Live data from Hacker News

What Did Not Happen At Mt. Gox

hackingdistributed.com

51–60 of 97 posts

Re: What Did Not Happen At Mt. Gox

#51
post #9

I think that his points against transaction malleability are invalid: - technical one - Bitcoin clients have a 100 ms delay before they relay messages. An attacker can compile a modified client that doesn't have these limitations and successfully outrun the rest. It was shown once that an attacker managed to successfully modify most of Bitcoin transactions on the network for some time in February - social one - IIRC…

Agreed. It's known that Mt. Gox was auto-retrying sends after the txids didn't match. FWIW, I submitted the 'what most likely happened' post last night: https://news.ycombinator.com/item?id=7328219 . It's a bit shorter and seems less speculative.

Can you link to evidence they auto-retried? Last I'd seen it required contacting their customer service for a manual re-send.

Re: What Did Not Happen At Mt. Gox

#52
post #50

Earlier quoted context omitted.

Born in France, so he speaks French. Involved with the internet, so he speaks English. Lives in Japan, so he speaks Japanese. This is not impressive.

Speaking as someone who is anti-Karpeles and unilingual: I think speaking three languages, regardless of context, is incredibly impressive.

It's extremely circumstance based. I have countless relatives that are tri- or quadri-lingual (or more), merely because they have different cultures in their background and/or were forced to immigrate. Those that are uni- or bilingual simply were lucky enough (or stuck enough) that they didn't move much. And I don't think there's any particular astonishing knack for languages needed to explain this.

Additionally, if you're exposed to a new language early in life, it becomes much easier to learn new languages in the future. And being immersed in it forces you to learn, as your survival depends on it.

So, incredibly impressive? Nah. Mind you, if someone is legitimately a fast language learner, given that I am not at all, it does impress me, especially if they truly master it and can think in that language.

Re: What Did Not Happen At Mt. Gox

#53
post #50

Earlier quoted context omitted.

Born in France, so he speaks French. Involved with the internet, so he speaks English. Lives in Japan, so he speaks Japanese. This is not impressive.

Speaking as someone who is anti-Karpeles and unilingual: I think speaking three languages, regardless of context, is incredibly impressive.

That's probably because of your upbringing and your surroundings. When English is your native language, and all the input you get (books, tv, music, internet) is in English, there's little incentive to learn more languages.

For a majority of the people on this planet, this isn't the case.

Re: What Did Not Happen At Mt. Gox

#54
post #9

I think that his points against transaction malleability are invalid: - technical one - Bitcoin clients have a 100 ms delay before they relay messages. An attacker can compile a modified client that doesn't have these limitations and successfully outrun the rest. It was shown once that an attacker managed to successfully modify most of Bitcoin transactions on the network for some time in February - social one - IIRC…

Author here. I think there is some subtlety around the technical point that may be getting lost. Ittay Eyal and I were the ones who discovered an attack against Bitcoin called selfish mining, where we showed how a miner could earn more than his fair share. This attack did not require, but could benefit from, the attacker racing against honest participants on the peer-to-peer network. Some members of the Bitcoin commu…

It'd be most accurate to say you rigorously described a kind of mining-cartel attack that had been discussed years earlier, but I know I won't convince you of that, because you only count published academic papers, and the earlier discussions of the same attack all happened in less-formal bitcoin forums.

Regarding MtGox scenarios:

Reliable evidence on what MtGox truly did is scarce, but people have widely speculated that at times they auto-reissued payouts, and without the protective measure of reusing the same inputs. It would be in character – see other examples of their recklessness below.

So while I share your doubt that malleability could have resulted in significant losses, there is a theory for that, which doesn't require extensive social engineering/human-in-the-loop processes. And, if it had been happening for years, only outsiders with a giant archive of long-ago race-losing transactions (that never reached blocks) would be able to estimate the magnitude of the losses. (I don't know any public source for such an archive.)

Similarly, at times Karpeles mentioned that the cold storage was a "paper-based RAID" in 3 parts, or some other scheme in 6 places. As the 'key man' in an enterprise that suddenly found itself atop $100MM+ in easily-transferable assets, his feared threats may have included kidnapping/extortion to force disclosure of the keys. Thus his cold storage scheme may have involved putting necessary key-shares totally outside his easy control, even via people and safety-deposit boxes in other countries. Any "key-loss" scenario should consider the chance law-enforcement-actions or other calamities, far from the MtGox offices or Japanese accounts, have made essential parts of the cold-storage keys unrecoverable, for now and perhaps permanently.

There's a forum thread from years ago where people mention 2600+ bitcoins MtGox lost from their own bad-transaction-issuing code (https://bitcointalk.org/index.php?topic=50206.0;all). Karpeles wrote his own SSH server in PHP. Over the years MtGox suffered SQL injection & cross-site scripting attacks. In the June 2011 'flash crash', the entire user database with weakly-hashed passwords was lost (supposedly via an auditor compromise), allowing outsiders to carry off some unknown number of artificially-cheap bitcoin – but MtGox made customers 'whole' via a database rollback. MtGox later that year made the customers of competing exchange Bitomat whole, at a cost of 17,000 BTC or more, after that exchange lost its keys.

So when speaking of MtGox, we're already in Alice-in-Wonderland territory, with both custom (and often unwisely eccentric) implementation choices, and overconfident grand gestures. It's hard to rule anything out, based on ideas from elsewhere about plausible engineering or business practices.

Re: What Did Not Happen At Mt. Gox

#55
post #41

Earlier quoted context omitted.

Author here. I think there is some subtlety around the technical point that may be getting lost. Ittay Eyal and I were the ones who discovered an attack against Bitcoin called selfish mining, where we showed how a miner could earn more than his fair share. This attack did not require, but could benefit from, the attacker racing against honest participants on the peer-to-peer network. Some members of the Bitcoin commu…

Another point is that evidence of significant tx-mal can't be found on the block chain prior to Feb 9 [1]. Now, it's possible that the search wasn't thorough enough, but I find that unlikely. Any reissued transactions must have occurred within a very short period -- a couple of weeks in February -- that could have been attributed to malleability. [1] http://www.righto.com/2014/02/the-bitcoin-malleability-attac...

That's only looking at one kind of malleability. Notably, I've been told that MtGox for years issued its own transactions in a non-standard format... so one potential 'attack' would be to mutate those to canonical form and race them into the blockchain. There'd be no evidence of such an attack in the blockchain: only someone who'd been long-archiving losing, non-canonical transactions from multiple places in the network would have a way to estimate the frequency/magnitude of such activity.

Re: What Did Not Happen At Mt. Gox

#56
post #26

> If I'm not mistaken the Nobel leaurate [sic] in question wrote an article entitled "Bitcoin is evil." That seems to be slightly more than asking questions.

> Nobel[sic] leaurate[sic]

Alfred Nobel had nothing to do with the Swedish Bank Prize. It's a scheme between a bank and the Nobel Foundation. http://en.wikipedia.org/wiki/Nobel_Memorial_Prize_in_Economi...

Re: What Did Not Happen At Mt. Gox

#57
post #37

Earlier quoted context omitted.

Where are all these horror stories?

http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... Here are some of my "favorite"(anger inducing) comments: ▻ Poor student, all he had... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Son's college fund wiped out... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Used many credit cards... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Holding coins…

>But none of them beat this one by a Reddit admin from awhile back:

Are you saying Nathanspups is a reddit admin?

Re: What Did Not Happen At Mt. Gox

#58
post #55
post #41

Earlier quoted context omitted.

Another point is that evidence of significant tx-mal can't be found on the block chain prior to Feb 9 [1]. Now, it's possible that the search wasn't thorough enough, but I find that unlikely. Any reissued transactions must have occurred within a very short period -- a couple of weeks in February -- that could have been attributed to malleability. [1] http://www.righto.com/2014/02/the-bitcoin-malleability-attac...

That's only looking at one kind of malleability. Notably, I've been told that MtGox for years issued its own transactions in a non-standard format... so one potential 'attack' would be to mutate those to canonical form and race them into the blockchain. There'd be no evidence of such an attack in the blockchain: only someone who'd been long-archiving losing, non-canonical transactions from multiple places in the netw…

That sounds a bit speculative. If someone has a link that shows one of these "non-canonical transactions," that might lend some credence to the idea. Furthermore, if Gox was always issuing weird transaction formats, then looking for addresses that show a statistic prevalence of these would be trivial. Showing that the attack took place would simply require showing addresses that occasionally issued a proper tx, but statistically favored outgoing transactions of the type you describe. That is, there will be evidence in the blockchain if the type of transaction you describe is very specific to gox.

Re: What Did Not Happen At Mt. Gox

#59
post #29

By the way have you seen Mark Karpeles public apology in Tokyo? (20 seconds in) http://www.youtube.com/watch?v=15IZtzWOzRU So he is French, educated in Paris and living in Japan since 2009? Speaks French, English and Japanese. Sounds interesting, he's no dummy.

The normal French academic school curriculum mandates three languages: French, a secondary language studied in-depth, and a tertiary language. So school leavers should be fluent in one, competant in another, and have the basics of a third.

If people are expected to learn languages early, polyglots are the norm.

Post reply on HN