Live data from Hacker News

Those 500K Bitcoins that caused the flash crash weren't real

mtgox.com

71–80 of 176 posts

Re: Those 500K Bitcoins that caused the flash crash weren't real

#71

Earlier quoted context omitted.

US currency hasn't even pretended to be backed by gold since the early 1970s.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. In terms of the question, how would it be handled from an FDIC perspective if it came to a worst case scenario... it'd be a shit-show.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically.

I think you're just rambling. Our currency isn't gold backed -- who cares how much the US govt. has in gold repositories and why does it need to be checked?

Re: Those 500K Bitcoins that caused the flash crash weren't real

#72
post #62

Earlier quoted context omitted.

It was crypt-MD5, the fact that they call it MD5 with salt is generous at best. They seem to have made the decision to move to crypt-MD5. I don't really have any faith in their ability to secure the servers.

True, but I think this has been fixed, assuming their new site is live: "The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing and soon will have an option for users to enable a withdraw password that will be separate from their login passwords."

Which means that they're not using bcrypt, which means they still have no idea what they're talking about and are probably insecure.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#73
post #6

"The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing" Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own? AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?

Yeah, when this very first happened, I was in the IRC room at onlyonetv interviewed Mark (via proxy). I kept shouting in IRC to ask them to use bcrypt and was told they were doing 1000xSHA-512. I later tweeted at MagicalTux to recommend bcrypt and was asked if multiple iterations of SHA-512 is good enough. He said that he was told bcrypt was not secure enough. How do these businesses succeed with business people that…

Don't confuse SHA-512 hashing once with SHA-512 hashing 1000 times though.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#74
post #6

"The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing" Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own? AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?

What is the benefit of bcrypt over several million rounds of SHA-512? It seems to me that repeating the hash function is the adjustable work factor that bcrypt seeks to allow and SHA-2 is already in most languages without an additional library.

No. Making Blowfish faster is equivalent to solving a hard cryptographic problem. We have a much weaker guarantee about SHA-512. While SHA is probably good enough, bcrypt is definitely better.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#75
That's fine, but it doesn't change the fact that Mt. Gox is sitting on untold amounts of users' funds, in both hard currency and bitcoins.

I've got 70 bitcoins in their system, and they have not responded to any attempts to contact them for two weeks now.

I've even gone so far as to contact Mark Karpeles directly through LinkedIn, and nothing.

They have lost all credibility. Aside from the fact that no one will ever trade with them again, the most likely next scenario is a flood of lawsuits from Mt. Gox members who have lost their money.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#76
post #62

Earlier quoted context omitted.

True, but I think this has been fixed, assuming their new site is live: "The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing and soon will have an option for users to enable a withdraw password that will be separate from their login passwords."

Which means that they're not using bcrypt, which means they still have no idea what they're talking about and are probably insecure.

They could be using PBKDF2, but if they were, they probably should have said the magic words. Also, the iteration count is kind of important. If it's triple-iterated, that won't do much good.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#77

Earlier quoted context omitted.

US currency hasn't even pretended to be backed by gold since the early 1970s.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. In terms of the question, how would it be handled from an FDIC perspective if it came to a worst case scenario... it'd be a shit-show.

They would just call up the federal reserve and have them print money. When accounts close down it's money that disappear from the money supply that the fed would replace.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#78
We can attempt to blame the owner of the compromised account for the recent events but at the end of the day the responsibility to secure the site and protect our users rests with us. The admin account responsible had more permissions than necessary, and our security triggers were not as tight as they could have been.

Those are good words to read. +1.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#79
post #49

Earlier quoted context omitted.

I understand that. I am curious how effective insurance deposite works in the face of a country-wide breakdown. I know Greece has a deposit fund, I'm curious to see how effective it'll be (does it actually cover 100% of the deposited money (up to the maxium per account)?)

It doesn't. The FDIC doesn't have a fraction of the money needed to insure a fraction of the money that is supposedly FDIC-insured. More over, the United States likely lacks the gold to back our current currency, let alone the currency needed to prop up those who lose money in the situation of the decreasing number of banks failing.

Its sad that this has been voted down because you mentioned gold, you're completely correct, other than saying "gold" instead of "wealth" or "power".

Re: Those 500K Bitcoins that caused the flash crash weren't real

#80

Earlier quoted context omitted.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. In terms of the question, how would it be handled from an FDIC perspective if it came to a worst case scenario... it'd be a shit-show.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. I think you're just rambling. Our currency isn't gold backed -- who cares how much the US govt. has in gold repositories and why does it need to be checked?

No he isn't. If ( just for the sake of the argument ) RMB replaces USD as the international currency base, US has absolutely nothing to back dollar value and prevent it from dropping.
Post reply on HN