That is huge.... 400+ private keys being duplicated to more than one person.
I hope counter measures are in place to prevent this in future. Is this in any way related to the increased reports on reddit of hacked blockchain.info wallets?
------------------------------------------------------------------------------------------------------------------------------------------------------------
Hi Redditors,
Team Blockchain here. We take privacy and security seriously and it’s deeply concerning every time someone reports a breach. The top three issues right now are:
•Malicious Tor exit nodes
•Weak password management
•Sophisticated phishing attacks
We have been working with some of the top bitcoin and network security researchers to identify malicious Tor exit nodes and warning users against the use of the Tor network in general. Sophisticated hackers are using Tor to compromise individual wallets and escape untraced. We’ve tweeted about this issue
https://twitter.com/blockchain/status/522454637115617280 and recommended that users disable Tor access within their wallets.
For those interested you can read more about the Tor network issue here:
http://www.coindesk.com/torban-monitor-bitcoin-over-tor-attacks/ If you want to disable Tor access as well as take some other steps to improve the security of your Blockchain wallets here’s how:
http://blog.blockchain.com/2014/10/22/5-tips-on-making-your-blockchain-wallet-more-secure/ The second issue we see is weak password management. It’s very tempting to use the same password online for different services but it also greatly increases your risk profile. We highly recommend using very strong, very unique passwords. Many community members rely on services like LastPass, Dashlane, or open source desktop solutions that never touch the web to create complicated passwords. Also, one of the strongest ways to improve security is to familiarize yourself with Two-Factor Authentication, which requires a unique and perishable code to gain access to your wallet.
You can set this up now here:
http://blog.blockchain.com/2014/04/...how-to-use-it-on-your-blockchain-info-wallet/ Over the past year, as Bitcoin has attracted a lot of attention it has also aroused the interests of digital thieves who create fake landing pages, send malicious emails, and even impersonate Blockchain employees to attempt to solicit login credentials. We have been spending tens of thousands of dollars quarterly, even when we were bootstrapped without outside funding, to take down phishing sites. We also work directly with Google, ISPs, and network providers to fight these issues daily.
There is always a tradeoff between convenience and security. We try to keep the barriers to wallet creation as low as possible so anyone in the world can create a Bitcoin wallet for free. We recently disabled automatic email backups because email access isn’t hardened enough for many users. To be clear, wallet backups have always been encrypted but if weak passwords were used there is a risk the backup could be brute forced by guessing common phrases.
We provide software that lets users manage and spend their own Bitcoins, without tracking, interference or permission. This also means that to a certain extent, our role is limited to educating users about best practices and innovating security features.
To this end, we are developing tools that will help users learn about security and audit their own security.
We've been blessed with a lot of great feedback that has helped us improve. If you have suggestions, we would welcome them here or at
[email protected] Source :
http://www.reddit.com/r/Bitcoin/comments/2nkias/this_is_a_list_of_rbitcoin_users_who_had_their/