Pages:
Author

Topic: [Emergency ANN] Bitcoinica site is taken offline for security investigation - page 43. (Read 224562 times)

newbie
Activity: 38
Merit: 0
From the new site:

Quote
For the technically inclined, we salt and encrypt passwords with bcrypt.

Bcrypt hashes passwords it doesn't encrypt them.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
I'm feeling sad for this "new owner" trusting his business operation to Intersango.

My apologies for double posting, but I'm wondering if "the investor" also has control of bitcoin.com.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
If the plan is for the forums to be the primary source of information for bitcoinica.com, there should at least be a PR rep to answer questions. Who is it and why aren't they posting?

Or maybe they are. Do all of Zhowtong's most recent postings stem from the same IP (assuming it's not masked)?
legendary
Activity: 1652
Merit: 1128
If the plan is for the forums to be the primary source of information for bitcoinica.com, there should at least be a PR rep to answer questions. Who is it and why aren't they posting?
legendary
Activity: 1692
Merit: 1018
It's great to see the new site up at bitcoinica.com to put everyone's mind at ease that things are progressing well in restoring the site... 

Nothing restores confidence like no official statements from the main source (Zhoutong was just an employee, not the owner).
legendary
Activity: 1099
Merit: 1000
I'm feeling sad for this "new owner" trusting his business operation to Intersango.
hero member
Activity: 686
Merit: 500
Shame on everything; regret nothing.
legendary
Activity: 1386
Merit: 1004
rjk
sr. member
Activity: 448
Merit: 250
1ngldh
All I know is, I prefer my systems to be owned by people that can fix them, not people that have to hire others to fix them. Not only that, but I forsee that there will be more of the same since Intersango et al are suddenly more valuable due to the acquisition of control of Bitcoinica.

Not many businesses work that way.
I guess that is a bit extreme and can't be expected always, but it is the way many Bitcoin related things work. Many current Bitcoin-related businesses have owners that still hack on their codebases. I guess what I meant to say was that I hope the new owner is at least smart enough to turn on a server and bash out a few linux commands.
vip
Activity: 490
Merit: 271
All I know is, I prefer my systems to be owned by people that can fix them, not people that have to hire others to fix them. Not only that, but I forsee that there will be more of the same since Intersango et al are suddenly more valuable due to the acquisition of control of Bitcoinica.

Not many businesses work that way.
donator
Activity: 1218
Merit: 1079
Gerald Davis
Um anyone else find the answer lacking?

There was never any exploit against the code base.  In linode hack the attacker used a "super-admin" account and the administrative console to reset an admin password, logged into the server and copied the private keys from the wallet.  End result was 40K BTC stolen.  So the "solution" to leaving server vulnerable to remote password reset was to do a tedious line by line analysis of the codebase (which has never exploited) and meanwhile install the code on a new server which had (almost) the same vulnerability as the prior server.

Really?  That was the impossible to determine flaw? The attacker did almost the same thing ALL OVER AGAIN in the recent attack. Compromise an off site email account, use the remote admin console, reset the admin password, login to the server and copy the private keys stealing 20K BTC.

Linode: Compromise a super-admin account, reset admin password, login to server, steal private keys from wallet, profit.
Rackspace: Compromise off-site email, reset admin password, login to server, steal private keys from wallet, profit.

Starting to see the pattern?

rjk
sr. member
Activity: 448
Merit: 250
1ngldh
All I know is, I prefer my systems to be owned by people that can fix them, not people that have to hire others to fix them. Not only that, but I forsee that there will be more of the same since Intersango et al are suddenly more valuable due to the acquisition of control of Bitcoinica.
legendary
Activity: 1386
Merit: 1004
Finally there is a notice on bitcoinica.com for users not on This forum.
hero member
Activity: 602
Merit: 500
Who are these so-called "owners" ?

Zhoutong claims it is not him => you claim it is not you => then who is it Huh

Just a hint from a another lurker here in the forum Wink

Zhoutong pointed out that the owner requested not to be publickly known.

This started a rather lengthy discussion right here in this thread about business and ownership in generall, but like it or not, such things are very common in the current world of business. I might be wrong, but just from the answers available here in the forum, I would be surprised to get any further disclosure on that topic.

Personally I'm glad that Team Intersango spoke up and clarified their position and the technical details.

--Ichthyo

hero member
Activity: 518
Merit: 500
hero member
Activity: 518
Merit: 500
Damn it! We nearly got rid of bulanula permanently!
Indeed. Too bad I did not die !

The world would have been a better place that way with evil people like me out of it ...
hero member
Activity: 686
Merit: 500
Shame on everything; regret nothing.

Damn it ! I almost got an epileptic seizure from that rjk.

Not trolling. I suffer from that and almost got shocked.

Please put a warning up for people like me affected.

Sounds like a scam  Grin
newbie
Activity: 35
Merit: 0
Damn it! We nearly got rid of bulanula permanently!
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending

Damn it ! I almost got an epileptic seizure from that rjk.

Not trolling. I suffer from that and almost got shocked.

Please put a warning up for people like me affected.

I was thinkin' 'bout postin' the same thing, but opted not to. Although I'm not epileptic (think not), I too felt strange afterwards of only viewing the images a couple secs. Odd!

~Bruno~
Pages:
Jump to: