Bitcoin Forum
May 07, 2024, 12:53:36 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
Author Topic: Instawallet/Bitcoin-Central Security Breach  (Read 85268 times)
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
April 02, 2013, 11:04:38 PM
 #161

In short "Keep your private keys private". Rule number ONE in Bitcoin land.

You're storing BitcoinSpinner users private keys in plaintext on their phones. How is this helping them to keep their private keys private?

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
1715043216
Hero Member
*
Offline Offline

Posts: 1715043216

View Profile Personal Message (Offline)

Ignore
1715043216
Reply with quote  #2

1715043216
Report to moderator
1715043216
Hero Member
*
Offline Offline

Posts: 1715043216

View Profile Personal Message (Offline)

Ignore
1715043216
Reply with quote  #2

1715043216
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715043216
Hero Member
*
Offline Offline

Posts: 1715043216

View Profile Personal Message (Offline)

Ignore
1715043216
Reply with quote  #2

1715043216
Report to moderator
dooglus
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
April 03, 2013, 01:54:41 AM
 #162

Thanks dooglus. Mine was off.

Yes, I think chromium has all it's "spying for google" features disabled by default.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
splat44
Sr. Member
****
Offline Offline

Activity: 384
Merit: 250



View Profile
April 03, 2013, 02:29:25 AM
 #163

If bitcoin-central.net has an update, I'm sure instawallet will come down the line! Usually this one is very safe!

either way the lesson will be "trust no one to hold your coins".
Seconded

Apparently every new batch of Bitcoiners will need to learn this valuable lesson.

If you aren't the sole controller of your private keys, you don't have any bitcoins.

Take whatever steps necessary to be the sole controller of your private keys people!
In short "Keep your private keys private". Rule number ONE in Bitcoin land.

bitcoin-central.net has updated its message

Still no mention of instawallet  Huh


Joost
Member
**
Offline Offline

Activity: 68
Merit: 10



View Profile
April 03, 2013, 07:29:41 AM
 #164

So do we think it is only affecting chrome users or is this just speculation?

Aside from that there is no news is there?
You would be surprised how many people got Google as their home page and type URLs in the page's search box instead of the browser's URL bar...

When you're using Chrome as your browser, (on the default settings) there is no difference between the two. None.
MysteryMiner
Legendary
*
Offline Offline

Activity: 1470
Merit: 1029


Show middle finger to system and then destroy it!


View Profile
April 03, 2013, 01:05:50 PM
 #165

For first Instawallet URL hack I think the Google Chrome is to blame. I never used Chrome outside VMWare test environment and I recommend anyone not to install Google Chrome on any computer for this privacy reason. If there is any technical need when Chrome is preferred over Firefox, then use SRWare Iron that have all bad things deleted. The use of URL as a private key is not a big security problem because SSL also encrypts the URL and prevents anyone from seeing it, including Tor exit nodes, FBI, etc. As long as the browser history are safe and not compromised, the URL is safe.

I have no idea about second hack. If it is true that the servers are suspected to be compromised, then it might take some time to install new operating system on new hardware, test and secure the setup before it is launched public again.

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 03, 2013, 01:20:15 PM
 #166

For first Instawallet URL hack I think the Google Chrome is to blame. I never used Chrome outside VMWare test environment and I recommend anyone not to install Google Chrome on any computer for this privacy reason. If there is any technical need when Chrome is preferred over Firefox, then use SRWare Iron that have all bad things deleted. The use of URL as a private key is not a big security problem because SSL also encrypts the URL and prevents anyone from seeing it, including Tor exit nodes, FBI, etc. As long as the browser history are safe and not compromised, the URL is safe.

I have no idea about second hack. If it is true that the servers are suspected to be compromised, then it might take some time to install new operating system on new hardware, test and secure the setup before it is launched public again.

So you think if I have used only Firefox in safe mode then it should be all good?
MPOE-PR
Hero Member
*****
Offline Offline

Activity: 756
Merit: 522



View Profile
April 03, 2013, 01:20:38 PM
 #167

In short "Keep your private keys private". Rule number ONE in Bitcoin land.

You're storing BitcoinSpinner users private keys in plaintext on their phones. How is this helping them to keep their private keys private?

Ouch.

My Credentials  | THE BTC Stock Exchange | I have my very own anthology! | Use bitcointa.lk, it's like this one but better.
Kotcha
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
April 03, 2013, 01:27:08 PM
 #168

What is the likelihood of us seeing our coins again guys? Getting worried about the severe lack of communication
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 03, 2013, 01:30:13 PM
 #169

What is the likelihood of us seeing our coins again guys? Getting worried about the severe lack of communication

No idea. I switch from positive to negative feelings nonstop. Driving me crazy. :/

One thing for sure though. If it turns out all right I am taking some profits and flying to a beach for a holiday. (Not before I finally get armory working though Wink )
Joost
Member
**
Offline Offline

Activity: 68
Merit: 10



View Profile
April 03, 2013, 01:31:40 PM
 #170

What is the likelihood of us seeing our coins again guys? Getting worried about the severe lack of communication

The lack of communication is definitely disturbing.. I can only assume they havn't got any time for communicating as they've got the entire team working round the clock on this thing, but a little memo every few hours would have been great.

