You think this hack is bad, wait till Twitter gets hit since so many of their IT / Security people have been fired and quit.
But eliminating all other things I have been saying for years unless you have a controlled multiple verification setup for updating anything like this you are just asking for trouble.
Yes but as I posted someplace else, it's somewhat a false security.
Do you check the hash of the file you downloaded against what is posted?
Do you have automatic updates turned off on your phone and not update till people have verified the posted code is the same as what is in the app store / play store?
And as I posted in another thread unless there has been a 3rd party audit of how they push the update to the store this is all just security theater.
Think about it, if there are poor controls to upload the compiled file to the store then it's all pointless.
DaveF gets a job with bigwallet as their IT hardware person. It's open source, it's audited, it's amazing beautiful code.
Friday @ 4:30PM as everyone is leaving for the weekend I post a corrupt fund stealing compiled app to the app / play store and walk out of the building, head to the airport and fly to some island with no extradition. Saturday AM they have the bad wallet pulled but by then I have 1000s (10000s?) of BTC that were sent to me before anyone knew what happened. And I'm on a beach sipping drinks out of a coconut.
On the other hand the shitty closed source wallet needs 2 people with security dongles to log into the PC that updates the code that is in the app / play store.
You might not know what the code is, and it may be crap with bugs, but they at least know that what they wrote is what is up there.
However, since as far as I know NONE of them publish / publicly audit how they push updates to the stores it's all just trust.
You may feel differently. You may disagree. That is fine, but IMO it really needs to be discussed.
-Dave
This is an edge case with the exchange imploding and everything else happening. So it could be the owners doing it, or it could be a low lever programmer that had access he or she should not have had and found a way to run with the funds.
It will probably take years to know the truth and even then we will never truly 100% know. With enough money involved, it's not that hard.
Remember it does not matter if the evidence exists or not, I can find it...
https://www.youtube.com/watch?v=c7o1tg1r_DM-Dave