Live data from Hacker News

Account hijacking on MtGox

homakov.blogspot.com

11–20 of 38 posts

Re: Account hijacking on MtGox

#11
post #7

I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

No rewards

dont know if you are interested but bex.io is hiring for security engineers/auditors, and most of their employees are remote. Since these guys puport to be a cookie-cutter template for running your own bitcoin exchange I'm sure they will need you. https://angel.co/jobs?slug=bex-io

Re: Account hijacking on MtGox

#12
post #7

I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

No rewards

That's a shame. What is your bitcoin address which we, and the rest of the community, could tip to?

Re: Account hijacking on MtGox

#13
post #8

Gox uses a special 3FA where it takes 6+weeks to get anything out of that exchange. See 144 page bitcointalk thread 'Mtgox delays [gathering]'.

6+ months, actually. Still waiting on one transfer.

So the higher price on Gox isn't worth trusting them to actually complete their transfers within their claimed 6week window? How much was the transfer for?

I guess it's better to use some other exchange for selling if Gox is taking 6 months to process some transfers...

Re: Account hijacking on MtGox

#14
post #2

Would 2 factor auth even fix this? If you are hijacking the session ID, the user has already authenticated.

In addition to login, 2FA is typically required for irreversible and other sensitive operations like transfers, for exactly this reason (local malware, XSS, etc, can steal cookies) This should be pretty much required for all services where users may have significant amounts of money at stake. And users need to be educated to actually enable it. Coinbase finally enabled 2FA for transfers (of more than $100/day) this w…

Looks like Coinbase 2FA is crap

http://www.reddit.com/r/Bitcoin/comments/1vjr7b/please_advis...

Re: Account hijacking on MtGox

#15
I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies.

http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...

Re: Account hijacking on MtGox

#16

Earlier quoted context omitted.

6+ months, actually. Still waiting on one transfer.

So the higher price on Gox isn't worth trusting them to actually complete their transfers within their claimed 6week window? How much was the transfer for? I guess it's better to use some other exchange for selling if Gox is taking 6 months to process some transfers...

The higher price is because of all the USD trapped in the exchange

Re: Account hijacking on MtGox

#17
post #15

I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies. http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...

While your WarpWallet is a nice initiative, it doesn't meet the 5th demand of a storage system; immune to physical coercion.

I'll just leave this here; https://xkcd.com/538/

Re: Account hijacking on MtGox

#18
post #14

Earlier quoted context omitted.

In addition to login, 2FA is typically required for irreversible and other sensitive operations like transfers, for exactly this reason (local malware, XSS, etc, can steal cookies) This should be pretty much required for all services where users may have significant amounts of money at stake. And users need to be educated to actually enable it. Coinbase finally enabled 2FA for transfers (of more than $100/day) this w…

Looks like Coinbase 2FA is crap http://www.reddit.com/r/Bitcoin/comments/1vjr7b/please_advis...

This happened the day Coinbase enabled 2FA on transactions, so it's hard to say whether it was before or after it was enabled.

Re: Account hijacking on MtGox

#19
post #17
post #15

I wrote a little blog article on how to store the majority of your bitcoin using a security-enhanced brainwallet. Part of the argument is that exchanges and online wallets are and will continue to be magnets for good XSS/CSRF attacks. Mt.Gox/Coinbase Engineers are fighting a difficult fight against well-incentivized enemies. http://maxtaco.github.io/bitcoin/2014/01/16/how-jason-bourne...

While your WarpWallet is a nice initiative, it doesn't meet the 5th demand of a storage system; immune to physical coercion. I'll just leave this here; https://xkcd.com/538/

That's not a totally fair analogy. The adversary in this case shouldn't even know you have bitcoin or a WarpWallet; so why would they bother to torture it out of you in the first place?

Edit: but I guess I agree, it would be a nice feature to have that we didn't think much about. I wonder what a solution would even look like.

Re: Account hijacking on MtGox

#20
post #7

I'm not sure whether Egor Homakov received a reward for reporting this to Mt.Gox which he clearly deserves. However we have contacted to Mt.Gox to understand if they would be launching a vulnerability reward program and the response we got is that they would launch one during Q1 2014. Read more at our blog about it. https://blog.crowdcurity.com/how-to-measure-the-security-of-...

No rewards

that's sad bro, you deserved a really fair gift for that discovery. I mean others (could've) used it. We need more people who report security issues and go public, if nobody listens.
Post reply on HN