Bitcoin payment processor BIPS compromised, 1295 BTC stolen
bitcointalk.org
bitcointalk.org
The part that intrigues me is the whole security aspect of it. Take your average bright guy and say "Lets set up a place where people can store and move around gold coins. All the gold coins are going to sit in your living room, and of course if anyone were to get there hands on those coins they could melt them down into pieces and resell them so that you never knew where they went. There is going to be more than a million dollars worth of coins in your living room, do you think you're door lock is up to it?"
Ok so its a stretch, but Bitcoin has two interesting properties, one it is pretty fungible, and two most if not all governments consider it about as 'real' as the gold in World of Warcraft. If CFAA doesn't apply (say the server is outside the US) then what exactly would you even charge someone with who "stole" 1000 BTC? It isn't recognized as currency by any jurisdiction on the planet as far as I can tell, so what got stolen? Numbers? Block chain data?
This fairly unique combination of properties quite possibly make Bitcoin the ideal target for thieves. Better than cash, better than raw gemstones, better than pretty much anything except possibly bearer bonds [1]. Have you seen how much security there is around vaults that hold bearer bonds?
And yet people create exchanges or wallet services or whatnot and then seem shocked when they get compromised by very sophisticated programmers [2], that steal all their BTC? You are surprised?
Given these huge thefts where is the money going? I mean is there a steady stream of redemptions at exchanges? Is there a note in the chain when the coin is transacted for cash? Should there be?
[1] http://www.investopedia.com/articles/bonds/08/bearer-bond.as...
[2] When the payoff is huge, the risk small, you can pay someone a lot of money if they are good to get you the coins.
Or someone who runs an online wallet service with a privacy policy, who can pretend to have their hands tied when people ask where the money went.
Wrong: http://www.forbes.com/sites/kashmirhill/2013/08/07/federal-j...
"First, the Court must determine whether the BTCST investments constitute an investment of money. It is clear that Bitcoin can be used as money. It can be used to purchase goods or services, and as Shavers stated, used to pay for individual living expenses. The only limitation of Bitcoin is that it is limited to those places that accept it as currency. However, it can also be exchanged for conventional currencies, such as the U.S. dollar, Euro, Yen, and Yuan. Therefore, Bitcoin is a currency or form of money, and investors wishing to invest in BTCST provided an investment of money."
The key here is that the judge is trying to understand if the transactions involved met the standard of being an 'investment of money.' Which he reasons to by establishing that you can convert currency to and from BTC and you can buy products with BTC. He doesn't address the question of people who create BTC out of the act of 'mining' it. Let's say Van Gough was alive today, you could use his paintings as "money" in exactly the same way, except Van Gough could make new money just by painting something. Which makes other things more complicated (are bottles of tide "money" if you can trade them for drugs? [2]) It sounds like this ruling simply allowed the SEC to move forward with their case, but I'll be interested to watch it to see if it gets appealed (the ruling). Clearly ruling to overly broad here would put the onus on people with collectibles to follow FinCen rules when trading them, which to date they have largely avoided.
[1] http://www.courthousenews.com/2013/08/06/Bitcoin.pdf
[2] http://www.theatlantic.com/business/archive/2012/03/why-are-...
I agree with my sibling comment that this seems an odd way to install a SAN.
The thing is, if you want to use bitcoin, you cannot trust third parties to hold your coins for you. If you want to support bitcoin in your business, you cannot trust other sites to handle the payment for you. Yes, it is not convenient. But you have everything available to handle this yourself and, yes, you will need someone competent to do that for you if you are not into it. Bitcoin is not meant for the average user or the unaware merchant and it might never be, people need to start accepting this fact.
This is almost an exact copy from the other thread here https://news.ycombinator.com/item?id=6793984. I assume it is fine as it is ok to post duplicates like this topic.
> BIPS was built by passionate bitcoiners and talented developers. BIPS is hosted in our private server facilities. Passwords are stored with a double salted SHA-512 hashing algorithm. Our entire website is protected with AES RIJNDAEL 256 encryption and we have encryption of data traffic with 2048-bit, highest assurance Extended Validation SSL certificate, with 99.9% Browser Recognition.
> BIPS protects your payment information with industry-leading security and fraud protection. On top of this, our server/database is regularly stored on tape backups. For added security you can also enable Secure Card and Google Authenticator at any time for up to 3 levels of authentication.
Is it possible to launder stolen bitcoins on Chinese exchange?
"Our private server facilities" sounds like they were trying to run their own facility for some misbegotten reason.
"A double salted SHA-512 hashing algorithm" sounds like a weak homegrown password hash. I'm guessing it was something along the lines of SHA512(salt1 + SHA512(salt2 + password)), which is pitifully weak compared to any sort of iterated hash (bcrypt, scrypt, PBKDF2, etc). It could also mean SHA512(salt1 + password + salt2), which would be even worse in a kind of sad, hilarious way.
"AES RIJNDAEL 256 encryption" is a perfectly normal SSL cipher. Referring to it as "RIJNDAEL" is a bit of a tipoff, though: Rijndael is not an acronym, so it shouldn't be capitalized, and it's simply an older name for AES, so it's entirely redundant in this phrase.
"2048-bit, highest assurance Extended Validation SSL certificate" is something you can get from any number of vendors. It isn't actually any more secure than any other SSL certificate.
"Industry-leading security and fraud protection" probably means nothing. Or, at most, possibly that they're using an off-the-shelf fraud detection service like Maxmind - which would have done little to nothing to protect them from a determined fraudster, let alone an attacker.
"Tape backups" just make it sound like they're using equipment from the 90s.
"Secure Card and Google Authenticator" are both decent features to implement, but suggesting that they result in "up to 3 levels of authentication" is amusing. Multiple possession factors ("something you have", like a security token or a cell phone with Authenticator) don't add together; to have three factors, you'd need a knowledge factor (a password), a possession factor, and a biometric factor. And they definitely don't have the last one.
And the inputs.io guy is not even close to paying half to what was "stolen". The inputs.io guy was also running coinlender and other services, which are all gone -- including himself.
[0] http://massively.joystiq.com/2011/08/12/biggest-eve-online-s...
I feel like having such a system in place would probably end up breaking a lot of the legitimacy (since you'd need over half of miners to agree to it, in which case some sort of "central" entity would exist)
BIPS didn't announce that they'd been compromised until over a week since the funds were sent out, so it's completely impossible at this point. If you wanted to get a transaction with one confirmation reversed, you would need to convince the two largest pools (ghash.io and btcguild) to mine a fork that doesn't contain your blacklisted transaction in under 10 minutes, and even then they'd create a very noticeable reorganisation. You'd also then have to race to get your funds out, as you know your keys have been compromised.
It's fairly impossible really.
Seriously, the moment I hear about a blacklist of coins on bitcoin is the same day I buy $5,000USD of Litecoin. I'll be a millionaire within 8 months.
Because, at the end of the day, you have to pay for your groceries and mortgage in dollars. B-but muh Subway sandwich
If a story about American dollars being stolen was reported on in China, what currency would it be reported in? Is the dollar just a wrapper for the Yuan?
> Every time a company loses somebody else's bitcoins, the main assumption should be that it was an inside job. It's way too easy for a company to take the money and say that they were hacked.
http://www.reddit.com/r/Bitcoin/comments/1rexob/bitcoin_paym...
Is it time for a PCI-like consortium that will validate your bitcoin storage security procedures? (Not that PCI is guarantee of anything, but at least following it prevents you from having full credit card data lying around in files).
I.e. analyze your fail-safes (which seem to be lacking) and validate that unless someone is holding a gun to the owner's head, that your 1000 bitcoins held for you in their "vault" cannot be sent off to a random address.
I think it's important and will have to happen eventually.
"Oh, we never said that our food is screened against infection - if you wanted that you should have checked out the premium section!"
"In the event of an obvious attack, we disconnect from the network and begin diagnostics after __ minutes of sustained activity."
No, you shut the thing down, you post a page that explains what is going on and what you're doing about it, then you open again when it's clear.
It's super easy for every competitor to get you out of business forever if you just shut down. DDoS is not like something especially hard or expensive to set up (depending on your service of course), but again, shutting down is not an option as a standard countermeasure.
Its so easy to steal your own bitcoin from yourself. How could a company profit from insuring against that?
Waits until you plug it back in.
Chances are they have more time than you do to play the game of attrition.
Maybe the attacker stole the coins and then DDoS'd the site?
It's all speculation, we're pretty light on details, but the whole DDoS-as-a-distraction thing seems a little out there to me.