Live data from Hacker News

Breaking open the Mt. Gox case, part 1

blog.wizsec.jp

81–90 of 99 posts

Re: Breaking open the Mt. Gox case, part 1

#82
post #70
post #61

Earlier quoted context omitted.

In the early days, Bitcoin exchanges weren't making enough money to pay for "real" engineering. Then things tended to take off so fast that just keeping the site up consumed all its resources. There were one or two exchanges that did things "right" (e.g. TradeHill) and were immediately driven out of business by their own high costs.

I don't buy that argument, if it implies that the site operators were anything but flabbergastingly incompetent. It's pretty straightforward to compute the sum of all coins in your wallets, I would assume. It's also straightforward to compute the sum of all account deposits tracked by your database. Just knowing those two numbers is really simple stuff, like a single SQL query on the DB. All they need to do is calcul…

Yeah, how dare you presume incompetence on the part of Magic: The Gathering Online Exchange, the internet's largest online trading card site turned financial exchange. /s

(Not physical cards traded online, mind you, these were virtual cards in the game Magic: The Gathering Online.)

They were simultaneously bit by an attack exploiting a fault in their wallet implementation in combination with transaction malleability. You can invert all the bits in a transaction id and if you also take the complement of the signature then the signature is still valid. The transaction still happens but you never see the transaction ID come over the network (it's actually the complement of the txid). After a while, most clients concluded that it wasn't broadcast successfully and either aborted or retry, so their wallet balance diverged. And yes they probably did not check it against the official client balance.

A significant number of frontend nodes participated in this transaction malleability attack over a sustained period of time, probably more than a lone-wolf attacker could access (although renting botnets isn't all that expensive, especially if you are sucking out bitcoin at the same time...)

The interesting question is whether they had someone on the inside, although it could also be explained by incompetence and an attacker probing for weaknesses who comes to realize that the bug wasn't being patched.

Re: Breaking open the Mt. Gox case, part 1

#83
post #5
post #2

So according to the following, Vinnik was aware of the origin of bitcoins that were sold on BTC-e: > Some of the funds moved to BTC-e seem to have moved straight to internal storage rather than customer deposit addresses, hinting at a relationship between Vinnik and BTC-e. and he was stupid enough to deposit them back to his account on MtGox: > Moving coins back onto MtGox was what let us identify Vinnik, as the MtGo…

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

"Flagrantly disregarding"

That BITCOIN IS NOT MONEY - so KYC IS NOT LEGALLY MANDATE At least not in civil countries.

I also disagree that Money Laundering is the root of all evil. The crime is the problem, fighting the symptoms of crime (it's pay) harder than the source is, eh, ludicrous.

But when you realise you actually sacrifice freedom of speech for it, that's when it gets /really/ icky. (US Supreme Court named financial transactions speech, as without donating to your cause your cause is f-kd. So it should be private & anonymous, or you give away the freedom of spending, which equals the freedom of speech)

So, do I want to increase my attack surface (=being named and known to the USGOV or whomever wrt buying/trading cryptocurrency and spending it where I will), or will I use BTC-e, which respects that freedom? Hmmm.

BTC-e always had a criminal vibe to it, so that might alter your choice. Regardless the vibe, you suggest self-censorship, ID'ing yourself and confessing wherever you spend, because..? You're afraid of Money Laundering? Check the Panama Papers - you're barking up the wrong tree. I think you're doing it because you're afraid of the panopticon seeing you hide yourself.

It's inhumane how effective this mechanism already is.

Re: Breaking open the Mt. Gox case, part 1

#84

Can't wait to get my refund :) It's still insane to me that MtGox never moved coins to a wallet or acknowledged the breach until long after it was too late. You would think if you have billions of dollars sitting somewhere and you realize someone is starting to take them you would, you know, do something .

>Can't wait to get my refund :) I had like 0.000001 BTC in mtgox and it was worth it for the cute sticky unfoldy postcard thing I got from the Japanese court.

I got that card and had 0 BTC in my account. I think they sent it to anyone who ever used the exchange, regardless if they had funds in it at the time it fell apart.

Re: Breaking open the Mt. Gox case, part 1

#85

Earlier quoted context omitted.

Give BTC a little credit, it's capable of giving you a solid rush and getting you(r bank balance) high. It doesn't always bankrupt you. That's a lot better than you can say of krokodil.

I don't even know what krokodili IS so I'll take your word for it, ha ha

It's what you get if you walk into a gas station determined to mix everything they have on their shelves and hope this results in a drug. It's a very cheap and easy drug to create, but its ability to destroy the user's body far surpasses more conventional drugs like heroin.

The life expectancy of a user is 1-2 years as their tissue starts to die.

Re: Breaking open the Mt. Gox case, part 1

#86
post #28

Earlier quoted context omitted.

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

Magic the Gathering Online Exchange ;)

Yes, I never realized.. seriously, I didn't until today. I thought it was meant to sounds like Knox and Mount to invoke images of gold, vault in a mountain side and so on.

Re: Breaking open the Mt. Gox case, part 1

#87

Earlier quoted context omitted.

Jed McCaleb built a beta release of a Magic trading card exchange for the MtGox domain. He then read about bitcoin in a Slashdot article posted on July 11th, 2010 after which he decided to write an exchange. McCaleb insists that the bitcoin exchange was completely different from the Magic cards exchange, but Mt Gox went live as a Bitcoin exchange July 18th, 2010 . So either McCaleb built a brand new exchange from the…

> So either McCaleb built a brand new exchange from the ground up in one week, or he reused code from his Magic card trading service. Or he spent some time writing the new service while the previous one was still running.

How could he have spent time writing a new service if it went from him getting the bitcoin idea from slashdot to launch in 7 days?

Re: Breaking open the Mt. Gox case, part 1

#88

Earlier quoted context omitted.

Give BTC a little credit, it's capable of giving you a solid rush and getting you(r bank balance) high. It doesn't always bankrupt you. That's a lot better than you can say of krokodil.

I don't even know what krokodili IS so I'll take your word for it, ha ha

It's an old obsolete but very potent pain killer that recently resurfaced in Russia and it makes you body rot and require amputations.

I think it's an apt comparison of the 'potence' of these two things. People who take coke don't rot alive and die within a few years. Similarly penny stocks are (relatively) harmless, never used to buy illegal stuff and people who do them don't go around saying that penny stocks will replace all finances and currencies and cause a revolution against the corrupt banker filled governments and accuse everyone of being governmental propagandists (yada, yada..), many of Bitcoin proponents on the other hand...

Re: Breaking open the Mt. Gox case, part 1

#89
post #24

Earlier quoted context omitted.

More like krokodil.

Give BTC a little credit, it's capable of giving you a solid rush and getting you(r bank balance) high. It doesn't always bankrupt you. That's a lot better than you can say of krokodil.

But many (not all of course, and probably a minority of people who do bitcoin) of its proponents seem as crazy as krokodil users with their snappy judgements, saying it's government propaganda that there is crime done using bitcoin, that bitcoin will replace all currencies, that 'revolution is coming', 'banksters are afraid', and other weird 'freedom' slogans, etc.

At the same time, in some weird massive cognitive dissonance, anytime one of these evil governments they hate so much decides to legitimize bitcoin in some way by recognizing it as some financial instrument or when USD/BTC rises (and let's remember - dollars are a fiat currency a.k.a. useless pieces of paper that bankers print and force people to use) they are giddy as hell.

I even seen comments saying that Satoshi becoming instant billionaire (richest in the world by far, in pure currency, not 'net worth' that's hard to liquidate and spend) if bitcoin really became global currency is deserved for his contribution to humanity. Can you imagine someone saying Dennis Ritchie should own 5% to 10% for his contributions to Unix, C, etc. (that largely went unrewarded and he died the same time Jesus of electronics Steve Jobs did so no one even cared). Or RMS for the FSF? I just can't imagine how much you have to like a thing (FOSS, Unix, C, Bitcoin, ..) to say its creator should be rewarded that heavily and become the richest person in Earth's history.

Re: Breaking open the Mt. Gox case, part 1

#90
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Lots of people in Bitcoin hate KYC and AML laws, and consider them invasive. I am one of these people. In itself, it's not an indicator of wrongdoing.

Yes it is. The laws were legitimately passed; agree or not, citizens have a duty to follow them, or else protest them directly if they find them onerous enough.
Post reply on HN