Hacker News new | ask | show | jobs
by davidw 4496 days ago
I'm inclined to agree with cperciva, who is no slouch with security stuff: https://news.ycombinator.com/item?id=7289273
1 comments

The statement is inherently flawed, regardless of its source. Because some exchanges were unaffected does not mean that MtGox was not affected, and the statement itself implies that other exchanges were affected which would be evidence in MtGox' favor.

I'm not saying MtGox was not incredibly incompetent, however nobody is helped by this false defensiveness over a very serious and clear bug in bitcoin that seems to have affected at least a few exchanges.

Regardless of MtGox' incompetence, this IS a serious bug in bitcoin for which a workaround is required, and without which a bitcoin theft is possible.

If this implementation is bugged:

http://blog.magicaltux.net/2010/06/27/php-can-do-anything-wh...

then is ssh broken?

Please state your point rather than providing just a link. I don't know what you are trying to say.
That a bug in one implementation does not imply a bug in the protocol.
I didn't say there was a bug in the protocol.

There is a bug in the REFERENCE implementation, which is used by almost every exchange. And one criticism of MtGox was that they used a custom version of the reference implementation, and should have used the standard one. You can't have it both ways.

Is there a reference implementation for SSH? I don't think so.

By your standards then SSH is broken, which is false. I don't want to have it both ways. I think if you are running a money service that you should not rely on variables that were known to be malleable since 2011. There's even a wiki page about it, on a site the guy owned, since Jan 2013. Either they run someone elses code and made sure it worked, or run their own code and made sure it worked - and by worked I meant worked the way they needed it to, not the way they expected it to.

Listening to Andreas, it sounds more like a feature than a bug and that's also why it hasn't been "fixed" since 2011 - organizations introducing blockchain technology into their stacks should know about that and develop work-arounds:

https://soundcloud.com/mindtomatter/e85-mtgox-and-malleabili...