Addressing Transaction Malleability
mtgox.com
mtgox.com
It is not even clear that the malleability problem is solvable. Besides the problem that there is innumerable ways to transform a transaction to give it a different hash without affecting scriptSig validity, it is simply unknown whether it is possible to algebraically transform an elliptic curve signature without invalidating it. If so, then no matter what you do to cover up the other holes, that gaping one is left open.
Transactions are malleable. Deal with it. If a transaction is observed on the network that has the same input outpoints and the same outputs, it is the same transaction, and mtgox should treat it as such. This is a simple check to do, and trivial to automate.
And instead of reporting only the hash to the user, they should record, report, and track the transaction itself. You should be able to go to your withdraws and see the actual transaction, including which inputs were used, and what the change address is. You can then go to any block chain service and verify for yourself if/when those same outpoints are spent in a modified transaction.
This is MtGox's problem, not bitcoin's.
https://bitcointalk.org/index.php?topic=8392.msg122410#msg12...
Mt. Gox could solve the issue without a change to the Bitcoin protocol by tracking the entire transaction and not just the hash.
But instead of fixing their own problem they make it sound like Bitcoin itself is broken.
Why would they do this? Cui bono?
If Mt. Gox has been scammed out of a large amount of Bitcoin, they may not own enough to fill withdrawal requests. If this is true, then a steep decline in the price of Bitcoin could allow them to cover the gap.
This is ass covering.
If it's a 'bug in the bitcoin protocol' it isn't their fault.
This is surprising.
So a guy who calls himself "Magical Tux" and describes himself as "PHP Developer working on some weird stuff, like a mail server (POP3/IMAP4/SMTP) written in PHP" was not able to build a reliable worldwide exchange?
Get over yourself, MagicalTux is not alone any more, and they're working hard on being a reliable exchange, the most reliable one out there as far as I am aware.
For one, one could use social networking site, even a relatively unknown one, without much to lose. It's not like people wired $1000 dollars to Facebook when it started.
So, yes, I could trust a random guy with some bs social site. With my money? Not so much.
>Get over yourself, MagicalTux is not alone any more, and they're working hard on being a reliable exchange, the most reliable one out there as far as I am aware.
If true, that just speaks very poorly of the state of bitcoin exchanges:
"""Or let's take that historic hack of Mt. Gox, which temporarily dropped the exchange rate to $0.01 per BTC, and involved a large Bitcoin heist. What they didn't tell you, was that several vulnerabilities in the Mt. Gox website and API were reported a while before the hack, and that the Mt. Gox staff more or less waved them away, completely ignoring their severity. This included MySQL injection vulnerabilities, just to put things into perspective a little. One of these vulnerabilities was almost certainly the attack vector that was used for the heist."""
http://cryto.net/~joepie91/blog/2014/02/10/why-mtgox-is-full...
(And of course now we have this new fiasco).
But his name is Mark Karpeles, its plastered all over the website, registration, and even his twitter account.
Please note that I'm not asserting anything about the qualities of the programmers of MtGox or the code quality running the exchange. It might quite well be shitty and bug-ridden, but that quality is totally unrelated to PHP.
No, I suggest that some random web developer, with no experience in finances, and without a big financial player behind him, should not really be trusted with people's hard earned money.
Counter to what you say, I could not care less if he did this in Scala or Racket instead of PHP -- I merely quoted the one-liner he gives about himself. He could have written Haskell in there and I would still have the same objections:
Who is he? What has he done before in the financial world? Why should people trust his skills at setting up a money exchange?
Note that, in my argument, I don't even care if he's a good programmer or not. He might outdo Rick Hickey and Simon Peyton Jones put together. What I'm asking is: why should we trust him? Ability to set up a good and safe money exchange AND not be a crook != ability to program.
Now you're making a different and more nuanced argument which boils down to "why should we trust him, even if he's competent." That's a reasonable question to ask - but the question of trust is a fundamentally different question from the question of competence. I might trust someone incompetent to be well-meaning and someone competent and capable might be completely untrustworthy. It might even be true that he's incapable and untrustworthy, but still - that's not the argument you made.
The fundamental problem with the older bitcoin exchanges is that they all started out when nobody in the financial world even cared about bitcoin: No technical knowledge, no investors, ... so basically trust had to be earned from 0 on. One point speaking for Mt.Gox is that they are still in business while other exchanges folded. Somebody seems to trust them.
Ever noticed how those are entirely your words?
I merely pointed out at his experience -- not picked on the particular language he uses. In fact I've supported PHP in other HN threads.
The language was only mentioned because HE used it in his bio blurb.
What I wanted to point in that blurb was: random web developer (ie. not a person with known expertise in financial software and money exchanges) and a silly nickname (ie. not really the short of mature behavior that inspires confidence in a major venture such as a financial service).
