Bitfloor Hacked, $250,000 Missing
bitcoinmagazine.net
bitcoinmagazine.net
One of the benefits of using a major bank (in the United States, for this example), is that your money is federally insured. You'll always see little logos or blips of text advertising that the bank is a "member, FDIC."
People take this for granted -- after all, if your bank is robbed, why should it be your loss? It's a little harder when the currency is anonymous and completely uninsured.
Many bitcoin exchanges will do their best to dip into their profits to reimburse users after they were hacked. I know that several major exchanges have already dipped into their own coffers to reimburse their users. However, they need to pay for this completely out-of-pocket, and even then there's nothing that indicates that they have to do so.
I think that bitcoin is an interesting idea, and certainly has gained a lot of traction for more privacy-minded individuals. Those that want to active day-trade it, though, should stick to standard forex markets, in my opinion. In fact, there is nothing to guarantee that the organizers of an exchange won't simply steal your money and disappear -- there'd be no way to prove that it was them, short of seizing their machines and hoping an incriminating bitcoin wallet was sitting there.
As a sidenote, the previous comment trumping up the FDIC is kind of misplaced. Government is needed for some things (like police), but not insurance.
From the article:
"BitFloor may take one of two options. They may either take the loss and continue running in an attempt to eventually earn the money back or, in the worst case, shut down entirely and begin an account partial refund process out of the available funds."
I assumed that "federally insured" was code for inflation, but the wikipedia article revealed that it is actually insurance: banks pay insurance fees to be in the FDIC.
> if someone breaks into your online bank account and steals all
> your money, legally you're on the hook unless you can prove the
> breach occurred on the bank's side.
Right, but that's not a valid comparison to what happened.If someone broke into your account, yes, you'd need to dispute the charges and prove that you did not drain the funds to your new Swiss bank account.
In this case, though, it's not an account that was broken into, but the exchange itself. If someone robs your bank at gunpoint or hacks into its backend servers, either way, you're not liable for the loss -- they're insured.
Individual security vs. organizational security are different in this respect. In fact, I'd argue that the individual security of bitcoin exchange accounts are even riskier than the exchange itself getting hacked: if your bitcoin wallet is compromised in any way, that money is gone forever. No one can do anything to get it back, and if the exchange wasn't compromised, they probably don't care about your terrible password (or malware-infested laptop, or compromised Internet connection, etc). If your bank account is hacked, and you report it, it's not your problem anymore.
If someone physically robs the bank and gets away with a large amount of cash that is arguably even more anonymous and non-traceable than bitcoins.
The only problem ought to be that bitcoin exchanges are not being insured, by who or that the currency happened to be bitcoin doesn't matter (as long as the insurance covers it).
Bitfloor admits to earning about $2100 a month. So it's a totally unregulated market, and it'd be easy to increase your earnings by 100x this month. During the time the wallet was left in an unencrypted location, just happened to get hacked.
I can't call the Bitfloor owner a thief, but reading his posts about looking to the future, and not to the past, no claim of a police report being filed, and the generic term "We got hacked!" make for some obvious conclusions.
(Even when not comparing them to other bitcoin ventures, which tend to set a very low bar.)
Another reason I doubt they would steal it is because "cashing out" now would be like Zuckerburg cashing out a year after starting Facebook. At least, from the perspective of someone who believes in bitcoin.
<shakes head>
What is with these bitcoin exchanges and their pathetic records on security? How is the currency ever supposed to go mainstream with these continual security lapses?
Those banks are often guarding a considerably larger amount of money, which is something to take into consideration. I think your point still stands though.
Meanwhile unregulated, nimble BitCoin exchanges struggle with the OWASP top 10.
So while the complexity is there, it's not clear to me that it correlates to an "attack surface" in the sense network security people use the term.
The true flaw of hacker attitude is underestimation of the job by focusing on the part that looks straightforward, namely the part in code.
A bitcoin bank is the application. The bit that's written in code is just a part of it. The actual spec is: under all circumstances, this will either work as a bitcoin bank, or fail safe, or in the worst possible case fail with data loss. That spec requires you to examine the behaviors of the system as a system - you may be sure your opponents see it as such.
And insuring bitcoins has its own logistical challenges that will probably scare an actuary.
Trust is a hard one as I'm sure the people who used bitfloor had trusted it until today.
A digression: Bitcoin would be the government regulator's wet dream if you could assign people addresses (and they could only use the assigned address), because you can trivially track all transactions. Actually, I have in mind a way to implement such a system in a (likely) cryptographically sound and enforceable way. But in theory, the government could outlaw cash and track all transactions anyway.
2) Feed your stolen coins into the service and make sure that the rate of this isn't too high
3) Profit (if someone asks you have the perfect excuse)
And in case you argue "using money from such a mixer service is suspicious": It doesn't have to be a mixer service. Use one of the numerous Bitcoin casinos. With the right games you can expect to win around 90% or more of the money that you've invested. And if you're lucky the coins that you get from the casino are different than the ones you paid them.
2. Announce you were "hacked"
3. Profit!
They should also allow users to check incoming transactions against this blacklist and reject them if they choose. I suppose you'd end up with a black market of tainted Bitcoin, but that's better than just allowing thieves to immediately exchange stolen coins for another currency or legitimate services/products.
To answer your second question: This idea has been discussed at length on bitcointalk.org by a lot of people. The idea is known as "tainting." There are a lot of problems with making it work in practice, so the concensus seems to be "don't go there."
To give you a sample of the (IMHO valid) objections: For one thing, it's difficult to verify which coins really should be tainted. (How do you know someone claiming certain coins should be tainted is trustworthy?) For another thing, tainting creates two "competing" bitcoin currencies, black coins and white coins. Finally, there is no central authority, so it would be challenging (though perhaps not impossible) to come to a "general concensus" on who should be in charge of declaring coins tainted.
I'm currently not sure about weather this is partially to blame or not. Would a dedicated server have made it harder to access the machine?
CampBX has been in operation for over a year, is based in Atlanta, and has successfully cleared multiple independent Pen-tests and security audits.
Give us a try! www.CampBX.com