Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Bitcoin thefts at MTGOX (Bitcoin exchange) confirmed to be CSRF vulnerability (bitcoin.org)
68 points by ezl on June 18, 2011 | hide | past | favorite | 48 comments


From the comments:

"Pretty sure Mt. Gox would have legal responsibility for coins/funds lost due to the exploit.

Allowing users who haven't read this thread to lose funds is negligent."

IANAL, but pretty sure this is completely wrong. That is what a completely unregulated market is like: freedom, but no recourse if something goes wrong. I have to wonder what happens when people who are used to the benefits of regulated markets (not saying there aren't downsides, just that there ARE benefits) enter into a market they assume is regulated, but isn't. With bitcoin, this is more than just a hypothetical musing.


All markets are implicitly regulated by a country's background civil-law doctrines, even if there aren't specific regulations of a particular market. For example, fraud can be alleged in any market; it's illegal to defraud someone, even in otherwise unregulated kinds of commerce.

In this case, 'negligence' is a doctrine that, in most countries, is at least in principle applicable to any interaction in any field of endeavor, though what exactly constitutes negligence might vary. That doesn't mean any particular claim would win, but the fact that a market isn't subject to a specific regulatory regime doesn't mean that you can't bring a claim of negligence.


People getting into bitcoin now are buying it because of it's decentralized unregulated nature. This whole p2p economy thing is very new, so you can't compare it to an established market like the US economy. It could easily be argued that market regulation doesn't add much value considering the constant and systematic recurrence of financial crisis in the US.


That is not so easy an argument to make as you seem to think it is. Several of the major sources of the recent financial crisis (the derivatives market, the rating of junk financial products as AAA, and the over leveraging of major financial firms) all suffered from lack of regulation (derivatives, rating agencies), or relatively recent deregulation (the over-leveraging).


Actually, the whole point of rating that stuff AAA was a regulatory arbitrage. Buying AAA-rated CDOs and buying credit default swaps against them was a capital-efficient way to lever up. And that level of leverage was only possible due to central banking backstops.

If deregulation caused the crisis, why weren't hedge funds (the least regulated entities out there) a big part of it? I seem to remember a bunch of the major investment banks (much more regulated) losing money because of their positions in mortgages (a very strongly-regulated investment).

It's really hard to describe the financial crisis without talking about decisions that only make sense in the context of gaming regulations.


Hedge funds may not have been a big part of this crisis. But the next to last major financial crisis is a case study in this: http://en.wikipedia.org/wiki/Long-Term_Capital_Management

Hedge funds were also more a result of a lack of regulation, or side-stepping current regulations by being defined differently, not so much a matter of deregulation. See it as regulators not stepping up or not allowed to step up and adapt.

It's not like regulation serves to make any financial crisis avoidable. But smarter, more adaptable regulation can limit the depth of the rot, help shore up the integrity and health of the financial system, and possibly allow for a softer landing.


The whole stupid AAA ratings regime is a government regulatory scheme-- only a handful of ratings agencies (they've opened it up a little since the crisis) were permitted by the government to rate bonds. Contrast that with equities, where there is no rigid "AAA" rating system and where thousands of analysts compete to provide the best research on stocks.

Over-regulation is at the heart of the financial crisis, from the broken ratings system to the role played by Fannie and Freddie.


This is absurd seeing as how we are purposefully led into these many "market crisis" by the federal reserve and the people who run it.

Your argument is ridiculous because you are making an assumption that the federal reserve and the like are acting in the best interest for the united states and the crises, "just keeps on happening" which is absolutely wrong.



IANAL either, but I'm not so sure if it's wrong. The fact that the market is "unregulated" in the sense that it doesn't have special regulations written about it the way that regular financial markets do doesn't mean that no laws apply.

On the other hand, is it even possible to prove (or even provide evidence) that someone stole your bitcoins?


Even if there are laws regulating Mt. Gox, given the fact that Mt. Gox is operated by a Japanese company, Japanese laws apply to Mt. Gox, meaning that anyone willing to take legal action against Mt. Gox would at least have to find a Japanese lawyer and litigate in Japan, which, I imagine, makes the process more complicated and possibly more expensive for most BitCoin users.


No, this is what US federal courts are for. You can even sue a foreign entity with no US presence in state courts (depending on the state). Maybe an expert could comment.


Huh? By what law? US courts (federal or not) have no jurisdiction over foreign entities without US presence.


You can also sue Zeus. It won't be worth your time, but you can do it, and people have done it.


Oh great, now I have another item for my To Do list.


All that you would accomplish by suing in state court is to waste a few thousand dollars securing an uncollectable judgment that neither the federal courts nor the Japanese courts will enforce.

If Mt. Gox doesn't have the minimal contacts (to the U.S. economy/legal system) necessary for federal court jurisdiction, you're SOL unless you are willing to sue in Japan.


The blockchain proves to everyone that your Bitcoins were transferred to a certain address. The only problem is to prove that the transaction was theft and not a legitimate transfer.


That's a pretty big problem, considering bitcoin is partly designed to prevent proving such things. There's no way to identify who that other address is. You can't even prove it's not yourself making a false theft claim.


Actually, I'm wondering how does a bitcoin bank avoid physical robberies? For example, a criminal or government officials physically kidnaps a bank official and demands the private keys? How do you implement the equivalent of cryptographic vaults that only trusted officials have access? In addition, how do you track the serial numbers of stolen bitcoins?


