TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The ShapeShift Hack

73 点作者 mdelias大约 9 年前

9 条评论

ikeboy大约 9 年前
Erik responded: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Bitcoin&#x2F;comments&#x2F;4gdxe9&#x2F;cornell_professor_doubts_shapeshift_story&#x2F;d2gy4iz" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Bitcoin&#x2F;comments&#x2F;4gdxe9&#x2F;cornell_pro...</a>
btilly大约 9 年前
So we&#x27;ve got three potential theories here.<p>1. ShapeShift has the right version of events.<p>2. Rovion is Bob who is having fun mocking and misleading the CEO, safe in the belief that he will never be caught.<p>3. Rovion is another insider who is providing himself with cover to blame Bob and an outside hacker if he&#x27;s ever caught.<p>This post criticizes the first theory on Rovion&#x27;s interaction not making much sense. And indeed it doesn&#x27;t unless Rovion is a fairly weird guy.<p>The second theory makes some sense. By telling this yarn, Bob managed to steal two more times, while having all evidence of how he did it the second 2 times not being taken as leads to who he is now or what he is doing.<p>The third theory makes a ton of sense. Rovion can either be someone who was already planning to steal. Or just an insider who saw how easy it was and was motivated to do the same.<p>One interesting detail is that Bob&#x27;s initial theft is just sitting in a wallet, untouched. So apparently he didn&#x27;t need that money. The first theory would say because he got paid by Rovion and can wait. The second theory would say because he made 2 other withdrawals that he can use. The third theory leaves that open.<p>Based on human nature I&#x27;d rank them 3, 2, 1. Based on his leaving a bunch of money untouched, and my opinions about criminals, I&#x27;d rank the theories 2, 1, 3. Either way the CEO should be dubious about the story he was fed by &quot;Rovion&quot;.
评论 #11567266 未加载
评论 #11567017 未加载
kcorbitt大约 9 年前
I agree that ShapeShift&#x27;s account has holes in it and the CEO seemed a little too willing to take Rovion at his word, but this rebuttal swings too far in the other direction. Some comments:<p>&gt; Red Flag #1. Bob is somehow able to connect with a hacker who has been hiding in their systems for some time.<p>Actually, in the original article Rovion says &quot;We contacted Bob.&quot; Which makes total sense -- if Rovion eg. had access to the email account of a ShapeShift employee, he would have seen the drama with Bob unfold and been able to contact him easily.<p>&gt; Red Flag #2. Rovion identifies Bob by his real life name &quot;Bob,&quot; without a moment of hesitation. &gt; Why on earth would Bob run a criminal business under his real name?<p>If Rovion had access to some internal communications at ShapeShift, he would of course have &quot;Bob&quot;&#x27;s real name and no reason not to use it.<p>&gt; Red Flag #3. Bob chooses to sell his backdoor access to Rovion instead of using it himself. &gt; Red Flag #4. Bob demands only 50 BTC for a backdoor.<p>There&#x27;s a lot more risk in stealing something yourself vs just providing information that can be used for theft. Letting someone else do the dirty work could definitely be a rational decision. And anyway, the hot wallet at no point after the original hack had 315BTC again, so the expected value of the second&#x2F;third hacks were a lot lower.<p>&gt; Red Flag #6. Rovion is a moralistic individual who not only is a thief himself, but wants to see Bob, another thief from whom Rovion supposedly obtained credentials, severely punished<p>It&#x27;s not surprising to me that someone could adopt a moral framework that let them steal from poorly-secured foreign companies while still considering it wrong to steal from your own employer.<p>&gt; Orange Flag #9. Voorhees talks derisively about Bob&#x27;s competence during the period of time when Bob was employed prior to the hack.<p>Many countries, possibly including Switzerland, do have a very high standard you have to meet to fire someone with cause. This process could be especially delicate if Bob is of an ethnic or racial minority.
rdtsc大约 9 年前
Isn&#x27;t this the standard scam -- crypto-currency exchange gets cleaned out by an insider&#x2F;owner and then a there is a story of an disgruntled employee or other evil hacker. Everyone is supposed to hate this made up hacker instead of suspecting the owners themselves.<p>Maybe it is just the news bias, but crypto-currency seems to attract shady characters. I understand the sentiment about the central banks and global cabal of money controlling plutocrats and all that, but then the same people turn around and hand money to a bunch of amateurs with a website and trust them instead.
评论 #11566940 未加载
评论 #11567233 未加载
Ontheflyflyfly大约 9 年前
Didn&#x27;t know<p>&quot;Who here remembers the story of a bank called X.com? It was a tiny, little-known online bank, until it was hacked and covered in the mainstream press during the first dot-com boom. Its popularity absolutely soared after the hack. I actually had an account on X.com, but if you didn&#x27;t and never heard of it, you may perhaps have heard of X.com&#x27;s founder, a fellow who goes by the name of Elon Musk.&quot;
braderhart大约 9 年前
It seemed to me like Rovion is Bob, but just taking on a different identity, hence the &quot;Let me know when you plan to arrest Bob&quot; comment.
评论 #11566851 未加载
评论 #11566870 未加载
buttershakes大约 9 年前
Finally, someone who took a stab at this. Ever since I read Shapeshift&#x27;s version of events I couldn&#x27;t help but think the entire thing was bullshit. Wild incompetance, improbable alliances, its just weird.
cubano大约 9 年前
I&#x27;m just kinda glad that my old-school, been-burned-100-times, cynical self, who also saw red flags galore into the original narrative, wasn&#x27;t <i>completely</i> nuts.<p>It&#x27;s a pretty solid takedown of all the issues in ShapeShift&#x27;s sketchy story.
评论 #11567942 未加载
AgentME大约 9 年前
&gt;By definition, Rovion was in deep undercover mode. How would Bob have gotten a hold of Rovion? Did he know of Rovion&#x27;s partial penetration? If so, how? If not, then how did they meet up? In any case, how did the two hackers exchange messages?<p>If the attacker didn&#x27;t have root or wasn&#x27;t using a fancy rootkit, it&#x27;s not surprising at all that his hack could have been discovered. Discovering the hack could be as simple as finding an unfamiliar php file that hosted a reverse shell in some directory. The attacker might&#x27;ve had some scripts in a folder. Communication could be started by editing one of the scripts to print a message instead.<p>A friend of mine as a student sysadmin once found a server was part of a botnet, figured out the bots communicated via an IRC channel, joined the channel himself, lurked for a while, found the operator connect one day, and talked. The server never had anything worthwhile on it, the server was re-imaged, the school never bothered pursuing legal action as the guy was in Russia, and I&#x27;m told they&#x27;ve played counter-strike together sometimes since then.<p>&gt;Why wouldn&#x27;t Bob take advantage of the backdoor himself? It&#x27;s not like he had much to lose. He&#x27;d already been ousted from ShapeShift and was already the target of an investigation.<p>Because he could get a bunch of money now and have someone else do most of the work probably.<p>&gt;Red Flag #4. Bob demands only 50 BTC for a backdoor. ... Why not split the proceeds in half, for starters?<p>If Bob has Rovion do all the work with the backdoor access, why would Bob trust Rovion to split the proceeds once he&#x27;s hit the motherlode? Much easier to get some money up-front and be done with it.<p>&gt;Red Flag #5. Rovion pays 50 BTC for a backdoor. ... How would Bob, then, demonstrate to Rovion that he wasn&#x27;t just a scammer, or a honeypot operator, but indeed had a legitimate backdoor to sell?<p>It probably wasn&#x27;t a single 50 btc transaction. Start it slow. (Just like how Erik managed to work out some trust with Rovion later.) Bob probably offered to not boot Rovion&#x27;s original access into the system for a few btc to start with, and they found somewhere to go from there.<p>&gt;Red Flag #6. Rovion is a moralistic individual who not only is a thief himself, but wants to see Bob, another thief from whom Rovion supposedly obtained credentials, severely punished, for being a thief.<p>Seriously, this is just grasping for straws. That doesn&#x27;t seem so strange. Or hell, maybe Rovion just wants to try to throw someone else under the bus morally. People trying to justify themselves is nothing new.