Contrary to the purely theoritical notion that such a nickname is "totally unrelated to competence" (which might be perfectly reasonable in theory), I'd say that in the real world it speaks volumes about maturity and self-perception. If my banker was calling himself "Crazy-Ass Joe" or "Mr Fancypants" I'd be similarly worried.
>One point speaking for Mt.Gox is that they are still in business while other exchanges folded. Somebody seems to trust them.
Well, to paraphrase P. T. Barnum, there is one person trusting them born every minute.
Clearly MtGox overlooked this and thought it was the obvious way to track a transaction.
Given that they're malleable, what use-case do they have now?
Now, any transaction coming from that temporary address (which can also be told to the user as "expect the money to come from this address", which might be separately useful for purposes other than transaction proofing) can be considered to be the transaction in question: the computed hash of the transaction is irrelevant.
Of course, I should not be able to solve this problem after two minutes of thinking about it; so: anyone mind teaching me what I'm missing? I can't imagine I could come up with a solution this simple so quickly to a problem that is apparently so well known and so problematic to such an established player in this space ;P.
An attacker can rely on this (the transaction ID from their perspective never confirmed) and ask them to resend the funds. The attacker doubles their money and suddenly Gox has outputs they think aren't spent, but really have been in a transaction ID they don't know is their own. When they roll these "unspent" outputs into new transactions they fail to broadcast, and then we are in the situation we are in today with a number of backlogged transactions.
Fortunately for them if any money has been stolen using this, they probably have the ID of the person in question.
Your system would work as a hack, but for somebody as big as Gox they would have a significant impact on the blockchain size for no good reason.
MtGox made a very bad decision in its choice of wording in this press release. It shouldn't have framed this as a "design flaw." The only reason this happened was because of MtGox's custom software. No one else was affected. By definition, that's not a design flaw.
Of course that's much harder, both in terms of algorithmic and code complexity, than just remembering a hash.
And, it doesn't require global agreement to deploy such a workaround.
http://news.ycombinator.com/item?id=6926472
http://news.ycombinator.com/item?id=7195024
http://i.imgur.com/5TAwopR.png
There are few times in my adult life I've felt like crying actual tears, but this is one of them.
Four times since that first comment, the bitcoin price has recovered to $1,000, then dipped back down again. Four times I didn't sell.
The silver lining is that Gox's explanation is correct on a technical level. There is every reason to believe this explanation to be true. This isn't (just) me being hopeful; this is because if you investigate whether it's true, you'll find out it is true.) For further details see https://news.ycombinator.com/item?id=7203544
Since I've only been able to withdraw 3.4 bitcoin, I'm at the mercy of Gox. It's entirely possible that I'll wind up with less than $1,000, from $11,000. An expensive life lesson, but at least it's recoverable.
EDIT: I apologize if this comment didn't contribute anything. I sometimes use HN for moral support. I'm just shocked at what's happened.
EDIT2: This surely shouldn't be the top comment... it's important to get information out to people in a crisis situation like this. This was just me being sad and gathering information from those more experienced. Thank you though.
So there's two paths from here: Either this is the experience that hardens you and makes you stop thinking "oh shit, I just lost two months' salary in six hours" (this happens all the time when you have a significant amount invested in a volatile asset), or you realize that things won't change and you can't live with the risk of losing your investment.
If you choose the latter option, you will also need to stop kicking yourself if three years from now, the asset you sold has trippled in value. In fact, you should stop kicking yourself right now. The problem here is your emotional reaction, not Bitcoin's volatility. I know how you feel; I've been up and down $30,000 this year over the course of a few weeks in the stock market, but second-guessing yourself only serves to waste your attention. Make a plan, know the consequences and stick to it.
But in general terms: Don't invest more money than you can stand to lose. Have an investment thesis. As long as this thesis holds, don't sell and don't even check the value of the asset you are holding. Don't invest in volatile assets with money that you will need in the near future (within five years or so).
Forget the price at which you bought your asset. Always keeping this in mind leaves you horrendously exposed to the "sunk cost fallacy". Ask yourself instead: If I had nothing invested, would I buy at this price? If the answer is no, that is a strong indication that you should just take the loss, or even sell if the price has increased.
You could also have a plan beforehand, i.e. sell if it's down more than 30% or if it's up more than 60%. And if you make such a plan, you need to stick to it.
Taking a 20% loss on an asset like Bitcoin, which has appreciated >10,000% in a few years is really not a big deal. This is the king of volatile assets. If you are consciously investing in such an asset, you should be able to shrug at either a 50% loss or a 100% gain. Most people would (perhaps rightly) call you crazy for keeping a significant part of your investment portfolio in such an asset.
I think you're too hung up on the fact that you used to have $X in BTC and now you have $Y. Instead, just start from the premise that you have $Y. Your goal isn't to recover your old $X, it is to grow your $Y as much as possible.
What is currently the best investment you see available to you? Is it Bitcoin, or any other cryptocurrency? Are you better off with cash or a low risk CD? Maybe a mutual or index fund, or is there a country whose debt is currently going for a good price?
Once you know where you're going, it's a lot easier to get there. If you think Bitcoin has the most potential at a level of risk you're willing to accept, leave your money there. If you think something else has a better combination of risk and reward, move your money there.
(Essentially: when you are behind you believe that you can quit while you're ahead, but when you are ahead you feel confident and prefer to press your luck)
In general, if you are investing some place that makes you feel anxious or emotional about the consequences, it's far too volatile and you should cut your investment down.
The best way to escape from this situation is to make an exact plan and stick to it. Would you rather walk away now, or risk a worse loss later? Then, at what value will you cash out? I understand you are attached to your initial investment cost, but really 100% is the valuation now, since the rest is sunk costs. Decide how you like, but firmly - take the emotion out of your decision making.
Else you'll be stuck in an infinite loop of second guessing yourself and what-ifs that do not contribute to either your financial stability or your sanity.
If the plan sucked, you can revisit it on a later round, and if not completely sure about your plan, you can do mini runs of it to test, but the important part is to stick to deadlines/commitments so the anguish stops.
Ultimate Goal: Produce 300k+ from 7k. Insanely unlikely, I know. But if things unfold like I'm hoping, this will nearly close out my mortgage; a life-changing event for a family man such as myself.
Disclaimer: Don't play with money you cannot afford to lose. I have 7k that I can burn on crypto. I won't be happy to lose it all suddenly, but it won't put me in the poor house or ruin my daughter's college fund. My true family funds are in e-trade.com collecting dividends 'n such.
Overriding-rule: Never be 100% fiat or 100% coins. Be ready to make a buy or sell at any moment.
Back in Nov 2013 I put in 1k and the market promptly crashed afterwards so I have 26 litecoins(at $40 each) I can't sell for a long while. I knew my luck from experience on e-trade, so this didn't phase me - it always starts this way. The next 1k I sent into crypto-coin world is at btc-e.com where I day-trade. At first I bought and sold quickly, simply making 4 to 5 dollars. Just getting use to how btc-e.com works and its transaction speed. Then I started to make bigger and more long-term bets as I observed the big swings. It appeared to me after a few months of watching that Litecoin biggest swings are between $18 - $29. So when MtGox had its recent issues and "Russia banned bitcoin" pulled the price down, I bought in. I'll make about $600 when Litecoin reaches $29 again. But on the other hand, if the price of bitcoin goes below $500, I will put in 1k for the 3rd time. If bitcoin falls below to single digit numbers[1], then I'll buy 3k more. This brings me to my limit of having 7k in the crypto-coin world. I will now sit back and wait.
If we ever see $1,000/BTC after the events I describe above, I will sell everything I have - producing at least 300k. I'm done. Or, BTC will simply fall into oblivion and I've lost 7k. I'm "fine" with that, but I'll always make sure to have copies of my private-keys for the rest of my life... just in case.
1. http://www.businessinsider.com/williams-bitcoin-meltdown-10-... ...very unlikely, but if it happens I'll have USD waiting.
That's not a plan.
Well, whatever you want to call it "plan"/"strategy"/"hope"/"insane dreaming". About this time last year, if I executed on my "plan" I'd have reached my goal in Nov 2013. Bottom line is I think bitcoin still has a disaster or 2 or 3 ahead of it that'll tank the price; only to recover a month or 2 later. With all this MtGox drama happening + "Russia banning bitcoin", I'm poised to move. Also, this list[1] was front-page of HN at one time. If #9 actually happens, combined with a disaster that makes the price tank - say, MtGox shutting down & "USA bans Bitcoin!!", then I'd be set.
I know my "plan" depends on 2 unlikely events. Probably won't happen, but this is bitcoin we're talking about. Nobody knows what will happen yet. This is my "plan" based on the craziness I see of bitcoin. Nothing really that special; buy low & sell high. Call me crazy but I say coins still has a few huge swings coming up in 2014. MtGox is already causing one right now. Even if these extremes don't happen, I got 1k that I'm day trading with under smaller swings that I'll at least earn back the 2k I've put in so far if not more.
1. http://lightspeedindia.wordpress.com/2014/01/13/bitcoin-2014...
Bonus: Reddit is doing a good job of getting people all riled up to cause these big swings... http://www.reddit.com/r/Bitcoin/comments/1xitx4/im_giving_1_...
You are being illogical about your investment. Go back to the moment you bought the Bitcoin. You apparently thought they were worth $1000 per Bitcoin at that moment, there is nothing wrong with that.
That you invested in Bitcoin means you expected them to rise, do you remember how much you expected them to rise? In what timespan? Does the price going down for now affect that estimation? In what way? Why would you sell your Bitcoin?
There's answers to all those questions that go in every direction, but they lie in the future, so the only thing you can do is make a reasonable prediction, and hope it was realistic enough.
Some people think Bitcoin will go to $10k, some people think Bitcoin will prove useless and die out. Decide in which camp you are.
About MtGox: If MtGox would somehow mess up bad enough that your money/btc is not safe there, that would hit the BTC so bad that its value would at least half, if not more, at every exchange. Trying to withdraw your bitcoin now is madness, you're just risking getting it stuck.
Be careful with your panicking. I myself am too afraid to go long on Bitcoin, if I had I'd have over 10x my original investment now, instead I just speculate and profit from panic sellers, it's fun and pretty low risk. I sell whenever Bitcoin is stable, and buy whenever there's panic.
I don't believe in Bitcoin being worth $1000 right now, but I do believe that the technology and ideas are solid enough, that whenever there's a panic the price will recuperate fairly quickly as people realize not actually all that much changed.
http://www.shareprice.co.uk/pages/risk-warning-trading : "You may not necessarily get back any of the amount you invested."
Secondly if you can't stomach the swings in Bitcoin, it's not the speculatory investment for you. You need to have a plan and stick to it. Buy and hold for 5 years is a reasonable plan.
I'm sorry if this isn't sympathetic, but you need to learn from your mistake.
The crypto also triggers a geeky faith in technology. Because the crypto is sound, it's just the way it's being used is problematic. And the institutions around it are very flaky, but geeks hate institutional politics and dream of eliminating it by technological fiat.
However, it must have really messed up their internal accounting. The problem isn't that they don't have the money - the problem is that they don't know which of the outputs that they own have been used, and which haven't. They have to fix the bug, parse the blockchain, consolidate that with their internal records of ownership, figure out which pending withdrawals have been fulfilled, which haven't, which have been paid twice...
There's a lot of things to do there, and they all need to be fixed before they can tell if a new withdrawal is legit.
They didn't address that in their statement. They may not even know themselves yet how much they were taken for. With the high number of transactions that were failing in the days leading up to the withdrawal halt it's pretty clear someone was exploiting this to double withdraw something was almost certainly taken the question is how much and can they recover.
http://www.cryptocoinsnews.com/2014/02/10/mt-gox-blames-bitc...
Excerpt:
<gmaxwell> The Gox press release seems a little ‘spun’ to me. They portray characteristics of the Bitcoin system well known since at least 2011 (which even have their own wiki page ) as something new.
These characteristics are annoying but don’t inhibit basic operation. They are slowly being fixed – but fixing them completely will likely take years as they require changing all wallet software. Correctly-written wallet software can cope with the consequences, and I cannot understand why they would gate their withdraws on external changes.
It sounds like they need to just watch for duplicate transactions as the protocol is built to prevent those.
I don't really see a use for tx ids if they keep the spec as-is then or am I missing something?
- Given $100k or however much it costs to 1-2 top quality devs to write a new exchange from the ground up. Very basic functionality, focus on efficiency and reliability.
- Take MtGox.com offline for a few hours
- Port all user accounts over to the new system
- Launch MtGox v2.
It blows my mind the total level of incompetence, wasted opportunity and lack of common sense MtGox have shown. Literally sitting on a money making factory and they didn't get their shit together for such a long period of time.
They do not deserve all the forgivness the market gives them, they are past the stage of a "bad apple" now and need to die for Bitcoin to move forwards.
http://www.reddit.com/r/Bitcoin/comments/1x93tf/some_irc_cha...
This information is very public, to the point where people have collected detailed information about the bad transactions going out and noting that they also agree with that story.
http://skanner.net/MtGox/mtgox_tx.php
Why has nobody else has issues like this? Well they have, talk to Coinbase, they've had their own share of problems with delayed transactions.
If you follow the article you'll find that some of the core bitcoin team is confirming the flaw.
But maybe reddit is right. Clearly.
moar credibility than <randomguy15> on any irc/dark/use-net I can think of.
Have a read through: https://bitcointalk.org/index.php?topic=458076.0
Also, why are you comparing IRC to dark and use-net, they're all completely different things?
Well, I don't see how trusting some random guy that started an "exchange" operating in his basement with your money is any wiser.
If that is true, it probably affects all alt-coins since they all fork back to btc.
However I bet it's just a matter of getting more confirms since attackers could be using fraudulent nodes to try to fool the network.
Yes, you should have kept reading:
> Note that this will also affect any other crypto-currency using the same transaction scheme as Bitcoin.
I say this as someone who personally had BTC withdrawals fail 3 months ago when they explained to me on IRC that they couldn't find a bunch of transactions with the TX ids they were looking for and had to rebroadcast them.
The one thing that makes me suspect otherwise is that they are holding a lot of BTC instead of a lot of cash.