Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hopefully they'll hire some security consultants as well.


Actually, the problem might have been exactly that. An updated posting on their sites says "It appears that someone who performs audits on our system and had read-only access to our database had their computer compromised. This allowed for someone to pull our database."


For a currency invented by a bunch of cryptography geeks, it's astonishingly insecure.


Mt. Gox is an exchange, not the currency. The currency is secure. This is analogous to a bank getting robbed.


That's right, and let's be clear here: Mt. Gox has been kind of a mess from the beginning. They've never appeared to have a clue about security, and performance has been a complete and utter mess for quite a while now. To give you some idea, the trade that blew through the entire buy-side took over 30 minutes to execute, and the exchange essentially slowed to a standstill during that time. I realize that there are a lot of orders on any exchange at any moment, but 30 minutes of downtime in response to a single order? Come on...that's not even to mention the complete lack of sanity checks or catastrophe reporting that you'd expect in any system like this that touches people's money - it should not have required people directly tracking down the site owner to get a human looking at this stuff!

That type of thing is maybe acceptable from a lean startup that's learning as it goes, but when you're transacting over a million dollars in trades per day, there's an expectation that you'll figure out what you need to do to get things running smoothly.

This might not be totally fair, but when I saw the .php extension on all the trade API URLs and noticed that there was a dynamically generated price chart on the front page (apparently not cached, based on how long it took to load) I was immediately suspicious of the competence of the Mt. Gox devs to handle the scale of what they'd created (or rather, AFAIK, the scale of the system that they purchased from the original creator)...I'm not really that surprised that security was completely botched, this has seemed like a very amateur operation from the beginning.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: