I think that his points against transaction malleability are invalid: - technical one - Bitcoin clients have a 100 ms delay before they relay messages. An attacker can compile a modified client that doesn't have these limitations and successfully outrun the rest. It was shown once that an attacker managed to successfully modify most of Bitcoin transactions on the network for some time in February - social one - IIRC…
Agreed. It's known that Mt. Gox was auto-retrying sends after the txids didn't match. FWIW, I submitted the 'what most likely happened' post last night: https://news.ycombinator.com/item?id=7328219 . It's a bit shorter and seems less speculative.
What Did Not Happen At Mt. Gox
51–60 of 97 posts
Re: What Did Not Happen At Mt. Gox
#52Earlier quoted context omitted.
Born in France, so he speaks French. Involved with the internet, so he speaks English. Lives in Japan, so he speaks Japanese. This is not impressive.
Speaking as someone who is anti-Karpeles and unilingual: I think speaking three languages, regardless of context, is incredibly impressive.
Additionally, if you're exposed to a new language early in life, it becomes much easier to learn new languages in the future. And being immersed in it forces you to learn, as your survival depends on it.
So, incredibly impressive? Nah. Mind you, if someone is legitimately a fast language learner, given that I am not at all, it does impress me, especially if they truly master it and can think in that language.
Re: What Did Not Happen At Mt. Gox
#53Earlier quoted context omitted.
Born in France, so he speaks French. Involved with the internet, so he speaks English. Lives in Japan, so he speaks Japanese. This is not impressive.
Speaking as someone who is anti-Karpeles and unilingual: I think speaking three languages, regardless of context, is incredibly impressive.
For a majority of the people on this planet, this isn't the case.
Re: What Did Not Happen At Mt. Gox
#54I think that his points against transaction malleability are invalid: - technical one - Bitcoin clients have a 100 ms delay before they relay messages. An attacker can compile a modified client that doesn't have these limitations and successfully outrun the rest. It was shown once that an attacker managed to successfully modify most of Bitcoin transactions on the network for some time in February - social one - IIRC…
Author here. I think there is some subtlety around the technical point that may be getting lost. Ittay Eyal and I were the ones who discovered an attack against Bitcoin called selfish mining, where we showed how a miner could earn more than his fair share. This attack did not require, but could benefit from, the attacker racing against honest participants on the peer-to-peer network. Some members of the Bitcoin commu…
Regarding MtGox scenarios:
Reliable evidence on what MtGox truly did is scarce, but people have widely speculated that at times they auto-reissued payouts, and without the protective measure of reusing the same inputs. It would be in character – see other examples of their recklessness below.
So while I share your doubt that malleability could have resulted in significant losses, there is a theory for that, which doesn't require extensive social engineering/human-in-the-loop processes. And, if it had been happening for years, only outsiders with a giant archive of long-ago race-losing transactions (that never reached blocks) would be able to estimate the magnitude of the losses. (I don't know any public source for such an archive.)
Similarly, at times Karpeles mentioned that the cold storage was a "paper-based RAID" in 3 parts, or some other scheme in 6 places. As the 'key man' in an enterprise that suddenly found itself atop $100MM+ in easily-transferable assets, his feared threats may have included kidnapping/extortion to force disclosure of the keys. Thus his cold storage scheme may have involved putting necessary key-shares totally outside his easy control, even via people and safety-deposit boxes in other countries. Any "key-loss" scenario should consider the chance law-enforcement-actions or other calamities, far from the MtGox offices or Japanese accounts, have made essential parts of the cold-storage keys unrecoverable, for now and perhaps permanently.
There's a forum thread from years ago where people mention 2600+ bitcoins MtGox lost from their own bad-transaction-issuing code (https://bitcointalk.org/index.php?topic=50206.0;all). Karpeles wrote his own SSH server in PHP. Over the years MtGox suffered SQL injection & cross-site scripting attacks. In the June 2011 'flash crash', the entire user database with weakly-hashed passwords was lost (supposedly via an auditor compromise), allowing outsiders to carry off some unknown number of artificially-cheap bitcoin – but MtGox made customers 'whole' via a database rollback. MtGox later that year made the customers of competing exchange Bitomat whole, at a cost of 17,000 BTC or more, after that exchange lost its keys.
So when speaking of MtGox, we're already in Alice-in-Wonderland territory, with both custom (and often unwisely eccentric) implementation choices, and overconfident grand gestures. It's hard to rule anything out, based on ideas from elsewhere about plausible engineering or business practices.
Re: What Did Not Happen At Mt. Gox
#55Earlier quoted context omitted.
Author here. I think there is some subtlety around the technical point that may be getting lost. Ittay Eyal and I were the ones who discovered an attack against Bitcoin called selfish mining, where we showed how a miner could earn more than his fair share. This attack did not require, but could benefit from, the attacker racing against honest participants on the peer-to-peer network. Some members of the Bitcoin commu…
Another point is that evidence of significant tx-mal can't be found on the block chain prior to Feb 9 [1]. Now, it's possible that the search wasn't thorough enough, but I find that unlikely. Any reissued transactions must have occurred within a very short period -- a couple of weeks in February -- that could have been attributed to malleability. [1] http://www.righto.com/2014/02/the-bitcoin-malleability-attac...
Re: What Did Not Happen At Mt. Gox
#56> If I'm not mistaken the Nobel leaurate [sic] in question wrote an article entitled "Bitcoin is evil." That seems to be slightly more than asking questions.
Alfred Nobel had nothing to do with the Swedish Bank Prize. It's a scheme between a bank and the Nobel Foundation. http://en.wikipedia.org/wiki/Nobel_Memorial_Prize_in_Economi...
Re: What Did Not Happen At Mt. Gox
#57Earlier quoted context omitted.
Where are all these horror stories?
http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... Here are some of my "favorite"(anger inducing) comments: ▻ Poor student, all he had... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Son's college fund wiped out... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Used many credit cards... http://www.reddit.com/r/Bitcoin/comments/1yv26o/gox_horror_s... ▻ Holding coins…
Are you saying Nathanspups is a reddit admin?
Re: What Did Not Happen At Mt. Gox
#58Earlier quoted context omitted.
Another point is that evidence of significant tx-mal can't be found on the block chain prior to Feb 9 [1]. Now, it's possible that the search wasn't thorough enough, but I find that unlikely. Any reissued transactions must have occurred within a very short period -- a couple of weeks in February -- that could have been attributed to malleability. [1] http://www.righto.com/2014/02/the-bitcoin-malleability-attac...
That's only looking at one kind of malleability. Notably, I've been told that MtGox for years issued its own transactions in a non-standard format... so one potential 'attack' would be to mutate those to canonical form and race them into the blockchain. There'd be no evidence of such an attack in the blockchain: only someone who'd been long-archiving losing, non-canonical transactions from multiple places in the netw…
Re: What Did Not Happen At Mt. Gox
#59By the way have you seen Mark Karpeles public apology in Tokyo? (20 seconds in) http://www.youtube.com/watch?v=15IZtzWOzRU So he is French, educated in Paris and living in Japan since 2009? Speaks French, English and Japanese. Sounds interesting, he's no dummy.
If people are expected to learn languages early, polyglots are the norm.