Pages:
Author

Topic: Mt.Gox: No SQL injection happened, switch to SHA-512, offline until 8:00 am GMT (Read 5424 times)

newbie
Activity: 21
Merit: 0
Quote
Not true. I had a buy order in around $12/btc that triggered on the way down and I was able to withdraw my BTC before the site shut down. I'd like to know how they plan to roll THAT back.

The way they'll have to deal with this is not roll back the buy-side of a transaction if it was withdrawn.  Roll back the sell-side and cover the difference.  I.e., if market price is 17 and you bought at 12, MTGOX will have to refund the BTC to the rolled-back seller from the MtGox stash or, if stash is too small, add $5 per BTC to your $12 per and buy them back on the open market then refund to seller.

No doubt some buyers withdrew, but if it isn't a huge percentage then MtGox should be fine to cover the loss from the fees its collected so far.  But we'll see what actually happens...
kjj
legendary
Activity: 1302
Merit: 1026
The excuse given was to blame the auditor.  And for privacy reasons, they won't name the auditor.

This doesn't make any sense at all.  What use is an audit performed by unnamed entities?  It's the credentials of the auditor which give credence to the audit they perform, is it not?

What use is it for an auditor to have password hashes?

No use whatsoever.

However, they are easy to overlook if someone asks you to make a quick dump of the database to give to the auditors.  Bet they'll have a formal policy and procedure in place before the next audit...
sr. member
Activity: 322
Merit: 252

Not true. I had a buy order in around $12/btc that triggered on the way down and I was able to withdraw my BTC before the site shut down. I'd like to know how they plan to roll THAT back.

Nice!  Stolen coin bonus!
legendary
Activity: 1022
Merit: 1001
May not have been an SQL injection, but it was sure as hell a Hot Beef Injection!!!

Ewwwwww!  Grin
sr. member
Activity: 282
Merit: 250
100-200 BTC + ~1000 USD stolen.  Doesn't seem too bad...

So.... could they, or someone, explain about the 200,000 -400,000 Bitcoins that was sold off, and drove the price down to 1 cent???

As far as I have gathered those transactions were internal to Mt. Gox and were never paid out. They weren't actual bitcoin transactions.

Not true. I had a buy order in around $12/btc that triggered on the way down and I was able to withdraw my BTC before the site shut down. I'd like to know how they plan to roll THAT back.
sr. member
Activity: 284
Merit: 250
May not have been an SQL injection, but it was sure as hell a Hot Beef Injection!!!

zing
newbie
Activity: 56
Merit: 0
is there a way to find out your trade number ? maybe from trade notification email or something ?

Quote
Once Mt.Gox is back online,  trades  218869~222470 will be reverted.

yes THIS ^^^

is there a database of trades and numbers?
sr. member
Activity: 322
Merit: 252
May not have been an SQL injection, but it was sure as hell a Hot Beef Injection!!!
hero member
Activity: 575
Merit: 500
The North Remembers
100-200 BTC + ~1000 USD stolen.  Doesn't seem too bad...

So.... could they, or someone, explain about the 200,000 -400,000 Bitcoins that was sold off, and drove the price down to 1 cent???

As far as I have gathered those transactions were internal to Mt. Gox and were never paid out. They weren't actual bitcoin transactions.
newbie
Activity: 27
Merit: 0
The excuse given was to blame the auditor.  And for privacy reasons, they won't name the auditor.

This doesn't make any sense at all.  What use is an audit performed by unnamed entities?  It's the credentials of the auditor which give credence to the audit they perform, is it not?




What use is it for an auditor to have password hashes?
full member
Activity: 209
Merit: 100
The excuse given was to blame the auditor.  And for privacy reasons, they won't name the auditor.

This doesn't make any sense at all.  What use is an audit performed by unnamed entities?  It's the credentials of the auditor which give credence to the audit they perform, is it not?

full member
Activity: 154
Merit: 100
is there a way to find out your trade number ? maybe from trade notification email or something ?

Quote
Once Mt.Gox is back online,  trades  218869~222470 will be reverted.
newbie
Activity: 42
Merit: 0
full member
Activity: 143
Merit: 100
100-200 BTC + ~1000 USD stolen.  Doesn't seem too bad...

So.... could they, or someone, explain about the 200,000 -400,000 Bitcoins that was sold off, and drove the price down to 1 cent???
member
Activity: 113
Merit: 10
100-200 BTC + ~1000 USD stolen.  Doesn't seem too bad...

I don't believe this, unfortunately Sad
newbie
Activity: 42
Merit: 0
Yeah, right.  The only crackable stuff they got were some idle accounts yet they managed to drive the price to 0.01$ and steal a bucketload of BTC.

And... you used unsalted md5?  Really?  Oh but that was two months ago so it's ok? Undecided Fuck me.  
legendary
Activity: 1218
Merit: 1000
For me it was Kevin Mitnick disguised as janitor...
full member
Activity: 209
Merit: 100
If the auditor was attacked by a hacker, how was it that the hacker knew that the auditor's machine was even bitcoin-related?  Something here doesn't pass the sniff test.

This screams 'inside job'.

legendary
Activity: 1218
Merit: 1000
Quote
It appears that someone who performs audits on our system and had read-only access to our database had their computer compromised.

Someone needs to audits the one who audits...  Roll Eyes
hero member
Activity: 840
Merit: 1000
100-200 BTC + ~1000 USD stolen.  Doesn't seem too bad...
Pages:
Jump to: