Live data from Hacker News

The Satoshi Nakamoto SourceForge account has been hacked

sourceforge.net

181–190 of 192 posts

Re: The Satoshi Nakamoto SourceForge account has been hacked

#181
post #156

if he has a lot of bitcoins, wouldn't it be smarter for him to just sell them right now ? I mean it's much safer to have real money in a bank account than to have bitcoins.

If he sell any of them it will be easy to track him down.

why track him down ?

Re: The Satoshi Nakamoto SourceForge account has been hacked

#182
post #55

Earlier quoted context omitted.

Ask Mt. Gox... Typically an exchange will keep most of its BTC in actual bank vaults. Similar to how you'd store a large amount of gold.

They claim they do but there's never been any 3rd party auditing or verification of this that I know of. In the gold business every reliable business has auditing and insurance while so far Bitcoin businesses are run like a regular startup with open offices. Who's cleaning the offices after hours with access to the workstations or servers, who are the hired developers and are they smuggling wallet stealing software i…

>There's never been any 3rd party auditing or verification of this that I know of.

I think that's intended to be a feature and not a bug. With Bitcoin 'third party verification' means other people no longer use a service after you've generously sacrificed your money to demonstrate their incompetence or malice.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#183
post #139

Earlier quoted context omitted.

> AFAIK he's not been accused of any crime either. I imagine the IRS really would like to audit him if he's an American citizen, however.

The euphemism known as an IRS audit would interfere in his life if an exchange into or out of USD took place. Anyone can attribute value to anything. That doesn't make it valuable. Taxation here would require provable gains or losses, as with USD. The transactions of people exchanging only in [bitcoins, metal, coffee beans, rocks, fancy/worthless paper], not in USD, do not imply that any taxable "gains" or "losses" o…

It might be covered under bartering.

http://www.irs.gov/taxtopics/tc420.html

Re: The Satoshi Nakamoto SourceForge account has been hacked

#184
Greetings,

We suspended s_nakamoto's account 2 hours and 17 minutes after the attacker gained access to that account.

After generating a list of changes made, confirming method of attack, and identifying no serious changes to project content, the project was restored to its pre-attack state, and the compromised user account was removed from the project.

Risk to the community is believed to be low, as file content wasn't modified.

Regards,

Roberto Galoppini, SourceForge.net

See https://sourceforge.net/p/forge/site-support/8512/

Re: The Satoshi Nakamoto SourceForge account has been hacked

#185

Earlier quoted context omitted.

Many (most?) SMTP servers will include the client IP in message headers. IIRC it's even required by ope of the RFCs.

Many (most) people connecting to an SMTP server will be doing so from behind nat. Finding out the users "real" ip address is 10.x.x.x isn't so exciting.

Actually you will usually find BOTH the private IP address behind the NAT and the public IP address of the router in the headers. Check out a few mails you've received from a few different sources, see for yourself.

I just picked the two latest I got (and redacted them) as an example.

The first one sent through GMail (SMTP I guess, not webmail) :

  Return-Path: 
  Received: from [192.168.1.18] (123-123-123-123...bbox.fr. [123.123.123.123])
          by mx.google.com with ESMTPSA id ...
          for 
          (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
and another one, through OVH this time :

  Received: from unknown (HELO ?192.168.0.23?) (xyz@abc.fr@123.123.123.123)
    by ns0.ovh.net with SMTP;
Both "123.123.123.123" were the public IP address from their DSL connections. In both cases as you can see, I could know both IP addresses.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#186
post #39

Earlier quoted context omitted.

Many SMTP servers include the IP address of the sender in the headers (usually the Received header). Just look around, you'll be surprised.

Using webmail would defeat that, though, right?

Depends on the webmail. Some do, some don't. Easy enough to test for yourself beforehand though.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#187

Earlier quoted context omitted.

Many (most) people connecting to an SMTP server will be doing so from behind nat. Finding out the users "real" ip address is 10.x.x.x isn't so exciting.

Actually you will usually find BOTH the private IP address behind the NAT and the public IP address of the router in the headers. Check out a few mails you've received from a few different sources, see for yourself. I just picked the two latest I got (and redacted them) as an example. The first one sent through GMail (SMTP I guess, not webmail) : Return-Path: Received: from [192.168.1.18] (123-123-123-123...bbox.fr.…

Good point. Looks like google doesn't add these headers if you're using their web interface and apparently the majority of people I email with don't leak this either, however once I started looking there's a surprising amount of emails in my inbox that do. I'm now trying to remember if I deliberately disabled this when I set up our new mail server or not...

Re: The Satoshi Nakamoto SourceForge account has been hacked

#188
post #151
post #133

Earlier quoted context omitted.

How's that different from non-digital information?

There is at least an original copy.

Yes, but a very slight degradation in making an analog copy of some pictures or records won't degrade their blackmail value.

Re: The Satoshi Nakamoto SourceForge account has been hacked

#189
post #49

Earlier quoted context omitted.

> But if you have a billion dollars of gold in your basement, you should be very, very paranoid. At close to 25 tonnes, and ~1.3m³, I'd like to see the engineering behind such a heist

Kill occupants of building, move 1.3 cubic meters of gold in 30 trips with transport van. Now you have a few other problems, such as making sure that you're not going to end up in the same way. Besides surveillance cam footage recording your whereabout during part of your trip and the distance being fairly easily estimated if you do two trips in quick succession leading to a possible ID and or location of the stash.…

> getting it out of there is fairly easy if you lack a conscience and have a van

new favorite HN quote

Re: The Satoshi Nakamoto SourceForge account has been hacked

#190
post #47

Earlier quoted context omitted.

This thread matches the "increases bob's chances of being a k00k" pattern from the recent thread patterns link: http://joeyh.name/blog/entry/thread_patterns/

Lol missing context: "Or he's really right and everyone else is wrong."

On HN I've seen that pattern and sometimes it was a well-respected poster, hammering on something pedantic and off-topic, derailing the thread. Point being, sometimes someone can be right, really knowledgeable and a (thread-localised) k00k.

added: then again, there's also something about HN's discussion structure (mainly lack of collapsing comments like Reddit has) that makes these derails get in the way much more than necessary. Reddit even has place for strings of puns without them significantly derailing the discussion.

Post reply on HN