Bitcoin Forum
June 18, 2024, 10:29:18 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 »  All
  Print  
Author Topic: Dumb Question : If I found a security flaw with a major bitcoin company ..  (Read 7282 times)
the founder (OP)
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
March 26, 2013, 04:24:15 PM
Last edit: March 26, 2013, 06:43:51 PM by the founder
 #1

THEY RESPONDED

I found a security flaw which allowed a thief to steal bitcoins from a company.
I contacted them and they don't reply,  what should I do?
I want to see the security issue resolved,  and the company in question is not responding to me.

The security flaw is so stupid that it most likely got overlooked.

EDIT:  We're talking a minor exploit that at most can yield 100 coins or so.   Not thousand,  not millions,  just 100 or so bitcoins.

It's not going to destabilize bitcoin, or affect prices to any large extent.  It's a single company that has a minor problem that they haven't contacted me back yet.

That's the extent of this flaw.   I asked for advice not because I wanted to freaking start a panic,  it's just how to get a company to respond.

100 BTC at max.... that's it.. nothing more.








Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
rme
Hero Member
*****
Offline Offline

Activity: 756
Merit: 504



View Profile
March 26, 2013, 04:28:07 PM
 #2

Make the flaw public will be the fastest way of been fixed.
sgravina
Sr. Member
****
Offline Offline

Activity: 451
Merit: 250



View Profile
March 26, 2013, 04:31:26 PM
 #3

I found a security flaw which allowed a thief to steal bitcoins from a company.
I contacted them and they don't reply,  what should I do?
I want to see the security issue resolved,  and the company in question is not responding to me.

The security flaw is so stupid that it most likely got overlooked.



Don't steal the coins.  You will be criminally liable for that even if you intend to return them and even if you do return them.  In fact returning them becomes evidence against you.

Just try again.
Sukrim
Legendary
*
Offline Offline

Activity: 2618
Merit: 1006


View Profile
March 26, 2013, 04:31:39 PM
 #4

Well, if you're a customer there you might not want them to be robbed from the outside...?!

You could transfer a nontrivial but also not business threatening amount of BTC to one of your addresses (maybe ennounce that here? On the other hand it might be easy to know which business has this flaw via network analysis) and then immediately send them back - that should hopefully trigger some alerts...

https://www.coinlend.org <-- automated lending at various exchanges.
https://www.bitfinex.com <-- Trade BTC for other currencies and vice versa.
sgravina
Sr. Member
****
Offline Offline

Activity: 451
Merit: 250



View Profile
March 26, 2013, 04:32:45 PM
 #5

Make the flaw public will be the fastest way of been fixed.

This also invites a lawsuit.
MysteryMiner
Legendary
*
Offline Offline

Activity: 1498
Merit: 1042


Death to enemies!


View Profile
March 26, 2013, 04:53:26 PM
 #6

Fuck the law, if you live in another country just grab the damn coins!

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
Elwar
Legendary
*
Offline Offline

Activity: 3598
Merit: 2386


Viva Ut Vivas


View Profile WWW
March 26, 2013, 05:04:00 PM
 #7

Is it the MtGox one where you can put anyone else's public Bitcoin address in the url and automatically get all of their bitcoins?

First seastead company actually selling sea homes: Ocean Builders https://ocean.builders  Of course we accept bitcoin.
christop
Member
**
Offline Offline

Activity: 84
Merit: 10



View Profile
March 26, 2013, 05:08:03 PM
 #8

Is it the MtGox one where you can put anyone else's public Bitcoin address in the url and automatically get all of their bitcoins?
Please tell me this is a joke.

Tips are always welcome: 17Z63hLi2ox4fCMhDqVJrLTJiXVcBMJpMo
Alpaca socks donations: 1sockzDWcF8mrC59CgiN7HAJm6xL7TiRW
Elwar
Legendary
*
Offline Offline

Activity: 3598
Merit: 2386


Viva Ut Vivas


View Profile WWW
March 26, 2013, 05:09:35 PM
 #9

Is it the MtGox one where you can put anyone else's public Bitcoin address in the url and automatically get all of their bitcoins?
Please tell me this is a joke.

 Tongue

First seastead company actually selling sea homes: Ocean Builders https://ocean.builders  Of course we accept bitcoin.
flix
Legendary
*
Offline Offline

Activity: 1227
Merit: 1000



View Profile
March 26, 2013, 05:10:09 PM
 #10

I found a security flaw which allowed a thief to steal bitcoins from a company.
I contacted them and they don't reply,  what should I do?
I want to see the security issue resolved,  and the company in question is not responding to me.

The security flaw is so stupid that it most likely got overlooked.



Take 100 BTC to prove it. Make it public. Return the coins when you get an apology and a thankyou.



Seriously, if I was in charge of that co. I would be desperate to be the first to know about potential flaws and would offer a sizeable bounty for anybody that pointed them out (with proof).
the founder (OP)
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
March 26, 2013, 05:20:40 PM
 #11

1.  I will not steal or publish the results.   

I had a few hundred coins stolen from me 2 years ago,  at today's prices it would be $20,946.88
I do not wish that to happen to anyone ever.

2.  I attempted for a second time to inform the company,  no response yet.  When it comes in I will let you guys know what I found and how the exploit happened... that's after giving the owners time to correct the problem.

I got blasted via private message on bitcointalk for not publishing the exploit and stealing coins.

