6 ms·
Statement on Mt. Gox
- aresant 13y agoTwo important items: a) Adreas is the Chief Security Officer of Blockchain and a well known / respected digital currency personality. b) The most interesting part of the article was a link to another post reviewing Coinbase's security practices (1) where he concludes "it appears that the Coinbase system contains the expected funds and their cold storage system and process appear to be operating according to security best practices." (1) http://antonopoulos.com/2014/02/25/coinbase-review/ http://antonopoulos.com/2014/02/25/coinbase-review/
- smtddr 13y agoIf anyone has 38mins to burn... http://techcrunch.com/2013/12/17/foundation-brian-armstrong-on-coinbase-and-bitcoin-security/ http://techcrunch.com/2013/12/17/foundation-brian-armstrong-... A Google Ventures video about coinbase security with Kevin Rose(from old Digg) asking a bunch of questions with Coinbase founder Brian Armstrong. Sounds very legit to me.... but... you _still_ shouldn't leave huge amounts of bitcoin in any exchange! Make[1] your own btc-address + private key and keep the coins there. And note that bitaddress.org can be git clone'd and ran on a computer without internet access. 1. https://www.bitaddress.org https://www.bitaddress.org
- argumentum 13y agoCoinbase isn't really an exchange (though it works as such for US dollars). It's mainly a hosted wallet service that provides apps, and merchant and developer tools to make it easier to engage with the bitcoin ecosystem.
- mindstab 13y agoA little regulation and over sight might have prevented all this. And with out it going forward all anyone can do is advise best practices, and then watch as some ignore them and also have their money stolen. Very wild west. Totally something I'll be staying well back from
- JHSheridan 13y agoJust like a little regulation and oversight stopped the housing bubble, tech bubble, etc. I'm not saying this is comparable directly to those situations, but we shouldn't forget that regulated markets have crooks and cheats too.
- wpietri 13y agoRemind me of where somebody said that regulation would have made everything perfect? I missed that post.
- mpyne 13y ago> A little regulation and over sight might have prevented all this. Yes, but that is completely contrary to the whole reason Bitcoin exists in the first place. If you wanted a regulated currency you'd get fiat. It's wild west by definition, which is good for popcorn-muncher like me... but bad for friends of mine who have lost a significant amount of money by "experimenting" with Bitcoin. :(
- kaonashi 13y ago>Yes, but that is completely contrary to the whole reason Bitcoin exists in the first place. Not really. Satoichi has shied away from the political motivations of a lot of the community.
- mpyne 13y agoWhat Satoshi does after releasing the creation has no bearing on the purpose behind creating something before they released it though. Realizing that you need to shy away from something after you do something doesn't invalidate the reasons behind why you did it.
- gnaritas 13y agoSatoshi's motivations were political, his first message in the blockchain makes that clear. He hasn't shied away, he's disappeared for obvious reasons.
- smtddr 13y ago>>I was part of the team helping to coordinate between the other exchanges to ensure that they could quickly resume operations which they did no more than 48 hours later. Some exchanges were in fact completely unaffected, revealing as false Gox’s claims that this was a bug in bitcoin. I don't think that reveals anything about what happened in MtGox. Also, don't know if anyone's noticed... but mtgox.com has a message now. http://i.imgur.com/YDONE4d.png http://i.imgur.com/YDONE4d.png And note the word "DONE" in that imgurl URL. Ominous...
- crystaln 13y ago"Some exchanges were in fact completely unaffected, revealing as false Gox’s claims that this was a bug in bitcoin." This reveals a lack of objectivity here. There IS a bug in bitcoin. There are workarounds, and some exchanges implemented those properly. Of course, MtGox should have followed best practices and implemented a workaround, but the above sentence is - on its face - flawed and biased. The fact that some exchanges were immune to the bug does NOT mean that bitcoin bears no fault or that Gox's claims are false. This was and is, in fact, an acknowledged and widely known bug in bitcoin.
- davidw 13y agoI'm inclined to agree with cperciva, who is no slouch with security stuff: https://news.ycombinator.com/item?id=7289273 https://news.ycombinator.com/item?id=7289273
- crystaln 13y agoThe statement is inherently flawed, regardless of its source. Because some exchanges were unaffected does not mean that MtGox was not affected, and the statement itself implies that other exchanges were affected which would be evidence in MtGox' favor. I'm not saying MtGox was not incredibly incompetent, however nobody is helped by this false defensiveness over a very serious and clear bug in bitcoin that seems to have affected at least a few exchanges. Regardless of MtGox' incompetence, this IS a serious bug in bitcoin for which a workaround is required, and without which a bitcoin theft is possible.
- eliasmacpherson 13y agoIf this implementation is bugged: http://blog.magicaltux.net/2010/06/27/php-can-do-anything-what-about-some-ssh/ http://blog.magicaltux.net/2010/06/27/php-can-do-anything-wh... then is ssh broken?
- crystaln 13y agoPlease state your point rather than providing just a link. I don't know what you are trying to say.
- xdarnold 13y agoUnder the presumption that it is true that ~750k BTC has been stolen, has anyone considered the possibility of orchestrating a 51% attack on the attacker(s)? Gox probably has logs of withdrawal requests. It might be daunting but feasible to sift the tx-MAL withdrawals from legitimate ones, then work with major pools and exchanges to double-spend stolen coins back to Gox. Gox could then be forced (by the same 51% majority) to pay legitimate requests for reimbursement by vendors or 3rd parties holding stolen coins they transacted for goods or services, given reasonable documentation. Leaving us with some but not unacceptable collateral damage.
- wmf 13y agoVigilante rewriting of the blockchain has been discussed before and it tends to get hung up on the issue of agreeing who's the thief and who's the victim.
- xdarnold 13y agoIt seems like there is a straightforward enough principle in this case to do so without much argument. Not that the method would be perfect. But isn't it preferable to the alternative?
- gliptic 13y agoThis would require you to discard all the blocks since the transactions started happening and re-mine them with those transactions excluded. This would be completely impossible unless you dedicated most of the mining equipment to this for months and asked those miners to part with their earned mining rewards until this rewritten chain caught up with the official one. Hardly likely.
- xdarnold 13y agoI don't think this is what I'm suggesting at all. If a popular majority of miners agreed to accept transactions double spending the original coins, this would be tantamount to generating 750k new Bitcoin, not initially invalidating any blocks or other transactions. With forensics on the initial theft, miners could then tree-traverse back up to blacklist future transactions on stolen coins. There are probably lots of ways to accomplish basically this. This would render all stolen btc dead in the water, hence the "force Gox to repay legitimate requests for reimbursement of those who transacted for stolen coins." That second part, though, isn't crucial to the idea. The community could just double spend the coins to mitigate harm done without attempting to stop the stolen coins downstream.
- diegocg 13y agoIt puts all the blame on Mt. Gox, assuming that their lack of good management is to blame. But I still see the lack of reversibility of transactions (one of bitcoin's strengths) as the major problem here. We live in civilized in a world where there are laws and polices and judges and banks and governments, but bitcoin tries to workaround them for no good reason. I'm still hoping that banks will take what to me is the bitcoin's biggest feature (multiple wallet addresses and the ability to easily make cash transfers to other wallet address) but without pretending that centuries of legal and financial traditions somehow don't matter.
- sigil 13y ago> But I still see the lack of reversibility of transactions (one of bitcoin's strengths) as the major problem here. "Stop Saying Bitcoin Transactions Aren't Reversible" http://elidourado.com/blog/bitcoin-arbitration/ http://elidourado.com/blog/bitcoin-arbitration/ The n-of-m multisignature facilities described in that article are the future of Bitcoin. You probably don't need multisig arbitration when you buy a coffee or a stick of gum, but you probably do when you're transferring large sums. Of course, there was no multisig protection in sight in the MtGox case, but then there was no blockchain in sight either. Far worse errors of judgement were made there. Bitcoin makes the use of arbitration services optional, and it makes the actual mechanics of arbitration services safer and more efficient. The arbiter in a 2-of-3 multisig transaction can't freeze or seize funds in transit -- hello PayPal! -- and takes zero action in the vast majority of cases, where there is no dispute. Banks, credit card companies, and existing payment systems like PayPal can't easily, optionally disintermediate themselves. They must play arbiter. And we must pay for it. > bitcoin tries to workaround them for no good reason. There's a good reason. Why do businesses today pay transaction fees when you use your card to buy that coffee? I'll just quote the opening paragraph of the original Bitcoin paper: "Commerce on the Internet has come to rely almost exclusively on financial institutions serving as trusted third parties to process electronic payments. While the system works well enough for most transactions, it still suffers from the inherent weaknesses of the trust based model. Completely non-reversible transactions are not really possible, since financial institutions cannot avoid mediating disputes. The cost of mediation increases transaction costs, limiting the minimum practical transaction size and cutting off the possibility for small casual transactions, and there is a broader cost in the loss of ability to make non-reversible payments for non-reversible services. With the possibility of reversal, the need for trust spreads. Merchants must be wary of their customers, hassling them for more information than they would otherwise need. A certain percentage of fraud is accepted as unavoidable. These costs and payment uncertainties can be avoided in person by using physical currency, but no mechanism exists to make payments over a communications channel without a trusted party." https://bitcoin.org/bitcoin.pdf https://bitcoin.org/bitcoin.pdf
- panarky 13y ago“Cold storage” does not “leak”. The idea that the funds were stolen, unnoticed, from cold storage, due to Transaction Malleability, strains the credulity of even the most gullible observers. This part of the story still doesn't make sense. One possible explanation that I haven't seen anywhere else is that MtGox lost control of the private keys to their cold storage. How else could 744,000 BTC disappear, without anyone noticing, from cold storage?