3 ms·
This is almost certainly hogshit, and anybody who has been paying even a little bit of attention over the last week can probably smell it. The "hole" in MtGox'
by blhack 13y ago
This is almost certainly hogshit, and anybody who has been paying even a little bit of attention over the last week can probably smell it.
The "hole" in MtGox's security was a social one. You could contact customer support and claim that you had not received your coins, and they could re-issue you new ones if they chose to. There is also no evidence that this ever happened.
This wasn't, and isn't, a flaw in the underlying architecture, it's just a way to convince a customer service rep that you weren't lying.
If SR was re-issuing coins automatically, it's because they were being intentionally stupid.
--
They're using this as a scapegoat. Either somebody ran off with the coins, or something otherwise hacked them and they're using this as an explanation.
- sillysaurus2 13y agoIf SR was re-issuing coins automatically, it's because they were being intentionally stupid. MtGox was re-issuing coins automatically. Due to this, Gox has lost money. Possibly a huge amount. Were they being intentionally stupid, or just stupid? Source: https://news.ycombinator.com/item?id=7222690 https://news.ycombinator.com/item?id=7222690 This transaction malleability flaw is certainly a convenient excuse. But if these people implemented their wallet software in the same manner as Gox, then they would've suffered the same fate: a loss of thousands of coins, which is exactly what they claim happened.
- deleted 13y ago[deleted]
- blhack 13y agoMaybe I just haven't had enough coffee today, but: where does it say there that gox was re-issuing coins automatically?
- deleted 13y ago[deleted]
- sillysaurus2 13y agoSorry, I should have linked two comments higher: https://news.ycombinator.com/item?id=7222457 https://news.ycombinator.com/item?id=7222457 You'll note that mtgox had funds taken from it. None of these other sites [did]. They're just being flooded with junk that screws up their transaction processing. It's not really the same thing at all.
- sdoowpilihp 13y agoStupidity is rarely intentional. That fact doesn't negate the stupidity.
- interstitial 13y agoCome visit East Texas, you'll change your mind. Stupidity is a lifestyle choice.
- blhack 13y ago>MtGox was re-issuing coins automatically They worded that very strangely in their statement about it: >This means that an individual could request bitcoins from an exchange or wallet service, alter the resulting transaction's hash before inclusion in the blockchain, then contact the issuing service while claiming the transaction did not proceed. If the alteration fails, the user can simply send the bitcoins back and try again until successful. Emphasis mine. The reference client certainly doesn't do this on spends. Why would gox have implemented it in this way? It doesn't make any sense at all.
- sillysaurus2 13y agoThe reference client certainly doesn't do this on spends. Why would gox have implemented it in this way? It doesn't make any sense at all. I've been researching the details of this disaster. Here's what I've gathered. This info came from Greg Maxwell, a bitcoin core developer. He got his information from the owner of MtGox himself: Gox implemented custom wallet software to deal with massive transaction volume. The reference client wouldn't cut it for their purposes. For what it's worth, Greg agrees with the decision to write custom software for high-volume exchanges. It seems pretty likely that other exchanges have also implemented custom bitcoin software stacks. In the scenario where Gox detected that a transaction failed, they automatically reissued the transaction. But that was based on the faulty assumption that the transaction hash couldn't ever mutate. This flaw was exploited to siphon bitcoin out of Gox. This doesn't matter very much for Gox because, conservatively, they've made at least 120k BTC in profits from trade fees. More likely in the range of 400k. So they'll be able to cover the losses. But this means it's entirely possible that other exchanges and web services with custom software stacks were hit hard by the malleability event, just like Gox was. It depends whether they were automatically reissuing transactions. If so, then they probably lost money.
- dobbsbob 13y agoI'm surprised they had any kind of online wallet. You'd think you would do manual transactions with offline keys if running a blackmarket, or the very least multiple sigs for any hot wallet.
- girvo 13y agoMulti sgi is exactly what The Marketplace has done, as well as not keeping BTC in an online wallet. It hasn't taken off, unfortunately.
- gwern 13y agoPeople find it hard to use, between i2p and multi-sig, and so they don't use it and then you have the usual chicken-egg problem. You might think i2p & multi-sig are trivial conveniences worth paying for security from site operators scamming you (currently the #1 cause of black-market death in my compilation), but we here, on HN of all places, should appreciate how important usability is and how hard ordinary people find crypto stuff to use: most black-market users can't even PGP-encrypt their addresses when ordering drugs. (You might expect 100% of addresses to be encrypted, but actually encryption rates range from 8% to 90%, depending on which marketplace & vendor you ask.)
- lugg 13y agoSource? I was under the impression MtGox was also processing withdrawals automatically and shut off withdrawals while they implemented a manual step (like all the other wallet sites already have.) I don't mean to be unconstructive, just trying to understand what you're saying here, I don't really see how a customer support issue such as you outlined would require shutting off withdrawals for multiple days.
- blhack 13y agoI might just be wrong. I'm interpreting their statement to mean that, but some people have pointed out that they've said other, possibly conflicting things. >This means that an individual could request bitcoins from an exchange or wallet service, alter the resulting transaction's hash before inclusion in the blockchain, then contact the issuing service while claiming the transaction did not proceed. If the alteration fails, the user can simply send the bitcoins back and try again until successful. https://www.mtgox.com/press_release_20140210.html https://www.mtgox.com/press_release_20140210.html