Live data from Hacker News

Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

dzoba.com

151–157 of 157 posts

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#151

Earlier quoted context omitted.

I signed up for Mint.com once. I liked the concept in theory. But then after an hour of using it, I realized just how incredibly stupid it is giving a third party total access to all your bank accounts. Then I immediately went and changed the passwords on all my bank accounts.

For most large banks it's read only access through purpose built scraping API's. Mint won't be stealing your funds. Generally this is due to Regulation of the financial information space.

But you still have to give them your regular (read/write) credentials.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#152

Earlier quoted context omitted.

Although the rules are complicated, I lived in Japan for awhile, and almost no one Japanese would be offended by a foreigner getting it only mostly right. This is not terribly hard. It suffices for foreigners to observe the basics. As explained below, Karpeles referred to himself as "ore". "Ore" is mostly used by men, and carries a boastful tone. Moreover, pronouns aren't necessary to make grammatical sentences, e.g.…

A fairly close analogy in English would be to randomly sprinkle the word "fuck" in your speech. I was once speaking to a good friend of mine here, in English. "Do you want to go out for yakitori?" "Go fuck yourself!" "... switches to Japanese Have I recently done anything very major to offend you?" "No, of course not." "Oh, OK, I was worried. So that phrase, that's something you would only say under extreme distress…

For those who don't know, _Coming to America_ starring Ediie Murphy:

http://www.youtube.com/watch?v=6yZOUvyElo4

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#153
post #67

Earlier quoted context omitted.

Can you explain what's wrong with this? If I had 1 million in $info[ 'balance' ]? Would $bean->Coins overflow?

Using floats to represent currency is a big no-no. Floats have limited precision, and some numbers aren't representable by floats. Go try adding 0.1 to itself over and over again in your favorite implementation. It is better to represent as integers or fixed-precision numbers. That way, you are dealing with exact quantities.

That's why I like lisp:

    (/ 10 17)
      => 10/17
    (+ (/ 10 17) (/ 4 9))
      => 158/153
=]

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#154
post #39

The code is ... interesting. Smells organic, not designed. Comments are rare but usually useful. Highly coupled. Static methods everywhere. Violates SOLID principles. Basically, ignores current best practices. Clearly not designed for any sort of automated testing, which should be the first damn thing you do when there's any sort of money involved. Hell, even when there isn't money involved. We'd already guessed that…

Way too much schadenfreude given Gox's history. Although contrary to popular belief Gox was never a Magic exchange, they were a Bitcoin startup at a time when Bitcoin was not much more than internet lols and pizza deliveries. The first thing you do when hacking together a stupid exchange for a joke e-currency isn't writing unit tests. You just write the code and blast it up on a domain you had lying around for a diff…

> schadenfreude

Epicaricacy. because you're speaking english.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#155

Consider not taking advantage of the illegal compromise of someone else's servers, even if you are very interested in the contents of their purloined data. You'd hate it if it happened to your startup, and odds are your startup has plenty of ways to get into equally private data. If nothing else, consider it your moral down payment on being able to criticize the NSA ever again.

The thing with NSA is not about privacy. It's about goverment violating it en masse in vastly useless and potentially malicious even Orwellian schemes.

I don't mind hackers doing what they must because they can. I consider them force for good when they get into rich and poweful peoples drawers and publish things. It's a reminder that no matter how rich you are and how many laws you have bought you are never outside of public scrutiny.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#156

The code is ... interesting. Smells organic, not designed. Comments are rare but usually useful. Highly coupled. Static methods everywhere. Violates SOLID principles. Basically, ignores current best practices. Clearly not designed for any sort of automated testing, which should be the first damn thing you do when there's any sort of money involved. Hell, even when there isn't money involved. We'd already guessed that…

I'd be less concerned about code quality and technical best practices and more interested in knowing if Mt Gox had any internal notion of preventing common stock market manipulation tricks such as wash trades and chandelier bidding. I bet a lot of bitcoin startups don't know what those terms mean and thereby shouldn't be operating a finance exchange.

Why would you want o stop that? It's like trying to stop kissing your fist before you roll the dice, because other players might be afraid that you are doing magic.

All the rules of traditional stock market are designed to prevent scaring of gamers so they won't leave casino. Bitcoin doesn't care about faint hearted gamers.

Re: Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?

#157
post #28

Earlier quoted context omitted.

I'm still getting almost daily phishing/malware from the Mt Gox leak in 2011, and I never even signed up for anything more than to see what it's interface was like. Can't imagine how that will be with people having copies of passports (supposedly).

My spam folder is also full of, well, spam addressed to the email address I supplied to Dropbox (and only Dropbox) when I first signed up there sometime in 2011 and later leaked (I think 2012). Sometimes I wish data privacy laws were stricter, but it appears that not even financial services laws are sufficiently strict, as just demonstrated here.

For those wondering, I finally got an explanation from them. It turns out they had a leak in 2012:

https://blog.dropbox.com/2012/07/security-update-new-feature...

It's surprising to me that my email address took 2 years to be used, but who knows.

Post reply on HN