Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: Hook^ on June 25, 2011, 03:16:47 PM



Title: Something I don't get about GOX.
Post by: Hook^ on June 25, 2011, 03:16:47 PM
There is something about their announcement that has been bothering me.  They said that their site wasn't hacked, but an auditor 'lost' the password hashes.  If that is correct, then why does their site say that it has vastly improved security?  If their site was already secure, why do they need to 'vastly improve' the security?

It sounds like a tacit admition to the sql injection rumors floating around. 


Title: Re: Something I don't get about GOX.
Post by: teflone on June 25, 2011, 03:18:26 PM
There was your money, .....     GONE!



Title: Re: Something I don't get about GOX.
Post by: relative on June 25, 2011, 03:18:57 PM
their official story is so full of BS I'm tired of even discussing it.


Title: Re: Something I don't get about GOX.
Post by: ploum on June 25, 2011, 03:23:14 PM
Typical reaction: if someone tried to break your door but finally stole your keys, you will want a more secure door.

In a sense, it is logical because they realized that, next time, someone might be able to break the door.


Title: Re: Something I don't get about GOX.
Post by: AtlasONo on June 25, 2011, 03:25:02 PM
Because it's what the people demanded.


Title: Re: Something I don't get about GOX.
Post by: julz on June 25, 2011, 03:25:40 PM
...If their site was already secure, why do they need to 'vastly improve' the security?
It sounds like a tacit admition to the sql injection rumors floating around. 

The database leak showed that the passwords were not stored particularly securely - so that at least needed to be fixed.
Because a fair amount of the account info is now public - that also forced them to implement extra security features e.g the IP address checking they did for account reclamation.
Also - they said they intended to keep the existing server 'as is' for investigation purposes.

It does seem a possibility that the auditor story is a cover story for an underlying sql injection vulnerability - but I don't see this as a tacit admission
 -  it's still just speculation as far as I can tell.




Title: Re: Something I don't get about GOX.
Post by: TraderTimm on June 25, 2011, 03:27:15 PM
We need more Mt.Gox threads guys, I think you are falling behind.

Only a few more before the front discussion page will be nothing but Gox! (As if that was the only thing going on at the moment.)


Title: Re: Something I don't get about GOX.
Post by: BTC Economist on June 25, 2011, 03:29:04 PM
Where did all the "hehehe" usernames come from?  I think those most have been SQL injected.  The hackers tested the system injecting users, then went for the whole database.  Gox is liars.  I don't know why anyone would trust any money with them.


Title: Re: Something I don't get about GOX.
Post by: TiagoTiago on June 25, 2011, 03:30:29 PM
Security is not just about software, but about the company guidelines when dealing with wetware as well


Title: Re: Something I don't get about GOX.
Post by: Mark Oates on June 25, 2011, 03:33:59 PM
ITS UP! I'M IN!