Well you get what you get in a free market; private companies/groups form that act as Consumer Reports. Still unregulated but then you have a trust network built up. Also, with more people entering and after this vulnerability has been exposed, there will be some more caution when using random websites.


In an open market, some company could offer security as a service, that's pretty much the theory for banks.


Who in their right mind thinks BitCoin is regulated? I ask this question rhetorically because places that I hold to be intelligent, HN/reddit, seem to continue to operate under the assumption that BTC should enjoy all the benefits of a regulated currency. Does the word "decentralized" not mean anything to anyone? Do people not realize that this currency has potential BECAUSE of the lack of central authority that would guard, protect and monitor their cash flows?


I imagine you can still attempt to sue them. However, yhe person to cast the first stone would probably incur the wrath of Anonymous or some such.


I've been thinking about bitcoins.

If there is some way clearing houses can prove they own a certain quantity of bitcoins, then, the bitcoins don't need to be physically transferred. This has some advantages. Firstly, the bitcoins can be secured off the grid. Secondly, the transfers between clearing houses are simply bookkeeping entries, meaning there is less bitcoins that need to be actually exchanged. In the event of fraud, there is some traceability and reversibility, since clearing houses can implement rules similar to what banks already do. For instance, monies deposited cannot be withdrawn straight away, until it is clear that there are no other claims on the money.


I think on a very low scale this is what Youtipit does(http://www.youtipit.org). People deposit their coins, tip them internally and this is handled by our bookkeeping system. If someone wants their coins out they simply withdraw them and the transaction goes out to the block chain. This has many of the advantages that you have stated (also tips are instantaneous, no need for confirmations)

If you give it a look I would like to hear your opinions on it.


So you basically have an internal currency that just happens to be bitcoin? Kinda like when you store $$ in a PayPal account?


You make it sound like a bad thing...But yes thats exactly what we have :-). Except with us there are no fees: no deposit fees, no withdraw fees, no fees to tip. If you can get over the fact that it is bitcoin based, its probably the cheapest way to reward someone online. This would not be possible without bitcoin. In fact we built the system to use USD and EUR initially but eventually realized that financial/legal costs were making the project totally unviable. Changing to bitcoin allowed us to continue and play with this idea of the 'Online street performer' and develop it somewhat.

I think what we do shows that there are some positive applications for bitcoin and it does open opportunities for online business. Unfortunately most of the press dwells on 'bitcoin for drugs' stories, why cant they to story about Youtipit!

... probably because there are far more people interested in buying drugs than tipping online :-0


How do you physically transfer bitcoins?

>If there is some way clearing houses can prove they own a certain quantity of bitcoins

The network knows exactly to what address (hash) each bitcoin belongs to. You just need to publish the addresses you own and prove you actually own them (by signing something with each of the addresses' private key).


MtGox has a 'dark pool' which works exactly like that.


Nice tip:

^There's no need to install an entirely separate browser. Make a new profile, just for Mt. Gox, and run it from a shortcut like this: firefox.exe -P "NewProfileNameHere" -no-remote

Then you can do the same for your other profile and run both at the same time, with no interaction.



Does Chrome support multiple profiles? I know you can launch an Incognito window, but Incognito windows share cookies, etc.


Incognito windows share cookies? That doesn't sound right... I would have thought incognito would prevent CSRF.


Yes, incognito windows and tabs share cookies. The cookies are deleted once you close the incognito window of course and are not shared between the incognito window and the regular browser window. But as long as one incognito window is open your cookies are still there.

Edit: You can easily test this by logging into GMail in Incognito mode and then going to youtube/google maps etc. and notice that you're still logged in. Even if you open a new incognito window.


Right. So open an incognito window; go to MtGox; do your business; then close.


Yes, with the --user-data-dir flag.


The Chrome dev channel has support for multiple profiles.

Incognito windows share cookies with other incognito windows but not the regular windows.


It is incredibility poor form that websites are still vulnerable to these attacks. Django made CSRF protection mandatory back in 2009.

http://code.djangoproject.com/wiki/CsrfProtection

and if you operating a website that is still is use today it must also guard against these attacks. See

http://www.squarefree.com/securitytips/web-developers.html#C...

there is absolutely no excuse for this other than incompetence or ignorance. Take your pick.



Misleading headline, as no actual bitcoins were stolen from this exploit according to the owner of MtGox.


I've seen one post on the forum from a user claiming to have had bitcoins stolen from his/her account.

While there's no way to know for sure, at the moment I find the user's claim more plausible than Mt. Gox's denial.


How would they know? (Serious question)


My guess is they're looking at the HTTP referrer field in their server logs. Normally, a CSRF exploit shows up as an HTTP request originating from a different site (i.e., other than mtgox.com). I think the referrer can be spoofed, though, which would disguise the exploit in the logs.


The referrer isn't spoofable in any normal browsers (and CSRF attacks occur within the user's browser).


[deleted]


That only tells you that a transaction occurred. It doesn't tell you who initiated it.


Any security researchers have link to a study detailing the prevalence of security lapses among a large sample of websites?

I hear about these attacks, and I'd be curious to know how vulnerable the sites I visit are.


As Lulzsec so clumsily illustrated, you can't know because most vulnerabilities are silently patched, or undiscovered (but still in use without the site's knowledge.) Any such index would more likely penalize the most honest than the most vulnerable.


Are you saying its better not to know? It wouldn't be hard determine is a site is CSRF vulnerable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: