Live data from Hacker News

Statement on Mt. Gox

antonopoulos.com

21–30 of 53 posts

Re: Statement on Mt. Gox

#21

Earlier quoted context omitted.

The statement is inherently flawed, regardless of its source. Because some exchanges were unaffected does not mean that MtGox was not affected, and the statement itself implies that other exchanges were affected which would be evidence in MtGox' favor. I'm not saying MtGox was not incredibly incompetent, however nobody is helped by this false defensiveness over a very serious and clear bug in bitcoin that seems to ha…

If this implementation is bugged: http://blog.magicaltux.net/2010/06/27/php-can-do-anything-wh... then is ssh broken?

Please state your point rather than providing just a link. I don't know what you are trying to say.

Re: Statement on Mt. Gox

#22
post #8
post #2

Two important items: a) Adreas is the Chief Security Officer of Blockchain and a well known / respected digital currency personality. b) The most interesting part of the article was a link to another post reviewing Coinbase's security practices (1) where he concludes "it appears that the Coinbase system contains the expected funds and their cold storage system and process appear to be operating according to security…

If anyone has 38mins to burn... http://techcrunch.com/2013/12/17/foundation-brian-armstrong-... A Google Ventures video about coinbase security with Kevin Rose(from old Digg) asking a bunch of questions with Coinbase founder Brian Armstrong. Sounds very legit to me.... but... you _still_ shouldn't leave huge amounts of bitcoin in any exchange! Make[1] your own btc-address + private key and keep the coins there. And n…

Coinbase isn't really an exchange (though it works as such for US dollars). It's mainly a hosted wallet service that provides apps, and merchant and developer tools to make it easier to engage with the bitcoin ecosystem.

Re: Statement on Mt. Gox

#23

Earlier quoted context omitted.

If this implementation is bugged: http://blog.magicaltux.net/2010/06/27/php-can-do-anything-wh... then is ssh broken?

Please state your point rather than providing just a link. I don't know what you are trying to say.

That a bug in one implementation does not imply a bug in the protocol.

Re: Statement on Mt. Gox

#24

Earlier quoted context omitted.

If this implementation is bugged: http://blog.magicaltux.net/2010/06/27/php-can-do-anything-wh... then is ssh broken?

Please state your point rather than providing just a link. I don't know what you are trying to say.

That a bug in one implementation does not imply a bug in the protocol.

Re: Statement on Mt. Gox

#25

Under the presumption that it is true that ~750k BTC has been stolen, has anyone considered the possibility of orchestrating a 51% attack on the attacker(s)? Gox probably has logs of withdrawal requests. It might be daunting but feasible to sift the tx-MAL withdrawals from legitimate ones, then work with major pools and exchanges to double-spend stolen coins back to Gox. Gox could then be forced (by the same 51% majo…

This would require you to discard all the blocks since the transactions started happening and re-mine them with those transactions excluded. This would be completely impossible unless you dedicated most of the mining equipment to this for months and asked those miners to part with their earned mining rewards until this rewritten chain caught up with the official one. Hardly likely.

Re: Statement on Mt. Gox

#26
post #6

Earlier quoted context omitted.

I'm inclined to agree with cperciva, who is no slouch with security stuff: https://news.ycombinator.com/item?id=7289273

The statement is inherently flawed, regardless of its source. Because some exchanges were unaffected does not mean that MtGox was not affected, and the statement itself implies that other exchanges were affected which would be evidence in MtGox' favor. I'm not saying MtGox was not incredibly incompetent, however nobody is helped by this false defensiveness over a very serious and clear bug in bitcoin that seems to ha…

Listening to Andreas, it sounds more like a feature than a bug and that's also why it hasn't been "fixed" since 2011 - organizations introducing blockchain technology into their stacks should know about that and develop work-arounds:

https://soundcloud.com/mindtomatter/e85-mtgox-and-malleabili...

Re: Statement on Mt. Gox

#27
post #20

Earlier quoted context omitted.

It's unfortunate that many people lost money (and some might have lost a lot), but if the ecosystem can recover from this without governmental regulation (as I expect it will), we have the first evidence (ever) that there is no need for a central authority to conduct oversight and ensure a robust currency. It looks likely that the free market, which includes the self-regulating actions by Coinbase, Blockchain and oth…

> we have the first evidence (ever) that there is no need for a central authority to conduct oversight and ensure a robust currency. No one has ever doubted that this was possible. 'Robust' currency has existed without a central monetary authority in the past (for millenia!). The reason the Fed exists is because its believe that it takes an existing 'robust' currency and makes it better.

""The Federal Reserve System (also known as the Federal Reserve, and informally as the Fed) is the central banking system of the United States. It was created on December 23, 1913, with the enactment of the Federal Reserve Act, largely in response to a series of financial panics, particularly a severe panic in 1907"" - http://en.wikipedia.org/wiki/Federal_Reserve_System

The common argument is that the modern, global economy is too complex to govern itself, and prone to disasters.

Re: Statement on Mt. Gox

#28
post #3

A little regulation and over sight might have prevented all this. And with out it going forward all anyone can do is advise best practices, and then watch as some ignore them and also have their money stolen. Very wild west. Totally something I'll be staying well back from

It's unfortunate that many people lost money (and some might have lost a lot), but if the ecosystem can recover from this without governmental regulation (as I expect it will), we have the first evidence (ever) that there is no need for a central authority to conduct oversight and ensure a robust currency. It looks likely that the free market, which includes the self-regulating actions by Coinbase, Blockchain and oth…

> It's unfortunate that many people lost money (and some might have lost a lot), but if the ecosystem can recover from this without governmental regulation (as I expect it will), we have the first evidence (ever) that there is no need for a central authority to conduct oversight and ensure a robust currency.

Define "robust."

Re: Statement on Mt. Gox

#29
post #25

Under the presumption that it is true that ~750k BTC has been stolen, has anyone considered the possibility of orchestrating a 51% attack on the attacker(s)? Gox probably has logs of withdrawal requests. It might be daunting but feasible to sift the tx-MAL withdrawals from legitimate ones, then work with major pools and exchanges to double-spend stolen coins back to Gox. Gox could then be forced (by the same 51% majo…

This would require you to discard all the blocks since the transactions started happening and re-mine them with those transactions excluded. This would be completely impossible unless you dedicated most of the mining equipment to this for months and asked those miners to part with their earned mining rewards until this rewritten chain caught up with the official one. Hardly likely.

I don't think this is what I'm suggesting at all. If a popular majority of miners agreed to accept transactions double spending the original coins, this would be tantamount to generating 750k new Bitcoin, not initially invalidating any blocks or other transactions.

With forensics on the initial theft, miners could then tree-traverse back up to blacklist future transactions on stolen coins. There are probably lots of ways to accomplish basically this. This would render all stolen btc dead in the water, hence the "force Gox to repay legitimate requests for reimbursement of those who transacted for stolen coins."

That second part, though, isn't crucial to the idea. The community could just double spend the coins to mitigate harm done without attempting to stop the stolen coins downstream.

Re: Statement on Mt. Gox

#30

Under the presumption that it is true that ~750k BTC has been stolen, has anyone considered the possibility of orchestrating a 51% attack on the attacker(s)? Gox probably has logs of withdrawal requests. It might be daunting but feasible to sift the tx-MAL withdrawals from legitimate ones, then work with major pools and exchanges to double-spend stolen coins back to Gox. Gox could then be forced (by the same 51% majo…

You are assuming that the thieves stole the bitcoin and just put them into a wallet somewhere.

Consider this simplified example:

A Gox thief sold the bitcoin on another exchange. Then I unknowingly buy that very bitcoin from that exchange. Now the blockchain is rewritten and my bitcoin is gone even though I am innocent of any crime.

The MtGox situation is tragic. But when you start messing with the fungibility of bitcoin, you introduce new consequences that reach much further into the ecosystem.

Post reply on HN