Those 500K Bitcoins that caused the flash crash weren't real
1–10 of 176 posts
Re: Those 500K Bitcoins that caused the flash crash weren't real
#2Congratulations to those who guessed correctly: http://news.ycombinator.com/item?id=2676467 http://news.ycombinator.com/item?id=2676986 http://news.ycombinator.com/item?id=2676612
Re: Those 500K Bitcoins that caused the flash crash weren't real
#3Re: Those 500K Bitcoins that caused the flash crash weren't real
#4Thank you.
Re: Those 500K Bitcoins that caused the flash crash weren't real
#5I for one won't be returning to mtgox.
Edit: Full-disclosure post http://seclists.org/fulldisclosure/2011/Jun/417 and relevant Bitcoin forum discussion http://forum.bitcoin.org/index.php?topic=20437.0
Re: Those 500K Bitcoins that caused the flash crash weren't real
#6Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own?
AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?
Re: Those 500K Bitcoins that caused the flash crash weren't real
#7"The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing" Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own? AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?
Re: Those 500K Bitcoins that caused the flash crash weren't real
#8What bothers me most is the bullshit explanations that were given initially. Claims of a DB dump being stolen from a financial auditor's laptop, assertions that no SQLi vulnerabilities were reported and couldn't have been responsible, etc. If it weren't for the full-disclosure post about various vulnerabilities in the site, would they have ever admitted any of this? I for one won't be returning to mtgox. Edit: Full-d…
Re: Those 500K Bitcoins that caused the flash crash weren't real
#9"The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing" Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own? AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?
The part that bothers me about that is "triple salted hashing". This could mean any number of things, all of which point to a misunderstanding of what a salt is for.
Re: Those 500K Bitcoins that caused the flash crash weren't real
#10That 2000BTC the thieves made off with is worth about $32,000 at the moment.