5 ms·
Anybody wondering how long it will take for Bitcoin to gain enough respectability for the FBI or Secret Service to get involved after hacks like this? If the s
by albertyw 13y ago
Anybody wondering how long it will take for Bitcoin to gain enough respectability for the FBI or Secret Service to get involved after hacks like this? If the same amount of money was stolen from a normal bank, it'd likely be covered by every news outlet.
- ChuckMcM 13y agoI don't think it is the FBI a BitCoin thief needs to fear. That said, it is fascinating to watch people getting caught out when they have a "few dollars" in BitCoin and now its "a few hundred thousand dollars" suddenly the security requirements change dramatically. One would hope that would be bitcoin wallet holders are taking notes and things like daily security audits are the new normal.
- jzwinck 13y agoThe BBC, Ars Technica, and others covered a theft one year ago of about one-quarter this much value (when converted to USD at the time). And the FBI was involved (not that they recovered the funds or anything): http://www.bbc.co.uk/news/technology-19633980 http://www.bbc.co.uk/news/technology-19633980
- at-fates-hands 13y agoNot sure about that. Also, I read somewhere that the going rate of solving bank robberies is around 75-80% and many robbers are only caught because a) they do something stupid like not wear a mask or do anything to conceal their identity, or b) continuing robbing banks until their caught. Considering hacks like this take time and a fairly high level of sophistication, not sure the FBI would want to employ the amount of long term resources needed to hunt these guys down.
- mrb 13y agoThe inputs.io hack required zero sophistication. Did you read TradeFortress' explanation? The hacker merely used the password reset feature on an email account, and then reset the Linode Manager password from the email.
- pbhjpbhj 13y agoThey had to get access to the email account first though; I thought it was a Google mail account with 2FA [can't be bothered checking back].
- patio11 13y agoBanks losing $1 million to hackers are not exactly science fiction. Typical outcomes including authorities not catching the thief, insurance paying out or the bank self-insuring, reiterating NDAs to employees who became aware of the theft, and absolutely no media coverage. [Edit to add: For avoidance of ambiguity, I'm really, really, REALLY not suggesting that "Since banks are equally insecure, bitcoins are a great idea." Of greatest interest to HN readers, if your bank has a security fumble and your account is debited $25,000 as a result of this, you will almost certainly be reimbursed for every penny of that post-haste.]
- rodgerd 13y ago> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hacks against us. We aren't perfect, of course. But these monkeys are barely on the same planet, never mind in the ballpark.
- lmm 13y agoSerious question, not trying to be rude. If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?
- TimJRobinson 13y agoUsually because they have to support IE6
- wikwocket 13y agoI suspect this because, every time there is competition between innovative features that are nice for users, and ensuring security/limiting exposure and attack surface, the latter concern wins with little discussion. What I mean is, if they implement a new whiz-bang feature, the best case is that people complain a bit less. But if their new feature opens up an attack vector or social engineering opportunity, they may suffer serious financial loss and very bad press.