Live data from Hacker News

I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

forum.bitcoin.org

101–110 of 319 posts

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#101

Earlier quoted context omitted.

This is absolutely not how the Mt. Gox database works. I know because I have access to the source code of the site. All that source code you're looking at means nothing if the attacker gained arbitrary SQL execution on the database.

If you had sql injection rights in the database, there would be no need to trade; you would just insert a few nice rows in the db for yourself, mark yourself 'super trusted' and then initiate a withdrawal. This wasn't a SQL injection attack in my opinion.

Hmm, but what if the attacker wasn't in it for the $currency?

What if he were in it to destroy Mt. Gox, as they say, "for the lulz"?

Making all their customers angry and causing a run on their escrow accounts might just do it more effectively than trying to withdraw whatever could be obtained through their online trading platform.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#102

Earlier quoted context omitted.

Why? There is a perfectly legitimate argument for letting him keep the funds. They were put up for sale, and he bought them. It was MtGox's systems that executed the trade. If the sell order was invalid, it was MtGox's fault, or the seller account holder's, not the buyer's.

I'm not really sure I agree with this. The right to sell something is predicated on owning the item in question. A buyer of stolen goods is unable to take legal ownership, it doesn't matter if he doesn't know the item is stolen. (i.e. I steal a car, and sell it to you, you don't own the car even though you gave me money and you didn't know the car was stolen) It does matter that the coins were not put up for sale by…

So, would you say the same if I placed a standing buy order two weeks ago, and it was automatically executed?

How is a buyer supposed to know if the seller is making a bona fide offer, esp. where the buyer may place its buy order in advance of the sell order?

I stand by my position that it's up to the exchange and the seller to protect against unauthorized sell orders.

Of course, under extreme circumstances, the buyer will see that something is out of place – as is exactly the case here, where the buyer came forward because he felt that the sell order was not valid.

BUT (and here's the most important point): who gets to decide when a case is "extreme" enough to put the burden on the buyer? It's not a call anyone should be able to make, unless there are clear rules, published up front.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#103
post #16

This reminds me of a conversation I was having with a friend a couple of days ago about network affects. Once a system gets too big, the nice people that started it start getting screwed by the people who don't understand (or care about) the founding ideals. The problem with a trading house like Mt. Gox is that some people assume that all of the players are altruistic (these "some people" being "me", somebody with a…

I'm actually almost glad Bitcoin has suffered these high-profile attacks. The amount of money actually lost seems to be relatively small, and its better attacks like this happen now, whilst the market is still small. Without regulation or reversible transactions, Bitcoin security has to be very good indeed, and this is the sort of incident that might encourage better security measures. Quite frankly, Mt. Gox never st…

I agree. Stress tests like this are inevitable, so the sooner they happen, the better hardened Mt Gox and other exchanges can become.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#104

Earlier quoted context omitted.

The poster does not seem like a malevolent person at all, but he was clever enough to post the $0.0101 bid order before other buyers in line knew what happened, and the commenters on the Bitcoin forum are clearly jealous. Well played, toasty.

He didn't place the $0.0101 order. "I also decided against this, when I realized that whoever placed the gigantic sell order was probably doing so for the exact same reasons and I knew how that would make me look."

"I had to try several times, but eventually I got a buy order in, offering to buy as many bitcoins as I could for $0.0101."

He did place the $0.0101 buy. Your quote is regarding withdrawing the bitcoins from Mt Gox.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#105

Earlier quoted context omitted.

Why? There is a perfectly legitimate argument for letting him keep the funds. They were put up for sale, and he bought them. It was MtGox's systems that executed the trade. If the sell order was invalid, it was MtGox's fault, or the seller account holder's, not the buyer's.

I'm not really sure I agree with this. The right to sell something is predicated on owning the item in question. A buyer of stolen goods is unable to take legal ownership, it doesn't matter if he doesn't know the item is stolen. (i.e. I steal a car, and sell it to you, you don't own the car even though you gave me money and you didn't know the car was stolen) It does matter that the coins were not put up for sale by…

When Nick Leeson traded fraudulently with Barings customer's assets did they get a do-over?

--

http://en.wikipedia.org/wiki/Rogue_trader - shows other examples too

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#106
post #53

Earlier quoted context omitted.

Uh, is that really so? So I can steal whatever I want, as long as I can sell it off fast enough? Say I am 99 years old and have only one week left to live. What if I go on a car stealing spree and steal Porsche cars for my extended family. Then I sell it to them for a symbolic 1 cent each, claiming that I have collected them over my lifetime and now want my family to benefit.

You've misread me. You, the thief, are still on the hook for your crime. The buyer, if they really are a bona fide purchaser for value without notice, is not. Your family would probably not meet the test, as this would be the first time they've heard of the Porsches. (IANAL, TINLA)

Yes, what I mean is that if I was 99, I wouldn't care much about being punished for being a thief. I could therefore make a lot of people happy. If not my family, then maybe I could go Robin Hood, steal from the rich and sell cheaply to the poor.

I can't imagine that it works that way. I can believe that as a buyer of stolen good without knowing they were stolen, you won't be punished. But you will still have to return the stuff. I am not a lawyer either, though.

If it works as you describe, let's found a guild of 99 year old Robin Hoods...

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#107
post #38
post #13

Although I can completely understand why this guy (the sumbitter?) disagrees with MtGox's solution, I thought it seemed perfectly reasonable. Even though MtGox never stated they'd interfere, being hacked is unexpected enough to allow some leeway with follow-up. If the flashcrash happened organically, I doubt MtGox would revert the trades.

It's not that they never stated they'd interfere, it's that they explicitly stated they would never interfere by publicly disclaiming any role as a counter-party. If they were hacked, it's their responsibility to make things right with the party that was hacked, and not interfere with anyone else's accounts/trades. Anything less does severe damage to faith in the exchange, which tends to lead people to only keep mone…

Although I understand your perspective, and I agree that they have to do something to "make things right," I'm still inclined to accept the rollback.

As much as I hate to use analogies, its the best way I can think to explain my reasoning. If someone (a hacker) robs a bank (user on MtGox), and they throw the money on the ground as they fleeing the scene of the crime, only for it to be picked up by bystanders (profiting users), what do you do?

To me, simply returning the money (rollback) seems to be the simplest effective solution. Maybe I'm being too utilitarian, but it seems too complex to add additional funds into the system, especially when we're talking about nearly 10% of the entire value of BTC. Additionally, it establishes a strange and dangerous precedent: hackers can get away with upsetting the market. And who can make sure the hackers & profiteers aren't working together?

I don't think there's really much you can do to repair faith in the exchange in the immediate future. More importantly, people will keep money as BTC the exchange if it is value is stable (or deflating). Even now, I'd be more worried about the market than hackers.

I'd love to see an insurance company spring up. It'd require major capital, but it'd really help strengthen the value of BTC by providing security and resolving nearly all of these issues. (Things I'd do with $1M...)

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#108
post #31

Earlier quoted context omitted.

you see, majority of bitcoin forum audience are traders themselves. they are in for money and they are jealous.

The poster does not seem like a malevolent person at all, but he was clever enough to post the $0.0101 bid order before other buyers in line knew what happened, and the commenters on the Bitcoin forum are clearly jealous. Well played, toasty.

He stole 600+ BTC, though. And now he resents giving back the BitCoins that are supposed to be "rolled back". Not so benevolent in my opinion.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#109
post #40

I don't see the problem with a rollback. Couldn't the legal users just redo all their transactions? It sounds to me, as the first commentator on bitcoin.org says, that someone would like to keep their fat booty.

> I don't see the problem with a rollback. Suppose I gamble my life savings, buy Kleenex shares. Tomorrow a report comes out showing that using paper tissues causes allergies and prolongs colds. The shares tank ... I'd like a rollback please! Strangely enough the guy that saw the report first and shorted those shares making millions doesn't want a rollback. Of course he wants to keep the money, he traded correctly on…

The difference is that the BTC being sold were stolen. It is a completely different thing from what you describe.

If tomorrow it was discovered that the BitCoin protocol has been hacked and BitCoins are worthless, a rollback wouldn't be justified.

Re: I'm the guy who bought 259684 Bitcoins for under $3000 yesterday

#110
post #33

Earlier quoted context omitted.

It would have many collisions with many shorter passwords. But almost certainly not any collisions with very simple and very short passwords. The hash output space is sufficiently large. Someone who (given infinite time) found a brute-force collision would likely find one of the shorter preimages first – you aren't really gaining anything by going ever-longer, after your preimage choice has as many bits as the hash o…

I suppose the defender could have a rainbow file of his own and purposefully choose a password which didn't hash-collide with a password of < N characters.

That's a fantastic idea for a web service. Google, are you listening?
Post reply on HN