Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The underlying issue here is that addresses created by the tool at fault can have their private key derived from public data. If you send it back, it'll just get stolen again. Furthermore, the typical way that someone proves ownership of an address is by making a transaction from that address with parameters set via private communication with someone else. But since the private key is knowable, anyone can do that. There's no generic way to prove ownership of an address if the private key associated with that address can be determined by an attacker.


Conceivably, the funds could be sent to an address that they send to before. Very far from perfect... could work if it's a centralized exchange, one could deposit to the same address more than once (or maybe there's a time limit for re-use iunno). And no way (good?) way of knowing you were sending to your own account on that exchange, or somebody else's.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: