Hacker News new | ask | show | jobs
by cbs 5224 days ago
>If this was the case, why couldn't every access to that wallet, which, assuming the above is true, necessarily occurs on other servers

From the sounds of it, this was that other server. All it did was operate on the wallet. And if they used other servers, then those would have been the target of the attack.

And, no matter how much damn encryption they have, they rooted the box that operates on the decrypted data, thats game over. The only attacker you would be able to thwart with more encryption would be the one who is able to root a linnode VPS, but unable to extract the key or decrypted wallet from from software running on that box. Sure, there is probably some number of attackers in that space, but security is a game of diminishing returns, and there are different security measures to take that are a much better investment of time than stopping that small slice of people.

1 comments

My reading was that the Linode with the hot wallet did not contain the software that operated on it. Perhaps it did, in which case you are right.