Their predicted 48 hours are nearly running out.. I had hoped to see them back online by now.  Embarrassed
Kotcha
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
April 03, 2013, 01:42:09 PM
 #171

I feel your pain steelboy. Kicking myself for not keeping them somewhere more secure, definitely a lesson learnt but hopefully not the hard way!

Yeah the communication has been apalling, and has probably tarnished the company a great deal - it looks like some people have lost A LOT of money, they deserve some sort of explanation. The fact that funds have been moved to this 'Instawallet Cold Storage' address is quite reassuring, unless it's an inside job and they are just stalling  Huh
twolifeinexile
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
April 03, 2013, 01:42:12 PM
 #172

What is the likelihood of us seeing our coins again guys? Getting worried about the severe lack of communication

The lack of communication is definitely disturbing.. I can only assume they havn't got any time for communicating as they've got the entire team working round the clock on this thing, but a little memo every few hours would have been great.

Their predicted 48 hours are nearly running out.. I had hoped to see them back online by now.  Embarrassed

Anyone have a private communication channel to them? Could anyone trying to get some info on this, customers/users are deserve to know the current status of the affair.
Joost
Member
**
Offline Offline

Activity: 68
Merit: 10



View Profile
April 03, 2013, 01:50:27 PM
 #173

That's odd. The font used on https://bitcoin-central.net/ and https://paytunia.com/ are different. You'd think they'd just point to the same HTML file..  Tongue

Oddly enough, Instawallet still displays the old downtime message. I can only hope this is an indication of priorities  Wink
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 03, 2013, 01:55:30 PM
 #174

I feel your pain steelboy. Kicking myself for not keeping them somewhere more secure, definitely a lesson learnt but hopefully not the hard way!

Yeah the communication has been apalling, and has probably tarnished the company a great deal - it looks like some people have lost A LOT of money, they deserve some sort of explanation. The fact that funds have been moved to this 'Instawallet Cold Storage' address is quite reassuring, unless it's an inside job and they are just stalling  Huh

Cheers mate. Hope you're not in as much as me.

The stalling thing is an option I suppose I just feel that as the owners are known there will be a lot of people ready to kick off if it has gone.
MysteryMiner
Legendary
*
Offline Offline

Activity: 1470
Merit: 1029


Show middle finger to system and then destroy it!


View Profile
April 03, 2013, 02:30:16 PM
 #175



So you think if I have used only Firefox in safe mode then it should be all good?
Yes. Firefox don't leak URLs unless some malicious add-on or antivirus/firewall does it. And the safe mode for Firefox are not meant to be "safer" mode of operation. It is only for troubleshooting purposes if some add-on or plugin causes it to crash.

The URL leak is not Instawallet fault, I found another service who still have exactly same problems. I did not manage to find any coins in there but it is only matter of time. At least I will work back the coins that have gone with Instastealwallet.

If I'm going to run away with 4000 coins I will not post message that I will be back. I will post something like this: "Na nana nana I got Your coins and You will not see them again, na na nanaana!" together with picture of Eric Cartman.

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
hous
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
April 03, 2013, 02:34:00 PM
 #176

how many coins you got in there steelboy?

I got 30 in there the price was  @ $103 each

now there $130 lol

crazy shit i hope get them back !!!!

steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 03, 2013, 02:35:55 PM
 #177

A lot more than that. Sad

Didnt realise how unsafe they were and i just started to realise before Easter that i needed to do something about it.

Started a thread to get some advice about the armory and setting it up, even bought an offline asus on friday ready to get it sorted this week.

Oh well....let's see. 
hous
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
April 03, 2013, 02:51:17 PM
 #178

yea not a good place to hold them mate. i was only using it as transporter not a wallet to hold.
 i hope you and every1 else gets them back.
I am leaving my computer at work today otherwise i am up all night waiting to hear something.
My opinon is they had a problem they managed to keep everyones coins safe now there going to profit from it before it goes back live!!

cheers


Joost
Member
**
Offline Offline

Activity: 68
Merit: 10



View Profile
April 03, 2013, 02:51:51 PM
 #179

I got 30 in there the price was  @ $103 each

now there $130 lol

At least you had BTC in there before the steep rise this morning Wink
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 03, 2013, 02:59:01 PM
 #180

yea not a good place to hold them mate. i was only using it as transporter not a wallet to hold.
 i hope you and every1 else gets them back.
I am leaving my computer at work today otherwise i am up all night waiting to hear something.
My opinon is they had a problem they managed to keep everyones coins safe now there going to profit from it before it goes back live!!

cheers




How do you think they can profit from it?
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!