Live data from Hacker News

Breaking open the Mt. Gox case, part 1

blog.wizsec.jp

31–40 of 99 posts

Re: Breaking open the Mt. Gox case, part 1

#31
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

>I have to admit, that is a reasonable assumption.

I really have to disagree. You get breached, you change your private keys. There shouldn't be a debate about that.

Re: Breaking open the Mt. Gox case, part 1

#32
post #28
post #22

It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

Magic the Gathering Online Exchange ;)

Re: Breaking open the Mt. Gox case, part 1

#33

The coin flow graph is terrific: http://wizsec.jp/images/theft_flow.svg Is this type of visualization common in Bitcoin? Is it a tool anyone can easily use? Edit , let me restate my question. "Is there a tool that generates Sankey diagrams from blockchain data that is easy to use?"

These are called Sankey diagrams.

I read this as Snakey and it still works :)

Re: Breaking open the Mt. Gox case, part 1

#34
post #28
post #22

It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

Yep. Mt Gox = MTG: Online Exchange

Re: Breaking open the Mt. Gox case, part 1

#35
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

> I have to admit, that is a reasonable assumption.

It costs dirt to move your coins. It's not remotely reasonable if you're in the Bitcoin world at all - if you have any reason to believe that an attacker had any access to your wallet the advice is always the same. Make a new wallet and transfer all the coins ASAP.

Re: Breaking open the Mt. Gox case, part 1

#36

Can't wait to get my refund :) It's still insane to me that MtGox never moved coins to a wallet or acknowledged the breach until long after it was too late. You would think if you have billions of dollars sitting somewhere and you realize someone is starting to take them you would, you know, do something .

>Can't wait to get my refund :) I had like 0.000001 BTC in mtgox and it was worth it for the cute sticky unfoldy postcard thing I got from the Japanese court.

When did you get that? I never received such a card.

Re: Breaking open the Mt. Gox case, part 1

#37
post #3

I remember a time when BTC-e was the most logical exchange to use, especially in the fallout of MtGox. I really enjoyed how straightforward the exchange was, and how easy it was to get started using their API. I don't think they're coming back after this.

[deleted]

Re: Breaking open the Mt. Gox case, part 1

#38
post #31
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

>I have to admit, that is a reasonable assumption. I really have to disagree. You get breached, you change your private keys. There shouldn't be a debate about that.

I think his point is that when it comes to stuff like this, our intuition about reasonable assumptions is wrong. And we must as both you and the parent post say, be systematic about the response.

Re: Breaking open the Mt. Gox case, part 1

#39
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Lots of people in Bitcoin hate KYC and AML laws, and consider them invasive. I am one of these people. In itself, it's not an indicator of wrongdoing.

I don't know what you're getting at here? We're not discussing wrongdoings, but violations of the law.

BTC-e was operating illegally for a very long time and everyone knew this.

If your dislike of KYC and AML laws led you to believe that BTC-e was on solid legal ground, then you're simply stupid.

Re: Breaking open the Mt. Gox case, part 1

#40
post #31
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

>I have to admit, that is a reasonable assumption. I really have to disagree. You get breached, you change your private keys. There shouldn't be a debate about that.

You don't have to disagree. I dont think he's arguing that you shouldn't change the keys based on that assumption.
Post reply on HN