Bitcoin Forum
July 23, 2024, 05:24:50 AM *
News: Help 1Dq create 15th anniversary forum artwork.
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Blockchain.info Unauthorized Withdraw  (Read 3360 times)
elrodvoss (OP)
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
April 26, 2013, 03:57:28 AM
 #21

Its the no log that really irks me.  How can a withdraw be made without an entry made.?
Agreed, this is the main worry in all this I think...

Blockchain.info is only a client. It doesn't store bitcoins itself, it only stores credentials needed to send bitcoins from your addresses (that is private keys for your bitcoin addresses). If his computer/phone has been compromised, these credentials might be logged/copied during one of his legitimate logins to blockchain.info and sent to the attacker. The attacker could then use these stolen credentials with any other bitcoin client (like Bitcoin-Qt, Armory, Multibit, etc) to send bitcoins - and that's why blockchain.info didn't have any suspicious logins.

Well i guess what Ill have to do is

  • Remake a new blockchain.info wallet.
  • Use a unique PW vs any other site.
  • Enable IP restriction so it can only be used at my home location

I would think that with those three, esp the IP restriction, at account creation, there should be no way a thief could access my account and view my private key.  Of course I have been wrong before.  Blockchain even states that the app will work, as long as its "synced" with account.  So that should be secure as well.  In my mind, that tells me that even if they got my password, they couldn't access my account due to IP restriction.



adamstgBit
Legendary
*
Offline Offline

Activity: 1904
Merit: 1037


Trusted Bitcoiner


View Profile WWW
April 26, 2013, 04:00:34 AM
 #22

it would be good to understand how the hacker got to copy the private keys in the first place. maybe blockchain can add implement a fix.
obviously these 2 guys are not the only people that lost coins this way... 500BTC in total was taken this way.

the blockchain wallet runs client side (JS) right?
when that wallet is running, is it possible to have some other client side app hack the JS wallet somehow?

@elrodvoss

Does your browser have Java enabled?  click here and find out-> http://isjavaenabled.com



simonk83
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


View Profile
April 26, 2013, 04:02:27 AM
 #23

Its the no log that really irks me.  How can a withdraw be made without an entry made.?
Agreed, this is the main worry in all this I think...

Blockchain.info is only a client. It doesn't store bitcoins itself, it only stores credentials needed to send bitcoins from your addresses (that is private keys for your bitcoin addresses). If his computer/phone has been compromised, these credentials might be logged/copied during one of his legitimate logins to blockchain.info and sent to the attacker. The attacker could then use these stolen credentials with any other bitcoin client (like Bitcoin-Qt, Armory, Multibit, etc) to send bitcoins - and that's why blockchain.info didn't have any suspicious logins.

Right, gotcha
elrodvoss (OP)
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
April 26, 2013, 02:55:51 PM
 #24

it would be good to understand how the hacker got to copy the private keys in the first place. maybe blockchain can add implement a fix.
obviously these 2 guys are not the only people that lost coins this way... 500BTC in total was taken this way.

the blockchain wallet runs client side (JS) right?
when that wallet is running, is it possible to have some other client side app hack the JS wallet somehow?

@elrodvoss

Does your browser have Java enabled?  click here and find out-> http://isjavaenabled.com




As stated in above responce,  java is running on computer

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!