Android vulnerability hits Bitcoin apps and more

When a random number is not so random, security pays the price

Android users of Bitcoin are being advised to upgrade their apps and re-secure their wallets after the discovering of a weakness in a component of the operating system responsible for generating secure random numbers. The weakness also affects some secure communication networks, and renders users vulnerable to theft of their digital currency.

The weakness lies with the Android implementation of a piece of code which is supposed to spit out purely random numbers. Instead of working as it should, the numbers it produces aren’t as random as they seem. These numbers are used by Bitcoin users as the public and private keys in the series of mathematical problems which makes up the “blockchain”, the record of transactions. If they are slightly predictable, then as a result, it is theoretically possible to work out someone’s private key from the public signatures they post, and steal money contained in the wallet.

The vulnerability was highlighted by developer Mike Hearn, who created the Bitcoin Wallet app. That app has since been updated, as have Mycelium Wallet and blockchain.info, two other popular wallet apps for Android. Bitcoin.org, a key website for the decentralised development community, advises users to “rotate” their keys. “This involves generating a new address with a repaired random number generator and then sending all the money in your wallet back to yourself”, they write. “Once your wallet is rotated, you will need to contact anyone who has stored addresses generated by your phone and give them a new one.”

However, the weakness in the random number generator has the potential to affect more than just bitcoin apps. Any app which relies on the generator for security is at risk, particularly if the programme requires a public and a private key. The nature of the flaw makes it overly easy to determine a private key if given a public key generated around the same time; as a result, any app which uses a form of public key cryptography, where the security of the encrypted content relies on the public and private keys being unrelated, is at risk if those keys were generated using the faulty generator.

In practice, though, the Bitcoin community is at the most risk here. It's one of the few situations where a public key is very public indeed, and the rewards for cracking it are so immediate that if people can try, they will. But it's hardly a mortal wound; the apps can be updated, and wallets resecured. If Bitcoin is really in danger, it comes from a source which many advocates of the digital money are celebrating. Earlier this month, a Texas court officially declared Bitcoin a "currency" in order to take action against a man accused of running a Bitcoin Ponzi scheme. What sounds like much-needed mainstream recognition is actually a double-edged sword, though. As a currency, it is now fair game for regulators. And sure enough, the New York Department of Financial Services is looking into the "Wild West for narcotraffickers and other criminals". Bitcoin will shortly need to grow up or shut up, it seems.

Photograph: Bitcoin.org

Alex Hern is a technology reporter for the Guardian. He was formerly staff writer at the New Statesman. You should follow Alex on Twitter.

Getty
Show Hide image

To heal Britain’s cracks, it’s time for us northern graduates in London to return home

Isn’t it time for people like me, who’ve had privileges and experiences not open to everyone, to start heading back to our local communities, rather than reinforcing London’s suffocating dominance?

I’m from Warrington. The least cultured town in the UK. My town.

I moved to London almost exactly five years ago. Not because I particularly wanted to. Not because I wanted to depart the raucous northern town that I still call home. Because it was my only choice, really. I’d done my stint in the call centres and had some fun. But that couldn’t, surely, be my lot?

After university, I’d already started feeling a little weird and out of place back in Wazza. There were fewer and fewer people who didn’t look at me like I’d just fallen off a futuristic space flight that’d given me a different accent and lofty ideals.

Of course, that’s because most people like me had already skipped town without looking back and were all in the capital trying to strike beyond the ordinary.

The young, the cities, the metropolitan elite are still reeling after last week’s vote and wondering how people, half of our people, have got it so horribly wrong. We’re different, divided, done for.  

One thing I’ve clung onto while I’ve been in London is the fact that I’m from Warrington and proud. It might not be a cultured town, but it’s my town.

But I wasn’t proud of the outcome of the EU referendum that saw my town vote 54.3 per cent to 45.7 per cent to leave.

To be fair, even in my new “home” borough of Hackney, east London, the place with the third-largest Remain vote, one in five people voted for Brexit.

Yes, in one of London’s hottest and most international neighbourhoods, there are quite a lot of people who don’t feel like they’re being taken along to the discotheque.

Perversely, it was the poorest places in the UK that voted in largest numbers to leave the EU – that’s the same EU that provides big chunks of funding to try to save those local economies from ruin.

In many ways, of course, I understand the feelings of those people back in the place I still sometimes think of as home.

Compared to many suffering places in the UK, Warrington is a “boom town” and was one of the only places that grew during the last recession.

It’s a hub for telecoms and logistics companies, because, ironically, its good transport links make it an easy place to leave.

But there are many people who aren’t “living the dream” and, like anywhere else, they aren’t immune from the newspaper headlines that penetrate our brains with stories of strivers and scroungers.

Warrington is one of the whitest places in the UK, and I’m sure, to many locals, that means those immigrants are only a few towns away. There’s already a Polski sklep or two. And a few foreign taxi drivers. Those enterprising bastards.

We have never seriously addressed the economic imbalance in our economy. The gaping north-south divide. The post-industrial problem that politicians in Westminster have handily ignored, allowing the gap to be filled by those who find it quick and easy to blame immigrants.

When schemes like HS2, which is plotted to smash right through the place I grew up, are pushed against all of the evidence, instead of a much-needed, intercity Leeds to Liverpool investment to replace the two-carriage hourly service, it’s like positively sticking two fingers up to the north.

But I am also a big problem. People like me, who get educated and quickly head off to London when things aren’t going our way. We invested in ourselves, sometimes at state expense, and never really thought about putting that back into the places where we grew up.

There weren’t the right opportunities back home and that still stands. But, rather than doing something about that, people like me lazily joined the gravy train for London and now we’re surprised we feel more kinship with a 20-something from Norway than we do with someone who we used to knock on for when we should have been at school.

That’s not to suggest that our experiences in the capital – or mine at least – haven’t made us a thousand, million times better. 

I’ve met people who’ve lived lives I would never have known and I’m a profoundly better person for having the chance to meet people who aren’t just like me. But to take that view back home is increasingly like translating a message to someone from an entirely different world.

“You know, it’s only because you live in a country like this that a woman like you is allowed to even say things like that,” assured one of my dad’s friends down at the British Legion after we’d had a beer, and an argument or two.

Too right, pal. We live in what we all like to think is an open and tolerant and progressive society. And you’re now saying I shouldn’t use that right to call you out for your ignorance?

We’re both Warringtonians, English, British and European but I can increasingly find more agreement with a woman from Senegal who’s working in tech than I can with you.

It’s absolutely no secret that London has drained brains from the rest of the country, and even the rest of the world, to power its knowledge economy.

It’s a special place, but we have to see that there are many people clamouring for jobs they are far too qualified for, with no hope of saving for a home of their own, at the expense of the places they call home.

It’s been suggested in the past that London becomes its own city-state, now Londoners are petitioning to leave the UK.

But isn’t it time for people like me, who’ve had privileges and experiences not open to everyone, to start heading back to our local communities, rather than reinforcing London’s suffocating dominance?

We can expect local governments to do more with less, but when will we accept we need people power back in places like Warrington if we want to change the story to one of hope?

If this sounds like a patronising plan to parachute the north London intelligentsia into northern communities to ensure they don’t make the same mistake twice... Get fucked, as they say in Warrington.

It was Warrington that raised me. It’s time I gave something back.

Kirsty Styles is editor of the New Statesman's B2B tech site, NS Tech.