Start of #mtgox buffer: Thu Jun 23 01:57:23 2011 * Now talking in #mtgox * Topic is 'Mt.Gox - Official channel - https://support.mtgox.com/entries/20208066-huge-bitcoin-sell-off-due-to-a-compromised-account-rollback - Official announcement in the next hours announcing time at which site will be back (at least 24h from announce). Recoveries will be processed during those 24h - Trading will resume 1h after site opening' * Set by MagicalTux on Wed Jun 22 16:28:08 market going way up without mtgox on th well... up to 15.8 ugh, if only I had my btc/dwolla that is in mtgox bitexplorer is pretty cool you can trace a bit coin back to it's birth quite easily * alyx is now known as alyxxx Why do I need to wait for a claim request process? My account only has one IP and I already confirmed my e-mail =/ draginx, because they need to see if there are multiple claims on one account Hmmm multiple *confirmed* claims? for example, if a hacker submitted a claim earlier, and then you tried to claim it 2 hours later but they already gave the account away instead, they wait for a period and compare claims, if there are multiple ah i see.. its for people who have 1 password for everything gotcha yeah but i mean i ever entered in the amount of BTC as well =/ yeah, i've only ever accessed my account from this machine and while my ip is dynamic, it doesn't appear to have changed in over two months so anyone accessing my account from any other ip is not me... just seems silly with over 20k claims even with 10 person staff it's going to take u guys a long time o-o unless u have a quick button "Release" and "Dont release" lol right the IP in itself should be good measure alng with my email confirm but, shockdiode, someone who previously logged into your account could say the same thing. u dont keep logs of IP? Ooofo: right, but somehow I seriously doubt that anyone else has logged in my account for 1, and 2 the vast majority of logins would be from this ip shockdiode: i dont tihnk mtgox logged IPs which is part of the problem wat except like a field called "ip" in the user table which can only store one ip ugh well whatever this is SPECULATION i dont actually know oh ok then id bet 5 btc ;) well, whatever anyway, it's maybe gonna some tay get sorted out some day* seems like it'd be fairly simple to have a table with userid/ip/date/success to store login history for a financial related site shockdiode: it is but u would also think SHA256 would have been the very least thing used for storing passwords no? and l-o-l at 512 :P yeah, i'll just stfu and stop thinking "well but... but...." because obviously these things did not occur to them ugh, i'm outta here lol take care peace dude sha256 would be a bad idea octuple rot 26 ftw as there are, well, a few machines that are specifically cracking sha256 say, 11.371Thash worth -_- bcrypt ftw did people lose their bitcoins throughout all of this? what do you mean by that? like if i login to my account wil it say 0.00 btc? if there were < 20 there will be <20 ah ok imho there is really nothing wrong with md5-bsdsalt even on GPUs its slow as hell to hash at least afaik i have heard about some action in here ... like Lulzsec took over the channel haha well someone claiming to be lulzsec did momentarily And it's all over already? oh yeah quite some time ago I missed the fun :-( didn't miss anything really. Hello. I have an account on mtgox and it has been more than 24 hours since I submitted my request. I haven't heard anything. Is this normal? if you click on the link in your claim confirmation email, you will see that the page automagically updates to say 48 hrs now, how way kool is that ? Juffo-Wup> i believe it's been said that claimed accounts will be sent out basically in a large batch shortly before the site reopens i also heard that makes sense to me, as well Hm. Ok thanks. Noone bothered to check Chanserv either, the lulzsec user id is still on the access list. R1card0: will everyone rejoin at once or will only certain users get to join at first? fuck knows em mloftis: haha i am beginning to realise that the only thing thats guaranteed, isnt what mtgox say Because some people might wonder why some users get the advantage of participating in the market early on while others are forced to wait. i am at the point now where i just want to cash out and leave it all behind And on the other hand, some people might wonder if only users with small amounts of coins can join so that mtgox can cover the transactions should everyone decide to cash out. a few days ago i thought, yeh mtgox is still the highest volume, cheap tfr costs etc but now im losing patience, mainly from keep being strung along I still trust mtgox more than other exchanges as long as this is handled well. Just updated the support site with some info about the claim process i am coming to the point where id rather do business with anyone else no matter the cost em: assuming they're not doign something wrong (BIG assumption at this point) there should *always* be enough BTC and USD to cover everything in the market since they're just acting as an exchange brokerage. So, as soon as they've rx'd "enough" requests?? What about the 10% of people who all ready reclaimed their accoutns. * Fairuser is now known as Fairuser|AFK MtGox_Adam, what does this actually mean tho ? [Update June 23 - 03:15 GMT] Clarification on the claim process. Once you have gone through the first step of reclaiming your account at claim.mtgox.com an email will be sent to the email address registered with your account. Within that email a link is provided that you will need to click. This will verify that you are the original owner of the Mt.Gox account that was reclaimed. it means we get to wait more still When we have received enough reclaim requests, a follow up email with further instructions on how to access your account will be sent out. how long is this going to take adam MtGox_Adam: FYI, you guys need to *fix* the Chanserv access list, LulzSecurity is still listed as having access on Chanserv here. mloftis: i just sent a message to MagicalTux about that, too Why not enable the accounts as soon as possible like the first 10% of people got? eric1: there are not already people trading on mtgox is there? when we have enough requests sounds like more delays mloftis: looks like it's taken care of now No one is trading right now, no one has access to the site. I had a very strong password and my exact balance. I think I would be one of the first to get my account back. MtGox_Adam, we are talking about 1) verification its our account, 2) having the ability to cash out We don't know exactly when, but everyone will be given 24 hrs notice before we allow logins how long is this going to take then it'd be a race to see who can register a given account first. then they'd have to halt an account, and take care of a dispute. . believe it's been said that claimed accounts will be sent out basically in a large batch shortly before the site reopens I don't know. I don't really care about leaving Mt. Gox, but I would feel better if I knew my account was there believe it's been said that claimed accounts will be sent out basically in a large batch shortly before lather, rinse, repeat. the site reopens because 24 hrs on the claim url has turned into 48 hrs (silently ) and now it sounds like we have to wait till you guys reopen x6763: yup looks like. Services has +es and -es heh. frankly, i dont have much faith you are going to reopen Sorry, client freak out there. Nonsense. MtGox_Adam: Okay, I guess. Keep us posted. I think even if you disabled trading, giving people access to their accounts would be a show of good faith, restore mutual trust, etc. that is what ,magical tux told us previously seems like everytime i sleep the goal posts are moved sry, someone mind pasting me the conversation you're referencing above in a pm? just got back in here. ty sure much appreciated R1card0: I am not holding my breath for anything to ahppen this week R1card0: they have a lot of work to do...i don't find any of the delays or anything to be at all surprising If it does I'll be pleasantly surprised well more like amazed x6763, i feel like im being held to ransom how so? i'm convinced they are trying as hard as they can to Do the Right Thing. I just feel like I do when ever something really important is out of my control.. somewhat helpless and impatient MtGox_Adam: 10% accounts filled in the claim. How much of the claims you got so far where processed yet? But after seeing all of the scared, ill-informed speculation, shit talking, and bitchin & moaning, I know I'd tell every to go suck a fat one and walk away. however, I say to myself.. "This too shall pass" Phraust: if a normall bank would just froze my and everyone accounts because they got owned, customers would be at LEAST already suing it's ass on evening first day waiting (so, monday) Shame this isn't a normal bank. it is regulated as a normall company it certainly isnt acting like a company it's not your friend Joe from chans that borrowed 15$ internet moneys, it's a company handling MILIONS OF DOLARS. We are extreamly patient. no answers to questions then MtGox_Adam ? * Phraust is patient. Phraust: If this was a normal bank and it opened in an insecure fashion that let their customres money get stolen, they would get sued even worse. Lol questions that have been already answered maybe? It'll open when it opens. I knew from the beginning investing anything in something so new was a risk. midnightmagic: was my q answered yet? Beats me, what's your question? 10% accounts filled in the claim. How much of the claims you got so far where processed yet? the big issue is that they weren't prepared for something like this...a few months ago, preparing for something like this might not have made sense as there weren't that many users and that much money or profits...but since it has exploded in growth, they've been so busy they've been unable to prepare for these types of situations, which is why we're here waiting for our money a few days after a big incident How is that any of your business? midnightmagic: lol what? * xelister beats midnightmagic with a tief-club you frozen my and thousand of people tens of thousands of dollars and you ask how it is our business to ask how fastly (or slowly) the actuall processing and UNFREEZING is going? lol? xelister: None, I suspect. If I were them I would be examining the claims and working on writing tools to automate as much of it as possible. they couldn't just roll things back and turn the site back on, as bgupta pointed out Hindsight is always 20/20. no one expected any of this, and it sucks that it happened. From what I understand, they were using a system they didn't build, and it got overwhelmingly popular. boo hoo, i hope the next mtgox has learned this lesson Paypal doesnt look so bad now :) Phraust: Yeah they bought mtgox fairly recently... noagendamarket: yeah it does R1card0: I think everyone has learned a lesson. As the holder of other peoples property, those people have an interest in knowing how you are managing their property. It is their business. including all of us.. WIth the DDoSing, all of the upgrades, plus they've been working on a completley new backend. According to the interview, the new guy there has only been working with them for 2 weeks. Sigh.. Whose fault is it that any of our BTC are stuck in there when we ALL knew exactly what MtGox came from? lolbertarians don't learn lessons So up until all of this, it was one man. yes midnightmagic: your fault for trusting some guy on the internet, his for being incompetent midnightmagic: hm? mtgox's fault OBVIOUSLY? you trying to say it is our fault that we choose mtgox ?! MagicalTux: has spent the last couple of months building a new system for mtgox and was planning on it going live by the end of last week...dealing with the ddos attacks and stuff slowed him down, and then the database leak and hacked account dumping a ton of coins on the market happened, and he decided to go ahead with setting up the new system now The fact is I learned exactly what a secure password is.. the old rules don't apply anymore in this world of massive distributed crack farms * xelister gives midnightmagic a worst-PR-person-ever reward he should have done that before buying the system Besides that, anyone who put so much in that they're hurting financially now that MtGox is down.. Like WTF. what kind of an idiot puts anything but play money into MtGox? Veiled the simplest of audits would have shown how insecure the bitcoin system is, he shouldn't have knowingly operated it mtgox system* midnightmagic: it's jed fault for not knowing heads from tails about security and coding pile of shit, and yours for enrolling it to handle milions of dollars without any real checking or response teams x6763: Ah so that means rather than processing claims they are probably busy with the new backend, while waiting for folks to submit. I'm no PR. but you people constantly fucking whining is getting redundant and repetitive. ^ midnightmagic: hm btw, you are... a developer at mtgox? e.g. how are you related to mtgox.com b s/b// bgupta: i think he's busy with a lot of things...dealing with the new system, processing claims, dealing with lawyers, dealing with what happened on sunday, etc Not my fault! I lose nothing I couldn't afford to lose if MtGox never comes back up. I don't about you guys, but I am kinda excited that the new mtgox is coming, and that this event happned while the bitcoin market was so small it's going to be very interesting. wait I am relieved on the second one.. not excited. all the panic derping is gonna be great to watch. derping? selling, buying, speculating, freaking out. nobody has more incentive to get this thing back online as quick as possible as MT... there'll be a ton of money to be made my savvy traders as people get back into their accounts darin_: exactly ezl_: lucky traders* holy cow.. by the time I get my money to tradehill btc wil be back at 17.50 bgupta: I'm excited the price has recovered pretty quickly and seems to be holding around 15 midnightmagic: I ment, are you responding as some representative of mtgox or something, or just as random customer like rst of us I don't think there will be a panic sell. * noagendamarket thinks there will be a run on the bank in a way all this time passing takes some of the edge out out of the panic gives folks a chance to reflect xelister, there are a lot of fan bois , perhaps some people like being lied to and messed around, each to their own i guess, does nothing for me personally a run on the bank is not the same as a panic sell, and since mtgox is fully escrowed. a run on the bank is not an issue No. I'm no MtGox shill. But in all my decades of experience I've never hear more pernicious whiners than all the people going on at such length attacking the people WHO ARE BASICALLY THE REASON ANY OF US MADE ANY MONEY AT ALL. hopefully people make better decisions with their cirtical funds in the future after all of this. Phraust: as if i know, right? lol caps lock trick eh, yeh i can see you experienced and like that, the main point is disregarded. Yah whatever no-caps loser. well irc doesn't support dbold or italics as far as I know For good reason. :) i learned that caps lockers are basically morons, in my decades on the interwebz just ascii wangs and capslock and such WHAT?! Uh huh. Then you've learned how to make judgmental decisions on zero evidence. Which is exactly how I pegged you. almost 15.70 midnightmagic: are you retarded today or what. Someone fucks up our MILION $, because being unbelivably incoptent, and are surprised people are complaining? But yes, midnightmagic has a point. The whining doesn't really serve any purpose. YOUR? lol teehee yeap mine and other customers you judge all you want Gimme a break. You had millions? Who gave you the balls to talk on my behalf? midnightmagic: how much money in USD+BTC is fucked up (frozen)? >1mln$ right? 400 btc+. Is it customers? yes. What do you dont understood xelister: Please don't quote me on this, but I think they said for those with multi million dollar balances you can contact them privately and get your money out early.. but you will need to send them special documentation. didnt people don't have multimillion dollar balances, they have large bitcoin balances xelister: I'm surprised though that if you have mutimillions in mtgox, that this bothers you. xelister: Look, don't get me wrong okay? I respect the fact that you've been working tirelessly (I've seen it) to promote bitcoin pretty much since before it got popular. indeed. (IE: you probably have a lot of money) bgupta: I ment in the summary milion worth of USD is frozen. Across all frozen accounts. Not that I had it all as long as mt gox doesnt touch the accounts of people who never traded during the crash and claim they did that will really be annoying But the constant rumours, endless unfounded speculation, and outright libel that I've been reading since MtGox went down is making me half-wish they lock down MtGox so tight none of the whiners can ever usefully trade again. .. without providing copies of passports and their firstborns, the way every other trading market is set up. this is obviously biggest security fuckup in history of bitcoin I had all my bid orders execute.. and tried to put some more in.. at like $1 before they shut it down. I saw the volume spike and price drop on bitcoinwatch and thought it was some crazy early adopter.. i dunno, that poor guy who lost 25k btc was a pretty big fuck up. bgupta : ye sure of course thats the most likely reason someone would sell at 0.01 lmao stop fooling urself I'd agree it was the most visible, but I'd argue that if this had happened a few months ago, folks would not be bitching so loudly It's bad. I agree. I've always agreed. I'm glad I use one-offs for every piece of info I gave MtGox. But all I see is bitches like that COCK Kevin who are demanding MtGox cover the proceeds of what would be a major crime in any sane court I'm aware of. fuck kevin, he even admitted he thought it is stolen funds Well it wasn't trading at 0.01 when I came online.. then to still want it is just absurd Any prosecutor worth his salt would be sharpening his knived right now to test Bitcoin fraud in court. midnightmagic: this is real life Howefver I thought maybe the big sale had triggered panic selling midnightmagic: why? it's not trading with magical cards, it's business and deals nobody cares about aspies losing money bgupta : what dont u understand? it all went to shit when the guy(?) manipulated the market to crash, everything from that point and afterwards is an effective of the hacker/fucker. Because this isn't WoW gold or EVE:Online ISK. this is sparta what jurisdiction would even prosecute many courts really could execute to consider the done trades as valid even @0.01, and cover loses from mtgox pocket. Clipse: I am talking about what I thought the day it happened before the news came out and the markets were closed past tense. it happens IRL in similar auciton portals I happened to be on vacation xelister: As a result of hacker activity? Name noe. bgupta : ok fair enough, I was live trading through it all and knew exactly from start to finish the shit thats going down is bullshit. well out of town at the beach midnightmagic: dialers usually they dont cover up security breaches for days beforehand xelister: I don't follow.. the only evidence exists on tuxs' server, who is proven untrustworthy thousands of cases. Always the victim of hacking had to pay I also feel strongly that what happened a week before when price dropped from 32 to 10 also had something scetchy in it but no one bitched bout that so I wont either. Nibiru_: That's why I said "sharpening his knives" and not "sending out cops to arrest people right now." Clipse: agreed Nibiru_: Not to imply that I agree that MT is untrustworthy. Just that the evidence is slim. midnightmagic: "dialer" troyan program hacks your computer into calling super-expensive phone numbers. You have to pay the phone provider, despite it was result of a crime/hacking. Court will agree. we had one guy crashing the market there with huge sale at $10-$12 when market traded at $30 xelister: Tested in what court case? very very suspicious but Im not going into that Clipse: I wondered if that was someone ddeliberately popping a bubble just want mtgox back on track :) midnightmagic: oh thousands. Google it bubbles always pop if you buy a picasso at a garage sale for 10 cents you dont have to give it back bgupta : I strongly believe it was legit funds from outside, but it was stolen funds is my believe that the person wanted to convert quickly xelister: Like http://www.theregister.co.uk/2004/06/23/spain_dial_scam/ ? when you later find out it wasnt stolen from inside mtgox more likely some wallet thief noagendamarket: you would if it was stolen how do we know that ? noagendamarket: And if hackers break into an art museum, steal 100 picassos and sell them in a garage sale? Stolen property. Clipse ah.. youre assuming it was stolen lol midnightmagic: looks like it, yea this is why we the no.1 crackdown should be to secure wallets, any thief would of wallet.dat files would try to convert his btc asap even before victoms realise shit is gone We have no other evidence to believe otherwise. and that could be our biggest market worrying factor midnightmagic: stolen property and still the mtgox art selling shop will cover from OWN POCKET it is rather that thiefs changes price tags in museum. Because the museum owner forgot to close the doors btw any progress for the claim requests? xelister : erm no, stolen property that is bought must be returned when found by police or whoever investigates strawf: it is not our business, midnightmagic said fact is thieves get away, legit buyer suffers allways like that Clipse: ok I agree. Aaaaaand? I would demand compensation from shop that sold me the stolen property of course. You imply I said that it's not our business to know how long it's estimated to get through each to our own claims. xelister : yes the onus is on the buyer anyways I hope the no1 priority is securing wallets to fight the backtracking the original person who got his stuff stolen gets his stuff back without much hassle everyone else inbetween suffer But you asked a different question earlier. You asked, specifically, "How much of the claims you got so far where processed yet?" Clipse: here mtgox is both the museum owner that forgot to lock doors AGAIN and allowed tags meddling, *AND* the guy that sold me the invalid-priced/stolen pictures. He should recompensate the guys that got robbed, and he should recompensate the guys that bought stolen art... xelister : the chain doesnt work like that lmao He didn't forget to lock the doors. An Art authenticator left the keys in his convertible. in ur example it would work like so, he would move back the stolen items he sold and he would take back any fee he charged for the selling of the product you would get ur purchased funds back * ChanServ changes topic to 'Mt.Gox - Official channel - https://support.mtgox.com/entries/20208066-huge-bitcoin-sell-off-due-to-a-compromised-account-rollback - Site opens back on Friday June 24th 2011 at 03:00 GMT' and the stolen funds would go back to original owner midnightmagic: yes. It was said how many people send claim request, but we (or at least I) are more interested in what is the speed of processing this requests. This is police talk for WHEN WE CAN EXPECT THIS TO BE OVER finally. ;) thats exactly what he is doing :D *polite everyone is getting back what they deserved, not what they think they deserve hmm xelister: we'll check all the claim requests at least once before the site opens so it means what date is realistic...? the one in the topic Friday Sorry but we were told we would have access to our accounts 24 hrs after claims, if approved. MagicalTux: keep up the good work, stay calm. You guys are awesome! R1card0: 24 to 48 hours MagicalTux: I was calculating 0.65% earlier on the volume you traded over the last 30 days, I'm suprized you arent retiring and letting someone else worry :P now you are saying we will let you know 24 hrs before we open Friday R1card0: we said we'd let people know 24 hours before we open Gotta get prices down on Friday Everybody's lookin' forward to the sellin selling ROFL xelister To the selling weekend! Prices getting down on friday friday friday, gotta start selling friday hahahahaha oh god so MagicalTux , by 12gmt tomorrow, i will have access to my account ? stephen colbert ripped the shit out of that song legend! ( that will be 50 hrs ) R1card0: by 3:00 GMT lol. and at 4:00 GMT, trading will open when this week ? friday friday .. are talking 24 hrs from now ? Clipse: as I see it. Mtgox negligence had 3 effects R1card0: are you fucking retarded 1) some people's coins where 'robbed' darin_, a little yeh 2) some people where sold on invalid price 1) coins that left the system due to theft afaik is covered by magicaltux and it wasnt as much as the overall damage that is being rolled back. MagicalTux: Thanks. 2) invalid prices rolled back, purchases refunded 3) -don't forget- some people that thought they maid an awesome bargain buying @15 or @10 or @5 , will find out the deal is called off eveyone forgets about 3 soooo, what're you proposing? that the government come in and regulate their behavior? Persoanlly, I'd file #3 under "tough shit". 3) people who thought they made a killing, fuck them.. amateurs.. either they knew its a bullshit situation(I did) or they can just deal with it like anyone else would. xelister: no we are all very clear about 3, and it's a great sign of quality of the exchange that that is exactly what MagicalTux will be doing ^ in real business, if you would officially propose me cars at 100 USD each because you misstyped 100000 - then I would rather say its your problem and you should deliver the deal xelister: not alot of ppl could bargain buy anyhow, it affects a few people... the trading Stalled and mainly API traders could get something thru and perhaps a few website traders MAJORITY couldnt trade, so it was in a sense unfair to them aswell I see ofcourse that @0.01 was ridiculous. but some traded say @12 (probably me too, had some bids) the funny part is it was only a short time frame No; courts don't make people sell stuff like that just because some ad-man decided he wanted a cheap Mercedes.. xelister : the dropped from 17.5 to 16 15 14 13 etc. all happened within 5-10mins it just takes that long for 0.01 selloff to take effect change reaction then by trading bots and boom! Clipse: i had often left bids @12 and @9 etc, even when prices where @17 others did too all this makes me not like how mtgox bashes kevin day xelister : thats unlucky, preset trades wasnt suppose to kickin if the start of selloff didnt get initiated when did MT bash Kevin? in the head when he implied kevin is a thief or ther hacker kevin got extremely lucky this may be true, but also may be false xelister: and you say that if those open orders were fulfilled, you would want to keep the coins? he must've had that 0.01 bid there for shits and lulz for a long time kevin is demanding compensation for taking advantage of a crime, how twisted and dishonourable is that? wolfspraul : of course he wants, but if it was reversed and it had to do with his stolen coins it would be a big NO NO NO santa clause wolfspraul: I say this is complicated matter, it is certainly not "oh sorry we fucked up... fuck you all trades are ROLLED BACK, problem brah?" * Phraust shakes his head. allinvain : he had placed the bids on the same day apparently according to him 20mins before the shit hit not shits and giggles long ago oh oh damn he even said so himself Clipse, in that case..he's trying to be clever allinvain: No, I think he put it in just before the hack happened, or possibly just during.. he however said he didnt play it 1-5mins before like within minutes. opportunism that's what it was point is it was same day, 10-20mins up or down scale xelister: what do you want? I don't get it, sorry. mtgox is doing the one and only right thing to clean this up. Prescient opportunism. and now he's mad that he can't keep his booty midnightmagic: drop to 0.01 MIGHT occured as a result of normal trading. If say sme comp4cash or other biggest fish would for some reason liked to cash out at once. xelister: but you know that's not what happened xelister : dream on, btc wont drop to 0.01 due to normal trading within 10-15mins might have != did if u really believe that you are in the wrong biz gultiy untill proven innocent ? roll back, back to business. mtgox is doing the right thing. agreed. why have interest in something that you feel strongly can drop to shits... bitcoin have been actually pretty fucking stable for such a new currency Clipse: if someone would drop 200,000 BTC then it would. Like if any of the early adopters would like to immediatelly cash in to say @8, and it would triggered mass panic to @1 and then everyone sells to @0.01 lol 200k at 0.01 yes legit all day long of course ppl would do that makes 100% sense xelister: Dude. The jerk is asking for compensation. Here's, effectively, what he's asking: "I took advantage of a crime, and even pulled some ฿ irrevocably out, knowing it was taking advantage of a crime. I want MtGox to pay me because I didn't steal any more." who woudl take that hit though? no investigation required its all legit ppl hate money its very humanistic xelister: you don't really take sides, unfortunately. So I don't know whether you want to keep those coins or not. But think it through - let's say this attack would have undermined confidence into all of bitcoin so much that they would be trading at 1 USD at other exchanges. Would you even be here making your point of keeping your buys at 12 USD or 8 USD? year ago who would say @20 BTC is legit? people couldn't belive when it went up to AS MUCH AS @0.20. BTC is super wind, anything is possible. lol wouldn't an early adopter want to sell in small chunks over a given period of time "I could have stolen everything. You should be thankful." That's sociopathic man. xelister : its pointless discussing this , you are arguing like a brick wall midnightmagic, who said that? artfortz could probably brake mtgox using his coins just to prove a point. allinvain: Yes. allinvain: I'm paraphrasing. midnightmagic, ah xelister : aaah but he wont cause fuck its worth alot of monecy SEE the point is proven straight up allinvain: But watch the interview with him that Bruce did. The guy's fucking brutal. hope artfortz does not get hacked wolfspraul: I didnt bought when the prices where falling. Perhaps some buy @12 of few coins. This is not very important midnightmagic : whos brutal? midnightmagic, Kevin? hmm..haven't seen the interview artforz is probably one of the least-likely person to be hacked, perhaps out of all of us. I shall give it a viewing xelister: yes but imagine they would be trading at 1 USD at other exchanges now. ok? would you argue to rollback or not rollback? wolfspraul: I say it sucks that everyone jumps to conclusions that kevin is hacker i saw his mug and what he typed on that chatroom thing you are hypocrits, where the price was dropping I bet almost everyone Clipse: That Kevin guy. The interview is f'ing brutal. would be buying @10 @5 @1 like crazy I certailny would : xelister I was live trading and logs can prove it lol funny enough I would..but only if it was during a genuine market panick I could have bought as much as I wanted via api I DIDNT not as a result of technical or human error xelister: that's why we will not forget people who got their trades rolled back cause i knew any legit company would reverse this shit and now its happening and im in the clear Yeah, but I wouldn't pull it out, or if I was stupid enough to, I'd be paying it back after I found out it was because of a multi-million-dollar heist-attempt. what I say is that imho the just thing to do another status update, about the clearest one yet Who knows what a drop like that means? Maybe it is legit. Damn straight I'd put a buy order in. is to compensate everyone that lost the occasion on the price falls, because it IS mtgox only fault that it was artifficiall and untrue fall probably not compenstae the entire @0.01 400K because that is really... rofl but figure out some satisfactory middle ground xelister : next time your bank defaults and you lose all your money, please tell them that story. i think you should all SUE MTGOX to MAKE THE GOVERNMENT REGULATE what goes on on your LIBERTARIAN BITCOIN EXCHANGE mtgox handling this perfect hehe haha sorry i mean i know maybe some of you have some real money in there Clipse: well everyone would be suing the banks. Or beating up owners if they can. Also, we aspire to do better then normal banks? :) but i have a hard time respecting you nonetheless you fucks moaning bout rollback put more pressure on mtgox than you would on your own banks. xelister : GOOD LUCK u cant sue a bank fucking funny story :) sure but i mean when last week everyone was like "yeah bitcoin and everything related are sweet because the government doesn't regulate/interfere" if a bank defaults, its gone! nothing to sue Clipse: people sue banks all the time u understand what defaulting mean? Juffo-Wup: too true. rofl and now you/they/etc are all like "SHIT! COME HELP ME, GOVERNMENT!": Clipse: if company bankrupts you can still sue the past owners in civil suit xelister : HAHAHA yes theoretically, ud never have more funds than the banks u understand that the minority have the majority see but suing people is asking the government to intervene in private affairs not the other way around Juffo-Wup: I'm not. Juffo-Wup: I am not telling to sue anyone. it is example good luck Juffo-Wup: And you're trolling. ehh, maybe sorta but i mean Juffo-Wup, how? suing is making use of the legal system.. how is the legal system tantamount to "government" Juffo-Wup: what alternative you propose yeah, and the legal system is something SOLELY established by the government say /some exchange/ just runs with money. what do you do" suing someone is asking the government to use violence on your behalf if not sue? government should only intervene to enforce the LAW, the government shouldnt be the LAW would it be better to send a knee capper after them ? and tell me please how would disputes be resolved in your ideal world? sadly the world doesnt seem to work like that no it wouldnt bust a cap in his ass? governments tend to want to be the law additionally; even if you think that civil suits are an appropriate use of government violence, what contract did you have, exactly, with mtgox, that you are asking the government to enforce by way of violence? so becoming being violent criminals and thugs is better then asking government to help? mtgox claims he has a contract through tibanne I disagree I actually wish ppl go so far to sue mtgox, the first day in the court room it would be overturned and mtgox can sue them for unjust lawsuit due to no signed agreements xelister, I often get the impression from what I read on the forum that many hold this belief..that somehow you're not man enough if you ask for the help of whatever established legal and justice system there is in place it would give me epic lolz as if the only institution you can rely on is the fist and the gun would you really resort to beating up any unhonest trader like if it's Somalia, before just suing him like a civilized person? oh hey xelister, i'm not saying you guys should personally resort to violence... but filing a lawsuit IS asking the government to threaten and/or use violence on your behalf Building a better future is better than asking the government for help. Participating in the new exchange MT was talking about is better than demanding government intervention. xelister : suing isnt civil Juffo-Wup: I know this is not good, but what are other options Juffo-Wup, nobody is going to sue mtgox..maybe Kevin oh ok then but he'd have one hell of a time well, lots of people talk about it! they're just talking with their ass kevin would need money to sue and then money to payout cause he will lose hehe I ment to sue in civil for example, not neceserly to make criminal charges and use police perhaps that's rather my point Clipse, he could "bank" on the money he "earned" civil involves jurisdications lol now ur playing different cards xelister: the government uses violence in enforcing judgments in civil suits. ^--------- all this is general talking on enforcing trades. NOT about mtgox, btw Juffo-Wup: yeap sort of. this is not perfect too rather the threat of violence we are all winning for once the majority gets the better end of the stick and a few from the minority will have to deal with not getting cheap buys tough shit, majority rules if I would be Kevin I would definatelly sue which is enough to make people comply with the judgement of a court good times meh. got what I was looking for. Gox re-opens on friday. if I would be mtgox I would settle with Kevin time to go lay some video games. err yes; violence-or-the-threat-of-violence xelister : no u wouldnt and your not mtgox wow, brutal. Remind me never to trade on an exchange you build.. its easy to type that shit to do it is just stupid Clipse: for chance to get some part of 0.5 milion? I would try Yeah this is a bit rich. The latent purpose of bitcoins is to give people who are independent enough the freedom to make exchanges without the governments interference. Many people who were attracted to bitcoins were attracted to its anarchical quality. xelister : are u on crack, settle with kevin for what? money you dont owe him ? what crack are u huffing? thanks em; you stated the point i was trying to make very eloquently :) Clipse: mtgox automatically executed an BINDING DEAL where it promised Kevin ~200,000 btc. For their own fault. xelister: under what contract was it a "BINDING DEAL" ? rofl xelister you believe that? mtgox should erally invest in insurance did you just think before typing? really If you couldn't handle being on the frontier then why were you fooling around with bitcoins in the first place? You could just buy dollars and park them in Bank of America and be content. Juffo-Wup: under the same contract under which we all have some ballance in mtgox and we are sure that this money in that ballances belongs to us and we wait to be able to again use it xelister : u do know as it stands mtgox could legally take all the money and you cant say shit about it? LEGALLY that is? how does that feel? xelister: and what contract is that exactly? lol Clipse: feels good man. legally bitcoins are recognized as money contracts don't have to be written down so legally you're all trading in monopoly money all of us technically donated funds into an account with him. and legally..oh fuck it..when will this end ok copumpkin, did you make a verbal contract with mtgox then? Clipse: mtgox is a trading company incorporated in japan. If it would "run with the money" it would be same as if online shop would run with money&goods - it would be a common theft case even. hes not a sleezy fucktard and he is sorting this out Juffo-Wup: did you make a verbal contract with people in a restaurant to pay them at the end of a meal? hes not egold or flooz or piss pots like that do you think they'd have no recourse if you walked out without paying? * xelister kicks Clipse firmly in the balls xelister: oh, theft? again, asking the government to intervene with violence WAKE UP Clipse Clipse: read some facts. mtgox is a company. inc in JP. xelister : Im awake, but your paint keeps dripping you never signed a fking contract with them doesnt matter if they are the prince of tartland copumpkin: haha good one you handed over funds do you signe a fucking contract with newegg? without any trading conditions signed Screw legalities. What bitcoins have already shown. And what they will continue to show. Is that we don't need the government holding our hand to take care of ourselves. If you do, no one here will stop you from being one of the settlers and leave the pioneering to us. can you understand that ? people seem to think the law only applies to signatures * copumpkin shrugs what if newegg would run with your moneyz and your radeonz you ordered? obviously they would be thiefs and it would be a case for both police and civil armchair lawyers are fun em: +1 im just giving you the technical bullshit you dont seem to digest well... luckily mtgox isnt sleezy fucktards and they are doing the right thing to move forward for all of us and earn good living for themself the proper way. Clipse: what copumpkin said. Do not be a retard. Think of newegg example or any e-shop. Dont need signed paper contract to make legall binding agreement so are armchair libertarians :P xelister: have you been a party in actual legal proceedings? whether in the form of private arguments between lawyers, or in the form of a public case? Juffo-Wup: oh, I'm practically a commie :) wolfspraul: yes you guys argue about this shit for a few hours EVERY DAY. really guys? I still enjoy bitcoin xelister : haha thats where you are wrong, when you make a payment you can reverse payment if goods not reserved received thats your insurance geist_, cleansing the soul oh yeah i think bitcoin is great; i just enjoy pointing out inconsistencies in others' expressed political views :) xelister: what are the terms of service you entered into when starting to use mtgox? (not yours, necessarily [copumpkin]) have you read them carefully? Clipse: not in method payments like bank wire, which is 90% of e-payments in most countries other then USA * Clipse awaits made up terms from xelister Juffo-Wup: oh, yeah, there are plenty :) xelister : the sender for wire must proof he didnt simply make a donation or transfer to mtgox, how will he proof it was for a service rendered with mtgox? see? its not so fking obvious as you try to make it. honestly, i'm sure there are plenty in mine as well copumpkin :) wolfspraul: the ones that MT linked on forum. What part do you have in mind? Force majeure does not apply in gross negligence. consistency is for the weak it's much more interesting to struggle with reconciling your inconsistent viewpoints to figure out what you actually value xelister: "gross negligence" does not apply without the use of violence on the part of the government, so what's your point? oh jesus christ bleeding mary I give up, this dildo is living on his own pizza island xelister: I've never seen terms of service for mtgox. url? Just as soon as I am able to, I'm buying more bitcoins on mtgox -- Personally I'm very enthusiastic about bitcoins future, and to me I still trust mtgox more than the other exchanges, pending them sorting this out promptly and transparently. there are no tos for mt gox em: me too! :-) copumpkin: agreed, 100% wolfspraul: where are the terms of service for the vietnamese restuarant I went to yesterday? Clipse: are you dense or what. Apply waht you say to some e-shop, that you wire money to and that then tells you "fuck you" and doesnt deliver the good you paid for. Can you sue here or not? em good move, watch as soon as mtgox goes online all the other wannabe miniture exchanges will benefit with higher exchange rate having spelled-out terms of service simplifies legalities copumpkin: what's your point? xelister : Im not going to answer your paint anymore, I tried to start civil now its just silly to waste my time a tos wont hold up in court anyway my point is F*** IT, WE'LL DO IT LIVE! http://www.youtube.com/watch?v=5j2YDq6FkVE I really would love to see a transcript of a case against mtgox public somewhere, that would be so much fun. you clearly have your own rotten examples wolfspraul: having shit spelled out clearly is a safer option from a legal standpoint. It gives your opponents fewer places to fuck you em: it's already been neither prompt nor transparent, your statement seems an oxymoron. wolfspraul: http://legal.tibanne.com/Tibanne_ToS_20100131.html wolfspraul: not having them doesn't mean there aren't implied legally binding agreements when the judge tries to understand that you wire money overseas to some account, and then... :-) Clipse: ok, I accept your defeat. wolfspraul: yeah, that money was clearly intended as a gift wolfspraul: I'm sure the judge will think that you happily intended it as a gift * Juffo-Wup continues to compete in the special olympics I only dealt with a Delaware LLC (from dwolla to mtgox). xelister : ROFL @ the legal TOS and then got bitter and are pretending you hate it :) thats not directed at the site mtgox.com never with any overseass company. you stupid mother fucker Clipse: this is the link which MT himself posted, you stupid retarded as idiot Clipse: this is the link which MT himself posted, you stupid retarded ass idiot lol :-) dens you are stupid as fuck, Clipse.. this conversation is getting more intellectual by the minute From a legal fking standpoint that link means absolutely horseshit some language deficiencies shining through here * copumpkin grabs some popcorn wow what the this is even more off topic than -otc talk :) Clipse: again, this is what MT himself said are the ToS. So you are arguing against own point. Bravo =) * copumpkin isn't allowed into -otc so I have to settle for this better than HBO xelister : from a legal standpoint it doesnt matter if he said it or not The btc community has become quite a bit uglier since Sunday. I'm off, just wanted to give a good thumbs up to Mark & crew that link isnt on the "trading site" its not directly hooked Clipse: this is where mtgox.com side linked as ToS. xelister: there are very little grounds of any legal action against mtgox right now. anybody who sends money to mtgox should understand that. it has in fact from legal standpoint nothing to do with it IT WAS DIRECTLY HOOKED BEFORE SITE WAS FROZEN looking forward for the end of this drama, I really miss mtgox :) JESUS CLIPSE GET your facts streitgh nelisky: adam's name isn't "crew" any -otc ops in here who have noticed I'm not a mad spammer and could thus promote me a little sooner than my 7 days? :) there are no precedence cases, afaik there's only mark and adam? yep oh fuck oh fuck , do you see the name MTGOX.com on that form ? Please for the love of sweet wine wow, two thumbs up! tell me that and you wont and no terms of service, only bits and pieces you think entitle you to something cause ur a fucking dumb cunt arguing over shit Mark, Adam, major cookie points to you lol loooooool it's gettn wacky in here Clipse: mtgox.com side said it is run by Tibanne Co. Ltd. you would do everybody a favor by trying this out in actual legal proceedings, and - keep us posted... thanks for everything, hope it all goes smoothly tomorrow DOESNT matter what he said cant you fucking understand how legalities work et mon cul c'est du poulet at the end it comes down to (I'll be drinking and having fun by 3am, I hope) * copumpkin considers implementing dinatural and extranatural transformations in his current major project can you on paper legally proof that the promise was related to the trading site I think that'd be more useful for humanity than this that TOS doesnt show any mention of mtgox.com so you are fudged no matter what Clipse: if mtgox.com says that our ToS are on clipse-is-stupid-fuck.com , then the ToS at clipse-is-stupid-fuck.com are binding. You do not get that? shockdiode, notre poule avec votre cour xelister : no i dont get how you can be this stupid Clipse: idiot, I admit that your group with my yard? wat Clipse: idiot, if sex-toys.com says the GPL licence on GPL.org is their license, is it binding? even ig GPL DO NOT HAVE SEX-TOYS.COM IN THERI LICENCE TEXT? lol our chicken in your back yard lol nonsensical french saying okeydokey :) xelister : if the license is directly linked on the site yes of course if its linking externally no * copumpkin 's IQ is going down by the minute reading this its not valid! Clipse, xelister, either of you feel like you're getting anywhere? Clipse: mtgox.com fucking linked to the ToS that I, and MT posted. at this rate it'll be negative in a couple of minutes this is external link, it would legally not be valid according to what u want mr_gant : i think this paint might dry soon. Clipse: lol LINKED!! LINKED! u stupid shit its not hosted locally on the same server goo goo ga ga so maybe by tomorrow this 'debate" would be over? Might be best to leave it then. on the same fking domain god! xelister: can you try that argument with your lawyer? seems some people here just don't buy it... hey once that paint dries I've got some grass you can watch grow over here Clipse: so if mypaint.com says they are under CC-3, as in copyleft.com/..../ - then you say this is NOT BINDING because the licence text linked is on other domain? LOL? gigo gagao shockdiode, sweet..sign me up bro! you got it xelister : if the contract or license is listed on their domain and on their server then its legal thanks! if I don't blink for 10 min can I get 1 BTC? if its external link that could be externally modified its not LOL lol Clipse: you are fucking idiot, go fuck self with a rake i'd give you one if mine weren't all currently tied up somewhere... heh shockdiode, mtgox? shockdiode: where could that be! shockdiode, heh.. i'm not sayin Clipse: also xelister: sorry but this forum should be moderated and you should be banned maybe, maybe not xelister : want BTC donation ? I can send you 1BTC so you can buy water to wash that sand out of ur vagina Clipse: it is not 'external site' anyway, both domains are belonging to same company. shockdiode, hope it's not tied in some hacker's wallet wolfspraul: Clipse isn't being much more productive wolfspraul: I say get rid of both of them, even though I agree with one of them Clipse: so it was not EXTERNAL LINK (even if we follow your idiotic idea that it has to be internal link) no, that's your purview I'm afraid lool copumpkin : Im just trying to figure out how to best communicate with paint drying sad but true wolfspraul: we are not on a forum and perhaps some of u find this interesting don't wanna step on your toes xelister: the beauty of actual legal proceedings (not imagined ones) is that every side gets to make their arguments. and there is typically no limits in creativity (or insanity) in what kind of argument people will be making. you've got that move down ;) i keed * copumpkin used to hang out in the original forum anyone been there? heh rome is a nice city so instead of getting stuck on a particular argument, it's more helpful to clarify that at the current state of bitoin and mtgox, we are all in uncharted waters legally. Clipse: hey dumbfuck, the link was internal xelister : prove it? want to continue with this hmm..I got it..I shall hack KEvin! muahaha xelister: If I had admin powers, I would have already banned you, that simple :-) and prove you didnt modify it I demand a more creative barrage of insults to go with my popcorn you guys were doing great for awhile there oh and also show me your signature since its a financial contract wolfspraul: If I have admin powers, I would fuck you with a rake again if only for the use of inappropriate language oh I guess you cant shockdiode: Thou paunchy boil-brained clack-dish! sorry buddy Away, you bottle-ale rascal, you filthy bung, away! copumpkin: nice work, you get a cookie Be put in a cauldron of lead and usurer's grease, amongst a whole million of cutpurses, and there boil like a gammon of bacon that will never be enough. hot damn all I want to know is, should I paint this wall red or blue, eitherway it will still be a fcking wall sigh Clipse: no problem in proving it, moron, look: your'e on fire son whois mtgox.com Thou misbegotten whoreson foot-licker! * Retrieving #mtgox modes... Don't ban xelister, geez, he's one of the more strident supporters of BTC. He's not like all the recent influx of psychopaths we're being plagued with.. whois tibanne.com both are owner-street: Suginami-ku / Fleur Tsuzuki 102 same owner can easily have different terms owner-city: Kugayama 5-24-30 owner-state: Tokyo-to owner-zip: 168-0082 Clipse, xelister : You should be women, and yet your beards forbid me to interpret that you are so. what you cant understand without signed paperwork you have no legs tos tand on if you wanted to sue like a retard xelister: do you want to try your arguments with an actual lawyer? be not lost so poorly in your thoughts, the both of you lmao wolfspraul: Are you going to get a lawyer in here? : please do afaik mtgox is working on tos, which would be great for everybody, especially after they have been tested in court a little. do it now I have more paint to throw on this wall oh jesus where is the log PAINT IT paint the cat! wolfspraul: all e-shops have online ToS. And Clipse says for unknown reason mtgox.com online ToS do not count. Even if MT himself said they count. Even if they are both hosted on MT's/mtgox's company domains. He makes no sense. fucker deserves it midnightmagic: nah, too expensive. mtgox is run on mutual trust and legal hot air right now, fine by me. xelister : thats allmost hearsay btw carefull and i'll be going to the stfu corner for a bit, good luck all id bury u in slumcourt ! wolfspraul: Course, he'd have to ID himself so we can verify it with a phone call tomorrow.. :-) mt did link to that tos on the forum oh and it was a different owner back then OOOPS now what uncle fucker fuck this is so much fun Clipse: just out of curiosity, how do you think restaurants work? or stores? no contracts are signed noagendamarket: Clipse says it doesnt count, becaue there is no signed contract. Retards. How they find their way into out bitcoin community :( In all the time I used MtGox I don't think I ever read (and initially couldn't find) the ToS physical ones copumpkin : you enter property anyway he would just tie you up in japanese court for years Clipse: so if it's on the street, you can steal shit? * xelister enters Clipse's property and punches some brains into his skull copumpkin : thats not what I said How about a big group hug? I said it would be straight forward case, there would be visual evidence, recording, pretty obvious truth to the case that can be used that is EXACTLY what you said lying faggot, [07:01:44] what you cant understand without signed paperwork you have no legs tos tand on if you wanted to sue like a retard Im stating that online case the way this worked isnt so obvious * copumpkin sighs xelister: ahh. did you notice that the tibanne tos do not talk about financial services, bitcoins, fiduciary obligations, etc? xelister : thinks he can just stroll in and sue and have a open and shut case oh it definitely wouldn't be open and shut wolfspraul: I tried to explain that to him he was still licking his vagina i need coffee [07:01:44] what you cant understand without ---------> signed paperwork you have no legs tos <---------------- tand on if you wanted to sue like a retard * midnightmagic hugs Clipse and xelister.. but having a big-ass contract and/or TOS isn't necessary to have a legal case. It helps simplify the case a lot, in general * copumpkin hugs midnightmagic hey Clipse if you enter a fucking taxi, do you sign a paper contract too? moron :-D you could say getting an account is a contract Clipse: sure I am not replying to xelister because I think he will read it or learn, more so that we have some more sane voices too, and not just being drowned out by trolls. you see this all started with how xelister said ppl should just sue (or something to that effect) and I started off that there is no way you can just go and sue you can contact the rusiian mafia though :) noone said we should all sue mtgox Clipse: he can try, but he won't make it very far :-) if he can even pay the retainers or whatever the first thing his legal counsel would be asking from him... and yes I started to go wacko jacko cause I am not tolerant of people who ignore obvious shit illetare moron Im sure they will follow the tos [07:07] xelister: illetare moron <--- fucking priceless Im framing that thanks darling! yeah typos are important here whahahahaha its just so fucking ironic clearly we look at things at a bit other level. nah i allready ignored all you said just after you typed that can I hire you as a type writer? [07:07] xelister: illetare moron [07:07] xelister: illetare moron [07:07] xelister: illetare moron its just to fucking brilliantly summed up need lot of paper contracts, going to use taxi tomorrow clearly meant to say illiterate but your to fucking stupid to insult me ROFL you'r Or it was deliberate.. MORE HUGS! * midnightmagic hugs you. so we all (non-idiots at least) agree that ToS posted by MT are binding ToS for Mtgox accounts? xelister: bottom line from me: you can try legal action, but from my insignificant experience I would advise you against it, because most likely you will achieve nothing besides spending a lot of money and creating a lot of paperwork. And I'm sure - you will never go there anyway, just trolling here :-) (plus what ever paragraphs where general law overwrites ToS) well he never had a box to say you agree to them wolfspraul: yea that is why I said I would sue in *kevin* place - he has 500,000 USD to gain or more. so no noagendamarket: if there where no ToS, then general laws apply, so even better for customers I suppose I would agree with that normally shops put up ToS not to make problems for themselves, but to restrict the defaul power of customers over such shops etc however sending someone money voluntarily means youre screwed not really I never agreed to ToS. I just hoped and jumped off the cliff after I heard Art used MtGox :-) basically he owns it hey noagendamarket you said you will sell r5970 for 5 BTC? still valid? (assume) yes still valid, xelister noagendamarket: ok, deal lol no, despite no written or electronic contract or ToS if I would send you 5 BTC and not get the good delivered (or easier - send USD) then I'm rather sure it is both civil case, and even for-police case right? s/no,/now, no,,,what goods were you promised ? its not like mt gox sells shoes if you would promise to sell radeon 5970 for 5 btc they dont sell anything they are company making legall profit, and they are registered as money exchange or similar service they are making profit on what? not on donations, they are not non-for-profit organization are we solo dancing? Im back.. ooooh again a retard statement Donations can go to anyone so it is on sales. Or fee for using the service (successfully) if they dont refund your trade fees then you might have a case I would say it is their core business to either 1) sell bitcoins or 2) provide service of automatic trading xelister : so you make the rules now? should apply for job at mtgox with your knowledge in either case, kevin used this service as always, but this time the service's part of deal was not keept theres plenty of cases where other markets roll it back no one gets sued for it while you can rise objections of @0.01 sell being ridiculous and so on, there is some case to consider xelister: I got some wise words for you, BEING STUBBORN DOESNT MAKE YOU RIGHT. and its all in caps for easy reading if the price was $5 now youd be clamouring for a rollback too there where cases with e-shops accidentally putting say HDDs for 1 USD or so. Their settled or complied lol xelister : thats before anyone used e&oe add that part and you can do whatever the fuck you want thats be resolved ages ago noagendamarket: this other places that did rollback, didn't they had clever ToS for that occassion before you could reach the keyboard to type porn on google I dont know the situation * kB is now known as Guest3950 Have you buys received confirmation emails for the claim process where they verify you own your account yet? noagendamarket: that MT's ToS ... if it would said like "if we are hacked then we can unroll what we see fit" then they would be clear probably xelister : I think I should sue you now, I had this vague idea that if I communicate with you it would be a binding promise that I wont get assaulted by shitty arguments. but that ToS just contained general Force Majeure which will not apply (it was their fault, preventable) you laid a false claim, who should I mail the lawsuit ? Clipse: you did not paid me to talk to me, dumbnut I did in valuable time if you paid someone else to do so, sue them time = money I lost money sarlangg: I haven't yet. I sue you If you didnt trade and suddenly there are bitcoins missing that would be grounds for something midnightmagic: Thanks, was wonderig if it was just me. wondering* Clipse: you are probably too slow to understand this, but mtgox.com was operating as a company and taking money, while I'm not other then that your example would make some remote sense xelister : what more do you want, read mtgox statement We realize that it will take many steps and vastly improved security to regain the trust of our users and the bitcoin community, but for now as a token of our gratitude for the extreme patience our users have shown, and as a way of saying we sincerely sorry for the breach of security that lead to the sell-off, we will be reducing trade fees to 0.3% (from 0.65%) for two weeks following Mt.Gox's reopening. Users who's trades were effectively cancelled during the the sell-off will be able to trade for free for 1 month following the reopening, and will also receive a free subscription to our upcoming 2-Step security authentication feature for as long as they hold their account. Isnt that as professional as it can be ? cancelled trades 1 month free trading noagendamarket: but this is the case. Kevin traded, wants to take out the coins system confirms he has... and now the coins will be missing (rollback) jesus now u think I should complain ? I had no trades god please drown urself Clipse: we are talking hypotetically about laws and ToS to learn something, not just bashing or defending mtgox.com case, as you probably think we are, close minded person you xelister : oh I didnt see the TOS for our discussion I could only make assumptions you seem to be good at that If I find a bag of money on the side of the road I dont get to keep it honestly noagendamarket: yes you cant sue the person who owns the cash and expect to own it then noagendamarket : this is all "hyptetically" according to xelister please dont divert the "hyptetical" discussion. noagendamarket: what if you go to a shop and see some painting for 50$. You buy it. It turns out it was picasso, and shop owner fucked up 1) allowed prices to be messed up 2) sold you the picture with such prices If kevin thinks he owns it then fuck him xelister : you must return the painting and get back your $50 from the owner. with the painting too? You say you do not own painting in above example? the shop owner that is althought a reward for returning the l;oot would be nice its pretty standard stuff mtgox is doing exactly that, hes returning the "painting" and returning the buyers money. right we all agree to moneybag-loot, but this is really more of shop with messed up price-tags problem hes getting one...free trades oh and hes giving freebees hes doing more than the normal trade would be Actually if the seller didn't know and deliberately priced it at $10, and there's no fraud, customer keeps painting. Antique dealers do that all the time Clipse: you do look like some retard hired to spam pro-mtgox support messages... can't engage in constructive broad discussion then go fuck self with a rake xelister : its not possible with you , cause you want me and others to agree to your ideology from every new angle you sir are full of shit we started arguing about what mtgox should have done, then you decided the argument is "hypotetical" and not about mtgox nemore I am pissed for the private emails leaking out midnightmagic: so if seller made the mistake, then indeed he should execute the trade - and it is all on him to recover his mistake, right? what the fuck is wrong with you not so much the rolled back trades * Looking up Clipse user info... xelister : if the police approach the buyer of the $50 painting sold by the shop priced at $50 (correctly or not) then it will be returned as original stolen goods if declared by the certified painting original owner this is standard stuff, why do you feel the urge to change the normal procedure? greetings its a wonderful day If the product was sold mispriced by the Original owner(read: not a stolen then sold product) the price would usually stand. This is not what happened with mtgox, situation described first is related to the mtgox situation. Clipse: yes it would be returned, and the shop owner should return at least the price a transaction requires the consent of both parties. in this case, the seller did not authorize the sale, therefore the transaction is null. taking the coin would be an accessory to the hack xelister : correct! ding ding but also due to his mistake the buyer lost awesome deal and this shop owner is returning the price who covers for that xelister: If the seller priced it at $10, and the painting was rung through, and customer did no fraud, I'm pretty sure customer keeps painting. Now, if another customer marked it down first.. Well, stolen goods. "awesome deal" doesnt matter Jesus. Dear guys who have no non-bitcoin trading experience: Flash crashes and subsequent rollbacks happen all the god damn time. There's an extreme precedent. I'm pissed at Mt. Gox because I had low buys, but anyone who has ever been through a flash crash before knows the routine but buyer had lost a painting actuall WORTH 100,000 USD. Lost it to police, due to SHOP fault. Should shop return the 50$ he earned, or should he return the WORTH - 100,000$ to the buyer Ooofo : carefull dildoboy might try to hurt your feelings. xelister : $50 aka sale is voided cause sale wasnt LEGAL xelister: The analogy fails because another customer is interfering.. Ooofo: who uses rollbacks? Do they have speciall ToS for this? you cant make a legal trade with illegal goods midnightmagic: another customer? watafak Sorry.. Criminal. xelister : are you a troll out of a fresh bush? your either extremely retarded or absolutely ignorant id hope for the latter Clipse: you write many words by little sense. Shut up the fuck, you must I write english, you speak baby. gooo goo gagga english xelister: you met anyone who's recovered yet? * csshih burps hai gais bougyman: noone is recovered, they announced afaik xelister: ah. midnightmagic: hm? I actually hope mtgox keep xelister's total booty of 0.20 BTC want to see xelister fight over it on fox news with pop corn and slush puppy midnightmagic: where exactly does analogy not hold? xelister is a cool guy not sure wtf you're talking about csshih : he might be cool, but hes dumb as turd no he's not xelister: you're getting a lot more profane tonight. have some chai tea. er chai you can't pass better title than you have is all you need to know damnit I hate it when people say chai tea, and I did it. csshih : ok hes terribly misunderstood xelister: Because another person stole the paintings and marked them down first. do yourself the trouble and scroll all the way up from start of argument, he position on the situation and where we are now xelister: the buyer can't lose something he never actually owned no progress, absolutely dillusional you can't pass better title than you have is all you need to know anyone else notice this? http://www.reddit.com/r/Bitcoin/comments/i6un9/more_mtgox_conspiracy_theories_the_43210987654321/ yeah it's reddit, though Here's a good article on non-bitcoin flash crashes and rollbacks: http://tinyurl.com/6k8vg4c the thief never had a property interest to sell so bigtime grains of salt. midnightmagic: since all the stealing, and re-selling-stolen, are all allowed by fault of the shop, should not the shop take on itself most part of resulting problems like need to return the painting that was worth 500,000 bougyman: I was speaking more to the fact that the balance of the wallet in the transaction was 432109.87654321 xelister: the shop is holding the painting on consignment for the actual owner, who has not authorized them to sell it for peanuts or, read backwards 12345678901234 xelister : how many times are you going to ask and receive the same answer? xelister: As the owner of an actual retail store, absolutely not, since it's not possible for me to pat down everyone who enters to make sure they dont have a pricing gun! :-) Former owner.. midnightmagic: someone priced the store at 0.01 and bought it from you? this is the 5th or 6th time you ask the same question, receive the correct answers and just keep firing it again. if BTCs would be stolen from credit card, then sent to mtgox, and so on, then it seems obvious mtgox (esp. if ordered by police, but not only) is free to block such trades and reverse them with no extra recompensations of course yes, shouldn't they? midnightmagic: ^ but this case is different, as here the mtgox ALSO allowed the steal in first place. You see difference? It is like coming to car salon that sels cars for 100 usd "sorry sir we messed up prises" "well thoug luck, I keep this car suckers - LEARN TO KEEP ORDER ON PRICES guys" kind of thing *typos the onus is on the buyer ALLWAYS with stolen property not the middle men you'll find that many stores won't honor a sales transaction for a hacked price if you buy something, "to good to be true comes to mind" then its your problem as the receiver xelister: No, because the cars were stolen and marked down by another douchebag without authority to do so. Mr2001: I know some shops do order prices resulting from own mistakes for example *do honor xelister : no shop will honor a product mispriced for $5mil go1dfish: yeah. crazysauce Clipse: this is a bullshit law, and fortunatell does not apply to BTC. Rememer they where @0.20 not so long ago xelister : so now you decide what law applies and doesnt applies? i didn't have a whole lot of btc in there, but quite a bit of USD * Fairuser|AFK is now known as Fairuser can you stick to one story? there was person orderd by court i've not heard anyone say the USD is safe, but i'm hoping it is. and not cherry pick please to honor a sale misspriced by ~20,000 USD. A private person, not company. (he sold his car for like 500 usd by mistake instead 20,000) the 500 000 never existed in the first place imo you just said, "bullshit law" and by your own decision it "wont apply to BTC" then you rip other laws out, "general laws" as you said, which do apply. what the fuck dude? xelister: in this case, the item was mispriced by a malicious third party who had no right to sell them, not by some mistake of the owner okay, I have a problem with people treating an exchange as a counter-party to trades Eh, doesn't matter. Nobody's out anything but time, so who cares.. i'm not treating them like that. Clipse: I can buy grossly under priced BTCs if I like / find a sucker, and no-one should block this possiblity. (not talking about hacking here) i'm treating them like either a money escrow or money transmitter, take your pick., the exchange facilitated the trade, sort of like how a hand truck facilitates stealing a refrigerator, but just because you can take possession doesn't mean you take ownership you want to see price-setting? rather than roll back to a time, most exchanges would just undo trades below a specific price xelister : yes you can, and if its stolen BTC it would be wrong. same goes to stolen BTC on exchange is wrong, luckily MTGOX can revert it to correct the wrong. lets remove any legal jargon and stick to right/wrong argument Ooofo: well we sure know what will be first paragraph definatell in new mtgox's ToS =) it was wrong, and in this situation mtgox can fix the wrong and make it right. Ooofo: Got any specific examples I can go verify myself? ToS is not important in comparison to standard practices. if it was a straight BTC deal you had no recourse, we actually do with the exchange. if you believe in property rights, you favor a rollback. if you don't respect property rights, you prefer to let the thieves get away with the loot "We can do ROLL BACKS when a) we are hacked b) .... c) ... d) ..." - sheeesh someone should think of that when crossed 1 MILION USD volume ;) Clipse: they cannot fix it for all, only for some. some lucky few got away with stuff, unless they have a time machine. * jetcore is now known as jetcore_ bougyman : for all, you couldnt buy stolen shit in the first place(or incorrect values that doesnt exist which would be paid out from other members) and some malevolent few, too. yeah, midnightmagic, look at that link I posted a second ago: http://tinyurl.com/6k8vg4c bougyman: mtgox is covering out of their pockets what? he said so himself the few that went out they have to cover it wasnt that much apparently mtgox is making like 10,000 ? 100,000 ? usd so they really should Ooofo: Also, these aren't securities, I'm not so sure it quite applies.. These are math results.. Honestly I'm not even completely sure we can "own" them. xelister : who are you to decide how much they can make and then how much they must put aside for others? midnightmagic: the site used to say "Buy and sell the commodity known as Bitcoin" even if they made a billion a day Clipse: batman they have no obligation to give out freebees of stolen funds i thought that was risky, inviting Commodity Trading regulators. xelister: CATWOMEN you sure do sound like one anyway... no one has gotten claim approval emails yet, have they? no and you sure sound like a turd dropping no Mr2001: no one was yet actually processed don't worry, they're doing all they can, just be patient. Clipse: well perhaps, I never talked to urmom Ooofo: Cool link!! xelister : she doesnt hang out in the slums you live bougyman: so the deadline is friday it seems what deadline? ok. when should we contact support if it hasn't arrived... by the time trading opens? bougyman: /topic Mr2001: within next 24hrs you will receive email you're gonna believe a timeline they present? exchange goes back operational within 25hrs roughly from now sorry, i lost the faith in their timeline predictions. bougyman: 3rd times the charm, if not Im going ballistic the 432109.87654321 output was created on the 12th.. a week before the incident MagicalTux: you around? MagicalTux: the latest update should be "Users whose", not "Users who's" I wonder how quickly SHA256 is going to be broken now haha.. copumpkin : hes french, atleast hes not retreating ;) you're using sha512 tehehehe damn had to :D Clipse: :) isnt MagicalTux JP no he lives there I'm not using sha512. Anyway it's all the same sha2 family lol must be hard time communicating. Don't all FR people speak only fr =) lol so now we have to pay mt gox for a secure account ? xelister : no the academie francaise would not approve of these other languages being learned wtf dudes some frenchmen can speak english, but they die a little inside each time noagendamarket: pay for a secure account ? noagendamarket : just for the absolute last resort secure method if you want it http://forum.bitcoin.org/index.php?topic=21405.msg268477#msg268477 they are giving ultimate extreme security options , most users wont require that, its for the absolute dumb retards. OMLET DU FROMAGE the baladeur and the ordinateur, and even the magnétoscope * copumpkin tries to come up with a suitably french name for bitcoin Clipse: so you applied? got a /written contract/ this time? ;) Clipse shouldnt all accounts have that ? monnaieoctet? xelister : on my cock noagendamarket: really mtgox's approach to security is scarrying... retarded people are smart enough to pay for security? copumpkin: corrected the "Who's" they security they are talking about the the fob that seems counterintuitive. MtGox_Adam: oh cool, didn't notice you here. Thanks! noagendamarket : afaik it cost them money, I dont know.. really dont care, just keep the database safe and my account will be safe copumpkin: thanks for the heads up :) when did the support site change from green to yellow? monnaienumérique? MtGox_Adam: np mr2001: I changed it about 45 minutes ago Doh, where's the update? monnaienumérique seems about right Mr2001 : exactly 24minutes ago oh sorry i meant 42 ;D MtGox_Adam: are you french? kind of funny that the 432K was moved on the 19th without a transaction fee Mr2001: it matures copumpkin: Negative. MtGox_Adam : are you cuban ? sharkasgo: ha. Yea we can have it in next block. Or week. Whatever lining up stupid questions ;) Clipse: I wish, but no xelister: but autumn isn't for another few months MtGox_Adam: was hoping for some native validation of my new name for bitcoin :( MtGox_Adam : are you female need to bitcoin forum post all answer cause if there isnt answers it means mtgox is running according to them. MtGox_Adam: did you all got drunk on sake when you realized you don't know first thing about security so spit out all answers asap ;D Clipse: Depends, will I get me anything? MtGox_Adam : it will get you a corner on longstreet with your name on it :) well, glad things are on track, I hope everything is right in my account when it's back up, but I trust mtgox will make it right if not MtGox_Adam/MagicalTux: Knock on wood, but congrats on the relatively rapid turn around. yeah you guys are doing a fine job under extraordinary circumstances Adam: We were shaking our fists at the screen here when Bruce said Canadians were the "same thing" Boo! Hiss! lol arent they ? :) heh intersting idea, what would had happened \kb noagendamarket if the 1000 $ / person-day limit would not be in place then we could money launder with impunity *hypothetically kevin would get 400,000 BTC he would probably have hit the limit of bitcoins we keep online would run for Mexico... MT would run for China? Taiwan? * xelister calls profesor for 1 what-if machine someone would be wearing concrete boots over that Im sure :) I don't want to imagine the bitcoin market once the japanese mafia finds out they can use this for a lot of things just the japanese mafia? wait till some politician finds out they won't have to hide their kickbacks and bribery anymore lol I wonder if there will ever be a "bitcoin mafia ? -------------------------- wait need me to protect your miners? HOLD THE HORSES DJ Mark Karpeles, the chief executive of Tibanne Co of Tokyo, which operates Mt Gox, told Thomson Reuters that the company was not averse to cooperating with authorities. "As a company handling Bitcoins, it is not our intention of doing anything illegal," Karpeles said via email on Tuesday. "We sent a letter to the Drug Enforcement Administration to address this issue." of course you do mtgox leaked our userbase + emails + passwords and now they bring in DEA ?! Why dea? silkroad Srsly? thats just fucked up... http://forum.bitcoin.org/index.php?topic=17693.0;all hmm well wait, that is just letter with explanation but. hmm.... was "the auditor" a dea agent ? the dea are idiots in the cyber arena calling mr. Green Thumb from CYPRESS hill * xelister has 4 cypresses and buying more libertarian holiday: http://www.youtube.com/watch?v=saWCZVggQAs MagicalTux: 432109.87654321 is that pattern random, or was it chosen deliberately? by patern I mean the fact that it looks like a countdown probably deliberate so it would be easy to search for go1dfish: it's deliberate want me to do it again? :) MagicalTux: yes, if you could send like a tiny amount to an address someone throws out that would do a huge amount to restore confidence I broke out the 432109.87654321 already but I'll make a new one I wonder if I've reclaimed my account correctly... do .424242 xelister: 424242.42424242 ? yeap just need to see a transaction happen from an account with a huge balance with an amount listed here to an address listed here connecting the offline storage and decrypting on a firewalled system~ 1AbTRVrRYGri1sZvqHBadnXaCHkuXJtV5N I'll make the transaction and push it manually this would completely restore a lot of peoples faith MagicalTux: post an address and I'll send you an amount MagicalTux, to get the "free month of trading" thing, will that be automatically done based on rolled back trades or do we have to apply somehow? Ooofo: it'll be automatic awesome I got all the data of all the affected users here go1dfish: no, not practical ok go1dfish: I'll send 424242.42424242 bitcoins from a bunch of 50kBTC addresses (and maybe on 42kBTC) to one well, two actually one will get the 424k, the other one will get the change ok, yeah all transactions get split that way as I understand it ready guys? Don't come after me claiming we have no coins after that hopefully I'll be able to work without getting too much disturbed after that~ yeah, ready MagicalTux: wasn't your last tx 432K btc? lost 8k? no thats just the amount someone suggested (the 424242) ah 42 is the answer to everything 42 is my password! lol hehe ic 42 is the solution to every block to wait what's going on, is he proving he has our bitcoins still? shit I just ruined the economy what does this help theres a lot of people crying wolf saying gox doesnt have their btc anymore don't send them to the bitcoin eater please :) mabus: tux is shuffling large numbers of bitcoins to show they are still under his control anyway, going to send to 1eHhgW6vquBY... the 424242.42424242 btc ok mh, forgot I cannot get connections from here, IRC is blocked MagicalTux: how is it going with the account claims btw? please dont accidently loose it all well then remember to transfer the 424k to proper address of 1R1QyDyYdV479bGxNGMVLEbhU3nEhx6u2 haha, raped. mabus: lol raping bitcoins mabus: I can't copy/paste from here to over there kingzzz: +1, imo it's better if he doesn't play around with his stash it's not the same computer, not the same network i'll read it over the phone if you want, i'm a nice guy lol anyway mtgox back open on the 24th to continue raping you... lube up your e-ass honest rape is fine meanwhile, I expect lulzsec to tweet that they're about to move 424242.42424242 btc ;) lol xD that would be funny 46 and 2 just ahead of me anyone here ever seen tom wopat's hairy butthole? all sweaty and sticky rim it! so wait you can't connect to the machine with the bitcoins, sorry im confused, it seemed like it was no problem before i'd stick a cracker between his ass cheeks and sop up all that sauce And now...? notallhere: who are you talking to ? dwebb: ... wut you MagicalTux cuddlefish: haha notallhere: the bitcoin client is not getting connections, that's a usual thing socks4 MagicalTux: i run with -noirc, usually connects faster. MagicalTux: upgrade .23 to solve that, FWIW. (there is a connect bug prior to .23 which can make every failed attempt take minutes) try starting bitcoin like this: ./bitcoin -addnode=69.164.218.197 -addnode=64.22.103.150 -addnode=173.242.112.53 -addnode=178.79.147.99 -addnode=184.106.111.41 -addnode=91.85.220.84 dwebb: if you addr.dat is full of crappy non-working