Earlier quoted context omitted.
Which means that they're not using bcrypt, which means they still have no idea what they're talking about and are probably insecure.
They could be using PBKDF2, but if they were, they probably should have said the magic words. Also, the iteration count is kind of important. If it's triple-iterated, that won't do much good.
Those 500K Bitcoins that caused the flash crash weren't real
81–90 of 176 posts
Re: Those 500K Bitcoins that caused the flash crash weren't real
#82If I had any bitcoins hosted on mtgox and, for some reason, had not already taken them out, I would do so right now . When you give them your bitcoins, you are trusting them to keep your money safe. I trust my money with my large bank for two reasons: (1) they have a large safe and have practice keeping people out, but more importantly, (2) if someone were to break in and take some of the bank's money, I would know t…
The reason Mt Gox needs to obsess over password database is because they don't seem experienced enough to secure the rest of their site. When it comes down to it, they are still a "PHP+mysql" site like all the others on the Internet. Would you store your funds at the Bank of Wordpress?
Re: Those 500K Bitcoins that caused the flash crash weren't real
#83Earlier quoted context omitted.
The reason Mt Gox needs to obsess over password database is because they don't seem experienced enough to secure the rest of their site. When it comes down to it, they are still a "PHP+mysql" site like all the others on the Internet. Would you store your funds at the Bank of Wordpress?
Is a site inherently safer if you use Java?
Re: Those 500K Bitcoins that caused the flash crash weren't real
#84Everybody should give the people behind Mt. Gox a break. These guys make real banks look good - no small feat!
March, 2011 – MtGox.com (Mt. Gox), now the world’s leading Bitcoin exchange, was purchased by Tibanne Co. Ltd. As part of the purchase agreement, for a period of time, Tibanne Co. Ltd was required to pay the previous owner a percentage of commissions. In order to audit and verify this percentage, the previous owner retained an admin level user account. This account was compromised. So far we have not been able to determine how this account’s credentials were obtained.March, 2011 – MtGox.com (Mt. Gox), now the world’s leading Bitcoin exchange, was purchased by Tibanne Co. Ltd. As part of the purchase agreement, for a period of time, Tibanne Co. Ltd was required to pay the previous owner a percentage of commissions. In order to audit and verify this percentage, the previous owner retained an admin level user account. This account was compromised. So far we have not been able to determine how this account’s credentials were obtained.
A quick search of Google for Tibanne Co Ltd leads to Tibanne.com:
DOMAIN: TIBANNE.COM
RSP: KalyHost
created-date: 2009-10-02 05:43:17
updated-date: 2011-05-25 15:15:09
registration-expiration-date: 2012-10-02 05:43:17
owner-organization:
owner-name: Mark Karpeles
Does this mean Mark sold Mt. Gox to himself and in the process created a superuser account so he could manipulate the exchange to his benefit? Sounds like he could be taking a page out of the Ultimate Bet / Absolute Poker playbook.
Probably would be willing to take him at his word if the explanation of the flash crash didn't change every few hours. And/or if he and others didn't mobb the guy who put in the low bid during the crash.
Re: Those 500K Bitcoins that caused the flash crash weren't real
#85If I had any bitcoins hosted on mtgox and, for some reason, had not already taken them out, I would do so right now . When you give them your bitcoins, you are trusting them to keep your money safe. I trust my money with my large bank for two reasons: (1) they have a large safe and have practice keeping people out, but more importantly, (2) if someone were to break in and take some of the bank's money, I would know t…
The reason Mt Gox needs to obsess over password database is because they don't seem experienced enough to secure the rest of their site. When it comes down to it, they are still a "PHP+mysql" site like all the others on the Internet. Would you store your funds at the Bank of Wordpress?
Re: Those 500K Bitcoins that caused the flash crash weren't real
#86Earlier quoted context omitted.
They could be using PBKDF2, but if they were, they probably should have said the magic words. Also, the iteration count is kind of important. If it's triple-iterated, that won't do much good.
Even with the iteration count, SHA512 is not exactly meant to be slow. They're taking the long way around to try and get the security of bcrypt... without just using bcrypt.
Increasing iteration count is synonymous with intending something to be slow. BCrypt itself uses a default of 2^10 iterations in most bindings. PBKDF2 + and an NIST studied hashing algo like SHA512 is a perfectly valid method.
Re: Those 500K Bitcoins that caused the flash crash weren't real
#87Earlier quoted context omitted.
Is a site inherently safer if you use Java?
Then if you use Wordpress? Yes.
Re: Those 500K Bitcoins that caused the flash crash weren't real
#88If I had any bitcoins hosted on mtgox and, for some reason, had not already taken them out, I would do so right now . When you give them your bitcoins, you are trusting them to keep your money safe. I trust my money with my large bank for two reasons: (1) they have a large safe and have practice keeping people out, but more importantly, (2) if someone were to break in and take some of the bank's money, I would know t…
The reason Mt Gox needs to obsess over password database is because they don't seem experienced enough to secure the rest of their site. When it comes down to it, they are still a "PHP+mysql" site like all the others on the Internet. Would you store your funds at the Bank of Wordpress?
That, though, in no way means that you can't build a good, secure website on the LAMP stack.
It's just a (rather obvious) fact that if you're a bad developer, then you're going to build an insecure site, most likely on LAMP. If you're a good developer, you're probably going to build a good site, which might be on a less common platform, but equally as (or more) likely on LAMP, too.