Live data from Hacker News

Account hijacking on MtGox

homakov.blogspot.com

1–10 of 38 posts

Re: Account hijacking on MtGox

#4
post #2

Would 2 factor auth even fix this? If you are hijacking the session ID, the user has already authenticated.

In addition to login, 2FA is typically required for irreversible and other sensitive operations like transfers, for exactly this reason (local malware, XSS, etc, can steal cookies)

This should be pretty much required for all services where users may have significant amounts of money at stake. And users need to be educated to actually enable it.

Coinbase finally enabled 2FA for transfers (of more than $100/day) this week: http://blog.coinbase.com/post/73364231652/security-updates-o...

Re: Account hijacking on MtGox

#5
post #3
post #2

Would 2 factor auth even fix this? If you are hijacking the session ID, the user has already authenticated.

Depends how 2FA is used. If on per/action basis it could save (you know the SID but don't know the OTP/token)

MtGox requires a new 2FA code for pretty much every action you can take (buy/sell/withdraw)

Re: Account hijacking on MtGox

#6
I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

Re: Account hijacking on MtGox

#7

I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

No rewards

Re: Account hijacking on MtGox

#10
post #7

I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

No rewards

Is there a quality bitcoin bounty reward program for vulnerabilities?
Post reply on HN