, currently looking for an Senior Infrastructure and Security Engineer/Manager position at a company that handles large amounts of money.
Why is the author being so nice to the theif over and over again? Even the last sentence!
Eric brought this all on himself. Obviously 'scared' and intimidated to discuss important things WHEN they need to be discussed.
Doing everything out of order -- like the background checks -- is a classic rookie move.
You are basically running an Online Banking Website. You need to be aware of immense risks...
...it just goes on and on. But its clear why there is so much drama, crime and corruption and this company.
Sad really. Who is to blame?
This is pure and simple Mr. Voorhees (CEO) incompetency. After all, Bob is a criminal and he was just doing his "job".
[1]
Despite our note to all employees to come into the office urgently, Bob, our head IT guy, the one responsible for security and infrastructure, arrives at 11:30am.
Soon after, Bob decides it’s time for his lunch break, and we don’t see him for an hour, during the worst incident in ShapeShift’s history
"Of course it's my fault. There's no-one else here who could possibly be responsible for anything".
The whole subtext of this was "Here's how I fucked up in leading this company", but then the actual text is causality. It is his responsibility to make sure employees are trustworth? Yes. Is he the cause of employees abusing trust? No.
He then also determined that his responsibility was to let people know what had happened, so that's what he did. He told us the things they used to figure out what happened in order to attempt (and fail, and then attempt again...) to prevent it from recurring.
Everything should be fully encrypted such that even a breach of trust from the hosting provider would not compromise your data/funds. I know this is hard to do, but it's mandatory when you're handling digital currency.
If you don't want to trust your hosting provider with anything, you have to own the hardware.
Because they control the hypervisor, they control everything. That means they have as much access and authority as the code that you are running on their servers have. So the only way to protect yourself from them is to limit what your servers (deployed on their cloud) can actually do.
So for instance you could have a secure backend server on a dedicated host in a trusted environment, with the cloud servers using an API to the backend server. If the API is suitably secure then the cloud servers could be compromised without allowing them to directly issue invalid commands in the same way the backend server could. Then you could use the cloud to scale out your web frontend without compromising yourself.
The same is true of hardware on the dedicated host (such as the "Trusted Computing" Module) that you do not control. If that (or the BIOS) gets compromised you might not even know that your host is no longer secure.
There's always the in-memory vulnerability, which is harder to mitigate, but requires an attacker with physical access to the hypervisor, so it's much more difficult to execute (as most meat-space hacks are).
edit: Bob didn't betray you. Your friends and family betray you. Bob stole from you.
I mean, that's baseline treachery right there.
I like shapeshift and have used it a bit. If you(generic) hate them, alt currency, or the CEO, I think it is fair to say that Bob is pretty shitty. Yes there are sociopaths and criminals everywhere. If you have met a sociopath in real life, it isn't simply a myth that they are charming and appear normal. So I agree with the sentiment that you should expect bad things at your company, but you seem to imply:
1. it should have been obvious Bob was a criminal
2. Bob is blameless?
2. This is a religious question. Whether Bob goes to hell or not is irrelevant to whether you've done your job well. Bob's responsibility was to be a good criminal. The CEOs responsibility was to be a good CEO. Both of them failed.
edit:
"If you have met a sociopath in real life, it isn't simply a myth that they are charming and appear normal."
It's absurd to diagnose someone as a sociopath because they steal from you. The problem is not that there are thieves in the universe, it's that you handed one the keys to the henhouse. That they lie about it, and manipulate you, is evidence that they are rational, not that they are crazy. If you feel betrayed by people other than your friends and family, you have boundary issues. Blaming your own failures on others is a good way to repeat the same mistakes over and over again.