Inputs.io hacked – 4100 BTC stolen
inputs.io
inputs.io
https://bitcointalk.org/index.php?topic=283756.msg3505394#ms...
And would insurances insure this kind of business ? Now are bitcoin wallets banks ? and are they subject to the same regulations ?
Is that guy a US citizen ? can he be sued by his clients ?
Bitcoin is a relatively new thing, would not be surprised to start seeing bitcoin insurance for these types of services.
> Is that guy a US citizen ? can he be sued by his clients ?
I think it would depend if his clients have contracts, otherwise its a caveat emptor deal, especially when dealing with bitcoin.
(A large part of the Euro crisis was the Euro central bank refusing to backstop banks itself, delegating that to national central banks which can't print money and can therefore run out themselves)
Insanity.
This should have been pointed out long ago. It's a terrible thing that people get away with this. Arrogant developers who think they can do without sysadmin skills when building crucial software.
It was. The creator smugly relied that it wasn't going to be an issue.
UPDATE: Correction - according to [4] it seems that almost all funds were stoled in the hot wallet, and the hacker was "nice" enough to not steal it all at once, presumably to stay undetected and come back for more. I'm not sure if I buy this argument though.
Also, according to the owners the hack occurred on 26th October [2]. It may be possible that if you deposited funds after that date you will receive full refund, as they should still be on their wallets. Unless hackers took that too.
UPDATE: Also according to [4] the funds that were being deposited after 26th were being withdrawn at the same time by other users. So they're as gone as the ones from before 26th. You will be refunded in full only if you deposited very recently.
This whole situation (and a bunch of previous ones) is also why at Bitalo [3], we are developing an exchange which will not have this problem, as we use multi-signature addressees to store the coins. This means that you need two signatures to spend funds - one from us, and second one from the user. We also never transmit users password over the wire, as we use SRP protocol for authentication.
In unrelated news, China just passed 1800 CNY per BTC :). I wonder how's the security status of chinese exchanges/wallets. Unfortunately I don't know the language, so can't test that.
[1] https://bitcointalk.org/index.php?topic=248803.msg3505884#ms...
[2] https://bitcointalk.org/index.php?topic=248803.msg3505966#ms...
[3] http://bitalo.com (in private beta, drop a message to martin@bitalo.com to receive an invite)
[4] https://bitcointalk.org/index.php?topic=248803.msg3506034#ms...
Also, it's a shame that this kind of breach happens, but it seems like it's been a while since a "$COMPANY hacked X BTC stolen" headline was out there[1]. There seem to have been more of those in the past and they appear with less frequency, which is a good thing, I guess.
[1] Silk Road doesn't count toward this recollection, since it falls under the "Bitcoin $COMPANY busted by the feds" headline, which will probably happen more often in the future.
From what I have read the current Fed stance is - if you think BitCoin is money, we are ok with that as long as you comply with all regulations.
For anyone who wants to get their missing BTC out of inputs.io (who doesn't), I've written a blog post here: http://bitcoinreviewer.com/inputs-io-hacked-refund/
Um....I don't see how anyone is okay with this answer.
No thanks, I'll stick with insured deposits. Imagine if your bank called you up and said "Your money is gone, but we're reeeeeally sorry."
[1] https://bitcointalk.org/index.php?topic=248803.msg3509247#ms...
https://bitcointalk.org/index.php?topic=111563.msg1208770#ms...
Coinlenders is a sister site to Inputs that share the same wallets. Coinlenders funds are being re-distributed to Inputs wallets. I obviously made a good decision to leave Coinlenders when I did as Coinlenders users are going to get perhaps 40% of their invested amounts back.
What really should happen is the owner (Tradefortress on BitcoinTalk) Should use his own massive stash of Bitcoins to compensate all his users.
That said, if I recall correctly, one case where the corporate veil can potentially be pierced in a lawsuit is negligence. IANAL, but maybe users would have a legitimate case against personal funds, assuming keeping a large percentage of deposits online was found to be negligent. It'd obviously be an incredibly complicated and expensive class action suit if it were to happen though. Also it would probably mean trying to bankrupt a guy who just got hacked and lost his company...
Perhaps this is illegal already - under local handling of stolen goods laws. People would likely be inclined to take up this policy were there a single case of legal enforcement.
I believe this would lead to a stable situation where those known-stolen bitcoins were worth far less than regular bitcoins.
The present loud reaction would become irrelevant. What's more, I believe it would benefit bitcoin to remove some of the danger of (irreversible) theft.
That said, tainting is not a path we want to go down. The potential for abuse is enormous, and rendering more and more coins useless.
Think transaction into a bank account : you cannot separate the money that was transfered in from what was already there.
We can taint accounts, but not individual coins.
Say there's a 50 BTC untainted wallet, and tainted 1 BTC is transferred in, then 1 BTC is transferred out. How do you decide whether that outgoing 1 BTC was drawn on the tainted portion or the untainted portion of the account?
If all transactions are public, in theory you could trace user, who has your bitcoin now. Than you could sue him to get your stolen stuff back.
tl;dr - both.
https://www.bitcoin.de/en?cr=1
https://www.bitstamp.net/
https://btc-e.com/
https://www.bitfinex.com/
https://localbitcoins.com/It's also safer because it seems the government isn't likely to setup a major investigation for the case of BTC "theft".
(I say "theft" because it is possible, but unlikely, that the owner of the wallet transferred the money to someone intentionally, to pay them or something.)
"Security + privacy The most secure wallet ever created."
Best advice I've read so far about bitcoins. All these services that's started up around keeping bitcoins for you, wallets, banks, they are all dodgy and no matter how well their marketing seems or how nice their webpages look, I think in the end - I'd like to keep my own money.
That said, it is fascinating to watch people getting caught out when they have a "few dollars" in BitCoin and now its "a few hundred thousand dollars" suddenly the security requirements change dramatically. One would hope that would be bitcoin wallet holders are taking notes and things like daily security audits are the new normal.
Considering hacks like this take time and a fairly high level of sophistication, not sure the FBI would want to employ the amount of long term resources needed to hunt these guys down.
[Edit to add: For avoidance of ambiguity, I'm really, really, REALLY not suggesting that "Since banks are equally insecure, bitcoins are a great idea." Of greatest interest to HN readers, if your bank has a security fumble and your account is debited $25,000 as a result of this, you will almost certainly be reimbursed for every penny of that post-haste.]
That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hacks against us.
We aren't perfect, of course. But these monkeys are barely on the same planet, never mind in the ballpark.
If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?
What I mean is, if they implement a new whiz-bang feature, the best case is that people complain a bit less. But if their new feature opens up an attack vector or social engineering opportunity, they may suffer serious financial loss and very bad press.
Heck, First Direct is one of the better banks in this country, but their website popups deliberately hide browser chrome including the address bar, which is just obviously terrible for security. But that's something that must have been deliberately added.
1. The standard "enterprise problems": strategic partnerships dictating toolsets and so on.
2. The standard "big company problems": many business units acting as fiefdoms who will be arguing over how much real estate they need on customer-facing channels.
3. Tensions between customers who are scared of "money" and "online" and want everything locked down vs customers who want the latest whizz-bang everything.
4. Regulations.
5. Customers spanning a range from high-value rural farmers with vast sums of agribusiness who are stranded on dialup (yes, they exist), customers who do their banking on whatever their work PC is (XP and IE6 is still a thing - out biggest surge of the day is the 9 am rush when people log in from work to do their banking), through to customers who want the latest and greatest HTML5 webbery.
Saying, "fuck it we only support WebKit and high speed internet" is not really an option.
But no one's gonna stop them from using it, and if you're the receiver, you wouldn't care where it came from.
One could imagine people still choosing to trade in these Bitcoins, but that such a penalty would forevermore reduce their value next to "unshunned" coins. Could legit businesses and people using Bitcoin collectively reduce the value of stolen Bitcoins in this fashion to discourage it without directly discovering who misappropriated them...?
Also, this is ignoring the entire problem of 'who decides what stolen means in a totally decentralized protocol?' That's non-trivial in and of itself.
It's a democracy. If the masses decide that Blockchain.info is blocking coins that weren't stolen for some nefarious reason, they can just ignore their warning.
The question is: do the majority of bitcoin users even care if they are using stolen coins?
It'd likely be along the lines of anti-spam lists. You might have one that's high-profile thefts or seizures. For that matter, these lists could be political, issue-based, or whatever.
It's ridiculous and unlikely to be followed if taken out to the extremes of issue-based disputes, but I don't think it's impossible for a significant number of people to agree not to transact in stolen Bitcoins, some on principle, some as self-preservation (the exchanges), and most because their utility is reduced by the first two groups refusing them. This also happens to increase the value of untainted Bitcoins.
This is the mechanism I always thought the feds would use to go after bitcoin. "Possession of stolen property" - My understanding of the law in my area is that I am breaking the law if I possess stolen property, even if I can prove that I obtained said property legitimately and even if I couldn't reasonably be expected to know that said property was stolen.
What if the feds decided to apply the same thing to bitcoins? I mean, what if you legitimately obtain bitcoins that are, in fact, stolen property? Or bitcoins that were used in a law-breaking transaction?
This is wrong. Every single transaction is saved, by everyone. It's the core of how the protocol works.
That doesn't mean there aren't ways to obscure who controls the wallets, but it's not untraceable, and 'distributed' has nothing to do with privacy.
This is my biggest reservation about bitcoin - they have taken the worst attributes of paper cash (pretty anonymous, not tied to a verifiable identity), and replicated them in a digital currency. If I'm transacting with someone I want to know who they are, in case of fraud or theft. People even openly run money laundering operations (mixing), and the community put up with it! In contrast, most people never store large values of money in actual paper cash anymore, they store it in a bank, which has identification and laundering checks, proper tracing of accounts to identities, immediate yet reversible transactions, and compensation if money is stolen. Bitcoin doesn't come out well in that comparison.
The other reservation I have about it is the lack of regulation - these exchanges which hold the money of lots of people are not regulated as banks are. No-one knows exactly what security they actually have (as opposed to say they have), sometimes people don't know who's behind them (I remember that 17 year old from Singapore talking here about starting one[1]), and there's no protection against market manipulation, speculation and cornering, or it seems against online theft. Given they have become so valuable so quickly, you can be quite sure the market is heavily manipulated, perhaps even in advance of thefts like this in order to gain the maximum benefit. What is the cause of the huge recent spike in prices for example? If bitcoin is to work as a currency and a store of value (the traditional roles of money), it does need regulation and verification, but I find it hard to see how that would come about, given the lack of a central authority and the lack of will to deal with incidents like this.
I'd love to see a digital currency that tried to emulate the advantages of digital cash, while doing away with the ability of a central government to print the currency ad infinitum - that's the big downside of our current state-backed currencies - it seems Bitcoin is not that currency.
I think the important part that's missing is this:
If you have the proper opesec, BTC is anonymous.
The 'BTC is anonymous' meme does nothing more than help people who don't know what they're doing get busted. It's like Sarah Palin's email account getting hacked because she picked security questions that were well-known. Even if you're not doing anything nefarious, you may want to keep certain transactions private. "BTC is anonymous" means that some people who don't fully understand how BTC works will be doing things they _think_ are private but actually are not.
And if you think people know how BTC work, just examine this thread.
About the lack of regulation and verifiable identities - that's the allure of it :) It's not just the lack of inflation, it's the whole "Wild Wild West" atmosphere :) Like, remember the Internet before the old people and politicians found out about it?
*simplified view Wallet 1 stores 50 bitcoin for(i = 1; i < 100000; i++) { Transfer 1 bitcoin from Wallet i to Wallet i+1 }
At this point, wallet 100000 contains exactly 1 bitcoin, that every transaction can be traced back to wallet 0. I understand that you would include more wallets, varying values, etc. But the point is every one of those bitcoins can be traced back to the original wallet which has the stolen funds.
The only way to make this behavior viable that I can see, is to have intermediate services that mix up funds.
So you have 50BTC Stolen funds in Wallet A. I run Wallet B, that takes transactions from many people. You give me the 50BTC that is stolen. I send you 50 bitcoins in small increments randomly over a set period of time, but from the other transactions I have. I do the same for other people, using the 50BTC that you sent me.
As such, my service mixed the coins through a common point, which now makes tracking the chain very difficult. If I didn't mix this with other people's transactions, and gave you back you're own coin numbers, the coins would just track through me back to the original stolen wallet.
This would need a party to offer this type of service, with enough volume to obscure the source, and for that service to not keep records (or not be inspected through other means).
Again, I want to re-iterate, my knowledge of bitcoin is somewhat superficial, so don't take this as an authoritative post on the subject.
They're called 'mixers.'
