Live data from Hacker News

New message from Mt. Gox

mtgox.com

111–120 of 181 posts

Re: New message from Mt. Gox

#111
post #66

Earlier quoted context omitted.

> or at the very least they don't give a crap about anything at all They were the market leader, with substantial revenue and lots of cash flow. Why they didn't prioritize hiring some people and securing their platform is still beyond my understanding. It's up there with the $100+ billion in cash Apple is evidently not using to hire enough code reviewers or implement adequate security processes for their most importa…

I couldn't agree with this more. It's human nature not to prepare for a theoretical risk. But once it's happened to you, and to many others in the same industry, it's just foolishness not to invest in prevention. I imagine there's also a bit of outsider-preference going on here. There's no lack of people who could have been hired to implement controls and audits that would have easily caught a slow leak of coins, but…

I don't think your (or their) equating "competent programmers and businesspeople with common sense" with "obsolete fiat economy" is what happened - it's not really a meaningful logical jump. There's got to be something else.

Re: New message from Mt. Gox

#112
post #67

Earlier quoted context omitted.

Presumably when Mt Gox's bank accounts get seized, whatever money in them will be used to pay off accounts with real currency balances. The people holding bitcoins will get nothing.

That brings up a point of confusion for me. As understand the news, Mt Gox didn't lose a single dollar. They lost 700K BTC. It is neither being pedantic, nor beside the point that this is not the same as $400M. It is the point.

If the leaked crisis plan memo is correct, then they had ~$50 million in dollars on account with them, and total cash assets around $22 million.

So, even ignoring the Bitcoin, they lost quite a lot of dollars.

Re: New message from Mt. Gox

#114
post #72
post #46

Earlier quoted context omitted.

> I'm sure there are still some anti-fraud regulations that would kick in... I don't know, but I don't think so. For the law you may be trading in monopoly money at your risk.

Intentional misrepresentation of fact for material gain doesn't seem to require currency of any sort. So Kome I'll make you a deal, I've got a ownership title for the Brooklyn Bridge and I'll trade this title to you for a case of beer... deal? Deal. Sucka. Then it goes to court. Assuming you can convince the court I knew the title was fake, and the case of beer is worth more than the fake title (maybe the title has a…

What about the people who exploited transaction malleability to defraud MtGox? Will someone go after them? Doesn't MtGox have their details?

Re: New message from Mt. Gox

#115
post #57

What are they doing in the page source there? Storing a message in a cookie then refreshing the page to display it? The second time you visit the page, you'll get your cookie-stored statement. Almost seems like they want to be able to change their statement without previous visitors seeing the changes.

I don't see anything like that. Here's the page source for me: MtGox.com Dear MtGox Customers, In the event of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly. Best regards, MtGox Team

Wait, I refreshed the page a few times, and once, I got:

  
	
		MtGox.com

  
    var AKSB=AKSB||{};AKSB.q=[];AKSB.mark=function(b,a){AKSB.q.push(["mark",b,a||(new Date).getTime()])};AKSB.measure=function(b,a,c){AKSB.q.push(["measure",b,a,c||(new Date).getTime()])};AKSB.done=function(b){AKSB.q.push(["done",b])};AKSB.mark("firstbyte",(new Date).getTime());
    AKSB.prof={custid:"223233",ustr:"",originlat:0,clientrtt:19,ghostip:"23.51.248.44",ipv6:false,pct:10,xhrtest:false,clientip:"130.223.174.194"};
    (function(b){var a=document.createElement("iframe");a.src="javascript:false";(a.frameElement||a).style.cssText="width: 0; height: 0; border: 0; display: none";var c=document.getElementsByTagName("script"),c=c[c.length-1];c.parentNode.insertBefore(a,c);a=a.contentWindow.document;a.open().write("");a.close()})(("https:"===document.location.protocol?"https:":"http:")+"//aksb-a.akamaihd.net/146060/aksb-a/aksb.min.js");
    
    
	
		

Dear MtGox Customers,

In light of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly.

Best regards,
MtGox Team

This is very odd behaviour.

Re: New message from Mt. Gox

#117
post #66
post #42

I'm one of those who lost a good amount on MtGox. It wasn't in there because I thought they are a bank, I put it there because I like to speculate from time to time. As such I was prepared to lose most if not all of it anyway. I didn't expect things to go wrong so thoroughly, but still that was the premise of my deposits there. So from that perspective, I'm not really mad about them losing the money. It's unfortunate…

> or at the very least they don't give a crap about anything at all They were the market leader, with substantial revenue and lots of cash flow. Why they didn't prioritize hiring some people and securing their platform is still beyond my understanding. It's up there with the $100+ billion in cash Apple is evidently not using to hire enough code reviewers or implement adequate security processes for their most importa…

I think the problem is that many people are reactive when it comes to risk. Most people tend to be risk averse, which is counterintuitive to the empirical observation that they don't prepare well for so-called "black swan" events. I suspect it's a case of moral hazard, which makes perfect sense. It's a lot easier to gamble someone else's money.

Re: New message from Mt. Gox

#118
post #46
post #29

Earlier quoted context omitted.

If there was any evidence of that they'd go to jail for a long time - even if bitcoin is not directly regulated, I'm sure there are still some anti-fraud regulations that would kick in...

> I'm sure there are still some anti-fraud regulations that would kick in... I don't know, but I don't think so. For the law you may be trading in monopoly money at your risk.

If not fraud, then simple theft.

Re: New message from Mt. Gox

#119
post #57

What are they doing in the page source there? Storing a message in a cookie then refreshing the page to display it? The second time you visit the page, you'll get your cookie-stored statement. Almost seems like they want to be able to change their statement without previous visitors seeing the changes.

I don't see anything like that. Here's the page source for me: MtGox.com Dear MtGox Customers, In the event of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly. Best regards, MtGox Team

This is what I see:

  MtGox.com loading

Please wait...

function xdec(data){var o="SOME_RANDOM_BASE_64_THAT_KEEPS_CHANGING";var o1,o2,o3,h1,h2,h3,h4,bits,i=0,ac=0,dec="",tmp_arr=[];if(!data){return data}data+='';do{h1=o.indexOf(data.charAt(i++));h2=o.indexOf(data.charAt(i++));h3=o.indexOf(data.charAt(i++));h4=o.indexOf(data.charAt(i++));bits=h1>16&0xff;o2=bits>>8&0xff;o3=bits&0xff;if(h3==64){tmp_arr[ac++]=String.fromCharCode(o1)}else if(h4==64){tmp_arr[ac++]=String.fromCharCode(o1,o2)}else{tmp_arr[ac++]=String.fromCharCode(o1,o2,o3)}}while(i

Re: New message from Mt. Gox

#120
post #66

Earlier quoted context omitted.

> or at the very least they don't give a crap about anything at all They were the market leader, with substantial revenue and lots of cash flow. Why they didn't prioritize hiring some people and securing their platform is still beyond my understanding. It's up there with the $100+ billion in cash Apple is evidently not using to hire enough code reviewers or implement adequate security processes for their most importa…

> Apple is evidently not using to hire enough code reviewers It's naive to think that the more people you throw at the problem, the less bugs there will be. See also: The Mythical Man-Month.

If you are saying "merely hiring more people to review the code won't work," then I agree. [1]

If you are saying "hiring more highly-skilled people to review the code won't work," then I'll disagree. App sec engineers can be had for the price.

[1] I say this despite the fact that this was a bug that leapt out at people who had no security knowledge. The one before this and the one after this won't be like that.

Post reply on HN