Live data from Hacker News

Bitcoinica MtGox account compromised

bitcointalk.org

61–70 of 108 posts

Re: Bitcoinica MtGox account compromised

#61
post #23
post #7

Hate to say this but if this sort of sloppiness continues, the bitcoin brand will be trampled so badly it will never get off the ground.

I doubt people are stupid enough to conflate Bitcoin with 3rd party websites that use bitcoins. Maybe a few will, but the success or failure of Bitcoin does not ride on a what a few dumb people do. And Bitcoin does not have a "brand." You could say, and probably meant, "reputation."

> I doubt people are stupid enough to conflate Bitcoin with 3rd party websites that use bitcoins.

Well, some of the most touted features of Bitcoin are that it's anonymous, untracable, and unfettered burdensome mandates like FDIC insurance and PCI-DSS compliance.

In this case, those features mean in all likelihood the thieves won't be traced or punished, the depositors' money won't be returned, and there was no independent auditing to catch crap security practices.

High profile thefts might make people think they don't need the features that Bitcoin is offering.

Re: Bitcoinica MtGox account compromised

#62
post #2

MtGox transfer limit maxed out: 40,000 BTC + 40,000 US$. At current BTC valuation ($7.66) that's 346,400 US$. By the way, the full Bitcoinica trading platform source code is posted there: http://depositfiles.com/files/2p6zvadzs

Doesn't seem to work out of the box.

Re: Bitcoinica MtGox account compromised

#64

Putting aside the way the Bitcoinica account got compromised, I wanted to mention that I learned the hard way that either Mt.Gox is rife with security holes or a lot of these breaches are actually insider jobs from someone working at MtGox : A month back I realized that I had around 40 BTC lying around and decided to sell them on MtGox. First, my Mt.Gox is mostly inactive, so I actually had to reset my password and s…

I've recently had upwards of $10K on mtgox and had no problems. Could it be that you have some malware with a keylogger on your computer?

Not that there aren't any keyloggers for Linux, I never found anything suspicious, nor have any of my other accounts been breached into. But yeah, if there is a keylogger, I bet it got installed from the Mt.Gox website itself ;)

Re: Bitcoinica MtGox account compromised

#65
post #2

MtGox transfer limit maxed out: 40,000 BTC + 40,000 US$. At current BTC valuation ($7.66) that's 346,400 US$. By the way, the full Bitcoinica trading platform source code is posted there: http://depositfiles.com/files/2p6zvadzs

Doesn't seem to work out of the box.

I haven't had the time to try it myself (still in the office). All I know is it's RoR.

Re: Bitcoinica MtGox account compromised

#67
post #29
post #25

This is starting to prove -- the hard way -- why regulations, certifications, and all that other stuff that feels like meaningless overhead the majority of the time has become a grudgingly accepted part of our lives. It comes back to the most difficult problem: you inevitably need to trust someone, so how do you minimize your risk in that trust? I always thought the Bitcoin trust issues would revolve around the inabi…

As the big banks in the USA have proven, government regulation is definitively not the answer to the question "How can you know whom to trust?" Seriously. Knock that shit off. It's a red herring. You can't abstract away the personal process of choosing trust anchors and metrics, no matter how hard you try. Changing your trust anchor to "the government" just means you end up getting fucked on a larger scale, over a la…

Is it not? How much money have you lost in deposit accounts with US banks?

Re: Bitcoinica MtGox account compromised

#68
post #59

Earlier quoted context omitted.

As the big banks in the USA have proven, government regulation is definitively not the answer to the question "How can you know whom to trust?” A common sentiment: “Big Government doesn’t work.” No, it doesn’t work. But in many cases, it’s less broken then no government a/k/a The Free Market. I’m reminded of Winston Churchill’s quip: "It has been said that democracy is the worst form of government except all the othe…

Without any rules, there is no such thing as personal property and therefore a free market cannot exist. You're describing anarchy, where people take what they want by force.

> You're describing anarchy, where people take what they want by force.

Like taxes taken by the government with the consent of the majority? Anarchy is solving for the general case.

Re: Bitcoinica MtGox account compromised

#69
It is worth noting that (some of) the people behind Intersango acquired and took over operations of Bitcoinica just before the recent hack that took Bitcoinica offline since May 2012 (see https://bitcointalk.org/index.php?topic=81581.0)

Intersango is currently the second largest bitcoin exchange after MtGox, and the largest bitcoin exchange for GBP (see http://bitcoincharts.com/markets/)

From their site(https://intersango.com/):

"Having never suffered a break in or major technical error, we are confident in our abilities to lead bitcoin into its rightful place in the real world."

Some blame for the May hack could be arguably attributed to Zhou Tong, however, having taken over for 3 months since...

Re: Bitcoinica MtGox account compromised

#70

The app and its infrastructure was created by a single, very inexperienced programmer. The app's original author, Zhou Tong, is only 17[1]. Not that age is an indicator of experience in general, but it's certainly the case here. I'm honestly shocked at the amount of trust placed in Bitcoinica. An interesting display of the oft mentioned Stockholm Syndrome happening elsewhere on the forum here https://bitcointalk.org/…

Well I do agree with you that Bitcoinica was not 100% secure. This hack really has nothing to do with the app or its infrastructure. - I didn't set the password. - I didn't have the power to change the password. - I shouldn't have access to the account. The root cause is LastPass account being stolen.

Agreed that you are not personally responsible for this particular attack, though I see it as the latest in a series of cascading failures, beginning with the initial attack. It's the lack of consideration of security - that can only be baked in from the outset - that's the real root cause.

If the application had been self-hosted in a physically secured location, the attack that exposed the LastPass credentials would not have happened (email reset of root passwords). It may not be cool, but the cloud/consumer-level hosting is not appropriate for applications handling large sums of money.

Post reply on HN