Live data from Hacker News

Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

dzoba.com

41–50 of 157 posts

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#41
post #28

Earlier quoted context omitted.

I'm still getting almost daily phishing/malware from the Mt Gox leak in 2011, and I never even signed up for anything more than to see what it's interface was like. Can't imagine how that will be with people having copies of passports (supposedly).

My spam folder is also full of, well, spam addressed to the email address I supplied to Dropbox (and only Dropbox) when I first signed up there sometime in 2011 and later leaked (I think 2012). Sometimes I wish data privacy laws were stricter, but it appears that not even financial services laws are sufficiently strict, as just demonstrated here.

Pretty much what mine is too, a pile of spam from various compromises services I should have done better than to trust. Mt Gox, Dropbox, Bitstamp (yeah, they never made a big mention of that one) and a variety of other small services.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#42

The code is ... interesting. Smells organic, not designed. Comments are rare but usually useful. Highly coupled. Static methods everywhere. Violates SOLID principles. Basically, ignores current best practices. Clearly not designed for any sort of automated testing, which should be the first damn thing you do when there's any sort of money involved. Hell, even when there isn't money involved. We'd already guessed that…

How is the exception handling? For instance, if something goes wrong when generating a new private key, could they still attempt the transaction but with a null key? (cf the earlier bug that lost 2609 bitcoins.)

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#43
post #23

Earlier quoted context omitted.

Yeah, that is really something. To think that people actually supplied that info. Wow.

I didn't, I signed up to an account and stopped at this point because unlike a financial institution they are not governed by laws that require this or would ensure the security of such data. But I totally understand why people did supply it. They supplied it because: 1) They've been trained to 2) For a while MtGox was actually the most well-known (and therefore trusted) of the exchanges On #1, every financial instit…

I signed up before they had ID verification about two years ago, and deposited a little money. Then a few months later I'd had my fun and I wanted to take my money back, but discovered they wouldn't let me withdraw unless I provided ID.

After some back and forth with them I somehat angrily provided ID and got my money returned. It later turned out that they had either been dishonest or incompetent in their argument for providing ID, and I got them to promise me that they had deleted any and all ID docs I sent them, specifically because of scenarios like this one.

Well, I hope they were telling the truth.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#44
post #23

Earlier quoted context omitted.

Yeah, that is really something. To think that people actually supplied that info. Wow.

I didn't, I signed up to an account and stopped at this point because unlike a financial institution they are not governed by laws that require this or would ensure the security of such data. But I totally understand why people did supply it. They supplied it because: 1) They've been trained to 2) For a while MtGox was actually the most well-known (and therefore trusted) of the exchanges On #1, every financial instit…

Money laundering legislation in Japan may well apply to them.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#45
post #5
post #2

In case my server goes, here is the text: Right now in ##mtgox-chat someone named nanashi____ claims to be speaking for a group of hackers who have gotten into Mt Gox in an attempt to figure out what happened. Nanashi says they have a DB dump and are looking at what to do with it. Nanashi gave these links: A conversation in Japanese with Karpeles and a Banker ( http://picosong.com/Y7di/ ) Some Mt Gox Code ( http://pa…

They have passport scans? I'm impressed by how hard MtGox is fucking up.

I am sure it said that they will 'dispose' of the scans after 2 weeks. Looks like they fucked up again!

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#46
post #16

I'm fluent in Japanese. I listened to the beginning of the recording and it's legit. One of the voices is almost certainly Mark Karpeles' (based on hearing his voice in his recent public apology -- his Japanese is broken but reasonably proficient). It seems to be a recording of a Jan 30 2014 meeting where bankers from Mizuho Bank are asking Karpeles various questions about Bitcoin, the nature of his business, his par…

Karpeles making mistakes with honorifics? That's odd, even though it would he incorrect, surely he could just -san suffix everyone and be done with it?

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#47
post #16

I'm fluent in Japanese. I listened to the beginning of the recording and it's legit. One of the voices is almost certainly Mark Karpeles' (based on hearing his voice in his recent public apology -- his Japanese is broken but reasonably proficient). It seems to be a recording of a Jan 30 2014 meeting where bankers from Mizuho Bank are asking Karpeles various questions about Bitcoin, the nature of his business, his par…

Karpeles making mistakes with honorifics? That's odd, even though it would he incorrect, surely he could just -san suffix everyone and be done with it?

I don't know about honorifics, but he was using "ore," according to Reddit. If he wrote the letter on the front page of Mt Gox, there are some weird/offputting polite language mistakes, too.

(I can't listen to the recording right now and wouldn't get much out of it even if I could, since I can't hear well enough. :-/)

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#48
post #16

I'm fluent in Japanese. I listened to the beginning of the recording and it's legit. One of the voices is almost certainly Mark Karpeles' (based on hearing his voice in his recent public apology -- his Japanese is broken but reasonably proficient). It seems to be a recording of a Jan 30 2014 meeting where bankers from Mizuho Bank are asking Karpeles various questions about Bitcoin, the nature of his business, his par…

Karpeles making mistakes with honorifics? That's odd, even though it would he incorrect, surely he could just -san suffix everyone and be done with it?

Japanese honorifics extend tremendously beyond name suffixes.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#49
post #39

The code is ... interesting. Smells organic, not designed. Comments are rare but usually useful. Highly coupled. Static methods everywhere. Violates SOLID principles. Basically, ignores current best practices. Clearly not designed for any sort of automated testing, which should be the first damn thing you do when there's any sort of money involved. Hell, even when there isn't money involved. We'd already guessed that…

Way too much schadenfreude given Gox's history. Although contrary to popular belief Gox was never a Magic exchange, they were a Bitcoin startup at a time when Bitcoin was not much more than internet lols and pizza deliveries. The first thing you do when hacking together a stupid exchange for a joke e-currency isn't writing unit tests. You just write the code and blast it up on a domain you had lying around for a diff…

McCaleb has said by email that MtGox was at least at some point used for trading or buying cards.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#50

Earlier quoted context omitted.

Karpeles making mistakes with honorifics? That's odd, even though it would he incorrect, surely he could just -san suffix everyone and be done with it?

I don't know about honorifics, but he was using "ore," according to Reddit. If he wrote the letter on the front page of Mt Gox, there are some weird/offputting polite language mistakes, too. (I can't listen to the recording right now and wouldn't get much out of it even if I could, since I can't hear well enough. :-/)

For those (like me) who don't know anything about Japanese, referring to yourself as "ore" seems to be inappropriate and likely unintended by Mark.

> Frequently used by men. It can be seen as rude depending on the context. Establishes a sense of masculinity. Emphasizes one's own status when used with peers and with those who are younger or who have less status. Among close friends or family, its use is a sign of familiarity rather than of masculinity or of superiority. It was used by both genders until the late Edo period and still is in some dialects.

https://en.wikipedia.org/wiki/Japanese_pronouns#List_of_Japa...

Post reply on HN