More than $215,000 stolen from Bitcoinica in Linode incident
bitcointalk.org
bitcointalk.org
Seriously, trusting ~$200 000 to the security of a general-purpose VPS provider? With no failsafes of any kind? Ever notice how real banks don't do that? Even if you don't want to build your own data center, you could at least chat with http://www.thebunker.net/colocation/ or another properly-paranoid data center.
At least these guys didn't leave all their Bitcoins on this machine...
I run a Bitcoin site that keeps a very small percentage profit out of a relatively large amount of coins in and out, which have to be held in trust for customers. Not only is our bitcoin daemon not running on our webservers (it's got its own dedicated box with all unnecessary ports closed and a vicious denyhosts policy that's locked me out more than once), we also set up low limits to immediate withdrawals so that no more is stored in the hot/withdrawals wallet than could be withdrawn immediately by players currently online (usually no more than $250), with all larger withdrawals processed in batches on demand. That lets us offload the excess coins to another wallet as soon as they're deposited, so in the worst-case scenario we might lose a couple hundred bucks. The cold wallet is stored in a truecrypt archive on a thumb drive in my pocket, with an encrypted backup stored on a server in a third country, manually, with each batch transaction. Moreover, a lot of our funds are moved out into USD and held for safekeeping to avoid excess Bitcoin risk.
This is why banks keep their money in a safe, not in the little drawers in front of the teller. And no offense to Zhou, but this should have been the obvious step to take from the beginning. Hopefully they'll do it now.
And they stole from at least 3 systems. One had $5; one $15 thousand, and one had nearly a quarter $million. Which makes me curious why they bothered with the $5 account at all. It's like robbing a bank, and stopping to smash a gumball machine in the lobby on your way in or out.
My guess is that the attackers have a fully automated exploit payload that transfers the bitcoin out. And ran it on every system they could get on, indiscrimitely. So this is not a one-off. I'd be very cautious about running the bitcoin daemon, at least without setting noirc=1 in its configuration.
http://blockchain.info/tx-index/2893660/d9804de366aa4c2a0156...
Is there taskforces that recognizes this? or is it just the wild west?
And yes, it is like the Wild West. That's part of the point of BitCoin, there are no chargebacks, and no-one can freeze your account. Once the money moves, the money moves. This has disadvantages if you are the victim of a theft (like this) and you're bitcoins are essentially gone.
The NSA is a US Governmental organisation. I don't they are available for private tenders.
However there are loads of private security companies.
This reminds me of a tangentially related incident where government servers were physically stolen by people dressed up as technicians. Even if you co-lo a dedicated server, if you store enough coins there, it becomes an attractive target for an attacker with some inside help.
Keep in mind that:
1) IO is expensive
2) the file will not be encrypted
3) the file will/should not be hosted on the same machine
4) the file will be accessed in excess of 1,000,000 times a day; maybe more.
The only thing I can think to do is do all the transactions with imaginary bitcoins until the end of the day then, at night, push all the transfers; almost like banks do.
I can't think of any huge disadvantage to manually managing the float on the transaction server.
This also removes features of bitcoin that some view as advantages, namely that there are no chargebacks and no-one can forcibly remove your funds. In bitcoin, once you have it, no-one can take it from you (unlike, say, paypal). This has disadvantages if you're the victim of a theft. Bitcoin is also a decentralised system, so you'd have to convince everyone that you are the victim of a theft, and that these transactions are to be rolled back. Other wise someone could pay for a service in bitcoins, then try to get everyone to roll back the transaction, and hence deprive someone of the bitoins.
http://www.fdic.gov/consumers/consumer/information/fdiciorn....
Individual cash deposits are also guaranteed by governments in most countries.
Bitcoins are not controlled by any government or central bank, but neither are they backed by one. And here we see the downside of that trade-off.
http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-...
In that case, the customer was demanding repayment of lost money, alleging the bank's security was negligent, and the bank was basically asking the court to say "it's not our fault somebody got his username/password".
And your summary was flat-out disingenuous; you presented it as the bank suing the customer, when in effect it appears to be the bank seeking a court declaration that the bank's own security measures were not at fault, as a response to the customer's claims against the bank.
(and clearly bitcoin is the polar opposite, based on capabilities and being irreversible, for now)
(http://news.bbc.co.uk/1/hi/technology/4072704.stm)
But a later case said that virtual property should be protected by law:
(http://news.xinhuanet.com/english/2009-05/24/content_1142726...)
Dutch authorities arrested someone for virtual theft:
(http://news.bbc.co.uk/1/hi/7094764.stm)
Here's another Dutch case, involving real world violence, which went to their supreme court:
(http://madisonian.net/2012/02/01/dutch-supreme-court-decides...)
That last one mentions US case about domain names.
I'd be really interested to hear from previous US court cases, or from lawyers, about this.
I don't recall the details, but I think there was another case (in a Starwars MMO?) where the hacker "got a way with it" and build a house for the money. His buzzer plays the games theme-music :)
I can't see how Bitcoins would be treated any differently. They're property, and they can be readily traded at an established value, so I don't see why someone couldn't be charged for stealing them.
The judge will make a limited effort to understand Bitcoins, but the core question will remain, "what harm was done and who was it done to?" The "owner" of the Bitcoins was, unquestionably, deprived of value.
So see it however you wish: Bitcoins as tangible property that was taken, or Bitcoins as tangible property that was irreparably damaged. Either way, the judge will ask the same question. Who was harmed and how?
Escaping the conclusion that the attacker's actions are responsible for the loss of value is impossible. You can bet that the State will consider these arguments very carefully if they catch the perp and bring charges against them. From there, it's up to the defense to find a jury so dumb that they'll buy the "Bitcoins aren't property" argument.
Regarding the arguments relative to video torrents, I believe this to be an error in logic. If I copy a video from a friend, that friend can continue to derive the original value from the video. That is, the friend can continue to watch the video and enjoy it. The act is different in that the original holder of the Bitcoins can no longer use them once they have been "copied" (to use your terms).
I'm pointing out the obvious. X bitcoins could be "worth" 5 cents or 500,000 in a matter of hours. Bitcoins were stolen not dollars therefore an accurate headline would say how many bitcoins were stolen and possibly the USD (or whatever) value parenthetically.
"You aren't dumb enough"
Stay classy.
"to actually believe that something people trade for real dollars has absolutely no value."
I never said it had no value. Baseball cards have value, no one pretends they are a currency and if anyone did people would rightly point out the many disadvantages like your baseball cards don't get the advantages of a real bank.
So could your US Dollars.
A fiat currency only has value as long as other people are willing to accept it as payment for various goods and services. That willingness is based on the belief that they, in turn, will be able to exchange the currency for other goods and services at a later time.
The same principle applies to bitcoins. But a cryptographic currency like bitcoin has advantages that USDs don't. For example that massive amounts of bitcoins can't just be whipped up "out of thin air" like paper money can.
The reason you're being called out for condescension/trolling is because the point you're making is entirely irrelevant to the discussion. Is Bitcoin a real/valid currency? It doesn't matter in the context of this theft. What's relevant is the value of those Bitcoins at the time they were stolen. That's how matters of theft are assessed. Criminal charges are levied based on the value of the items stolen.
Another thing to consider is the thoughtlessness of discussing the relative merits of Bitcoin as a currency when someone just lost a couple hundred thousand dollars. Someone's life is sucking really hard right now, and pedantry is a great way to put people off. This just seems like a really inappropriate time and place to have that discussion.
I just can only hope the attacker spends the BTC instead of burns them: burning would do far more damage to Bitcoin than just stealing them.
Yet another man who wants to punish honesty? They could claim that the attacker used the proper user credentials to login on the server and nobody would be able to disprove that.
>They have a track record of having security issues
Please, provide a proof-link.
>they are not PCI compliant;
No credit card credentials have been stolen. It's that bitcoin service kept the keys insecurely. Bitcoin transactions should be signed on a machine w/o public access from the Internet (1) and have a threshold for transactions which have not yet been reviewed manually (2). Having these two practices implemented they would lose not more than that threshold (say, $1k-$5k).
>and unless they replace every single last BTC, I am going to just go ahead and state they never did care about their customers.
I have not heard about such a practice in the digital world. Nobody can make a 100%-secure system. But everyone can stay honest and improve security when a vulnerability has been found.
They're a VPS host. I mean, cats aren't PCI compliant either, but it doesn't say much.
You shouldn't be using a VPS for this sort of thing for many reasons, mind you.