Live data from Hacker News

Account hijacking on MtGox

homakov.blogspot.com

21–30 of 38 posts

Re: Account hijacking on MtGox

#21
post #7

Earlier quoted context omitted.

No rewards

dont know if you are interested but bex.io is hiring for security engineers/auditors, and most of their employees are remote. Since these guys puport to be a cookie-cutter template for running your own bitcoin exchange I'm sure they will need you. https://angel.co/jobs?slug=bex-io

lol, this guy is a legend around here. If he wanted a job, he'd have it.

Re: Account hijacking on MtGox

#22
post #19
post #17

Earlier quoted context omitted.

While your WarpWallet is a nice initiative, it doesn't meet the 5th demand of a storage system; immune to physical coercion. I'll just leave this here; https://xkcd.com/538/

That's not a totally fair analogy. The adversary in this case shouldn't even know you have bitcoin or a WarpWallet; so why would they bother to torture it out of you in the first place? Edit: but I guess I agree, it would be a nice feature to have that we didn't think much about. I wonder what a solution would even look like.

IIRC, Julian Assange worked on torture resistant passwords: users memorize a maze that they would have trouble doing under duress.

Re: Account hijacking on MtGox

#24
post #7

Earlier quoted context omitted.

No rewards

dont know if you are interested but bex.io is hiring for security engineers/auditors, and most of their employees are remote. Since these guys puport to be a cookie-cutter template for running your own bitcoin exchange I'm sure they will need you. https://angel.co/jobs?slug=bex-io

You have no idea who this fellow is, right !?!

Given his street cred, I doubt he needs any help looking or finding the work he'd like to do and totally do so on his and his terms alone!

Re: Account hijacking on MtGox

#25
post #15

I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies. http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...

I just submitted this to HN expecting to be taken to the most recent submission of it, but was surprised to discover it hasn't ever been submitted. Sorry. https://news.ycombinator.com/item?id=7083393

Re: Account hijacking on MtGox

#27
post #23

Earlier quoted context omitted.

That's a shame. What is your bitcoin address which we, and the rest of the community, could tip to?

just homakov@gmail.com on coinbase

Ok, just transferred $100 to your coinbase account. Since this was transferred directly to your mail within coinbase, the transaction does not get included in the blockchain. Let me know if you didn't received them. Best Jacob, CrowdCurity.

Re: Account hijacking on MtGox

#28
post #23

Earlier quoted context omitted.

just homakov@gmail.com on coinbase

Ok, just transferred $100 to your coinbase account. Since this was transferred directly to your mail within coinbase, the transaction does not get included in the blockchain. Let me know if you didn't received them. Best Jacob, CrowdCurity.

Wow, Thanks!

Re: Account hijacking on MtGox

#29
post #24

Earlier quoted context omitted.

dont know if you are interested but bex.io is hiring for security engineers/auditors, and most of their employees are remote. Since these guys puport to be a cookie-cutter template for running your own bitcoin exchange I'm sure they will need you. https://angel.co/jobs?slug=bex-io

You have no idea who this fellow is, right !?! Given his street cred, I doubt he needs any help looking or finding the work he'd like to do and totally do so on his and his terms alone!

Nobody hires egor in fact. Not wow.

Re: Account hijacking on MtGox

#30
post #29
post #24

Earlier quoted context omitted.

You have no idea who this fellow is, right !?! Given his street cred, I doubt he needs any help looking or finding the work he'd like to do and totally do so on his and his terms alone!

Nobody hires egor in fact. Not wow.

I always thought you would get a lot of work via HN people. It surprises me but I don't find it hard to believe. Why it doesn't surprise me is because security and pen testing work is as much about sales, marketing and presentation - perhaps more than skill.

Some of the best security guys I know find it hard to pitch their services, so they end up working low-end generic programming or sysadmin jobs. I've tried to get more and more of them involved in my work (I do contract pen testing while also doing my own sec startup at the moment) by including them in proposals I write up, works out well. I messaged you on twitter.

Post reply on HN