Bitcoin Forum
October 25, 2025, 01:06:28 PM *
News: Pumpkin carving contest
 
   Home   Help Search Login Register More  

Warning: Moderators do not remove likely scams. You must use your own brain: caveat emptor. Watch out for Ponzi schemes. Do not invest more than you can afford to lose.

Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 [14] 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 ... 1348 »
  Print  
Author Topic: ASICMINER: Entering the Future of ASIC Mining by Inventing It  (Read 3918493 times)
Jutarul
Donator
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
August 27, 2012, 11:44:41 PM
 #261

Update

All pending orders are either executed or cancelled. There is still one trade unpaid yet.

The IPO is finally closed. Extra shares have been sent. Please check, and contact me if there's any mistakes. Thanks.

I assumed those shares were the 'extra' free shares block buyers were promised (I did not receive any extra shares today Smiley )

So I am still a bit confused...

Give him a few days. You were correct in assessing that the "extra shares" are the 10% bonuses. However not all 200K shares were distributed, which is why at the end there will still be some shares leftover, which will get distributed to shareholders after all accounts are settled. If you didn't receive your bonus and you are a block buyer you need to PM him.

The ASICMINER Project https://bitcointalk.org/index.php?topic=99497.0
"The way you solve things is by making it politically profitable for the wrong people to do the right thing.", Milton Friedman
nedbert9
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250

Inactive


View Profile
August 27, 2012, 11:45:03 PM
Last edit: August 28, 2012, 12:58:08 AM by nedbert9
 #262

Edit:  Session Fixation attacks, based on my cursory understanding, would not be limited by the use of 2FA.
However, after the compromise I both enabled 2FA and deposited some BTC in the account.  BTC is still there.
It's just unclear what happened.  Buyer beware.

Hello, everyone.

I wanted to let everyone know about the compromise of my GLBSE account on 8/23.

The price dip for ASICMINER indeed resulted from the compromise of my account.  3000 shares were sold at 17:00 GLBSE time (?) for approximately 23 BTC.

The most important message I have for you is that GLBSE is not secure without 2FA enabled.  I had recently created the GLBSE account for the specific purpose of owning ASICMINER.  The account was created on a system lacking any prior security compromises.  The account password was a new, unused 14 character, mixed case, mixed character class.  

Taking responsibility for the fact 2FA was not enabled on my account contributed to the theft of the shares.  On the flip side of this GLBSE is a dangerous place for the uninitiated with Google 2FA.  I say this since my impression was that Google 2FA was only available to smart phone users.  This is why I didn't use it.

Nefario has investigated GLBSE logs in attempt to establish any pattern or method used to compromise the account.  Nefario's judgement is that it is unclear how my account was compromised.  Nefario gave no further  information regarding IP accesses, but only suggested that:

Quote
From what I can tell the only thing that would allow someone access would be a session fixation attack, where they set the session id in your browser for GLBSE to something they know. Then when you login to GLBSE they can just use the site as you (because you're using their session).


There are a number of possible reactions to what I've said.  Such as,

1.  Use 2FA, stupid.
My use case is pretty clearly stated above.  If you don't tell users it's dangerous not to use 2FA, and at the same time not provide the links to any necessary security software that is 3rd party OSS and not supplied by Google directly, then there is a certain element of negligence on the part of GLBSE.

In fact, if it's so dangerous, evidenced by my predicament, GLBSE should not allow account creations without the use of the Google 2FA.

2.  GLBSE negligence you say?  Hog-wash.  
No, GLBSE is a financial institution and should not leave it's users unaware and unprepared - which, yes, requires a higher level of user notification and security requirements - only to be raped.

Food for thought.  Do you think Bank of America Web portals are vulnerable to Nefario's suggestion of Session Fixation?  If that were the case my BoA account would be f'ed right now.
It isn't.  And none of any other my important online accounts have been tampered with.


Nefario's position is the same as past incidents of this nature involving shareholders.  I presented the option to Nefario of me reimbursing those who purchased the ASICMINER shares as a result of the compromise in exchange for the recall/reversal of the share sale.  Nefario declined any share reversals.  

A 22 BTC theft costing me both a good investment opportunity and a $3000+ debt to the security issuer.


I sincerely wish ASICMINER success.  Enjoy my the cheap shares.  
puffn
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
August 28, 2012, 12:06:21 AM
 #263

How does this give a 3000+ dollar debt to the issuer? Wouldn't they be ambivalent to share sales not involving them?

Looking for safe diversification? YABIF: Good Returns, Low Fees, Low Risk.

GLBSE
Bitcointalk Page

I hold significant interest in
Bitcoin Mining Investments
nedbert9
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250

Inactive


View Profile
August 28, 2012, 12:20:26 AM
 #264

How does this give a 3000+ dollar debt to the issuer? Wouldn't they be ambivalent to share sales not involving them?

The transaction between myself and friedcat hadn't been finalized.
DutchBrat
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
August 28, 2012, 12:25:56 AM
 #265

How does this give a 3000+ dollar debt to the issuer? Wouldn't they be ambivalent to share sales not involving them?

The transaction between myself and friedcat hadn't been finalized.

Sorry to hear !!!  Sad
LoweryCBS
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250


firstbits 1LoCBS


View Profile
August 28, 2012, 12:28:28 AM
 #266

(case for 2FA)

You convinced me. 2FA is now enabled.
Jutarul
Donator
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
August 28, 2012, 12:30:52 AM
 #267

The account password was a 14 character, mixed case, mixed character class.  

Sorry for the obvious question. But did you use that password also for a different website?
Also, if you talk about security breaches, please state the OS, browser, other software running and whether you were on a public network or at home..

A 22 BTC theft costing me both a good investment opportunity and a $3000+ debt to the security issuer.

I sincerely wish ASICMINER success.  Enjoy the cheap shares.  

If you need to get some more shares I bet friedcat will understand and give you an opportunity to buy some from the left-over stack of shares before they get handed out. I certainly wouldn't mind.

Share reversals are tricky so I am not surprised to hear that Nefario refrains from doing that.

That leaves the question about who's liable for the 300 BTC damage. I am surprised that Nefario has problems retracing the BTC flow. (unless of course the attack "only" intended to do damage to you and the 22 BTC are still in your account)

The ASICMINER Project https://bitcointalk.org/index.php?topic=99497.0
"The way you solve things is by making it politically profitable for the wrong people to do the right thing.", Milton Friedman
nedbert9
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250

Inactive


View Profile
August 28, 2012, 01:21:49 AM
 #268

The account password was a 14 character, mixed case, mixed character class.  

Sorry for the obvious question. But did you use that password also for a different website?
Also, if you talk about security breaches, please state the OS, browser, other software running and whether you were on a public network or at home..

A 22 BTC theft costing me both a good investment opportunity and a $3000+ debt to the security issuer.

I sincerely wish ASICMINER success.  Enjoy the cheap shares.  

If you need to get some more shares I bet friedcat will understand and give you an opportunity to buy some from the left-over stack of shares before they get handed out. I certainly wouldn't mind.

Share reversals are tricky so I am not surprised to hear that Nefario refrains from doing that.

That leaves the question about who's liable for the 300 BTC damage. I am surprised that Nefario has problems retracing the BTC flow. (unless of course the attack "only" intended to do damage to you and the 22 BTC are still in your account)


New, unused password.  Win 7, chrome.  Only antivirus, chrome, trucrypt and serviio running.  Nothing out of the ordinary for the day of the compromise other than visiting #bitcoin-otc.

I have no cash to handle the debt and also buy significant amount of shares.

The proceeds of the theft were withdrawn immediately to
http://blockchain.info/address/1FxjKn6fsdQ9iYoiH1otehKbkDXJj9Jkdg
The balance is 42 BTC.  I have no idea why since I summed the sale transactions to about 23 BTC.

I appreciate the sympathy.
Jutarul
Donator
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
August 28, 2012, 01:51:02 AM
Last edit: August 28, 2012, 02:08:17 AM by Jutarul
 #269

New, unused password.  Win 7, chrome.  Only antivirus, chrome, trucrypt and serviio running.  Nothing out of the ordinary for the day of the compromise other than visiting #bitcoin-otc.
Yes that's odd. I take it the Win 7 comes from a legit source... Pirated OS are a major technique to set up botnets.

I have no cash to handle the debt and also buy significant amount of shares.
If the Nefarios investigations turn out that it's not entirely your fault, but likely a bad combination of security weaknesses, I guess ASICminer may just write the debt off. But that's not up to me to decide.
However, I find it odd that the position is a debt - are you just reluctant to pay for shares you received and got "stolen" from your account?
 
The proceeds of the theft were withdrawn immediately to
http://blockchain.info/address/1FxjKn6fsdQ9iYoiH1otehKbkDXJj9Jkdg
The balance is 42 BTC.  I have no idea why since I summed the sale transactions to about 23 BTC.
Ok. It's fresh. Lets see where the money goes.


I appreciate the sympathy.
I had a standing buy order for 100 shares at 0.08 which got filled. All I can offer is to sell it back to you at this price. Maybe we could organize the share reversal ourselves if Nefario doesn't want to do it. All which is required for people to step up and provide their transaction information which is available as csv on GLBSE. Here's mine:

buy,2012-08-23 17:00:00,0.08,ASICMINER,100,,,

Funny. It's exactly 17:00:00. Now that's timing Wink

To prevent this thread from getting spammed with these messages I offer to organize this list. Just send me a PM with the corresponding transactions. I'll then compose a summary post.

