Bitcoin Forum

Other => Beginners & Help => Topic started by: psilos on April 01, 2013, 07:31:50 PM



Title: Bitcoin central Security breasch!!!
Post by: psilos on April 01, 2013, 07:31:50 PM
Guys,

since a few hours , the bitcoin exchange site bitcoin central is down for maintenance due to security reasons!!!

Anybody has some further information about the issue????


Title: Re: Bitcoin central Security breasch!!!
Post by: XXthetimeisnowXX on April 01, 2013, 07:37:08 PM
Guys,

since a few hours , the bitcoin exchange site bitcoin central is down for maintenance due to security reasons!!!

Anybody has some further information about the issue????

no but this will push it to the top so we can get some one who does


Title: Re: Bitcoin central Security breasch!!!
Post by: discopete on April 01, 2013, 09:16:12 PM
hopefully they'll have fixed it before Europe wakes up tomorrow and nobody notices.

personally i believe that they have caught it before any actual accounts were compromised but it should still serve as a warning that any high profile bitcoin players will be a target for hackers.

there's an excellent thread here about securing your wallet :-)


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 01, 2013, 09:58:34 PM
well, what i m concerned about is the panic reaction from the users once the site is up again


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 01, 2013, 10:01:26 PM
April 1st?

  ;D if that s the case, then the guys at the bitcoin central have really big guts


Title: Re: Bitcoin central Security breasch!!!
Post by: benwoody on April 01, 2013, 10:08:25 PM
According to their site:

Quote
[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.

The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.

We thank you for your patience and will provide updates exclusively on this page as they come in. We are committed to resuming service as soon as possible. Expect normal service to resume within 48 hours.
- bitcoin-central.net (https://bitcoin-central.net/ (https://bitcoin-central.net/))

Note that they also own https://instawallet.org/ (https://instawallet.org/) and https://paytunia.com/ (https://paytunia.com/)


Title: Re: Bitcoin central Security breasch!!!
Post by: Nubarius on April 01, 2013, 10:22:57 PM
This is being discussed on the main forum section too: https://bitcointalk.org/index.php?topic=164143.0

There's some reassuring news as it seems that Bitcoin-Central are in control of most of the funds.


Title: Re: Bitcoin central Security breasch!!!
Post by: benwoody on April 01, 2013, 10:29:45 PM
Judging by the bitcoin-central Github repo, I'm wondering if this isn't due to the version of Rails they were using:

https://github.com/davout/bitcoin-central/blob/master/Gemfile#L3 (https://github.com/davout/bitcoin-central/blob/master/Gemfile#L3)

3.1.3 had a slew of security patches this year: http://www.cvedetails.com/vulnerability-list/vendor_id-12043/product_id-22568/version_id-129541/year-2012/Rubyonrails-Ruby-On-Rails-3.1.3.html (http://www.cvedetails.com/vulnerability-list/vendor_id-12043/product_id-22568/version_id-129541/year-2012/Rubyonrails-Ruby-On-Rails-3.1.3.html)

Of course, just because this is on the Github repo, doesn't mean they are using this code in Production.


Title: Re: Bitcoin central Security breasch!!!
Post by: Otaci on April 01, 2013, 10:37:25 PM
I cant post to the thread because of my newbie status.

There's a large transaction which hasnt been mined because it depends on some unconfirmed transactions that had no transaction fee. Presumably, they were trying to transfer the BTC from the cold storage to a more secure account, so they want it to happen quickly.

Could they resubmit another transaction? A duplicate of the large one except for the unconfirmed dependency. This would presumably go through fast. It would be a double booking, but they wouldn't care since they are doing it. When the miners get round to it, they will reject the old original transaction.


Title: Re: Bitcoin central Security breasch!!!
Post by: benwoody on April 01, 2013, 10:41:29 PM
There's a large transaction which hasnt been mined because it depends on some unconfirmed transactions that had no transaction fee.

So it'll be confirmed, just not relatively soon.  I take it there are some maths around the size of the transaction to the size of the transaction fee to give a roughly estimated confirmation time?


Title: Re: Bitcoin central Security breasch!!!
Post by: Otaci on April 01, 2013, 10:44:29 PM
There's a large transaction which hasnt been mined because it depends on some unconfirmed transactions that had no transaction fee.

So it'll be confirmed, just not relatively soon.  I take it there are some maths around the size of the transaction to the size of the transaction fee to give a roughly estimated confirmation time?
Yes, but since there was some sort of security breach, they may want it to go through as quickly as possible. Assuming that is the case, would the method I described work to get the majority of the funds through quickly. Note that I have nothing to do with these guys, I'm just curious.


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 02, 2013, 09:09:18 AM
As you have probably already noticed, both large tranactions are now confirmed.

So hopefully the site will be up and running soon and all the coins/euros will be still there  :)

But still I think that the bitcoin Central guys should regularly update the site so we know what s exactly happening.


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 03, 2013, 08:14:00 AM
and while we are waiting for bitcoin central to "resume its services", the bitcoin value has been rised up to 112 euros !!!  :o


Title: Re: Bitcoin central Security breasch!!!
Post by: Eluc on April 03, 2013, 08:33:01 AM
I've made a quite large tranfert to Paytunia just one week ago, and I'm still unable to buy my bitcoin. This weekend I've made another transfert to Bitstamp but it's still unavailable on my account and every f***ing minutes I check BitStamp the price goes up very fast ! It's driving me so crazy right now...

I had such trust in Paymium as they were associated with a bank and as they will be offering credit card to spend Bitcoin but now I'm more and more spectical on their future and the future of my money on their account.

Are you guys ampting to take action after the site will be back, in order to get a payement of the damages they cost to their customers ?? I mean all this time they've got a lot of BTC sleeping on their account so they can give compensation at least.


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 03, 2013, 08:47:27 AM
well, i had the same issue.

I made a transfer to bitcoin central to buy some extra bitcoins right at the day that the site went down and and while the bitcoin value was still down to 75 euros.

I am not familiar with the legal issues so I cannot comment on that


Title: Re: Bitcoin central Security breasch!!!
Post by: psilos on April 03, 2013, 09:02:29 AM
And btw it s still strange that davout , the guy who is actively involved with bitcoin-central has since dissapeared from the forum.



Title: Re: Bitcoin central Security breasch!!!
Post by: Phinnaeus Gage on April 08, 2013, 07:27:06 AM
And btw it s still strange that davout , the guy who is actively involved with bitcoin-central has since dissapeared from the forum.



So, the guy who assured me all is well is gone? I can't wait to suck his dick as my way to thank him. Hopefully, he'll take the time to stick it up my ass first. Wait, that's already been done.


Title: Re: Bitcoin central Security breasch!!!
Post by: wopwop on April 08, 2013, 07:30:41 AM
KAPOWNED BITCHES

Few million dollar heist and the press/people doesn't even know it