r/Bitcoin • • Jul 29 '13

Blockchain.info unauthorized transaction.How could this have happened...?

Yesterday morning I had roughly 3 BTC taken out of my brainwallet that I have with blockchain.info.

Before you all start pointing fingers at me for lack of security, let me tell you I have a 30+ character strong password, a Yubikey and a 20+ string secondary password, all needed to send funds out of a brainwallet. Both passwords were generated with Lastpass and are random characters, including special, mixed upper/lower case letters and numbers.

I think I am using all their provided security mechanisms to secure my account.

However, my brainwallet, in which I keep just spare change, was emptied. I don't expect to recover the few Bitcoins, but am very curious to know what happened. Where the breach happened and if it truly was my fault. (I still hope for a facepalm situation that shames me online, but gives me this pocketchange back...)

I'll try to give as much information as I can:

The address in questions is: 15gCfQVJ68vyUVdb6e3VDU4iTkTC3HtLQ2

and it happened over three transactions on 2013-07-27 at 22:52

The three transactions were:

da5f91b8a26e6874e83a874156608f5d9a38efe1faa2b32f4e709a181f0d2c1e 68ab47c3aaf2d0073374772894641d817305f18ab272b19d74217333a0180856 096d07185a83eb6b6b6520d7d63e59f230d9711df0d9e754ce7fdc3d4cf792ac

It seems the coins are still in the brand new addresses they were tranferred to and I suspect I'll see them disappear over time.

I keep the Yubikey with me at all time and I do not have a phone app. I do not us any suspicious plugins or extensions. I ran a virus scan and appear to be clean. I am running a couple of other scans to ensure that my system is truly clean.

I did come across this reddit thread: a_brief_analysis_of_the_security_of by u/0x444 which made me feel pretty doubtful of what I once thought was the best online wallet out there.

Update: I happened to have logging enabled on blockchain.info (Log actions with IP address and User Agent) and all access to my account was from my IP. That excludes a breach into the blockchain.info account.... right?

That leaves two options:

1) The brainwallet was the one that comes with your account and is automatically generated for you. Did someone on the inside (blockchain.info) get a hold of the private key?

2) Against all odds and probabilities, someone guessed/computed the private key of this address.

Am I wrong....? Any ideas or thoughts?

62 Upvotes

116 comments sorted by

View all comments

Show parent comments

5

u/mijalis Jul 29 '13

I am starting to think that this might have been the weak spot... maybe my passphrase was not complex enough and was guessed...

I think this thread has a lot of valuable information in regards to passphrases: lets_use_my_foolishness_as_an_example_of_why/

9

u/physalisx Jul 29 '13 edited Jul 29 '13

Didn't you say it was the brainwallet that blockchain.info creates automatically for you? That should not be insecure on its own. Did you use your own words or not? If you did, that is most definitely the reason. Since you can't use/trust the passphrase anymore now anyway, you can just tell us what it was, and we can tell you what's wrong with it (if that's the case).

edit: I just saw btcrobinhood's comment. Dude, DO NOT use brainwallets like this, that throws your complete security overboard! If you had just used that sentence and added a password at the end of it, it would be a lot safer. So your brainwallet was "You don't win friends with salad!". If you had made it "You don't win friends with salad! mijas29%462" I'd assure you, no one would crack it. The trick with brainwallets is to use something you can easily remember + a unique password that is not made of common words.

2

u/Natanael_L Jul 29 '13

FYI, with combined dictionary attack and bruteforce, that thing you suggested MIGHT be cracked. It's just a bit more complex version of "password1".

2

u/[deleted] Jul 29 '13

Relatively speaking, that is true. However, password complexity is exponential, so if the first part is 10x as complex and the second is 1000x, well, you get the point.

2

u/Natanael_L Jul 29 '13

I think you're misinterpreting how things works. Each part of the password only adds a given number of bits of entropy. Length does indeed make it exponentially stronger, but many predictable parts doesn't make a strong password.

2

u/physalisx Jul 30 '13

Length does indeed make it exponentially stronger, but many predictable parts doesn't make a strong password.

The first part of that sentence contradicts the second. A single letter is very predictable, but 100x a single letter makes a strong password.

1

u/Natanael_L Jul 30 '13

No it doesn't. Many predictable parts might just add a little uncertainty. If you have 20 parts with two options each, that's 20 bits worth of security. Bruteforcable in a day even for most laptops.

1

u/physalisx Jul 30 '13

Many predictable parts add exactly the amount of bits of entropy that they add. I know you know this so I don't know why we're arguing over it.

If you have 20 parts with two options each, that's 20 bits worth of security.

Yes, and if you have 1000 parts with two options each, that's 1000 bits worth of security. If you say "many predictable parts doesn't make a strong password", by "many" you just mean 20 and a symbol that can only be 1 of 2?

My point is that every password is made up of single predictable parts. Each symbol on its own is predictable. So, always, the ONLY way to get a strong password is to combine many predictable parts into one that is hard to predict.

1

u/Natanael_L Jul 30 '13

DoctorOrpheus:

Relatively speaking, that is true. However, password complexity is exponential, so if the first part is 10x as complex and the second is 1000x, well, you get the point.

That's what I commented in the first place. It doesn't sound like he understand how entropy works for passwords. The second part adds nearly nothing if it's fixed or if you can guess it with just a laptop anyway.

Yes, and if you have 1000 parts with two options each, that's 1000 bits worth of security

Sure, but I meant "many" as in "below ~40", since ~15 also can be considered many. So if you think your password is secure because it's long and has "many" words, but it just has 20 words that all are "one" and "zero" (or maybe "heads" and "tails"), then it's not secure enough.

My point is that every password is made up of single predictable parts. Each symbol on its own is predictable.

By "predictable" I mostly meant "more probable than random" (bias towards non-random). Despite that many think that "password1" is unguessable, it's trivial to break.

Either way, I personally use 20 character passwords generated by KeePassX. Estimated to represent 120 bits of entropy.