Live data from Hacker News

Peter R’s Theory on the Collapse of Mt. Gox

bitcointalk.org

91–100 of 125 posts

Re: Peter R’s Theory on the Collapse of Mt. Gox

#91

When bitcoin started it was touted as anonymous, reliable and secure against fraud and theft by central authorities (especially government.) I had some doubts (and other interests) so didn't bother getting into bitcoins. Now we find out that bitcoin definitely isn't secure, and fraud by central authorities is just as possible as with any complex system of representing monetary value. I really think it's a universal L…

> Now we find out that bitcoin definitely isn't secure

If anything is secure, then bitcoin is. That doesn't mean that it protects people from their own incompetence when it comes to security, there's no getting around that at this stage.

> and fraud by central authorities is just as possible as with any complex system of representing monetary value.

Only when you actually trust a centralised authority with the private keys in question, which people should not be doing in the case of businesses like mtgox which were obviously utterly incompetent right from the start. Plaintext passwords in http get queries embedded in plaintext emails? Come on, that would've twigged my "this is a really dumb idea" sense even before I started software development.

> MtGox turns out to be no different to the FED and any other fiat money authority.

Exactly, which is irrelevant to the security of bitcoin itself. It's like saying a currency itself has a security vulnerability because a security guard at a bank was incompetent, it doesn't work like that.

> I think I'll stick to keeping gold and silver pieces in an old sock.

Gold and silver are just as vulnerable to centralised betrayal when held by a third party, and bitcoin is just as invulnerable to centralised betrayal when you hold it yourself. Your analogy compares two entirely different situations in order to make one look better than the other.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#92

Earlier quoted context omitted.

Couldn't a bitcoin exchange publish a list of accounts that they use to hold coins for customers, and similarly, request that their bank confirm that the sum of customer funds is greater than X? I mean, we might not see exactly the number of things we expect, but if it's holding over 95% of the value expected (through those mechanisms), and shows a successful trend of having increases when it claims and decreases whe…

Well, Dollars are held in bank accounts that can be verified. Bitcoins are not held in bank accounts. They are long strings of numbers in essence and "storing" bitcoins involve putting these numbers on a hard disk that isn't connected to anything. I don't know enough about the bitcoin protocol to say this is possible but if an exchange could exhibit the public keys of their bitcoins without exposing the private keys,…

This is achieved by making a transaction between two wallets you control - this is recorded on the blockchain. Karpeles / MTGox did this previously to prove that they had a certain amount of BTC. see https://bitcointalk.org/index.php?topic=21436.0 for more details (search for 424242).

Re: Peter R’s Theory on the Collapse of Mt. Gox

#93

tl;dr: Mt Gox had a lot of coins stolen in 2011 and has been running a fractional reserve ever since. Mark tried to delay the inevitable insolvency by creating a bot to manipulate the price, and eventually tried to cover it all up by blaming "transaction malleability" attacks. One of many plausible explanations. It's going to be really interesting seeing how this actually plays out.

Im sorry but what is there to "play out"? The show is over. There is a bankrupcy filed protection that will decide what to give to whom but thats about it. We will never find out the truth. Even after extensive investigation, if any, you dealing with anonymous wallets over period of years that been sicking coins out of gox. Definite answer who did it, who knew it, even how they did it, will never come.

It will be interesting to see how this will affect the business practices of other Bitcoin exchanges.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#94
post #37
post #31

Earlier quoted context omitted.

Bitcoin folks need to understand that fractional reserve banking doesn't mean holding less in assets than you have in liablilities; it simply means that you hold less cash (or very liquid assets) than you have liabilities. What the author of this post describes is just fraud, not fractional reserve, and while libertarian types love to conflate the two, they are emphatically not the same thing.

Well "fraud" implies deception. I think the argument that "libertarian types" make is that very few people understand how money works at a high level (namely that the money supply can increase up to the money multiplier), and perhaps that the people who administer high level finance deliberately set things up to benefit themselves at the cost of the "common man." I don't think many people argue that fractional reserv…

Murray Rothbard is probably the most influential example. He argued that fractional-reserve banking is fraud and should be effectively outlawed by regular tort law (not by government regulation).

He had a bit of a running disagreement with Von Mises over it: http://www.garynorth.com/public/9714.cfm

Re: Peter R’s Theory on the Collapse of Mt. Gox

#95
post #48

I'm thinking about opening up an exchange for crypto-currencies with a guarantee that deposited coins are put directly into a cold wallet. The only drawback I can see is that (so far) I don't see an easy (and secure) way to make withdrawals instantaneous. Perhaps my background in hardware systems leads me to solutions that use physics to solve certain security problems, but to me, sending bitcoins to an unconnected c…

Use 2-of-3 multisig: https://gist.github.com/oleganza/9232293

User owns a key protected by his password and your server never knows it. Another key is stored unencrypted on the web server (like in "hot" wallet). Third key is stored with your staff, encrypted by their personal password (like in "cold" wallet).

Normal withdrawal: user key and web server's key sign the transaction and it's instantly available.

Security analysis:

1. User forgot their password: he contacts staff that uses their key + web server's key to move funds to new destination.

2. Hackers have taken the web server: they see the key, but it's not enough to move anyone's funds.

3. Staff lost their keys: users still can access their funds if they still remember their passwords.

4. Hackers stole user's computer: they may instantly withdraw some amount up to an arbitrary daily limit. (Withdrawal can also be protected by 2-factor authentication.)

5. Hackers stole staff's keys (e.g. from a personal computer): they still need to break into web server. When staff realizes that keys are compromised, all funds must be moved immediately to new keys.

In other words, users have a hard proof of ownership of specific coins. All coins, no exception, are protected by two differently stored keys. So no need for hot/cold wallet difference.

If you want to block some BTC for trading, webserver will implement that easily: when you withdraw coins, it will move blocked portion to someone else's address.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#96
post #37

Earlier quoted context omitted.

Well "fraud" implies deception. I think the argument that "libertarian types" make is that very few people understand how money works at a high level (namely that the money supply can increase up to the money multiplier), and perhaps that the people who administer high level finance deliberately set things up to benefit themselves at the cost of the "common man." I don't think many people argue that fractional reserv…

Murray Rothbard is probably the most influential example. He argued that fractional-reserve banking is fraud and should be effectively outlawed by regular tort law (not by government regulation). He had a bit of a running disagreement with Von Mises over it: http://www.garynorth.com/public/9714.cfm

That article was interesting about the utilitarian Mises vs the natural law Rothbard, but it was completely wrong about the 100% reserve clause Rothbard insisted as essential being necessarily enforced by the state.

It sounds like the writer has not heard of Rothbard's proposed anarchocapitalist systems, polycentric laws and competitive arbitration and enforcement organisations.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#97

This shouldn't be surprising. The same sort of things would happen back in the good old days when we were on the gold standard. Usually the catalyst in those days was some sort of financial stress at moment of weakness for the bank. In the 19th century, Typically this was in the fall before the receipts from the harvest came in. Small banks would have minimal reserves, and failures could easily cascade. I'm surprised…

> I'm surprised with all of the rhetoric about fiat money that nobody figured this out sooner.

My experience has been that goldbugs usually just don't want to be told about or think about this, so I'd expect things to be the same among Bitcoin supporters. And presumably a number of the clever boys will quietly reason that even if, later on, Bitcoin goes the way of all money, the people who were in on the ground floor will still have made their killing.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#98
post #48

I'm thinking about opening up an exchange for crypto-currencies with a guarantee that deposited coins are put directly into a cold wallet. The only drawback I can see is that (so far) I don't see an easy (and secure) way to make withdrawals instantaneous. Perhaps my background in hardware systems leads me to solutions that use physics to solve certain security problems, but to me, sending bitcoins to an unconnected c…

You can't put money directly into a cold wallet, if I understand correctly. If you can manipulate it directly then it's hot by definition.

Let's say I have a machine that's not connected to the Internet, but I develop a serial protocol that allows the transfer of bitcoins across RS-232, and build a cable that only has the receive signals connected at my "secure" machine.

If I wanted to take it further, the "secure" machine could print that wallet onto paper or could robotically insert flash drives into a USB port (in such a way that removed keys were dropped into a bin the robot couldn't reach into.

This is only one of many ways I can think of that would allow the automatic creation of cold wallets ... the only way to attack such a system is to gain physical access.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#99

Earlier quoted context omitted.

Mark was the CEO, the lead developer, the lead business guy, the lead operations guy, and nearly everything else you can think of. He likely had unlimited power to doctor anything he liked, and probably in a way that would not make it easy for other employees to notice. Even if they did use source control, he could probably mask those commits. Honestly I'm not even sure how many other technical employees they had. I…

Would also explain why he never grew the team out more -- would make it more difficult to control the situtation.

Wow, this is something that's been bothering me for some time. Why didn't Mark grow the team? He evidently didn't have any employees, just a handful of contractors.

This would explain why.

Re: Peter R’s Theory on the Collapse of Mt. Gox

#100
post #24

Earlier quoted context omitted.

Which is why government insuring bank deposits isn't such a crazy idea. If the government collapses and can't stand behind the policies, then you have some really big problems on your hands and it is likely that private insurers wouldn't have fared much better. If the government doesn't collapse, everyone gets made (more or less) whole again. Basically, when the government is your insurer, there is no "Who insures th…

Right, because if government does not collapse there is nothing stopping them from printing all the money they need to cover their obligations.

If you want a real word example, you can read about the Corralito ("child's playpen") in Argentina in 2001: http://en.wikipedia.org/wiki/Corralito
Post reply on HN