Instawallet Hacked
notice.instawallet.org
notice.instawallet.org
Is this a joke? They can't be serious.
MtGox has even given away free YubiKeys in the past to help keep people's accounts secure. Does Chase or BofA anyone else offer that kind of security? :)
https://en.bitcoin.it/wiki/Cold_storage https://mtgox.com/press_release_20120215.html
There's nothing stopping anyone from setting up a bank that handles your bitcoin transactions, and therefore can reverse transactions between two parties.
Replace "Bitcoin" with "Dollar" and you see how strange your statement is.
Bitcoin is anonymous, so I could transfer my money to my account at another bank, report fraud, and the bank could never know unless the other bank told them. If the other bank tells them, or you set up a centralized register of transfers or accounts, you're just mirroring the current systems.
Bitcoin doesn't have The Man, so there's no motivation not to do so fraudulently - what's the worst that happens if a bank realizes you're trying to defraud them? You've already moved your money elsewhere.
Chase has a thing where it texts you a code as well.
Not to mention the costs that security brings, a friend of mine is locked out of what is now $50k worth of bitcoins, just can't remember the password on the encrypted store.
All of these wallet service companies employ people and many, many successful hacks are performed by exploiting the people involved / mistakes the people make.
So while software with enough hardening can eventually get to a state that's quite safe, as long as people are an active part of the security chain, you're going to have valid attack vectors.
It points out again how careful you have to be when suddenly there is "real money" on the line.
I've yet to see the "exit strategy" where an enterprising crook sets up an exchange and then loots it once its net value is high enough. But I would not be surprised to see that happen. It has happened in the brick and mortar world with banks, no reason it shouldn't be any different in the digital world.
Just an idea ...
Even the 0.8->0.7 reversal was hard for some miners to swallow. And in that case it was only accepted because only doubly-spent transactions would be reversed. Singly-spend transactions would just transfer over to the new chain.
I don't expect to ever see a Bitcoin fork where a cryptographically valid, singly-spent, included-in-a-block transaction is reversed.
Some merchants don't give a shit, AKA "it's your own fault if you get robbed," but lots of people don't like to help thieves.
It's been a while since I looked at the protocol -- can you "reject" a payment? Or return it?
If you're a merchant, you'd have to do origin tracing of the funds in all the wallets you accept. It's not as simple as just creating a blacklist, that would be very easily avoided. The only thing that might work is getting all miners to refuse to accept transfers from the "bad" address to ANY other address (good luck, that's never going to happen).
One problem is that bitcoin launderers could intentionally send a portion of stolen coins to legitimate wallets. That would make a blacklist difficult to maintain, to say the least.
And you should never assume you just got smart.
Another alternative is that the Instawallet people just decided to keep the "money" you had stored there, and retire to a small Caribbean island.
You'll never know.
Edit: Forgot to link to their guidance
http://fincen.gov/statutes_regs/guidance/html/FIN-2013-G001....
On a side note... New Business plan:
1. Setup an online Bitcoin wallet service 2. Wait a while till people actually trust/use it 3. "We got hacked"
Something tells me you're not the first to come up with this.
but i've seen people do worse illegal risk/reward decisions before. much worse.
People: Only keep an amount you are willing to lose in an online wallet. Keep the rest offline and encrypted.
If you are using it as a commodity to trade, well, it's perfect.
Unless you're about to buy a car or a house with bitcoin, there's no need to store tens or hundreds of thousands of dollars worth in an immediately useable (and hence potentially stealable) status.
No online wallets are secure, nobody should be using them, but unfortunately the bitcoin system is still a bit too complicated for a lot of people.
Honestly, I am curious if the security researcher (who alerted them to this problem and then griped out lack of payment in the article) is the person responsible.
I informed some BTC places of security problems a few years ago, and was roundly ignored, although they put the fixes in place, from what I recall. I wasn't upset because I wasn't expecting anything.
EDIT
Reading that page . . . depending on a URL staying secret as your security? Wow, that is asking for disaster.
I don't like to shame people who make security mistakes, but if you are online wallet vendor, shouldn't you have some common sense?
They did say so at one time or another I believe, but that was long long ago.
The Bitcoin industry needs bank level security. They're doing some things right (most exchanges offer 2FA), but they've got a long ways to go.
Law enforcement hired hackers to screw it and now awaiting at the front door to take a much closer look at everyone who'll start whining about lost funds. :)
Also, this is something that a smart and savvy government would do. If large governments are ever smart and savvy, they're only that in specific contexts.