nodes already it can still get hung up on the first one it tries. lies. * nanotube is sad nobody is wielding the banhammer indeed i need to go squeeze out a bitshit I got one, here MtGox_Adam got one too dwebb: facts. but fixed in .23. (not suggesting that MagicalTux go about upgrading the uber wallet right now though) gmaxwell: I always wait at least 1 month before upgrading bitcoin or port patch manually MagicalTux : can you clarify something for the bitcoin forum people, the security issue. Is it going to cost a fee (once off or monthly) for the security addon for users? oh got one connection Clipse: you mean the sms thing ? the connect patch is pretty straight forward. I've was running it for weeks prior to .23 ... and it even applies to way old code. -ChanServ- Invalid parameters for REGISTER. -ChanServ- Syntax: REGISTER <#channel> nope refering to the "free security addon for people who had trades open for a lifetime of their account" that looks like its not free for other members what do you refer to with that? -ChanServ- #bitcoin-mtgox is already registered to rasengan. they're the ones that get their passwords properly encrypted? lol mabus: 0.1 BTC per byte of hash my bank has a token that costs $25 hah nehow let MagicalTux answer before you lots spray your diarea all over this channel ;) MagicalTux: Yeah, do OTP auth! it's really easy to implement if you can email/snail-mail stuff cuddlefish: working on stuff even google sends me a postcard :) cuddlefish: oh fond memories of s/key... I hope its not rsa key :0 I checked RSA key just to see it's 500kUSD setup, and 100kUSD per year not viable They're rather expensive. yea. MagicalTux: christ cuddlefish: ? fuck bitcoins, i should sell rsa tokens MagicalTux: mail out arduinos with LCDs and seeded PRNGS! it'd be cheaper i vote for gpg auth via signed or encrypted otp :) there is competition which is less expensive, e.g. http://www.cryptocard.com/ nanotube you would :) cuddlefish: a bit too big <[Author]> MagicalTux: How about http://code.google.com/p/google-authenticator/ ? noagendamarket: :) But you're still talking on the order of $50 tokens all in all. MagicalTux: D: gmaxwell: Gosh, if only there was a way to pay for things over the internet lawl ye like to transfer shit oh well ;) mh the bitcoin client rebroadcasts transactions randomly every how ? MagicalTux: 30-60 min, iirc cuddlefish: well if you really want something personally buy a yubico and load it with a long random password. gmaxwell: it's not two-factor and it doesn't change cuddlefish: yubico can how, though you need software support. it can work in a challenge response and a skeyish mode. gmaxwell: sure, but MtGox does't support it the skeyish mode doesn't need client software support. gmaxwell: wait, what? * kapejod_ is now known as kapejod it automatically changes your PW? cuddlefish: it needs server support. gmaxwell: yes, exactly cuddlefish: the challenge response mode requires something on the client too— it doesn't just act as a usb keyboard for that. for RSA, the key themselves cost only 50$ per key, the server support costs 500kUSD + 100kUSD/year MagicalTux: I, personally, would pay <= $100 for 2-factor auth MagicalTux: http://www.yubico.com/ No server costs for yubico otp mode. gmaxwell: I don't like this "cloud" thing relying on a separate server for that we only paid 20k for setup where i work MagicalTux, admittedly that only came with 1 appliance and 30 keys, either way it was a waste of money as they are now compromised also is this yubikey compabible with most OS ? notallhere: I asked for a server license for 5000 keys :p MagicalTux: yes, everything. It's a USB keyboard as far as the OS is concerned. oh nice hey people, you prefer black or white ? :D MagicalTux: and there is regular open source authentication code for it. In one time password mode it's just like skey.. you hit the button and it plays out a fresh password that only the server can validate. tokens? black always bet on black :) black I knew it MagicalTux: isn't white the "war colour" anyway? :P its the apple colour :) MagicalTux: Heck, just give us a PRNG algorithm and a per-account seed. we'll figure it out from there purple :P xD ordering some yubikeys MagicalTux: secureID tokens? securid = RSA yeah, i saw mention of that up above. just wondered if that's the ultra security package. you could do a btc transaction based login system, or at least a way for someone to unlock an account. send 0.x amount of btc from a pre arranged address. i guess you'd be fucked if someone stole your wallet though notallhere: not even needed to send money, you can sign messages with your bitcoin private keys, there's a patch for that somewhere also, wasn't rsa hacked a few weeks ago? and another thing i can't understand, is why they stored the seeds for tokens they already sold and the information on who they sold token with what id would be good if a yubikey generated a btc address lol but I think an external device is better in this case ar: customer losing their seeds MagicalTux: the seeds are on the keys client ssl certs aren't that expensive, and people could layer their own factor on top of their cert. get the yubikey to generate a bitcoin address then send coins to it and they have the seeds on a machine connected to the internet... that was indeed lame MagicalTux: or at least the serial numbers on which the seeds are based ar it was hacked, but only if the attackers are able to keylog a number of valid logins from someone with a key, i think they figure out the seed this way bougyman: if someone compromises your system and can sniff your password then they can grab the client cert too. I know that PCI thinks client certs are two factor, but I think they are stupid. gmaxwell: right, that's why I said users could add another factor. notallhere: I think they just need a number of valid ones in order to sync it. like a biometric device to unlock the client cert. it's not two factor with just a cert, I agree with you. mtgox iris scan :P bougyman: which leaves the cert in ram where it can be copied by a trojan. :) (but we're mostly agreeing, I agree) they control that cert, they can protect it as much as they do (or don't) want. seperately from mtgox we need to convince yubikey for a key with firmware that can hold a bitcoin private key and sign transactions presented to it. :) bougyman: what biometrics? fingerprint readers can be easily fooled yes ar: again, that would be up to the user. you could plug it into the bitcoin client fingerprint is rather weak. like protecting your bitcoin wallet, there's only so much you can do. if someone owns your machine, they own your machine. yubikey ordered noagendamarket: sadly the low cost formfactor of the yubikey would give it no way to independantly show you the txn before signing it, so a trojan could just feed it txn to send all your money to the badguy. :( http://bitcoinmonitor.com/ <- btw, 424242.42424242 :( bougyman: not so, if you had a secure hardware device with your key in it and a little screen to show txn for you to approve, then your machine could be owned all up and you'd be mostly safe. right, then they just have to steal that little secure hardware device thats a whole lotta bitcoins gmaxwell: yep it should show the desination address as well as the amount bougyman: plus the password used to encrypt the key in the devices memory. linux-livecd is what many people use for secure browsing in their ebanks etc. wumpus: yea, it has to show the output address and the amount. bougyman: and they couldn't do this from their desktop in nigeria. :) (well they password they could get, but they'd have to fly to wherever you are and mug you. Unless you're in nigeria, in which case you're screwed) wumpus: it also needs some mode that lets you copy out the key onto paper to make a backup in case of loss, but I'm not sure how to prevent someone from using that while you're not looking. :( (you put the paper in a safe, then put the safe in a safe) gmaxwell: that's the eternal dilemma isn't it, either you secure it very well and lose it easily, or you have to spread it around a bit with higher risk of stealing but lower risk of loss - MagicalTux is ~MagicalTu@unaffiliated/magicaltux * Mark Karpeles MagicalTux on #mtgox +#bitcoin-otc MagicalTux using kornbluth.freenode.net Frankfurt, Germany MagicalTux is logged in as magicaltux MagicalTux End of /WHOIS list. - wumpus: yea, I think for most people the risk of loss is actually much greater than the risk of theft. I expect a new rash of "omg lost big wallet" threads in a month or two resulting from the security concerns now. especially after encrypted wallets get deployed. yes that's also holding me back from implementing things like external wallets - MagicalTux is ~MagicalTu@unaffiliated/magicaltux * Mark Karpeles MagicalTux on #mtgox +#bitcoin-otc MagicalTux using kornbluth.freenode.net Frankfurt, Germany MagicalTux is logged in as magicaltux MagicalTux End of /WHOIS list. - I'm dead scared of users misusing the feature and accidentally deleting wallets gmaxwell: WALL OF TEXT and yes with encrypted wallets users have the risk of losing the key to encrypt the wallet, with no way to recover it ever wumpus: kinda makes me wonder if the encrypted wallet shouldn't support some kind of escrow feature on day one... good point... or some kind of "here is a printable version of your master key which is weakly encrypted so that decoding it requires searching a 48 bit keyspace; print it and put it in a safe" so ive been afk for a bit, did the transaction go through? http://blockexplorer.com/address/1eHhgW6vquBYhwMPhQ668HPjxTtpvZGPC yes awesome, that explains the price rise [10:04:04] Has anyone received their account back to Mt.Gox? [10:04:34] I've been waiting 41 hours after submitting the claim page proof etc I have not. gmaxwell, rofl @ 42 if this works fine, we'll provide yubikeys with AES key private to Mt.Gox cool MagicalTux: what percentage of account requests have been approved so far, out of curiosity? What is the average wait time for requests to be approved? i dont think theyve started sending out confimrations yet tuoppi: 1 day past the time you stop asking so.. infinite so far MagicalTux: can I use my own yubikey? - I already have two Ycros: I don't wanna poke the yubikey servers, but I'll see I just ordered some yubikeys for the people here MagicalTux: you don't have to poke their servers and to ship too Ycros: if you use the yubikey AES key, you do, right? you can run your own stuff, there's open source implementations of the server-side stuff you can integrate it into pam, your own websites, etc. I guess yubikey doesn't give their private AES key to anyone MagicalTux: why not just support OATH OTP? We can install our own softkeys on iphone/android MagicalTux: you can upload your own key into the yubico servers i think yubikeys are OATH compatible also anyway they are oath compatible MagicalTux: the thing about yubikeys is they're reprogrammable MagicalTux: working with yubico's OTP is merely a default setting yep I saw that you can give me a private aes key for me to use, and I can program it into my key and I plan to reprogram them a bit :) the keys will support 2 different programs I'll make it possible one is on short press, one is on long press need to try here first 1~2 weeks for shipping they say can someone ban this retarded "HamWallet" from support.mtgox.com? this kid has some serious mental issues EskimoBob: url? https://support.mtgox.com/entries/20208066-huge-bitcoin-sell-off-due-to-a-compromised-account-rollback?page=8 User suspended yeah thats obnoxious you can find hes verbal vomit from every page, He keeps changing hes name and with a userpic like that he's obviously from 4chan have claims started being accepted/rejected yet? are there rejection emails? My status: "Account recovery request submitted at 2011-06-21 16:12" - