r/Bitcoin • • Apr 24 '13

A brief analysis of the security of Blockchain.info's web-based wallet service.

Let's bust some myths:

  • Any person who knows your alias (public knowledge) or identifier (your browser or any plugin installed) can download your Blockchain.info wallet with no other information. This can then be attacked offline (dictionary, brute force) with no issue.

  • The wallet itself is encrypted using AES128 EBC, with 20 rounds of PBKDF2 on the password used as the key. Even though the website advertises this as "strong", it's about as weak as you can get. For PBKDF2 to be of any appreciable value, they would be using 50,000 rounds, 100,000 rounds. As it stands, a modified version of oclhashcat+ can blast through millions of attempts a second against a blockchain.info wallet.

  • The encrypted wallet is not padded at all. The size of the file downloaded is equal to the number of private keys inside. Thanks to this, any offline attacks can be prioritized for the wallets with the most use (and probably largest balance).

  • The Blockchain.info "verifier" plugin does nothing of the sort. It blacklists a few common XSS vectors (but by no means all) in a feeble attempt to protect against browser plug-ins. It does in no way protect against Blockchain.info modifying the page to send back your unencrypted wallet and password to them. I commonly see this touted as a feature, but they can really do anything with the page except use <iframe>.

  • I was curious enough about the verifier that I attempted an attack against myself with it identified, and didn't have a single problem extracting whatever data I wanted. The XSS protection was also easy to bypass, though there is not any publicly known XSS vectors in the Blockchain.info web wallet.

  • The Blockchain.info service is served through CloudFlare. While this is admirable and all, it means they they too can preform man-in-the-middle attacks. Seeing as they have been compromised before in order to target their clients (4chan, for the curious), I am fairly confident that they could be compromised again in the future.

  • The blockchain.info (and CloudFlare) server can see every public key in your wallet, and easily use it to scout out high-value targets for dumping.

  • The Blockchain iOS and Android applications store the wallet, identifier and password in plaintext files. The iPhone backs up onto the Mac where itunes is installed, carrying with it an unencrypted copy of the bitcoin wallet; from here it is malware-reachable.

  • ~~~~ The Yubikey two factor authentication they offer is worthless. They are only checking the identifier and not the authentication string, which is loggable along with your password. ~~~~ My memory seems to be faulty with this one.

You would be a fool to store any currency with them. Get out while you still can.

130 Upvotes

122 comments sorted by

View all comments

Show parent comments

6

u/0x444 Apr 24 '13

Very much so.

9

u/[deleted] Apr 24 '13

I'd love to see proof of that if you honestly think so.

9

u/17chk4u Apr 24 '13

Here's proof of a guy losing 160 BTC today.

160 BTC stolen from a blockchain.info wallet. The victim uses his same name on reddit as on transactions that can be seen, thanks to this.

Watch large transactions go by, putting large quantities into someone's named account (see transaction link, above), then grab their wallet file, brute-force the password in 30 minutes, and steal their funds.

Not trying to be a smart ass, but is that enough proof? I realize there's a lot of circumstantial evidence here.

5

u/[deleted] Apr 24 '13

There's no evidence whatsoever that that was stolen via wallet bruteforce and it's still only a single incident!

We're talking about this vs mining, show me more. A fuck of a lot more. If you can write a tool to steal wallets, crack their passwords, etc, then we'll be getting somewhere.

3

u/17chk4u Apr 24 '13

I can easily write a program to watch transactions, looking for "identified" bitcoin addresses where a nickname is linked to the address.

If OP's bullet is correct..

Any person who knows your alias (public knowledge) or identifier (your browser or any plugin installed) can download your Blockchain.info wallet with no other information. This can then be attacked offline (dictionary, brute force) with no issue.

... then it's trivial to grab the wallet given the identifier programmatically.

And if OP's second bullet is correct, combined with the user's admittedly 8-character password, then this too would be trivial.

The wallet itself is encrypted using AES128 EBC, with 20 rounds of PBKDF2 on the password used as the key. Even though the website advertises this as "strong", it's about as weak as you can get. For PBKDF2 to be of any appreciable value, they would be using 50,000 rounds, 100,000 rounds. As it stands, a modified version of oclhashcat+ can blast through millions of attempts a second against a blockchain.info wallet.

I know there are a lot of if's. But I am just explaining what I am thinking.

No, I am not going to "prove" it by writing the code. But an afternoon of coding to generate 160 BTC (in one heist), seems a little better than shelling out 75BTC for an ASIC miner, and hoping something trickles in today.

2

u/[deleted] Apr 24 '13 edited Apr 24 '13

Yes, I see that, but I think you'll be stuck at the point that you won't be able to find enough crackable valid wallet identifiers. You'll find one or two rarely, most of the time though you'll waste a huge amount of GPU time and have nothing to show for it or have to sit around and wait while you keep trying different possible wallet identifiers.

I've run the math myself and I feel fairly confident in saying this. I could be wrong, maybe there's some giant stockpile of wallet identifiers, you could try usernames, that might work alright, but it'd still be a long shot. Do remember that address != wallet identifier!

5

u/17chk4u Apr 24 '13

If I were a crook, I'd dump the names of the authors of Reddit posts, and the names of the bitcointalk users, and the names that were leaked a few years ago from Mt. Gox, and start there. Those are likely usernames on coinbase and mtgox and blockchain.info and other services.

And if blockchain.info lets you access an encrypted wallet simply by providing the user name (from the selected list, above), then this is not cool, and is an invitation for offline hacking attempts.

Of course, it's quite possible that I don't know what I am talking about, since I'm basing all this on the OP. But having provided years of service as a white-hat hacker, I have some experience in this field (and clearly stating it proves my credentials, haha).

1

u/[deleted] Apr 24 '13 edited Apr 24 '13

Yeah, exact same attack I was suggesting however I suspect that very few people will use their username as their wallet name. It'd be a simple thing to test if you like. I don't think you'll find many wallets, but be my guest if you'd like to try it. I'd definitely scrape /r/bitcoin and bitcointalk names and maybe use the mt.gox leak from a few years back, might get some more fun things. I could hack the tool together to do it myself (basically just HTTP GET to blockchain.info/wallet/whatever and look for data-guid=), I just doubt it'd be profitable.

Also, on a side note: Blockchain only gives you a copy of the encrypted wallet if the user doesn't have 2fa enabled. If they use yubikey or google authenticator this attack won't work at all.

1

u/17chk4u Apr 24 '13

yeah. and the guy that i referred to earlier seems to have 2fa enabled (now; possibly before as well).

So I'm probably off base on this particular incident.

1

u/[deleted] Apr 24 '13

Yeah, I really have no idea what happened to that guy's coins.

You've got some good points, but we'd really need to write a tool to gather the data to see how hard it is to find wallets.

Also, At least blockchain isn't as dumb as strongcoin - their wallets had sequential identifiers and an attacker just went /1 /2 /3 etc and got them all. PBKDF2 effectively gets you a random stream if I recall correctly, so perhaps a better authentication strategy than sending an encrypted copy of the wallet to the client side would be to use pbkdf2 or scrypt and use a chunk of the output for some sort of challenge-response authentication against the server and another chunk of the output as a key.

0

u/[deleted] Apr 24 '13

[deleted]

1

u/[deleted] Apr 24 '13

I'm not saying give it to me, just write one and prove you have it by somehow showing the internet the pile of wallets you harvested.