I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...
No rewards
Account hijacking on MtGox
11–20 of 38 posts
Re: Account hijacking on MtGox
#12I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...
No rewards
Re: Account hijacking on MtGox
#13Gox uses a special 3FA where it takes 6+weeks to get anything out of that exchange. See 144 page bitcointalk thread 'Mtgox delays [gathering]'.
6+ months, actually. Still waiting on one transfer.
I guess it's better to use some other exchange for selling if Gox is taking 6 months to process some transfers...
Re: Account hijacking on MtGox
#14Would 2 factor auth even fix this? If you are hijacking the session ID, the user has already authenticated.
In addition to login, 2FA is typically required for irreversible and other sensitive operations like transfers, for exactly this reason (local malware, XSS, etc, can steal cookies) This should be pretty much required for all services where users may have significant amounts of money at stake. And users need to be educated to actually enable it. Coinbase finally enabled 2FA for transfers (of more than $100/day) this w…
http://www.reddit.com/r/Bitcoin/comments/1vjr7b/please_advis...
Re: Account hijacking on MtGox
#15http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...
Re: Account hijacking on MtGox
#16Earlier quoted context omitted.
6+ months, actually. Still waiting on one transfer.
So the higher price on Gox isn't worth trusting them to actually complete their transfers within their claimed 6week window? How much was the transfer for? I guess it's better to use some other exchange for selling if Gox is taking 6 months to process some transfers...
Re: Account hijacking on MtGox
#17I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies. http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...
I'll just leave this here; https://xkcd.com/538/
Re: Account hijacking on MtGox
#18Earlier quoted context omitted.
In addition to login, 2FA is typically required for irreversible and other sensitive operations like transfers, for exactly this reason (local malware, XSS, etc, can steal cookies) This should be pretty much required for all services where users may have significant amounts of money at stake. And users need to be educated to actually enable it. Coinbase finally enabled 2FA for transfers (of more than $100/day) this w…
Looks like Coinbase 2FA is crap http://www.reddit.com/r/Bitcoin/comments/1vjr7b/please_advis...
Re: Account hijacking on MtGox
#19I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies. http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...
While your WarpWallet is a nice initiative, it doesn't meet the 5th demand of a storage system; immune to physical coercion. I'll just leave this here; https://xkcd.com/538/
Edit: but I guess I agree, it would be a nice feature to have that we didn't think much about. I wonder what a solution would even look like.
Re: Account hijacking on MtGox
#20I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...
No rewards