Pages:
Author

Topic: Bitcoinica MtGox account compromised - page 27. (Read 156012 times)

rjk
sr. member
Activity: 448
Merit: 250
1ngldh
July 13, 2012, 03:19:12 PM
Tihan is right.. patrick/amir/donald should've changed the LastPass master password, if not created a whole new account (using a different e-mail, not [email protected] which is a big red flag). Not to mention securing the MtGox account. Hell, zhoutong should've revoked those API keys that day long ago (he even said the hacker could've used them).
The API keys were revoked immediately, read the beginning of the last "hack" thread. The problem this time is that the withdrawal was via a normal login, which wasn't protected with 2 factor authentication.

As for the API-key-as-a-master-password fuckup, well I don't have enough info on that to make a judgement. Was that password implemented in the assumption that the source would not be released? Perhaps that's what it was set to AFTER the previous hack (stupid)? Maybe no one correlated it with the API key, and didn't realize the significance?
sr. member
Activity: 325
Merit: 250
Our highest capital is the Confidence we build.
July 13, 2012, 03:17:56 PM
Quote from: Doesn't really matter
Two things are infinite, the universe and human stupidity, and I am not yet completely sure about the universe.

By malice, negligence or whatever, the sad truth is that this is already nothing but a huge scam.

Doesn't make sense to stay kicking this dead body, lets just move on...
legendary
Activity: 1372
Merit: 1008
1davout
July 13, 2012, 03:16:33 PM
Tihan is right.. patrick/amir/donald should've changed the LastPass master password, if not created a whole new account (using a different e-mail, not [email protected] which is a big red flag). Not to mention securing the MtGox account. Hell, zhoutong should've revoked those API keys that day long ago (he even said the hacker could've used them).
The API keys *were* revoked.
legendary
Activity: 1372
Merit: 1008
1davout
July 13, 2012, 03:15:48 PM
Will you say the same to those who will experience a loss once pirateat40 runs?
lol
legendary
Activity: 826
Merit: 1001
rippleFanatic
July 13, 2012, 03:15:17 PM
Tihan is right.. patrick/amir/donald should've changed the LastPass master password, if not created a whole new account (using a different e-mail, not [email protected] which is a big red flag). Not to mention securing the MtGox account. Hell, zhoutong should've revoked those API keys that day long ago (he even said the hacker could've used them).

[...]
While the initial hacker had the ability to cause this breach it is likely that it was not taken advantage of until many users had access to the sourcecode in a recent leak:

Code:
genjix:~/tmp/bitcoinica_legacy/config/initializers$ cat mtgox_credentials.rb 
if Rails.env.production?
  MtGox.configure do |config|
    config.key = "c02e1a27-5524-449f-ba65-aff9581ddedc"
    config.secret = '83U1ROG++O3vwBqFrxpcdyLIoChpgnowImy1oMVQwBLalaLevZDmWeCPJFTrYW00OQ7XUgG53LsIL2pBZ2PQgA=='
    end
end
Sourcecode download link: http://depositfiles.com/files/2p6zvadzs
[...]

Had anyone heard of this source code leak? This is the first time I'm hearing of it..
legendary
Activity: 1078
Merit: 1003
July 13, 2012, 03:15:02 PM
@DarkEmi @hatshepsut  and all others.
Sorry to put you up front with the hard truth, buth...
Rule #1: Don't invest money you cannot afford to lose.
I am pretty sure iam not the first one that tells you this right?

Blame the victim is never a good argument.


Will you say the same to those who will experience a loss once pirateat40 runs?
hero member
Activity: 812
Merit: 1001
-
July 13, 2012, 03:07:57 PM
@DarkEmi @hatshepsut  and all others.
Sorry to put you up front with the hard truth, buth...
Rule #1: Don't invest money you cannot afford to lose.
I am pretty sure iam not the first one that tells you this right?

Blame the victim is never a good argument.
legendary
Activity: 1372
Merit: 1008
1davout
July 13, 2012, 02:47:25 PM
PS: BRB, all. Making a fresh pot of coffee. Anybody want some?
Count me in baby
sr. member
Activity: 897
Merit: 284
July 13, 2012, 02:43:14 PM
And now everyone imagine that it is year 2020 and 1 BTC worth 1 000 000 USD 1kg of gold.


First we need the americans to realise what a kilogram is. Smiley

Imperial units 4 life!!

 Tongue
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 02:41:42 PM
did anyone else find it ironic that this happened on friday the 13th?  

I did, hence one of my over-the-size-limit Readers Digest Large Print posts. (though at the time I was bringing attention to the time of day [local] that Mt Gox support was posting)

~Bruno~

PS: BRB, all. Making a fresh pot of coffee. Anybody want some?
hero member
Activity: 504
Merit: 500
July 13, 2012, 02:39:11 PM
And now everyone imagine that it is year 2020 and 1 BTC worth 1 000 000 USD 1kg of gold.


First we need the americans to realise what a kilogram is. Smiley
is that some several thousands of grams?  Grin


kidding, in case you arn't sure.
hero member
Activity: 504
Merit: 502
July 13, 2012, 02:37:38 PM
And now everyone imagine that it is year 2020 and 1 BTC worth 1 000 000 USD 1kg of gold.


First we need the americans to realise what a kilogram is. Smiley
hero member
Activity: 812
Merit: 1001
-
July 13, 2012, 02:33:39 PM
And now everyone imagine that it is year 2020 and 1 BTC worth 1 000 000 USD 1kg of gold.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 02:29:46 PM
May I suggest people tuck away their lynch mob mentality for a second and instead try and use some usually a lot more productive rational thought before responding in this thread. Yes the situation is fked up but there's no need to start throwing around various threats of violence.

You all knew there was a counterparty risk involved when you decided to use their service.

(still reading and at this point now)

The only violence I've mentioned is that I may need to hide my fictitious blasting rod from my sister before she finds and lubricates it (I hope) so that she can stick it up my ass for having her go through the embarrassment she encountered at the restaurant, having me spend an hour explaining to her exactly what is going on and offering up proof that the shitload of money I make does come from the selling of smelly old barn wood and not fleecing others in the world via Bitcoin, a word she didn't even know how to spell (seriously).

~Bruno~
hero member
Activity: 761
Merit: 500
Mine Silent, Mine Deep
July 13, 2012, 02:22:05 PM
Welcome back Tihan, you have been missed since your last brief visit to this forum.

It would appear that a lot of misinformation has circulated since the date of my last post. Considering the many inconsistencies, I will assume astute readers here have already discounted the versions of facts presented by the Consultancy.

That is funny because the last time I spoke with a certain Bitcoinica representative (about a month ago) I was told that you were misrepresenting the facts and preventing them from exposing the truth because you were unwilling to nullify their NDA:

The Consultancy members accepted that responsibility on April 24 as operators and General Partners of Bitcoinica LP. There is ample written documentation to confirm this.  

I believe this to be true, but would you care to back up that claim with some references?

There are still a lot of unknowns surrounding recent events but the Consultancy's responsibility for Bitcoinica and its password security is not one of them. The fund will be considering all legal options.

I assume you are considering all legal options for the benefit of Bitcoinica customers?

There's something with Tihan going on, but I am not following that because it's unneeded drama for me - it seems he got fired, although I'm not sure for what.

It appears you got fired. What is your current role with Bitcoinica LP?
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 02:17:09 PM
Remember this:

Quote
To be honest, your age isn't a problem, because the average above-average developer is still not competent to write this sort of software. If you had been doing security and financial software since birth, I might consider putting a bit of trust in the kitty to start.

I'm going to pitch a different take than a few others: Yes, great initiative, please keep trying things and building things, but end this project now. There are no probable outcomes where you do not end up having to explain where thousands of dollars of other people's money went to some angry people. There's also very nontrivial odds of being on the wrong end of armed Federal agents, based on some of the other comments you've made here. This is a horrible, horrible first-project sort of project.

Let me put it this way: Would you be willing to convert the BitCoins in your system into cash, put it in your front window, and post daily pictures of the pile of cash to your Facebook account, set to public visibility? Because that's roughly what you're doing.

+1 to this guy.

Will you quit quoting him, for it makes me start wondering, again, how he got up to speed so quickly on having a command of the English language after reading his follow-up reply.


Quote
Yes, we have. I admit that I didn't make it visible on the site itself. But the system checks every single user every 5 seconds.
We have two metrics: net value and minimum net value. When NV < MNV, all positions are immediately liquidated. When NV < 2MNV, a warning is visible on trading panel. (Future feature: margin call email)
These metrics are completely transparent, showing in different colors to represent health status. Once you give it a try you will know.

Unless they make a Rosetta Stone on Rails I'm not aware of.

~Bruno~
hero member
Activity: 504
Merit: 500
July 13, 2012, 02:13:30 PM
I had no idea at all that the above took place until close to a week after Zhou Tong (no more ZT) started that thread about this recent hack about a month ago, and was approached by Jerry at my favorite restaurant that I no longer frequent as often, one I was closed to having the Albanian owner start accepting Bitcoin, with, "Why did you steal my money?" in front of the regulars of which I've known for years.

~Bruno~

PS: Note the butterfly effect.

That's heavy, bro.. :/


@thread Just to make sure I am following things correctly;

1. Intersango purchased or was purchasing Bitcoinica and agreed to handle returning the old customer funds?
2. Intersango was handed all the account passwords, securely encrypted in a LastPass account?
3. Intersango changed all the old passwords except for the one password that secured all the others?
4. The password for Lastpass just happened to be Bitcoinica's MtGox API key?
legendary
Activity: 2156
Merit: 1072
Crypto is the separation of Power and State.
July 13, 2012, 02:09:42 PM
I LOL'ed when i saw this thread. Like last time and the time before that.

Yep.  I was all



I'm sorry for all involved. I have to say that bitcoin really is the most amazing geek soap opera. If the bitcoin value was backed by drama it would be stratospheric.

I know, right?

Just when I thought nothing could be more entertaining than the epic Pirate threads/flamewars/huge side bets, along comes this.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 01:59:58 PM
Quote
Last bit of advice: Bitcoinica should put all their USD deposits in a real bank account, with real bankers.

I assured my once friend (more like a close acquaintance), let's call him Jerry (his real first name that he goes by), to not worry about any USD he may have tied up in this Bitcoinica cluster-fuckery, for any fiat (I told him dollars) will surely be in some bank. No place else! It never occurred to me that said money would be in some Mt Gox account. Not in a thousand years. And since I'm speaking of timetables, it never occurred me in a million years that a password hack would happen a THIRD time involving Bitcoinica.

Now, you want to hear something really funny? There are people here in Sandwich that believe that I'm somehow involved with all this. Their proof: Joined this forum, of which they honestly believe is the Bitcoin homepage, around the same time as the Tom Williams hack; Currently, I'm the second highest poster on this official Bitcoin website; and, I must have made all my money from ripping off others worldwide with this invention of mine since they are all aware that I was a broke dick only two short years ago when my dad, a truly broke dick, died.

Here's the kicker: 95% of said people above who believe such nonsense don't even own or know how to operate a computer. Not even Jerry, for he get's his information from his daughter (then passes on what he learns to the others, daily), who works at the bank I bank at and, with his instructions to her, by recommendations by me, indirectly, invest a percentage of his recent financial gain into Bitcoin, choosing Bitcoinica as his most locally choice at the time.

I had no idea at all that the above took place until close to a week after Zhou Tong (no more ZT) started that thread about this recent hack about a month ago, and was approached by Jerry at my favorite restaurant that I no longer frequent as often, one I was closed to having the Albanian owner start accepting Bitcoin, with, "Why did you steal my money?" in front of the regulars of which I've known for years.

So there you have it. A guy who loves Bitcoin, only has $1,000 tied up in the currency as an investment (bought cheap enough); 0 disposable coins at the moment, but will get more so that I can play with the big boys; a $100 a month smartphone contract; three people who have ordered custom leather products from my brother-in-law but have not paid for them, keeping that information from him and the community until now, but WILL NOT mention names (Martin was paid by me via dollars, so he's not out any money); and now have the EPA on my ass because of this randomly linked article (you're smart enough to put the pieces together), turned in by one of my once close acquaintances (guess what the daily fine is that I'm looking at).

That said, they don't make a font size big enough to express what the hell I'm going through because I simply spread the good word about Bitcoin, then had it thrown back in my face. That only leaves one main orifice left, but fortunately for me, a couple family members are eyeballing that hole now, wondering why the hell I'm still monkeying around with this Bitcoin thingy, for they're now getting their uninformed information from...wait for it...our favorite restaurant's patron saints, owner and staff. I may have to hide my vintage blasting rod and Jergens, for I have this weird feeling... (humor is how I maintain my sanity--no meds, and still eat and sleep well).

Thanks for listening, all. Bless. (though not an active believer, but do express the spirit of the word)

~Bruno~

PS: Note the butterfly effect.
hero member
Activity: 761
Merit: 500
Mine Silent, Mine Deep
July 13, 2012, 01:59:48 PM
As a Bitconica customer:

  • I had no positions, no leverage, and was using it as an interest bearing savings account.

And now *THIS* happens?

When will you people learn that there is ONLY ONE VIABLE TYPE OF BTC SAVING ACCOUNT --> heavily encrypted and backed up bitcoin wallet/brainwallet/paperwallet in a secure place ?

How about NOW? (Admittedly too late...)
Pages:
Jump to: