Live data from Hacker News

Those 500K Bitcoins that caused the flash crash weren't real

mtgox.com

111–120 of 176 posts

Re: Those 500K Bitcoins that caused the flash crash weren't real

#111
post #80

Earlier quoted context omitted.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. I think you're just rambling. Our currency isn't gold backed -- who cares how much the US govt. has in gold repositories and why does it need to be checked?

No he isn't. If ( just for the sake of the argument ) RMB replaces USD as the international currency base, US has absolutely nothing to back dollar value and prevent it from dropping.

Of course it does - the strength of the US economy.

The US economy may be fucked up in many ways, and may face some harsh transitions if it can no longer rely on the strength of the dollar as an international currency, but it is still a large economy. The loss of that strength will not magically result in the dollar having "no backing".

Certainly, if the dollar was replaced by the RMB internationally, the dollar would start to drop against other currencies - until it reached a realistic equilibrium point.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#112
post #80

Earlier quoted context omitted.

I was more referring to the fact that we fail to produce proof of the limited amount of gold that we claim to have and every attempt to audit it is rebuked magically. I think you're just rambling. Our currency isn't gold backed -- who cares how much the US govt. has in gold repositories and why does it need to be checked?

No he isn't. If ( just for the sake of the argument ) RMB replaces USD as the international currency base, US has absolutely nothing to back dollar value and prevent it from dropping.

Pretty much every useful currency these days is "backed" by absolutely not one single atom of metal.

Which, it turns out, works just fine -- the belief that gold has value is roughly as magical as the belief that saying some words can turn wine into blood (and a prime sign of religious dogma in both cases).

Re: Those 500K Bitcoins that caused the flash crash weren't real

#113
post #48

Earlier quoted context omitted.

An exchange. That accepts deposits. And holds your money for you. Like a bank.

A bank is a legally defined concept, this exchange is not one.

There is a difference between reading the statement as "mtgox offers some services which make it look bank-like" and "mtgox is definitively a bank as defined by applicable laws".

The difference, in case you're curious, is willful pedantry, and really just clutters up the thread.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#114
post #95
post #62

Earlier quoted context omitted.

True, but I think this has been fixed, assuming their new site is live: "The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing and soon will have an option for users to enable a withdraw password that will be separate from their login passwords."

Not sure why I'm downvoted, SHA-512 is obviously better than MD5 and we don't know the details. The constant spewing that bcrypt is the only way to hash a password is getting old fast. Ok, whatever, keep downvoting, fuckers.

The reason you're being downvoted is because this has been explained a fair number of times on HN. The problem with using SHA-* or MD5 for hashing is that those algorithms are designed to be fast. This means that it's relatively easy for a cracker with a dump of the database to bruteforce passwords, since they can try gazillions of combinations very quickly. Hell, they can even parallelise the task on EC2 and get it all done in an hour.

By contrast, computing bcrypt takes a significant amount of time and CPU. It's slow. It's designed to be slow. It's designed so that you will need a LOT of CPU power to bruteforce it.

So, no, SHA-512 is not much better than MD5. It's still a fail.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#115
post #55

A reminder that MTGOX originally stood for "Magic The Gathering Online eXchange". When a site designed for trading cards online turns into the world's biggest Bitcoin exchange you better believe there's not going to be an appropriate level of security underneath it.

A reminder that people who make sweeping generalizations about subcultures they like to make fun of aren't worth listening to.

(also: http://news.ycombinator.com/item?id=2697975)

Re: Those 500K Bitcoins that caused the flash crash weren't real

#116
post #55

A reminder that MTGOX originally stood for "Magic The Gathering Online eXchange". When a site designed for trading cards online turns into the world's biggest Bitcoin exchange you better believe there's not going to be an appropriate level of security underneath it.

Hah, I didn't know that. I thought it stood for "Mount Gox", a play on "Fort Knox"...

Re: Those 500K Bitcoins that caused the flash crash weren't real

#117
post #34
post #31

Earlier quoted context omitted.

don't disagree with most of what you said, but...you sure about this part? I would know that I could still withdraw my money because they have enough cash on hand for me to do so. http://en.wikipedia.org/wiki/Fractional-reserve_banking Or if you want a more practical example, keep watching Greece (or look at what happened to Argentina 10 years ago).

> don't disagree with most of what you said, but...you sure about this part? Yes. I am sure. I have far, far, far less than 0.000001% of the total money in the bank. If they could not produce this much money when I wanted it, there would be other serious problems. > Or if you want a more practical example, keep watching Greece If I was in Greece, I would not have my money in one of their banks.

> Yes. I am sure. I have far, far, far less than 0.000001% of the total money in the bank. If they could not produce this much money when I wanted it, there would be other serious problems.

Last year, a branch office of a large bank in Finland was barely able to produce 10 000 euros in cash when I wanted to withdraw it.

The clerk just didn't realize he shouldn't mention it.

Don't be so sure.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#118
post #6

"The new Mt. Gox site features SHA-512 multi-iteration, triple salted hashing" Why not use a standard key derivation function such as PBKDF2 or bcrypt to provide some confidence in the system rather than inventing their own? AFAIK bcrypt is strong because of Blowfish's expensive key setup. How does this compare to SHA-512?

What is the benefit of bcrypt over several million rounds of SHA-512? It seems to me that repeating the hash function is the adjustable work factor that bcrypt seeks to allow and SHA-2 is already in most languages without an additional library.

What is the benefit of bcrypt over several million rounds of SHA-512?

Most advances in cracking cryptographic hashes is not from Moores law, but some insight or breakthrough in the underlying algorithm. i.e. someone figures out a way to make MD5 brute forcing 2^(lots) faster. Usually these are not done overnight, but are chipped away bit by bit.

We are getting there with SHA512. The edges are starting to give. Warning signs are apparent. Eventually someone will reduce it to nothingness. 1000 iterations of nothingness is nothing ness.

SHA-2 is already in most languages without an additional library.

Oh dear god this is a terrible way to make a security decision. You have to install software no matter what you do. Unless you're writing software with a magnet in raw machine code, you will have to install additional software. Take the few minutes to install the bcrypt library.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#119
post #3

That 2000BTC the thieves made off with is worth about $32,000 at the moment.

It wasn't thieves, was it? It was just a guy who bought bitcoins during the crash and withdrew some. That's perfectly legal, from where I'm standing. EDIT: It looks like the guy I'm talking about only withdrew 640ish coins, so this must be someone else.

No, MtGox said that the thief was able to make a larger withdrawal (approximately 2000 BTC) before our security measures stopped further action.

Re: Those 500K Bitcoins that caused the flash crash weren't real

#120

Earlier quoted context omitted.

Even with the iteration count, SHA512 is not exactly meant to be slow. They're taking the long way around to try and get the security of bcrypt... without just using bcrypt.

> Even with the iteration count, SHA512 is not exactly meant to be slow. Increasing iteration count is synonymous with intending something to be slow. BCrypt itself uses a default of 2^10 iterations in most bindings. PBKDF2 + and an NIST studied hashing algo like SHA512 is a perfectly valid method.

Iteration is valid, but what is this about "triple salting"?

Googling "triple salted" sha -gox gives me 13 results, of which 3 are about caramel cupcakes and none are serious evaluations of such an approach. It sounds like homebrew security.

Post reply on HN