I hope that a few years from now if I was on the other side of the table people would handle it like this rather than freaking stealing coins.   If people were Honourable they would reward this type of behaviour rather than sending private messages like that... 







Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
fcmatt
Legendary
*
Offline Offline

Activity: 2072
Merit: 1001


View Profile
March 26, 2013, 05:24:09 PM
 #12

1.  I will not steal or publish the results.   

I had a few hundred coins stolen from me 2 years ago,  at today's prices it would be $20,946.88
I do not wish that to happen to anyone ever.

2.  I attempted for a second time to inform the company,  no response yet.  When it comes in I will let you guys know what I found and how the exploit happened... that's after giving the owners time to correct the problem.

I got blasted via private message on bitcointalk for not publishing the exploit and stealing coins.

I hope that a few years from now if I was on the other side of the table people would handle it like this rather than freaking stealing coins.   If people were Honourable they would reward this type of behaviour rather than sending private messages like that... 









just remember this.

NO GOOD DEED GOES UNPUNISHED

watch your back.
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 26, 2013, 05:26:17 PM
 #13

...If people were Honourable they would reward this type of behaviour rather than sending private messages like that... 


Thank you for setting a good example.

the founder (OP)
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
March 26, 2013, 05:29:50 PM
 #14

whoever just tipped me .035 thank you!


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 26, 2013, 05:31:18 PM
 #15

I once worked for a guy who said "Do the right thing" pretty often.
He ended up ripping me off.


just remember this.

NO GOOD DEED GOES UNPUNISHED

watch your back.

The OP is right to be an honest person.
just remember this:
You get what you deserve.

MiningBuddy
Hero Member
*****
Offline Offline

Activity: 927
Merit: 1000


฿itcoin ฿itcoin ฿itcoin


View Profile
March 26, 2013, 05:33:49 PM
 #16

1.  I will not steal or publish the results.   

I had a few hundred coins stolen from me 2 years ago,  at today's prices it would be $20,946.88
I do not wish that to happen to anyone ever.

2.  I attempted for a second time to inform the company,  no response yet.  When it comes in I will let you guys know what I found and how the exploit happened... that's after giving the owners time to correct the problem.

I got blasted via private message on bitcointalk for not publishing the exploit and stealing coins.

I hope that a few years from now if I was on the other side of the table people would handle it like this rather than freaking stealing coins.   If people were Honourable they would reward this type of behaviour rather than sending private messages like that... 
Good for you man! This is what we need, more genuine and honest people like yourself around here.
If you found a flaw in one of my sites I would be sure to buy you a beer or two at the very least!

the founder (OP)
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
March 26, 2013, 05:42:24 PM
 #17

No Reply to the first or second attempt. 


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
MysteryMiner
Legendary
*
Offline Offline

Activity: 1498
Merit: 1042


Death to enemies!


View Profile
March 26, 2013, 06:04:31 PM
 #18

You are either attention whore trying to cause bubble burst and there is no exploit

or

You are so rich that don't care about money or reward for your unique skills.

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
tysat
Legendary
*
Offline Offline

Activity: 966
Merit: 1004


Keep it real


View Profile
March 26, 2013, 06:07:39 PM
 #19

You are either attention whore trying to cause bubble burst and there is no exploit

or

You are so rich that don't care about money or reward for your unique skills.

I'm guessing option #1, this combine with someone else trying to cause a panic makes more sense than either post does alone.
bbit
Legendary
*
Offline Offline

Activity: 1330
Merit: 1000


Bitcoin


View Profile
March 26, 2013, 06:11:00 PM
 #20

Send me all their coins?


           █████████████████     ████████
          █████████████████     ████████
         █████████████████     ████████
        █████████████████     ████████
       ████████              ████████
      ████████              ████████
     ████████     ███████  ████████     ████████
    ████████     █████████████████     ████████
   ████████     █████████████████     ████████
  ████████     █████████████████     ████████
 ████████     █████████████████     ████████
████████     ████████  ███████     ████████
            ████████              ████████
           ████████              ████████
          ████████     █████████████████
         ████████     █████████████████
        ████████     █████████████████
       ████████     █████████████████
▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
▬▬ THE LARGEST & MOST TRUSTED ▬▬
      BITCOIN SPORTSBOOK     
   ▄▄
██
██
██
██
██
██
██
██
██
██     
██
██
             ▄▄▄▄▀▀▀▀▄
     ▄▄▄▄▀▀▀▀        ▀▄▄▄▄           
▄▀▀▀▀                 █   ▀▀▀▀▀▀▀▄▄
█                    ▀▄          █
 █   ▀▌     ██▄        █          █               
 ▀▄        ▐████▄       █        █
  █        ███████▄     ▀▄       █
   █      ▐████▄█████████████████████▄
   ▀▄     ███████▀                  ▀██
    █      ▀█████    ▄▄        ▄▄    ██
     █       ▀███   ████      ████   ██
     ▀▄        ██    ▀▀        ▀▀    ██
      █        ██        ▄██▄        ██
       █       ██        ▀██▀        ██
       ▀▄      ██    ▄▄        ▄▄    ██
        █      ██   ████      ████   ██
         █▄▄▄▄▀██    ▀▀        ▀▀    ██
               ██▄                  ▄██
                ▀████████████████████▀




  CASINO  ●  DICE  ●  POKER   
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
   24 hour Customer Support   

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
Pages: [1] 2 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!