The ASICMINER Project https://bitcointalk.org/index.php?topic=99497.0
"The way you solve things is by making it politically profitable for the wrong people to do the right thing.", Milton Friedman
DiabloD3
Legendary
*
Offline Offline

Activity: 1162
Merit: 1000


DiabloMiner author


View Profile WWW
August 28, 2012, 02:32:03 AM
 #270

You want a told you so? If a website has 2FA of any kind, USE IT. PERIOD. DOUBLY SO IF IT IS A FINANCIAL WEBSITE LIKE GLBSE.

I have no clue why the fuck people think this is optional. I've asked nefario to mandate it to use GLBSE, but he gets all bitchy about it. Banks frequently do it (especially in Europe), so why not GLBSE? Just fucking do it.

Jutarul
Donator
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
August 28, 2012, 02:41:24 AM
 #271

You want a told you so? If a website has 2FA of any kind, USE IT. PERIOD. DOUBLY SO IF IT IS A FINANCIAL WEBSITE LIKE GLBSE.

I have no clue why the fuck people think this is optional. I've asked nefario to mandate it to use GLBSE, but he gets all bitchy about it. Banks frequently do it (especially in Europe), so why not GLBSE? Just fucking do it.

You're bashing the wrong guy. Wait for when you learn something the hard way and then receive nothing but contempt. That's no way to tread someone who fell victim. The way I see it there are currently a few explanations: 1) hacked windows 2) leaked password hash (does anybody know which hash function GBLSE uses?) 3) Not enough entropy in the password 4) glitch in GLBSE (actually the exact match with 17:00:00 makes me worried, let's see what others have)

The ASICMINER Project https://bitcointalk.org/index.php?topic=99497.0
"The way you solve things is by making it politically profitable for the wrong people to do the right thing.", Milton Friedman
friedcat (OP)
Donator
Legendary
*
Offline Offline

Activity: 848
Merit: 1005



View Profile
August 28, 2012, 02:45:45 AM
 #272

The difference gets distributed to existing shareholders.
https://bitcointalk.org/index.php?topic=99497.msg1107204#msg1107204
I'm very sorry, but the "extra shares" here means the extra shares for bulk purchasers. (10% for >=5,000 & 12.5% for >=10,000)
Sending leftover shares proportionally to shareholders is technically very hard. It is hard to track who owns how many, and for people who hold only a handful of shares it is impossible to give them fractional shares.

However, the proportion of the company represented by each share could be adjusted. I'm considering making it a little higher to compensate the shareholders if the recent 300BTC trade doesn't end up well, as a plan-B (plan-A is that my partners and I fill the gap).

MrTeal
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 28, 2012, 02:54:04 AM
 #273

I think I must be misreading this, but are you saying that friedcat transferred the shares to you before you paid? And that some time between when you got them and when you would have paid you got hacked, lost the money, and now you can't afford to pay friedcat back?
Bitcoin Oz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Wat


View Profile WWW
August 28, 2012, 03:04:41 AM
 #274

I think I must be misreading this, but are you saying that friedcat transferred the shares to you before you paid? And that some time between when you got them and when you would have paid you got hacked, lost the money, and now you can't afford to pay friedcat back?

Yes thats what hes saying.

MrTeal
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 28, 2012, 03:07:51 AM
 #275

I think I must be misreading this, but are you saying that friedcat transferred the shares to you before you paid? And that some time between when you got them and when you would have paid you got hacked, lost the money, and now you can't afford to pay friedcat back?

Yes thats what hes saying.
Then it doesn't sounds like a $3000 debt for the issuer, it sounds likely nedbert needs to start selling his hair, blood and sperm to raise $3000 pay friedcat for the shares he bought.
eb3full
VIP
Full Member
*
Offline Offline

Activity: 198
Merit: 101


View Profile
August 28, 2012, 03:16:22 AM
 #276

I was also surprised friedcat sent me so many shares before I had paid him.. and I don't even have a good forum reputation yet.

"With four parameters I can fit an elephant, and with five I can make him wiggle his trunk." John von Neumann
buy me beer: 1HG9cBBYME4HUVhfAqQvW9Vqwh3PLioHcU
HorseRider
Donator
Legendary
*
Offline Offline

Activity: 1120
Merit: 1001


View Profile
August 28, 2012, 03:34:01 AM
 #277

@nedbert9

I have get 168 shares during this hack @0.085 per share. I would like to give 0.00388888BTC*168=0.64BTC to you.

please give me your GLBSE account.

I guess the bitcoin transfer between GLBSE accounts is free, right? who can give me a confirmation.

16SvwJtQET7mkHZFFbJpgPaDA1Pxtmbm5P
imsaguy
General failure and former
VIP
Hero Member
*
Offline Offline

Activity: 574
Merit: 500

Don't send me a pm unless you gpg encrypt it.


View Profile WWW
August 28, 2012, 03:40:50 AM
 #278

@nedbert9

I have get 168 shares during this hack @0.085 per share. I would like to give 0.00388888BTC*168=0.64BTC to you.

please give me your GLBSE account.

I guess the bitcoin transfer between GLBSE accounts is free, right? who can give me a confirmation.

bitcoin transfer is free, shares aren't.

Coming Soon!™ © imsaguy 2011-2013, All rights reserved.

EIEIO:
https://bitcointalk.org/index.php?topic=60117.0

Shades Minoco Collection Thread: https://bitcointalk.org/index.php?topic=65989
Payment Address: http://btc.to/5r6
nedbert9
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250

Inactive


View Profile
August 28, 2012, 05:03:58 AM
Last edit: August 28, 2012, 07:07:39 PM by nedbert9
 #279

You want a told you so? If a website has 2FA of any kind, USE IT. PERIOD. DOUBLY SO IF IT IS A FINANCIAL WEBSITE LIKE GLBSE.

I have no clue why the fuck people think this is optional. I've asked nefario to mandate it to use GLBSE, but he gets all bitchy about it. Banks frequently do it (especially in Europe), so why not GLBSE? Just fucking do it.

You're bashing the wrong guy. Wait for when you learn something the hard way and then receive nothing but contempt. That's no way to tread someone who fell victim. The way I see it there are currently a few explanations: 1) hacked windows 2) leaked password hash (does anybody know which hash function GBLSE uses?) 3) Not enough entropy in the password 4) glitch in GLBSE (actually the exact match with 17:00:00 makes me worried, let's see what others have)


I see I've started to derail the thread.  Obviously, my comments were meant to inform everyone of what happened and I should have expected a number of responses.

Sorry for that.


On the point of 2FA.  Yes, it's a big deal and it's foolish not to use it.  It's foolish just the same for a financial service to operate at less than secure mode as default and then not take a rigorous approach to inform users by explicit notification and links to any 3rd party OSS software required to establish a sufficient level of protection (and this is especially true in the case for Google 2FA as Google's primary use case is with the use of smart phones and can mislead uninitiated users).  I'm just re-iterating what I said in my original post, so obviously this falls on deaf ears to some.  I fault Mt. Gox and any other site that doesn't enforce 2FA.  I use Yubikey.  So, there.

In my case the problem is two fold.  One, neither Nefario or I know exactly what happened.  Though on the day of the compromise circumstances could have allowed a security vulnerability not limited by 2FA.  
That's the Session Fixation vulnerability.  Despite Nefario's refusal to take any responsibility for such a vulnerability it's an old, common vulnerability where security whitepapers have stated that the only effective countermeasure for Session Fixation is to design the Web application to use strict session controls that limit session id creation and tightly control their invalidation - or need for revalidation.

Edit:  Some have jumped to the conclusion that this *IS* what happened.  This is my best assumption.  I typically log out and don't leave sensitive sites open.
I think I have a good idea what might have happened.  My GLBSE session was still active after closing the browser tab.  I spent some time on web freenode and was probed and compromised from that source.
Speculation, but it's the best thing I can come up with.

Use 2FA and don't have any other browser window open while using GLBSE.  I am your example to learn from.


LazyOtto
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


View Profile
August 28, 2012, 05:44:42 AM
Last edit: August 28, 2012, 06:09:23 AM by LazyOtto
 #280

Sending leftover shares proportionally to shareholders is technically very hard.
I'm sorry to hear that.

However, isn't that a commitment you made?

--

edit - added the below:

Any other approach is a modification to the terms under which we bought shares. That is, gave you BTC/money with the understanding that "this is how things will be done - do you wish to buy in under those conditions?".

*Any* changes of those terms is non-trivial. It is a slippery slope. The more the original terms are changed, without a formal share-holder vote, the less confidence that those terms will be ultimately honored.

--

"without a formal share-holder vote"

BTW, this is also a problem inherent in how only 30k shares were offered to the general public. This mechanism allows, for example, votes of the following nature to be passed by the 'big players' who gave you BTC directly rather than via the GLBSE public auction.

1) Any holder of less than 5000 shares will be deemed a 'Class B' shareholder.
2) Holders of 5000 shares or more will be deemed 'Class A' shareholders.
3) All benefits and remunerations described in the original terms will only apply to 'Class A' shareholders.
4) 'Class B' shareholders will get whatever is left over, if anything, after the 'Class A' shareholders get all they want.
 
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 [14] 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 ... 1348 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!