1. It takes three months to get you BTC back, and only up to a max of 50. If you have more, it will take longer.
2. If the hackers can figure out your url and key, they can dispute your claim. If they actually get their claim in before your legit claim, their claim is favored.
Yikes. I would not want to be either an Instawallet employee having to sort that mess, or a client with their BTC frozen for months and potentially at risk of being stolen.
"Important information on claims submission:
For the first 90 days we will accept claims for individual Instawallets. Your wallet's URL and key will be used to pre-populate a form to file the claim.
After 90 days, if no other claim has been received for the same url, your Instawallet balance under 50 BTC will be refunded. If several claims have been filed for the same url, we will process those claims on a case by case basis, under the presumption that the claim we received first belongs to the legitimate balance holder.
Claims for wallets that hold a balance greater than 50 BTC will be processed on a case by case and best efforts basis."
A good look at previous thefts. The last page contains links to the current Instawallet issue.
There was mention of a missing/broken robots.txt which allowed GoogleBot to index them, but what I'm stuck on is how it learned about them in the first place; where they actually doing something utterly insane like autopublishing a sitemap, or was there some bug allowing g'bot to sniff/guess the URLs?
I've seen odd behaviour in my logs from google crawls in the past, like g'bot traffic within minutes of adding a new DNS entry/vhost to a domain, with absolutely assuredly no mention of it publicly available. I suppose it's possible they're watching DNS zone changes and scheduling a tentative probe, but it's a bit creepy (especially if you're disorganised and haven't got the robots.txt set up right away)
I personally keep my bitcoin wallet encrypted with GPG, I manually (like a safe) decrypt it when I want to make a bitcoin transaction and encrypt it when I'm done.
Faking a high alexa ranking may be possible, but faking a low alexa ranking is not.
You can't fake the fact that next to nobody went to instawallet.
You need to be the sort of idiot who runs feature-free bloatware before you can contribute to their ranking system.
Yeah it's only worth $1 800 000. Nothing to worry about.
Sources: https://blockchain.info/address/1LrPYjto3hsLzWJNstghuwdrQXB9... (btc amount) https://blockchain.info/stats (current price)
I'll add this to my list of things that people know they should do but are too lazy to take a few minutes and setup: don't repeat passwords, use a password manager, make regular backups, don't use GoDaddy.
Stop thinking you're the exception dammit, these things don't take that much effort to do properly.
I suppose someone could customize a small Linux live CD to boot, not touch the hard drives, load an encrypted wallet off a secure jump drive and encourage backups. It's fairly straightforward if you use a dm-crypted jumpdrive and, say for example, Tails.
You don't bootstrap a bank.
(Plus I did some basics with Bitcoin a few years ago and got pissed off at the protocol and moved onto less annoying things.)
Many (if not most) of the security vulnerabilites of the past years come from perfectly safe components assembled in an unsafe way.
Crypto-engineering is hard.
Blockchain.info can't touch my coins. But if there servers are compromised, a hacker could inject a tiny, tiny amount of JS and have my ID/password sent to... anywhere... and then the hacker could access my account. I'm curious to know how you'll get around that vulnerability.
Or, we can dispense with having DRM on hardware we personally won. How about a protocol for providing a secure bitcoin wallet in the cloud? Basically, everyone runs their own open source mini-OS in their own obfuscated VM (1), which a smartphone app sets up for you and to which a smartphone app only acts as an interface. The wallet information is never on the smartphone, and the DRM is never on your own hardware.
Such an infrastructure would have many other uses, not just bitcoin.
(1) The security of each VM instance would be on an economic basis. Each one might be breakable within a week, say, but the system could be set up in a such a way that the week old information isn't work enough to motivate the effort.
Because honestly, I don't actually fully trust myself. The chance is not negligible that I get a trojan with a keylogger that watches for me to open my wallet. So I store some of my coins online as a hedge against my own stupidity and the inherent insecurity of desktop computing.
I may, in the future, move a large portion of my coins into a fully offline (generated on a machine that's never seen the internet), safety-deposit-box stored wallet. But that's a little bit excessive at this point.
The weakest link is then DropBox + your BTC-client password. Or I guess if someone has modified the live environment on your jump drive or if they have a sophisticated attack on your UEFI/BIOS.
Thanks.
I like BlockChain. There's still an amount of trust and I can think of ways it could be compromised, but they do a pretty good job architecturally of preventing your loss in the case they're compromised (well, depends on how they're compromised)
Anyway, those instructions will give you a secure paper wallet and an account that will enable you to still check your balance through blockchain.info.
(Note, this method keeps your private keys on the paper wallet, and the public key with Blockchain which enables balance checking but prevents compromise via blockchain.info)