Frozen Funds
vircurex.com
vircurex.com
> Before the wild speculations beginn, the service will be recovered and we pay the losses out of our own pockets.[0]
From the forums it looks like they lost funds again in May 2013 due to the RoR code execution bug (CVE-2013-0156):
> After investigating the security breach we have to come to the conclusion that the attacker has been able to get root access to the systems.
By the sounds of things they've been insolvent for over a year after both breaches and at this time just happened to get more withdraws than deposits.
Terrifyingly in January, they "cleaned up" the server and kept on using it afterwards[2].
[0]: https://bitcointalk.org/index.php?topic=135919.msg1448056#ms...
[1]: https://bitcointalk.org/index.php?topic=49383.msg2102708#msg...
[2]: https://bitcointalk.org/index.php?topic=135919.msg1448204#ms...
I wish a real security expert would publish good practices for using crypto wallets
For context, I'm implementing a compute exchange: https://www.stackmonkey.com/ - whitepaper: https://github.com/StackMonkey/xovio-pool/blob/master/whitep...
While I'm not implementing a crypto currency exchange, I will still have to disburse float based funds over short periods of time. As the site code will be responsible for this, there exists a hypothetical opportunity for a bad agent to break in and siphon off those funds. I'm toying around with making it impossible to withdraw funds once they are deposited by a user. If funds were limited to penny value drips to keep instances running, the site could be made aware of larger transfers of value out of given addresses. If that was noticed by the system, another secret system could 'pull the plug' on the API tokens for the Coinbase API. I'll need Coinbase to implement token revokes in their API...
Better, if the code is Open Source, I can have more eyeballs on it to prevent such an eventuality. You can review my code here: https://github.com/StackMonkey. The pool controller is the one which will need to be closely scrutinized. The appliance can only watch incoming payments, so it's not really that venerable. I choose to make all this code Open Source because it will be in charge of customer funds and, more importantly, the infrastructure of the Internet.
Moving forward, I don't think it's a good idea to use anything hooked up to your Bitcoin float that isn't Open. Still, it's a choice people can make freely, even if it's a poor one. Education matters.
There is no silver bullet. The only secure software is software that has been used by millions of people in millions of ways and been slowly but surely improved. This software will still have bugs to be found, but far less than something newly written.
EDIT: And unit tests are not the solution either - do you have a unit test to check for a timing vulnerability? I thought not... (Counting off one of the many ways I've heard to make secure software)
Just don't trust random websites with your money unless you have some form of insurance. It's not a hard concept.
The HTTP api that's accessible over the internet would not be able to connect to the database, instead it would perform its actions by making requests to multiple services, every service having the absolute minimum api endpoints required. A user creation service. A user details service. An authentication service. A trade submission service. A trades reading service. Each of these servers would run on different VM's, if the money is there, make that different hardware.
Where possible the data would be split into different databases, a trade database, a users database, a wallets database.
The different services would have their own login credentials to those databases, would not be able to even connect to databases they don't need, and their credentials on those databases would only allow them to execute the queries that they need to do. (If a database you use does not allow for fine enough access control the service would access the database through a middleware that does.)
If that seems like a lot of work, I bet you there are security professionals reading this laughing at it knowing this is just a sane basic architecture, and that I'm a rookie and they'd do a dozen more stuff.
My point is just: Even if there's a 100kloc in your system, it doesn't mean it's impossible to secure. Even a 100kloc system will have a limited attack surface that can be divided, and controlled.
Hacked May, 2013. Blame the exchange's devs who didn't do security updates.
It's unfortunate that those that have deposited since then have subsidised those that withdrew after the hacks.
So in a system built around this, any hack, from good old Mitnick-style social engineering attacks, to something purely technica, will cause irreparable loss. Any computer , network, or even individual that has control of enough coins will have a huge target planted on their heads, because all thefts are final.
The security systems on a regular bank do not put fraud avoidance as their number one priority: That's just number two. What they really care about is fraud detection, because for most forms of fraud, and especially the ones that could ruin a bank, early detection allows them to undo the damage. If I could take a billion from Bank of America, and there was nothing that could be done about it after the fact, there would be millions of people working on finding ways to do just that. The payoff would be too great for it not to happen multiple times a year.
So the best the Bitcoin fanatics can hope for is for the major thefts to be rare. Still, they will happen, it's just unavoidable when the stakes are that high, and the rules so in favor of the thief.
Other commenters here have mentioned n-of-m multisignature transactions. This article describes how multisig works, and how it can be used to implement better arbitration than what's been possible with traditional payment systems.
Unfortunately we're in the early days of Bitcoin here: support for multisig isn't common, and neither is the awareness of just how important it is for large transactions. We'll get there though.
Say A buys from B with C as arbitrator. A can pay C to claim B never sent the goods and both A and C will be better off (A gets goods for a fraction of what he would have paid B, C gets fees from both parties plus a bribe).
1. Arbitration services can be decoupled from payment services. With multisig, buyer and seller get to choose an arbiter they trust based on reputation, jurisdiction, experience arbitrating similar kinds of transactions, etc. This is an unbundling of what credit card companies do today and opens up an entirely new and competitive market. As your scenario shows, reputation will be everything for these new companies. Evidence of foul play will be disastrous. However, in the less-than-competitive market of bundled payment and arbitration services we have today, evidence of foul play in arbitration doesn't even seem to make a dent (consider PayPal).
2. Which brings up another point: arbitration with multisig is safer for buyer and seller. In their dual role as arbiter, PayPal can and does freeze funds in transit indefinitely. A Bitcoin 2-of-3 multisig arbiter cannot do this if both buyer and seller agree there was no problem. The arbiter is simply outvoted.
3. The flip side of that is: arbiters don't have to get involved at all in the vast majority of transactions that aren't disputed. They don't have to process payments. They don't have to transfer money. They don't need all that infrastructure. They only get involved in settling disputes, in which case they cast their vote by signing the transaction to the buyer or seller. This should make arbitration services cheaper and more efficient on the whole.
4. Finally, unlike current payment systems, Bitcoin makes arbitration services optional. Whole classes of transactions suddenly become cheaper because of this. In the current system we're paying for arbitration services we don't even need. I'm not going to dispute that $3 charge for a cup of coffee. If you're friends and family making a larger payment to me, I don't need arbitration either.
Like Eli Dourado, I also think we're on the verge of some very interesting things happening in arbitration:
"What excites me most about the decentralized arbitration afforded by multisignature transactions is that it could be the beginnings of a Common Law for the Internet. The plain, ordinary Common Law developed as the result of competing courts that issued opinions basically as advertisements of how fair and impartial they were. We could see something similar with Bitcoin arbitration. If arbitrators sign their transactions with links to and a cryptographic hash of a PDF that explains why they ruled as they did, we could see real competition in the articulation of rules."
It would also make trades a little more difficult in that users that are slow in signing off a transaction slows the trade down. The buyer has to wait until the seller has performed an action. Could you DoS an exchange with multiple buy/sells that you don't release?
To your point: I suspect multisig doesn't help solve the problems we keep seeing with exchanges. An exchange converts between currencies, and wants to make transactions easy. A bank keeps your money safe, and wants to make transactions more difficult to that end. Unless you're a currency day trader, I don't see a reason to conflate the two.
Personally, I'm appalled by the fact that we've built a system that makes it easy for individuals to secure their own funds, and yet we're using it to entrust funds to third parties who don't have a clue. All in good time I suppose.
-You can cash out (steal) an arbitrary amount of people's coins, blaming it on a "hack". If technically competent you can make it look as legitimate as you like, even giving a detailed post-mortem.
-This will probably tarnish your operation and possibly your internet rep if the Google juice flows that way.
So how much is your internet reputation worth? Personally, there's probably a number that would sway me.
Until these incentives are changed somehow, with regulation or otherwise, it will happen.
One solution is m-of-n transactions, which Bitcoin already implements. Set things up so that any two of three keys can sign a transaction and spend your coins. The online service gets one key, you keep another on your computer, and a third goes in your safe deposit box.
Normally, you spend by signing a transaction from your computer and asking the service to do the same. The service can't spend coins without hacking your computer. If the service goes away, you pull the third key out of your safe deposit.
Uncharitably, I could say "So we've determined you're a thief, now we're just haggling about the price."
But actually I don't think that thinking that there is a number that would probably sway you, means that that number really would. I'd like to think you'd actually say no to any number, through to billions.
At the end of the day, morality isn't nearly as elastic as people suppose. You either have it or you don't.
I'd like to believe that, but most of what I've learned about sociology and economics says otherwise.
Just to be clear on what I'm not saying, I don't claim this will solve all problems. I also don't claim that it is preferable to keep a significant amount of one's currency in a remote account. But people are going to do it anyway, angry/snarky/intelligently-worded arguments not withstanding. Why not embrace the transparency these platforms offer to buoy user confidence?
Even if you could start your own exchange using this codebase more easily, most of the value from such a service comes from professionally maintaining quality infrastructure, providing trustable guarantees on security, etc. The alternative is a series of crappily-coded exchanges that will continue failing due to poor code and lack of transparency. I don't know how to solve the problem of nefarious parties starting exchanges with this code, but solving that problem isn't my intent.
large fund withdrawals in the last weeks which have lead to a
complete depletion of our cold wallet balance
versus We'll take the current available cold storage balance and distribute
it based on the below described distribution logic
Is the cold wallet completely depleted or isn't it?And why choose such a cockamaime distribution scheme? 50% to the largest accounts and 50% to the smallest accounts?
Why not pro rata based on each account's balance?
So the largest accounts will enjoy 100% recovery while those in the middle get less, or even zero? This gives preference to certain accounts while providing the illusion of fairness.
Yet again, there's no disclosure of a balance sheet, no visibility to total assets and liabilities.
Why do people continue to trust their funds to incompetents and fraudsters?
Because they live in a world where they can trust the system. However, in bitcoin land, they still behave they can still trust the system.
Bitcoin and the core developers are the only group you can trust to any extent, really.
At this point its a gamble. You either give up and admit Vircurex has lost all of your wallet or you keep using them and hope the profit they generate from you will make its way back into your wallet while at the same time hoping they don't have any more security issues. Its not so much "trust" as it is hope.
I think your overall argument is based on cognitive dissonance. You'd like everyone to be paid in full immediately. That makes perfect sense to me, but it remains they lost funds. With that fact at hand, you can no longer hold the expectation of everyone being paid in full immediately and the situation of lost funds getting resolved. This makes you angry, and so you lash out with blaming statements which are logically flawed. Simply put, you are attacking something with an approach that makes no sense. The reason it makes no sense is because you are having an unresolvable argument with yourself! Honestly, I see no way of fixing this in a better way than what they have implemented. To me, that indicates we should extend some amount of trust they'll resolve this in a way that gets people's money back to them.
Your last statement is probably the most valid, but may not be 100% applicable to Vicurex. I agree they appear to have been incompetent (which implies they may still be incompetent) but they don't appear to be fraudsters. Mt. Gox was both, if you ask me, because they never did a decent job of disclosing. To your first point, Vicurex should come clean now they've frozen funds and give estimates of recovery time.
Perhaps to hide outright theft by Vircurex.
If you don't receive funds, you might conclude your account balances fell somewhere in the middle... or perhaps they didn't distribute any funds at all.
There's no way for users to know how large their account balances are relative to others.
50% of the amount will be distributed top down and the other 50% will be distributed bottom up. "
This seems, even by their own example, awful! It penalizes the holders with an average number of coins
What could be better: for example, take 50% and pay at least X BTC to the holders. If the user has less than X BTC they receive their balance.
Then, from the other 50% pay proportional to the value. For example, 1BTC for each BTC in balance (minus what was payed in the first step)
This is the ideal scheme if you wish to selectively repay a few shills whilst advising others that they will just have to wait.
"Just one year ago, a study by Computer scientists Tyler Moore Southern Methodist University in Dallas, Texas) and Nicolas Christin (of Carnegie Mellon University) found 40 exchanges offering bitcoin services. Of those 40, 18 went out of business — 13 without warning, including five that collapsed instantly following cyber attacks. Almost all of the exchanges that collapsed took their investors funds with them. They estimated that: “Exchanges handling 275 Bitcoins’ worth of transactions each day have a 20 percent chance of being breached, exchanges handling 5570 Bitcoins have a 70 percent chance of failure” It was calculated that in 2013 the median lifespan of any Bitcoin exchange is 381 days, with a 29.9 percent chance that a new exchange will close within a year of opening. So following their academic study, Moore and Christin calculate a 1/3 failure rate for Bitcoin exchanges…"
http://www.cryptocoinsnews.com/2014/03/22/bitcoin-foundation...
This is laughable. No effect on future deposits? Who in their right mind would continue to use them after this?
1. http://www.reddit.com/r/SilkRoad/comments/1ylnmd/btc_not_sho...
How can they justify anything but equally sharing the burden of the loss? "We owe X total and have Y available, so all accounts will get Y/X of their owed funds unfrozen, and the rest remain frozen."? I'm really not following the logic.
bitcoin itself as the protocol/platform has proven to be quite solid
the trick is to not keep coins in exchanges unless you are into trading, but then you know that you are taking a risk
There have been a couple of these actually:
http://www.pcworld.com/article/2109000/bitcoinstealing-malwa...
http://www.computerworld.com/s/article/9244772/Bitcoin_marke...
http://www.coindesk.com/cointhief-mac-malware-steals-bitcoin...
And the most famous probably, cryptolocker - http://en.wikipedia.org/wiki/CryptoLocker ...though this is more a ransom strategy than just out-right theft.
It has a lot more to do with bad code, bad storage policies or bad intentions on the part of the exchanges, and most of them point to transaction malleability - a design flaw in the original protocol - as their excuse.
There are several exchanges in the works but they are bogged down with regulation and not able to open.
I don't know whether that's true, but that's what s/he wrote. It's an easy enough to understand and plausible notion.
Bitstamp seem to be doing the right things but I doubt that they can legally operate in US or take transfers from/to US as they are doing.
If you want to make a trade then sure, put a couple hundred bucks in or whatever, but realize that whatever you have in the exchange could disappear at any time.
I guess that's it for all the technologists giving simplistic lessons to some States about how they should manage their economies/banking systems.
I suppose I should also delete my Vircurex api library while at it.
It's fucking amateur hour here.
That's the beauty of this whole thing. The users self-select exchanges that are insecure because they're easy.
Can't wait for this currency to completely fade into obscurity - that's where it belongs because surely it has proved to not be a viable currency at all.
Naturally there's about a 25% premium for DOGE on Vircurex over other exchanges right now.
TL;DR exchanges can prove that:
-they own specific amount of bitcoins
-and that your bitcoins on their exchange are included in this amount
https://bitcointalk.org/index.php?topic=22929.msg5286474#msg...These stories are a bit alarming and can have some of us wondering if the exchanges we are using actually have the amount of coins they claim to have...
Besides, I don't think losing the keys is the root cause of many exchanges' solvency issues.
So, the problem becomes one of scale. For example, a bank can survive a small unauthorized withdrawal, but large thefts are what kills the business. Limit the withdrawal sizes and shut down everything at a core level when that security is breached.
The ability to move massive amounts around securely is a pipe dream.
The whole problem here looks to me as a flaw in the design of current crypto currencies, because transfers take that long to complete you will always need escrow type services to make it useful.
Most US Financial regulation stemmed from Depression-era screwups. Thankfully, people-who-say-fiat are in their own little world that I can mostly ignore, but in the real, we're not doing much better with regards to forgetting the lessons of the depression. The 1999 Glass-Steagall repeal, for instance, was a major cause of the issues of the past decade.
The only way would be to use multisig, and have a trusted third party allow the coins to be moved if it was not suspicious.
Companies will be (and already are) getting smarter, by hiring security experts to audit software and detect vulnerabilities, and more transparent, by providing public accounting of funds to prove they are not running Ponzi schemes or fractional reserves.
Of course it does. Not 100%; but mostly. Your bank has multiple people handling all cash transactions, mandatory account balancing on at least a daily basis, all sorts of controls on its operations that you have no idea exist because the system facing you doesn't show them to you. It has these because they are required by law. Your bitcoin exchange has none of these.
Do you think government is required to provide insurance?
If the consumers demand these of their merchants, it will happen in the long term on their own accord, and government is not necessary to make it happen.
You mean like the FDIC or SIPC?
The 2nd problem and more serious problem is insurance fraud. You cannot be sure the people claiming to lose the coins actually lost them. In fact, forget my first point. The insurance fraud aspect renders any hope for bitcoin insurance void. If someone has any ideas how to even begin to run an FDIC-type thing on bitcoin, I'd love to hear how one would deal with insurance fraud.
Insurance companies. Where do you think that consumer insurances companies insure themselves? Companies like Lloyd's and Munich RE have dozens of billions of dollars in insured amounts.
Insurance companies are generally quite conservative and regulated institutions and like to make a profit. Sure, they'll insure some crazy things like satellite launches where one launch vehicle explosion means the space insurance industry as a whole makes a loss that year, but they'll only do that because of enormous premiums.
Tack those enormous premiums onto Bitcoin exchanges' costs of doing business and suddenly Western Union money transfers would look cheap.