Live data from Hacker News

The Satoshi Nakamoto SourceForge account has been hacked

sourceforge.net

61–70 of 192 posts

Re: The Satoshi Nakamoto SourceForge account has been hacked

#61
More details via Wired: http://www.wired.com/2014/09/satoshi/

1) A pastebin threating to dox Satoshi for 25 BTC: http://pastebin.com/7gbPi8Qr. Address has received less than .02 BTC thus far: https://blockchain.info/address/19pta6x1hXzV9F5hHnhMARYbRjux...

2) The GMX screenshots show 11k+ emails in the inbox, with one from as far back as June 2013

Re: The Satoshi Nakamoto SourceForge account has been hacked

#62
post #58
post #4

Satoshi's account on p2pfoundation.ning.com also made the first comment since he said "I am not Dorian Nakamoto." back in March. It says: "Dear Satoshi. Your dox, passwords and IP addresses are being sold on the darknet. Apparently you didn't configure Tor properly and your IP leaked when you used your email account sometime in 2010. You are not safe. You need to get out of where you are as soon as possible before th…

If Satoshi can't configure Tor correctly how is Joe Blow supposed to figure it out?

If the Tor leak thing is true, this could add to the evidence for the common speculation that Satoshi is a collective pseudonym.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#64
post #37
post #34

Earlier quoted context omitted.

"Security through obscurity" being bad only applies to cryptography, and have no bearing whatsoever to the concept of security in real life. To answer your question, actually, yes, it's almost proven to be the most effective measurement for one's safety: don't want to get hurt? Don't let people find you: get in a forest/ mountain range and hide.

Now First Blood is an underrated movie but I'm not sure it, or anything else, supports your claims. Hiding in the mountains has been a proven way of lowering life expectancy for millennia.

Hey now, mountain air and the regular exercise of a vigorous outdoor life style increase ones life expectancy!

Oh sorry what were we talking about? I thought this was the weekly "Where you should move to/away from" thread.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#65
post #55
post #53

Earlier quoted context omitted.

Does this same danger also apply to bitcoin exchanges? Are they heavily guarded? Just wondering...

Ask Mt. Gox... Typically an exchange will keep most of its BTC in actual bank vaults. Similar to how you'd store a large amount of gold.

They claim they do but there's never been any 3rd party auditing or verification of this that I know of. In the gold business every reliable business has auditing and insurance while so far Bitcoin businesses are run like a regular startup with open offices. Who's cleaning the offices after hours with access to the workstations or servers, who are the hired developers and are they smuggling wallet stealing software inside to transfer to themselves while on a flight to Brazil, who is writing their custom wallet and is it robust, how do we know they didn't copy every address to themselves. Lot's of security questions I've never seen addressed by any of the big exchanges. There was a payment processor startup that posted their office to bitcointalk.org which was floor to ceiling open glass windows with laptops facing the outside. How many binoculars are trained on those laptops across the street to get logins.

Some friends of mine trade large amounts of Bitcoin on a regular basis and there's never been much of a delay withdrawing. I doubt they are going to a bank to physically take out printed keys everyday for every transaction over $10,000 or phoning 5 people to combine keys. I bet the backups are kept in a safe deposit box, the cold wallet is likely an offline system anybody can walk up to with some kind of feeble authentication judging by past Bitcoin exchange incompetence.

Many of the smaller exchanges are using Blockchain.info wallets as their hot wallet too but won't admit it.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#67

What are the signs that it has been hacked, the sourceforge page looks correct, has it been recovered?

They changed the description to "buttcoin" (which has now been reverted), made some private information public, and removed the administrators. See: http://www.reddit.com/r/Bitcoin/comments/2fuuzf/the_old_now_...

Re: The Satoshi Nakamoto SourceForge account has been hacked

#68

More details via Wired: http://www.wired.com/2014/09/satoshi/ 1) A pastebin threating to dox Satoshi for 25 BTC: http://pastebin.com/7gbPi8Qr . Address has received less than .02 BTC thus far: https://blockchain.info/address/19pta6x1hXzV9F5hHnhMARYbRjux... 2) The GMX screenshots show 11k+ emails in the inbox, with one from as far back as June 2013

screenshot not loading for me

Re: The Satoshi Nakamoto SourceForge account has been hacked

#69
post #8

Earlier quoted context omitted.

So could someone explain how an IP address would leak when using an email account? I suppose potentially in the SMTP header, but this would assume he was using a email server running on his own personal ip, right? So is the guess here (assuming this is even true) that he had an email server running at home, leaked the ip, and then was attacked when someone found it?

gmail, for instance, includes the client IP address in mail headers. I learned this myself recently from an article here on HN, https://news.ycombinator.com/item?id=2083798 Haven't checked it myself, just reported there by a former gmail engineer in the context of their anti-spammer efforts.

Gmail has NEVER included the IP in headers (you can easily check this yourself). Hotmail/Outlook on the other hand ...

Re: The Satoshi Nakamoto SourceForge account has been hacked

#70
post #53

Earlier quoted context omitted.

Does this same danger also apply to bitcoin exchanges? Are they heavily guarded? Just wondering...

Not at all, you can freely walk into most exchange offices. Theoretically an armed robbery of exchanges and payment processors would be the perfect crime. Commit private address to memory or tattoo it on yourself in code, after the robbery forcing them to transfer to your public address and waiting out confirmations turn yourself in to the police and do the 5 yrs. Walk out with millions worth of bitcoins on your arm.…

They'd keep you in indefinitely for contempt of court for not handing over what you'd stolen.
Post reply on HN