> Again, I want to re-iterate, my knowledge of bitcoin is somewhat superficial, so don't take this as an authoritative post on the subject.
You've got your head on straight. Here's one small aspect you're missing: there's no connection between a person and a wallet, and there's no transaction costs, so just make a million wallets and send random amounts to each one, and then send them through a mixer, and then to each other some more, and then to a mixer....
If these unfortunate folk knew their internet security they would know better than to pump their money into random internet wallets, despite claims that it's the "most secure wallet ever created".
"Everyone should learn to write" does not mean that everyone is an author.
HACKDOO (TROJAN) = $1100 Can steal information from any computer, informations like username and passwords, other account login details and credit card details.
VAMPIRE 3.5 = $200 Helps in hiding your ip unlimitedly. you can use any ip address you want
SOFTWARE BUG WESTERN UNION VERSION 2013 = $900 Western Union Bug is a software that cracks Western Union databases and gives the DATA of Western Union infomation for payment made to any country in the world. It scans the Western Union worldwide database and gets you MTCN from any country and city you choose just within 20 Minutes of clicking on the button start hack The Western Union Bug 2013 version comes with two types of Activation code, the first 20 digit activation code logs you into the first panel whereby you do fresh transfer while the second 20 digit activation code logs you into the Western Union database You can also use the software to make a fresh transfer by also scanning out a Western Union agent logins and using it to make a transfer to any Western receiving country in the world It is easy to use. And make quickly countries such as Africa, EU, CA, AU. TEACHING FEES BUY BANK HACKING SOFTWARE
I will teach you Hacking 3 months with all softwares for $3000 Become a hacker today. Contact me Odidollarsman@gmail.com
Bank transfers are now available to the following countries : USA UK EU Canada Australia Russia Singapore Dubai Vietnam
$2,000 - $10,000 per transfer to Personal accounts (Checking accounts, Savings accounts, Current accounts, Standard accounts) Transfers over $10,000 are available to Business or Corporate accounts only
Same day service to UK/USA/EU/Canada/Australia - 1 to 2 business days service to Russia/Dubai/Singapore,
Contact: odidollarsman@gmail.com
Bitcoin's digital fungibility, which will always be a curse to some, will always be its greatest virtue. Distrust is one of its most valuable effects. Respect it or don't respect it. That's up to you.
> The attacker was able to bypass 2FA due to a flaw on the server host side
Which flaw is this? Is it a known issue for Google? I would like to know more details.> flagged as stolen
That would imply some sort of centralized authority to decide exactly what 'stolen' means. Even if a third-party service kept track, it'd be meaningless in short order, as mixers exist...
When the client sends the address the change is returned to a new change address, and the wallets are being designed now to never reuse addresses.
So it would become very hard to determine which of the outputs are change addresses and in the same wallet.
In other words, each time a coin changes addresses there is a plausible deniability for the owner of the receiving address that s/he received the coin as a result of a legitimate transaction (sale of goods/services, donation, whatever)
Blockchain.info has tagged it as inputs.io hack. And a couple users have tagged it as well with public messages. But besides that, as far as I know, all anyone can do is watch it get drained.
[1] https://bitcointalk.org/index.php?topic=248803.msg3509247#ms...
You bought into a system where coins could be permanently lost because you forgot a password.
You bought into a system where the government cheerfully gained control of a large share of the market by simple confiscation.
You have recreated money. But you aren't even good at it! You still think that simple cryptography will excuse you from the fact that you're greedy bastards.
The reason I hate Bitcoin is that it intentionally promotes a counter-establishment treatise, and you have the batshit insane gall to claim that it is different.
I'm venting.
As opposed to a system where coins can be permanently lost because you have a hole in your pocket?
It's nice to see you.
It's easy to permanently lose cash, too.
You're stuck in a place where you're trying to differentiate yourself from Wall Street and you are exactly like Wall Street.
And then you compare the total BTC in circulation and its equivalence in USD... and...
What the fuck do you think you're doing?
Do you think you're toying with trillions of dollars?
The banking machine is ignoring you. It simply doesn't care.
You can permanently lose cash if destroyed in a fire.
Your cash or bank account can be confiscated easily by the government.
Etc.
Of course, unlike cash, Bitcoin has advantages because it offers the option to prevent these losses: you can back up a Bitcoin wallet. You can avoid government confiscation (password-protected wallet). Etc.
How about digital cash?
Also, Bitcoin can be confiscated by the government, along with the computer/server it sits on (see silk road). A $5 wrench or a jail cell will deal with your encryption. You can also permanently lose it if someone copies your wallet/backup and then spends it particularly while it is on one of these exchanges - that's because transactions are not reversible or traceable to a verified identity.
Technically, I think Bitcoin sounds really substantial and love the idea of creating/spending keys which avoid government inflation, but the axioms on which the usage is based are all wrong -
I've never lost money in a fire, and never will. I don't want to avoid government confiscation by technical means (which fail), I want to avoid it by law. I don't want to be able to launder money (or for others to). I don't want my transactions to be anonymous and to have no central authority and no accountability when theft/fraud happens.
Not if you specifically want to prevent this. A bitcoin private key is 256-bit ECDSA, which provides 128 bits of security. If you can remember a 10 word randomly generated diceware phrase[1], you can securely store bitcoins in your brain.
[1] calculating the private key as a SHA256(phrase) for example
Somehow, I don't think the government will leave you that option ;) You'll stay in prison and have the means to use the bitcoins confiscated or outlawed. They can also confiscate all your other assets, like the house your family lives in.
There are many options available to a sovereign government which mean that relying on purely technical measures will not defeat them, because they have a monopoly on force, up to and including lethal force.
Implemented correctly, it's much much more difficult to steal or seize than cash while at the same time being much much easier to smuggle to places with no extradition where money trumps the rule of law.
Just declare this person an enemy of the state/terrorist and there you go - to you and your encryption.
If he does I'd be very surprised if he can ever spend it, even if he does somehow get to a copy. Torture is not the only or most effective avenue to thwart encryption or your plans to keep money from them, they could claim enough back-taxes to bankrupt you, repossess anything you buy etc, etc.
You also have scenarios that are not as drastic, where the adversary is not a government but, for example, a powerful (ex-)spouse trying to seize some of the assets in illegal ways during a divorce going wrong. Etc.
Your refusal to acknowledge this usefulness of Bitcoin makes your criticism look weak and one-sided.
> permanently lost because you forgot a password
You don't have to encrypt your wallet, that's up to you. If you believe that not even knowing the password of an encrypted wallet you should be able to recover your bitcoins your problem is actually with cryptography in general.
> the government cheerfully gained control of a large share
Powerful entities have power, welcome to the real world.
> the fact that you're greedy bastards
huh? can you expand on this?
> it intentionally promotes a counter-establishment treatise
Nop, Bitcoin is a technology, and neither the paper nor the Bitcoin Foundation is "counter-establishment". Actually the last one is trying really hard to make Bitcoin "pro" establishment.
Sorry I don't wanna be rude but your post is absurd.
But I don't see how it's relevant - this is a site about start-up news and Bitcoin is exactly where the opportunities for start-ups are. It's not like they're posting porn or something - probably the next PayPal will come from someone reading these links and comments here.
Although I admit that sometimes there are too many links about politics on HN, but you can say politics is also kind of relevant to the start-up world, especially when it concerns policy decisions about technology.
In conclusion, I'm yet to see an irrelevant link on HN. The algorithm works as advertised IMHO.
However I think your dismissal of Bitcoin is wrong. Not because it doesn't have flaws, and not even because it's guaranteed to succeed—there's no telling when a crypto breakthrough could cause Bitcoin to crash and burn faster than tulip bulbs—but rather because Bitcoin is the most interesting development in currency of the past millennium. There's simply no denying it has unique properties of considerable interest, regardless of ideology or affiliation.
Imho it represents and inflection point in human history, by virtue of solving a previously unsolvable algorithmic problem (distributed consensus), at least in the context of digital currency.
BTC's solution wasn't even technically possible until two other major innovations - the construction of the internet, and the invention of the Bittorrent protocol. And 'Satoshi's' insight that a simple time delay via proof-of-work finally tied it all together and made possible the first (technically) viable distributed currency.
All the remaining problems are minor by comparison and will eventually get solved, in the same way the modern banking system eventually solved problems of bank robberies and fraud - not so much completely solving them, but by making them extremely difficult to pull off and/or get away with, reducing the odds and risk to levels acceptable for the general public. Same will happen with BTC and its infrastructure over time as well.