Hacker News new | past | comments | ask | show | jobs | submit login

The finger-pointing at BGP is red herring: the problem is that the stratum protocol has zero authentication. If you can intercept those streams, you can trivially ask anyone to start mining for you instead. This could also have been done using DNS poisoning, ISP-side intercepts, or anything else in the standard bag of tricks. http://blog.kevmod.com/category/bitcoin/



Indeed, for bitcoin it's a solvable problem, however let's not let that distract us from the monumental revelation that BGP hacking is so easy to do that someone motivated by a relatively paltry reward can pull it off.

This is one aspect of bitcoin that I really like, it shows us where the weaknesses are.


You're certainly not looking, because BGP insecurity is very old news.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: