Live data from Hacker News

How I got robbed of 34 btc on Mt.Gox today

bitcointalk.org

151–160 of 251 posts

Re: How I got robbed of 34 btc on Mt.Gox today

#151
post #45
post #25

Earlier quoted context omitted.

It sends log messages to http://www.galaxyjdb.com with your OS information and the state of the app.. /insert.php?o=*os.name*&u=*APPDATA*&ip=java.io.tmpdir&e=*APPSTATE* It appears to download an exe from http://g2f.nl/0lczsoo Then it tries to execute the exe: System.getenv("APPDATA") + "\\AdobeUpdate-Setup1.84.exe"; If at any point in the process it hits an exception, it sends the code for that exception to the galax…

AVG detects this as Luhe.Fiha.A Here's a mnetion from 2011: ( http://answers.microsoft.com/en-us/windows/forum/windows_7-s... ) So, someone using an OS heavily targeted by malware decides not to use anti-malware software, and to have javascript and apparently java enabled in the browser, and then chooses to visit an URL advertised in a chat window - that URL is unknown to that person, does not match the URL they're o…

The saying goes, never attribute to malice what can be explained by stupidity.

But they also say, just because you're paranoid it doesn't mean they aren't after you.

So I'd say this may very well be the authors of the malware astroturfing and trying to fool others into ignoring it

Re: How I got robbed of 34 btc on Mt.Gox today

#152
post #65
post #35

MtGox really does run a subpar operation. There should be additional security checks when transferring money out of an account, and there should be the option to enable multifactor authentication. Back when they were originally hacked, this should have become top priority for them, along with making their service rock solid. If people are hacking and stealing from you, it's obvious you have something of value and nee…

This wasn't someone hacking MtGox. This was someone on a vulnerable OS, running without malware protection, with Java active in the browser, visiting an unknown link, and possibly giving an application permission to run. (Although maybe it didn't need permission to run?) To get to that point the person needed to ignore several well established security principles.

I agree that the user is largely at fault here, but would you consider this acceptable if the same thing happened on your bank website?

I'm not familiar with Mt Gox but it's unacceptable if they don't have two factor authentication.

EDIT: Scrolling down, it appears they DO offer two-factor authentication. nvm.

Re: How I got robbed of 34 btc on Mt.Gox today

#153
post #100

Earlier quoted context omitted.

In this analogy, his cash was held by the bank. He can say someone impersonated him to send it. But unfortunately he did not take advantage of two factor authentication and he got phished. Actually from reading more, i don't understand if MtGox is involved at all. Did the executable just steal the wallet.dat file from his hard drive and have nothing to do with MtGox?

Did you read the FA? It was clearly stated that 1. the transaction took place in MtGox, and 2. the rest of his bitcoins were safely encrypted in his hard disk.

Right - I read that part. But then, I read the exploit, which is the running of a .exe on his local system, and not a javascript XSS attack. It's very confusing.

Perhaps the .exe logged into his MtGox account through the browser? If so - I don't understand why he would think MtGox is culpable in any way, particularly if he was running java in the browser, clicked YES to all the warnings that said horrible things were going to happen to him, AND wasn't running two-factor auth on his account.

He went out of his way to let the hacker exploit his system. I would hope that anyone as "technically savvy" as him would have known these were all really, really bad things to do.

If there is any consolation, it's that the 34 bitcoins are likely going to be worth less than a $1000 by the end of today.

Re: How I got robbed of 34 btc on Mt.Gox today

#154
post #71

Earlier quoted context omitted.

That is true. 1) You really shouldn't be running java applets unless you are certain you want to. I have had Java disabled for about a year and have only seen a page that required it once. 2) The domain name should've been a dead giveaway 3) Why would MtGox refund it? You got your money stolen by someone else. It's not MtGox's fault at all.

One would expect a certain level of security measures for a site that directly influences your financial situation. Most CRUD applications require you to put in your old password when changing your new one. Apparently you can actually trade coins away from your account without typing your password on MtGox. That's just ridiculously unsecured.

I don't think that'd solve the problem though. His password was stolen. So the hacker had the password and entering it twice would be the same barrier as entering it once.

Re: How I got robbed of 34 btc on Mt.Gox today

#156
post #16

Earlier quoted context omitted.

...and banks will only compensate if they really have to because there are laws compelling them to do so. If they can get away with saying it's your fault they will. While I have sympathy for the author it was a pretty silly thing to do.

"Federal Reserve Regulation E guarantees that US consumers are made whole when their bank passwords are stolen" From http://research.microsoft.com/apps/pubs/default.aspx?id=1618... Of course, as that paper points out, the traditional electronic money system is incredibly reversible. If someone transfers $50,000 from my personal bank account to someone else's bank account, it's pretty easy for it to be undone. The bot…

> If someone transfers $50,000 from my personal bank account to someone else's bank account, it's pretty easy for it to be undone.

That depends on the timeframe. Once the money has been moved out of that new account again things start getting much harder.

Re: How I got robbed of 34 btc on Mt.Gox today

#157

Earlier quoted context omitted.

Not really. Most banks I've asked would not refund if the victim did not take proper security measures, and the OP in this case most certainly did not.

Banks are required to make users whole, even if the user's password is compromised. At least for individual accounts. (For businesses the situation is different.) http://research.microsoft.com/apps/pubs/default.aspx?id=1618...

It depends very much on local laws in your country, from what I've seen.

Re: How I got robbed of 34 btc on Mt.Gox today

#158
post #76

Isn't this exactly what Bitcoin was created for - to allow unregulated access to currency? I guess people don't really realize what unregulated actually means - and nor do they realize why you really do want regulated currency. This kind of thing happens all the time with real banks, but with real banks, all transactions can be traced and reversed. Law enforcement can follow the required documentation to find the own…

Fair point, most of the mistakes were on the author's part. MtGox isn't completely blameless, they had a cross-site scripting vulnerability, and they should probably enforce some stronger security around logins from new computers. Something like Steam's approach where every login from a new computer needs to be verified with a confirmation code.

Re: How I got robbed of 34 btc on Mt.Gox today

#159

Earlier quoted context omitted.

If you download the blockchain from the P2P wallet client it always takes forever. You should download the blockchain once, put it on a USB drive, and then copy it into .bitcoin before you bootstrap a new machine with a wallet. There are also sites that offer downloads of tar'd versions of the blockchain, or torrents. Pretty much anything is going to be faster than downloading via a bitcoin client.

Nothing possibly could go wrong downloading the blockchain from a torrent site....

This is basically true, actually. It'll either work or it won't, and you're just out of the bandwidth if it fails verification. At the absolute worst, you won't be able to accept any blocks from the network as a whole if it's fake, because the hashes won't line up. IIRC the official client (and most others) also include a hard-coded hash part way through the chain to help ensure you're on the correct one up to that point.

That's of course assuming there isn't some exploit in your client, due to e.g. unsafe reading of the file that could allow it to execute arbitrary code hidden in the blockchain file.

Re: How I got robbed of 34 btc on Mt.Gox today

#160
post #129

Earlier quoted context omitted.

This thread appears to have a download/torrent for a recent version of the blockchain data. It's about 4.7GB, apparently. https://bitcointalk.org/index.php?topic=145386.0 So does that mean if you're not using BC via a wallet service, it requires at least 4.7GB of disk space in order to do its thing? How is this amount of data expected to grow in the future?

It's going to grow hugely (at least as long as punters keep using bitcoin); there's an expectation that clients will switch away from using the full history sooner or later, and there are mechanisms prepared for remaining reasonably secure with shorter histories.

Hah, so eventually only a few people like central power figures in the bitcoin community will be running with the full blockchain eh? Probably my favorite thing about bitcoin is how, despite its explicit goals, the more adoption it sees the more it looks like it will turn into the same old thing we already have.
Post reply on HN