Mt. Gox Has Been Hacked by People Trying to Find Out What Happened?
dzoba.com
dzoba.com
EDIT: Listening to snippets from the rest of the recording, it seems that Mizuho is explaining that they want to cancel Mt Gox's accounts with the bank. Karpeles seems to be protesting and asking why the accounts are being shut down. The guy from Mizuho explains (at 28:00 for Japanese speakers out there) that it's a combination of a lot of factors, including recent technical issues, which make the bank uncomfortable dealing with Mt Gox. Karpeles also mentions following the orders of the Financial Services Agency (金融庁)
EDIT2: 15:00~16:10: Mizuho guy explains that the Mt Gox bank accounts will have to be shut down eventually. Karpeles says that he understands that position, but he thinks that the bank has been rude about trying to force the closure, and would appreciate a more cooperative approach.
EDIT3: 18:00~19:00: An awkward discussion of Karpeles' Japanese. The Mizuho person seems to be offended by Karpeles' rude Japanese, which frequently lacks the correct honorifics that would be expected in a business setting. A woman (I think she's on the Gox team?) explains that Karpeles' first language is French and that he means no offense.
I can work on a fuller description of the call, but just wanted to get a quick verification of its authenticity out there, along with some snippets of the contents.
http://www.reddit.com/r/Bitcoin/comments/1zepgt/mark_apparen...
(I can't listen to the recording right now and wouldn't get much out of it even if I could, since I can't hear well enough. :-/)
> Frequently used by men. It can be seen as rude depending on the context. Establishes a sense of masculinity. Emphasizes one's own status when used with peers and with those who are younger or who have less status. Among close friends or family, its use is a sign of familiarity rather than of masculinity or of superiority. It was used by both genders until the late Edo period and still is in some dialects.
https://en.wikipedia.org/wiki/Japanese_pronouns#List_of_Japa...
The closest thing I could think would be to conduct a business meeting in which you only describe your actions and refer to yourself in the third person, and then only as "Big Mark".
"Big Mark understands your position but thinks you're being a bit rude about all of this. Big Mark thinks we should cooperate more" etc, etc
Why is it that way? I don't know the history, but the short answer is, because that's the way it is used.
On the other hand, I'd say that the bank person has enough reasons besides the honorifics to be really angry at the guy. The info posted indicates that they want to get rid of him and given that they cite technical difficulties, it might well be possible that their tech team already suspected the "non-banking-grade" software quality we are now hearing about.
Does it require concentration for a native to avoid faux-pas in a discussion? Can it become much more difficult depending on your social origins (i.e. how effective is it as a social discriminant)? I'm wondering how much time and thought is typically spent on those matters, to the detriment of actually thinking and communicating information.
(I guess this post is extremely rude from a japanese PoV, but I'd genuinely like to understand all this better, and I'm sure typical HN readers can understand this approach)
Complicated grammar in general generally comes from historical traces: there often is a literature associated to it, nuances that express best the ambiguities of life and what you might want to hide from. Case in point: relationship statuses, and the many way to say ‘mmh friend’.
When associated to people via honorifics, these are things people care deeply about, both because they came at what seem a cost (PhDs are hard, promotions longed for, and Noblesse Oblige) and, after being repeated every time one was addressed to, became a core part of your identity. The fact that they are flattering makes it even more crucial. Think of parents who insist on being called ‘Mum’ and ‘Dad’: of course you know what their first names are, but using them can be seen as a lack of love, or respect for their authority, or consideration for the spectacular sacrifice they made. It remains hard to explain why on the spot: it just hurts, and comes off as defiant.
There is finally (and that is certainly true in Japanese high society) an attachement to class & country, a way to protect what was once precious and unique and unpregnable. That actually takes the form of genuine and sincere preference for the formal and appropriate: I would be offended if someone told ‘I love opera, it's so-o fricking cool!’ Yes, it is, and I consider the Opera to be a very buoyant and accessible art form, like Hollywood; but it still comes with a decorum that became part of my enjoyment of it.
Japanese, especially business people, are confronted to foreigners enough to understand that doesn't come naturally. Kerpeles however does more than ignore that: even in French (probably the second most culture riddled with grammatical antique quirks -- and I'd know, I am French and love those) he comes off as defiant, irrespectful, and likely to have willingly commited what some accuse him off. That’s not ignorance from his part, but open lack of respect for institutions. Those could be modernised and improve, but they still serve a purpose. Like anyone who's worked at university, I don’t call ‘doctor’ anyone with a PhD, but I still think it’s the most compelling experience someone can go through and I’d understand if, like in Italy and Germany, that remains part of everyday interactions.
As explained below, Karpeles referred to himself as "ore". "Ore" is mostly used by men, and carries a boastful tone. Moreover, pronouns aren't necessary to make grammatical sentences, e.g. "I went to the bank" = "Ginko ni ikimashita" = "[Bank] [to] [did go]".
The only function of the word "ore" is to emphasize your own high status relative to whomever you're speaking to. In a bar, after a couple of drinks, among equals, it's quite typical for all the men (usually not women) to use "ore". But in a formal business meeting --- this is known to be an absolute no-no by anyone who has formally learned even a small amount of Japanese.
A fairly close analogy in English would be to randomly sprinkle the word "fuck" in your speech.
I was once speaking to a good friend of mine here, in English.
"Do you want to go out for yakitori?"
"Go fuck yourself!"
"... switches to Japanese Have I recently done anything very major to offend you?"
"No, of course not."
"Oh, OK, I was worried. So that phrase, that's something you would only say under extreme distress when you had maximal desire to offend me, or I suppose you could use it jokingly between friends, but neither you nor I generally talk that way."
"I learned it from a movie. I thought it meant "No.""
"You might want to not repeat it ever again."
Along the same lines, I was getting a shave from a super hospitable barber last November in Gifu and the topic of conversation in very broken English (from him) and correspondingly broken Japanese (from me) was basically whether I had seen all of his favorite American movies. We were chatting and laughing quite a lot. When the time came for him to shave around the Adam's apple, he pointed right at my face and said: "You! Shut up!" It was so funny: He had obviously picked that up from a movie, but it took everything in me not to feel a little hurt, even though I knew he didn't mean to say what he said with that sort of edge. I can only imagine how many times I've done something similar in reverse. :-)
I'm probably forgetting about some leaks, and who knows how many security breaches were never discovered. The internet is not a safe place.
Sometimes I wish data privacy laws were stricter, but it appears that not even financial services laws are sufficiently strict, as just demonstrated here.
I think the laws and awareness are good enough atm, but no laws and probably no amount of knowledge or auditing will stop a data leak from indadvertedly occurring.
In summary I have spent at least five to ten minutes (and likely more) on spam brought to me by Dropbox without any compensation. How about a fixed payout of, say, 100€ per leaked detail (username, password, email etc.), payable immediately to each customer? At least companies with bad security would be out-of-business soon.
I have stopped using Dropbox shortly after receiving the first such spam email, so I cannot comment on more recent leaks.
https://blog.dropbox.com/2012/07/security-update-new-feature...
It's surprising to me that my email address took 2 years to be used, but who knows.
Right now in ##mtgox-chat someone named nanashi____ claims to be speaking for a group of hackers who have gotten into Mt Gox in an attempt to figure out what happened. Nanashi says they have a DB dump and are looking at what to do with it. Nanashi gave these links:
A conversation in Japanese with Karpeles and a Banker (http://picosong.com/Y7di/) Some Mt Gox Code (http://pastebin.com/W8B3CGiN)
Nanashi also posted personal information on those employed by Mt Gox including phone numbers and addresses. Nanashi says the group plans on releasing more info. Nanashi also said they group plans on not releasing the huge store of passport scans they found… Hopefully this group has the public’s best interests at heart.
I'm impressed by how hard MtGox is fucking up.
But I totally understand why people did supply it.
They supplied it because:
1) They've been trained to
2) For a while MtGox was actually the most well-known (and therefore trusted) of the exchanges
On #1, every financial institution in the world goes through some form of KYC (Know Your Customer) anti-laundering process that involves identity verification. And people are so used to doing this when signing up to financial accounts that they failed to comprehend that MtGox (and other exchanges) is not a financial institution being regulated by the same safeguards for their data.
On #2, even if you accepted that they were not a financial institution almost all of the bitcoin exchanges are asking for verification. And the larger more well-known exchanges are viewed as "least risky". It's a herd-like mentality, if these thousands of others did it, it must be safe.
I never supplied the info, to this or other exchanges, but I totally see why excited people who feared missing out as the price rose were willing to do so.
After some back and forth with them I somehat angrily provided ID and got my money returned. It later turned out that they had either been dishonest or incompetent in their argument for providing ID, and I got them to promise me that they had deleted any and all ID docs I sent them, specifically because of scenarios like this one.
Well, I hope they were telling the truth.
Maybe this can serve as a warning that the tedious processes used by banks and other institutions handling "serious" money can't just be disrupted away.
Here is the link you added to the IRC transcript:
"Nanashi" (japanese: Anonymous) claims to be in Serbia, but posting on behalf of a Russian group.
Clearly not designed for any sort of automated testing, which should be the first damn thing you do when there's any sort of money involved. Hell, even when there isn't money involved.
We'd already guessed that last bit, given the previous mentions of them having no testing/staging/QA environment.
Although contrary to popular belief Gox was never a Magic exchange, they were a Bitcoin startup at a time when Bitcoin was not much more than internet lols and pizza deliveries. The first thing you do when hacking together a stupid exchange for a joke e-currency isn't writing unit tests. You just write the code and blast it up on a domain you had lying around for a different project.
Cue runaway success, a company sale or two, scaling issues with complicated technology and not much precedent legal or otherwise, and this is what you get.
There is nothing at all surprising about this code. And it seems Gox's problems were much more deeply rooted than the subjective non-compliance of their code with "best practices".
The Wayback Machine disagrees.
http://web.archive.org/web/20070701000000*/http://mtgox.com
Whether it was open as one is unclear, but that was the obvious intent here.
Also, remember that the current owners aren't the original owners. This code is wrong in design but new in attempted style, made or majorly updated within the past year or two (based on the language features used).
As soon as you write anything where a bug causes money to change hands, even on a laugh, you write some tests.
Epicaricacy. because you're speaking english.
The leaked code seems to just be an internal API for twiddling wallets. There doesn't seem to be any logic here for either the txid conflict retry bits or the hot/cold transfer bits.
All the rules of traditional stock market are designed to prevent scaring of gamers so they won't leave casino. Bitcoin doesn't care about faint hearted gamers.
I don't mind hackers doing what they must because they can. I consider them force for good when they get into rich and poweful peoples drawers and publish things. It's a reminder that no matter how rich you are and how many laws you have bought you are never outside of public scrutiny.
$bean->Coins = (int)round($info['balance'] * 100000000);
Really? Currency as a float and rounding? Just so that he can later: $client->sendToAddress($addr, $bean->Coins / 100000000);
I'm ready to believe in any error "due to a bug" they claim now.It is better to represent as integers or fixed-precision numbers. That way, you are dealing with exact quantities.
an infinite number of them in fact
That said, yes, floats are a bad idea for financial arithmetic.
x = 0.1 #=> 0.1 10.times { x+=0.1 } #=> 10 x #=> 1.0999999999999999
-> (for/sum ([_ (in-range 10)]) (/ 1 10))
1
Yeah, I know, I'm cheating - `(/ 1 10)` returns a rational? which is not flonum?. Using `0.1` makes it inexact like it should be: -> (for/sum ([_ (in-range 10)]) 0.1)
0.9999999999999999 (/ 10 17)
=> 10/17
(+ (/ 10 17) (/ 4 9))
=> 158/153
=]In practice that means you can't be sure if `1/1000000` is higher or lower than the value you expect it to be. (to be pedantic, yes you can, because it's well defined, but it can spoil your calculations) When you deal with money, you want the result to be always precise.
(even controlling inputs/outputs is not enough, since internally they sometimes split the values into 40%/60% for transfers)
Or you just stick to ints (or whatever type has unlimited integer range in a given language). Simple solution here is safer than the clever one. Especially if you're sometimes confused about the types and write `round(mt_rand($amount 0.4, $amount 0.6))` even though mt_rand returns ints.
1ex or 10^x is what you probably want.
Why e was chosen to represent that may be due to 7-segment-only displays on (some) (early) calculators. I still think it was a bad choice because of this very issue.
A full explanation can be found here: http://stackoverflow.com/questions/3730019/why-not-use-doubl...
If this is 64-bit PHP, any realistic bitcoin amount multiplied by 100000000 would still be within the integer range (2^63 - 1) and can be passed around without any loss of precision ...
... unless $info['balance'] has anything below the decimal point. As soon as you're dealing with fractional bitcoins, the amount will be converted to a float before it is multiplied by 100000000 and then back to an integer. So even in 64-bit PHP, the code can't avoid passing bitcoins around as a floating point number.
Realistically it is extremely unlikely in 64-bit PHP that the loss of precision caused by this single line of code (and the subsequent casting back into float) will ever round up to a satoshi. The (int)round() just makes sure that you get an integer rather than a double-precision float, because PHP loves to turn your values into other types behind your back. Nonetheless, if the program keeps casting numbers between int and float all over the place, eventually it may begin to lose a satoshi here and there. At the scale of Mt Gox, the errors will definitely add up. That's why you should never touch a float with a ten foot pole if you're dealing with money.
The correct way to handle monetary amounts in PHP is to use the bcmath extension, which enables arbitrary precision.
Good lord. Lose all your bitcoins AND your identity. Mt. Gox can't go away fast enough!
* People who know how to properly right code, don't mess with bitcoin because they understand the involved complexity and high risk of error since money is at stake
* People who don't give a damn about the complexity and are prone to risk, but lack the technical skill to support their ventures (MtGox was 50% of the time not scaling well enough. The website was slow even when not under DDOS).
What MtGox shows, IMHO, is that there's a market out there for serious, professional-grade bitcoin exchangers.
http://www.reddit.com/r/Bitcoin/comments/1zeurx/alleged_mtgo...
We know from the leaked mtgox crisis plan doc that they have 550,000 verified accounts.
Each user who wanted to be verified had to scan at least 2 documents- a passport+license and a electric bill of sorts.
Assuming both documents alone were only 100KB combined (and its likely way more than that since scans are usually 500KB+ per document) than we can estimate the file size:
550,000 x 100KB = 52.45GB
Thats more than double the claimed 20GB.
In fact, even if we believe that every persons doc is in the DB; and assuming nothing else but passports is in there- you are only allowing for 20KB per document
I don't know if the regulatory requirements state that you must keep a photocopy, but in case you do not it would be foolish to store more data than you need.
In any case, regardless of what was found or how, it's completely inexcusable that such sensitive data isn't encrypted asymmetrically the moment they receive it.
--
I just saw this also in ##mtgox-chat.
What legitimized this was the fact there was a portion where MtGox connected to Eligius's servers to broadcast free transactions.
Eligius and MtGox had a partnership where MtGox provided free hosting for their pool in return for their acceptance of MtGox's transactions with no charge.
I still have no clue why this kind of information would be kept on a public-facing server.
It's reaching a bit, but they may be scans of passports for foreign employees who need to be registered with proof of identity but do not (for whatever reason) have a form of identity that the Japanese government considers "official."