Bitcoin Forum
November 13, 2024, 02:49:35 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 [78] 79 »
  Print  
Author Topic: [Emergency ANN] Bitcoinica site is taken offline for security investigation  (Read 224562 times)
S3052
Legendary
*
Offline Offline

Activity: 2100
Merit: 1000


View Profile
May 27, 2012, 05:16:25 AM
 #1541

the remaining funds excl. 18k btc should be there .
I guess its not a matter of IF but HOW they refund as without the database the process is tedious

repentance
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
May 27, 2012, 05:19:58 AM
 #1542

Haven't been following this.  Is it clear yet, you know, that anyone will get any coins back or not?

Roughly 20% of the Bitcoins they held were lost but USD are apparently fine.  One of the VCs with a silent interest in Bitcionica has said that the losses will be covered and I'd be inclined to believe him as they just received half a million dollars in seed funding for their Bitcoin projects and need to be seen to be reputable in order to grow their CoinLab business.

They do have accounting records, even though they don't have an image of the database as it stood at the time it was deleted.  While that's not a perfect record, it's nowhere near as catastrophic as having no records would be - it might just take a bit longer to piece the information needed to return funds and Bitcoins to users together.

All I can say is that this is Bitcoin. I don't believe it until I see six confirmations.
fivebells
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
May 27, 2012, 05:21:58 AM
 #1543

...without the database the process [of determining remuneration] is tedious

Ha ha, that's one way to describe it. 
proudhon
Legendary
*
Offline Offline

Activity: 2198
Merit: 1311



View Profile
May 27, 2012, 05:27:08 AM
 #1544

Haven't been following this.  Is it clear yet, you know, that anyone will get any coins back or not?

Roughly 20% of the Bitcoins they held were lost but USD are apparently fine.  One of the VCs with a silent interest in Bitcionica has said that the losses will be covered and I'd be inclined to believe him as they just received half a million dollars in seed funding for their Bitcoin projects and need to be seen to be reputable in order to grow their CoinLab business.

They do have accounting records, even though they don't have an image of the database as it stood at the time it was deleted.  While that's not a perfect record, it's nowhere near as catastrophic as having no records would be - it might just take a bit longer to piece the information needed to return funds and Bitcoins to users together.

Hmmm, ok.  I guess I'm just going to let this cook for a while and move on.  Maybe in a few weeks I'll get a surprise email that their ready to return my coins.  In the meantime, I still want to try this new BitInstant thing and buy a few more coins.  I've only got a few hundred coins in any exchange now.  Everything else has been moved to paper and brain wallets.  I'm keeping one hot wallet with small amounts for day to day stuff, but otherwise everything else is is staying locked up tight.

Bitcoin Fact: the price of bitcoin will not be greater than $70k for more than 25 consecutive days at any point in the rest of recorded human history.
Phinnaeus Gage
Legendary
*
Offline Offline

Activity: 1918
Merit: 1570


Bitcoin: An Idea Worth Spending


View Profile WWW
May 27, 2012, 05:35:19 AM
 #1545

Haven't been following this.  Is it clear yet, you know, that anyone will get any coins back or not?

Roughly 20% of the Bitcoins they held were lost but USD are apparently fine.  One of the VCs with a silent interest in Bitcionica has said that the losses will be covered and I'd be inclined to believe him as they just received half a million dollars in seed funding for their Bitcoin projects and need to be seen to be reputable in order to grow their CoinLab business.

They do have accounting records, even though they don't have an image of the database as it stood at the time it was deleted.  While that's not a perfect record, it's nowhere near as catastrophic as having no records would be - it might just take a bit longer to piece the information needed to return funds and Bitcoins to users together.

Hmmm, ok.  I guess I'm just going to let this cook for a while and move on.  Maybe in a few weeks I'll get a surprise email that their ready to return my coins.  In the meantime, I still want to try this new BitInstant thing and buy a few more coins.  I've only got a few hundred coins in any exchange now.  Everything else has been moved to paper and brain wallets.  I'm keeping one hot wallet with small amounts for day to day stuff, but otherwise everything else is is staying locked up tight.

I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~
repentance
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
May 27, 2012, 05:40:40 AM
 #1546



I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~


Remember that in this case the hacker was able to delete the backup, so I don't think that exchanges saying that they have a backup means much.  How often they make back ups and how they back up are pretty critical to their ability to recover from a critical incident and who has access to the back ups determines whether they are also vulnerable.

All I can say is that this is Bitcoin. I don't believe it until I see six confirmations.
Serge
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
May 27, 2012, 05:43:43 AM
 #1547


I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~


they need daily off-site backups at the very least, not just a (single) backup. these daily backups should be kept very safe as well
Bitcoin Oz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Wat


View Profile WWW
May 27, 2012, 05:48:39 AM
 #1548

There should be a prediction market where you can bet which site will get hacked next Smiley

Just like assassination markets except for websites....

Vladimir
Hero Member
*****
Offline Offline

Activity: 812
Merit: 1001


-


View Profile
May 27, 2012, 06:59:57 AM
 #1549

There should be a prediction market where you can bet which site will get hacked next Smiley

Just like assassination markets except for websites....

That would be cool, but only if owners of websites could take the other side of the bets. This would kind of allow some to finance information security efforts.  LOL.

-
Maged
Legendary
*
Offline Offline

Activity: 1204
Merit: 1015


View Profile
May 27, 2012, 07:01:55 AM
 #1550

Is this relative/relevant?

http://boingboing.net/2011/06/08/ocean-bank-lost-3000.html
Quote
Ocean Bank, which allowed hackers to withdraw more than $300,000 from a customer's account, won't have to cover the loss. A Maine judge said its account security was "not optimal," but ultimately ruled for it because hackers obtained account credentials using malicious software installed on the customer's computers. Ocean asserted that its due diligence was covered by verifying a password.
Not at all. This is not a case where just a customer's account was hacked.
I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~
We're not an exchange, but I'll go on record as saying that Bitcointalk.org has daily backups mirrored to at least 2 different locations other than the datacenter that we're hosted at. This is in addition to industry standard backup and recovery solutions deployed onsite.

Yes, believe it or not, but your posts and PMs on this forum are actually better preserved than your current balance at Bitcoinica.

DiabloD3
Legendary
*
Offline Offline

Activity: 1162
Merit: 1000


DiabloMiner author


View Profile WWW
May 27, 2012, 07:03:26 AM
 #1551

Yes, believe it or not, but your posts and PMs on this forum are actually safer than your current balance at Bitcoinica.

I lol'd.

Phinnaeus Gage
Legendary
*
Offline Offline

Activity: 1918
Merit: 1570


Bitcoin: An Idea Worth Spending


View Profile WWW
May 27, 2012, 07:35:25 AM
 #1552

Is this relative/relevant?

http://boingboing.net/2011/06/08/ocean-bank-lost-3000.html
Quote
Ocean Bank, which allowed hackers to withdraw more than $300,000 from a customer's account, won't have to cover the loss. A Maine judge said its account security was "not optimal," but ultimately ruled for it because hackers obtained account credentials using malicious software installed on the customer's computers. Ocean asserted that its due diligence was covered by verifying a password.
Not at all. This is not a case where just a customer's account was hacked.
I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~
We're not an exchange, but I'll go on record as saying that Bitcointalk.org has daily backups mirrored to at least 2 different locations other than the datacenter that we're hosted at. This is in addition to industry standard backup and recovery solutions deployed onsite.

Yes, believe it or not, but your posts and PMs on this forum are actually better preserved than your current balance at Bitcoinica.

Dude, that means I'm/we're counting to 63,000,000 with images in that Newbie thread. That'll take forever!  Grin


I guess this would be a perfect time to ask the operators of every single Bitcoin exchange if they have a backup of their database. Each and every one of them should go on record stating that they do. I suggest that this should be done within the next 48 hours. Any exchange that does not go on record in stating that they do within this time frame, users of those exchanges should immediately remove their funds from those exchanges.

~Bruno~


they need daily off-site backups at the very least, not just a (single) backup. these daily backups should be kept very safe as well

I guess that's what I meant--proper backups. While we're at it, I think all backups should be open-source so that we can all see that they're backup. We're going to see them anyway, but at least then a hacker wouldn't have anything to do, unless they all pooled their resources and hacked via adding funds to databases, coupled with becoming Grammar Nazis.
Bitcoin Oz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Wat


View Profile WWW
May 27, 2012, 07:54:24 AM
 #1553

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

muyuu
Donator
Legendary
*
Offline Offline

Activity: 980
Merit: 1000



View Profile
May 27, 2012, 07:57:49 AM
Last edit: May 27, 2012, 08:42:37 AM by muyuu
 #1554

Is this relative/relevant?

http://boingboing.net/2011/06/08/ocean-bank-lost-3000.html
Quote
Ocean Bank, which allowed hackers to withdraw more than $300,000 from a customer's account, won't have to cover the loss. A Maine judge said its account security was "not optimal," but ultimately ruled for it because hackers obtained account credentials using malicious software installed on the customer's computers. Ocean asserted that its due diligence was covered by verifying a password.

Not at all.

User gets hacked, hackers withdraw using user's interface. No other user is affected other than the hacked user, who's responsible of his own account.

This is like someone got the passwords to your bank account online interface from you and pwned you. You are responsible of not revealing your passwords. Sure, allowing such massive withdrawals is probably over the top but it's most likely something the user decided or agreed to.

GPG ID: 7294199D - OTC ID: muyuu (470F97EB7294199D)
forum tea fund BTC 1Epv7KHbNjYzqYVhTCgXWYhGSkv7BuKGEU DOGE DF1eTJ2vsxjHpmmbKu9jpqsrg5uyQLWksM CAP F1MzvmmHwP2UhFq82NQT7qDU9NQ8oQbtkQ
cypherdoc
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
May 27, 2012, 09:34:03 AM
 #1555

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

thats a good saying.
David_Benz
Donator
Newbie
*
Offline Offline

Activity: 56
Merit: 0

you got hacked bitch!


View Profile
May 27, 2012, 10:01:04 AM
 #1556

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

VERY good saying.

I am the Bitcoinica Hacker.
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 27, 2012, 11:41:36 AM
 #1557

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

thats a good saying.
Additionally, rjk's Third Law Of Backups states that if your backup procedures are rigorous and the backups are stored in at least 3 locations, you will never ever have to recover from them. If however they suddenly disappear due to a freak accident, that is the day you are guaranteed to need them the most.

Kind of like the Law Of Extra Parts also by rjk: if you need 5 screws to complete a project, and you bring only 5, you are guaranteed to lose one of them. If however you bring 6 screws to a project that needs only 5, you are guaranteed to always have 1 left over.

Grin

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
DiabloD3
Legendary
*
Offline Offline

Activity: 1162
Merit: 1000


DiabloMiner author


View Profile WWW
May 27, 2012, 12:07:15 PM
 #1558

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

thats a good saying.
Additionally, rjk's Third Law Of Backups states that if your backup procedures are rigorous and the backups are stored in at least 3 locations, you will never ever have to recover from them. If however they suddenly disappear due to a freak accident, that is the day you are guaranteed to need them the most.

Kind of like the Law Of Extra Parts also by rjk: if you need 5 screws to complete a project, and you bring only 5, you are guaranteed to lose one of them. If however you bring 6 screws to a project that needs only 5, you are guaranteed to always have 1 left over.

Grin

The generic version of that is just Diablo's Rule #1: Redundancy in planning is not paranoia.

paraipan
In memoriam
Legendary
*
Offline Offline

Activity: 924
Merit: 1004


Firstbits: 1pirata


View Profile WWW
May 27, 2012, 01:24:24 PM
 #1559

Yes, believe it or not, but your posts and PMs on this forum are actually safer than your current balance at Bitcoinica.

I lol'd.

Great, seems like some people would have done a better job by asking you guys how it's done.  Roll Eyes

BTCitcoin: An Idea Worth Saving - Q&A with bitcoins on rugatu.com - Check my rep
JusticeForYou
VIP
Sr. Member
*
Offline Offline

Activity: 490
Merit: 271



View Profile
May 27, 2012, 04:50:52 PM
Last edit: May 27, 2012, 05:11:14 PM by BTC_Bear
 #1560

Theres an old saying that a backup doesnt exist untill its in 3 separate places Smiley

Nice to see the Rule of 3 is still a universal constant.

Guy: How many guys have you slept with?
Girl: 2

Answer: 2*3=6



Girl: How many girls have you slept with?
Guy: 9

Answer: 9/3=3


How many back-ups should you have?

Answer: 3


.
..1xBit.com   Super Six..
▄█████████████▄
████████████▀▀▀
█████████████▄
█████████▌▀████
██████████  ▀██
██████████▌   ▀
████████████▄▄
███████████████
███████████████
███████████████
███████████████
███████████████
▀██████████████
███████████████
█████████████▀
█████▀▀       
███▀ ▄███     ▄
██▄▄████▌    ▄█
████████       
████████▌     
█████████    ▐█
██████████   ▐█
███████▀▀   ▄██
███▀   ▄▄▄█████
███ ▄██████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████▀▀▀█
██████████     
███████████▄▄▄█
███████████████
███████████████
███████████████
███████████████
███████████████
         ▄█████
        ▄██████
       ▄███████
      ▄████████
     ▄█████████
    ▄███████
   ▄███████████
  ▄████████████
 ▄█████████████
▄██████████████
  ▀▀███████████
      ▀▀███
████
          ▀▀
          ▄▄██▌
      ▄▄███████
     █████████▀

 ▄██▄▄▀▀██▀▀
▄██████     ▄▄▄
███████   ▄█▄ ▄
▀██████   █  ▀█
 ▀▀▀
    ▀▄▄█▀
▄▄█████▄    ▀▀▀
 ▀████████
   ▀█████▀ ████
      ▀▀▀ █████
          █████
       ▄  █▄▄ █ ▄
     ▀▄██▀▀▀▀▀▀▀▀
      ▀ ▄▄█████▄█▄▄
    ▄ ▄███▀    ▀▀ ▀▀▄
  ▄██▄███▄ ▀▀▀▀▄  ▄▄
  ▄████████▄▄▄▄▄█▄▄▄██
 ████████████▀▀    █ ▐█
██████████████▄ ▄▄▀██▄██
 ▐██████████████    ▄███
  ████▀████████████▄███▀
  ▀█▀  ▐█████████████▀
       ▐████████████▀
       ▀█████▀▀▀ █▀
.
Premier League
LaLiga
Serie A
.
Bundesliga
Ligue 1
Primeira Liga
.
..TAKE PART..
Pages: « 1 ... 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 [78] 79 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!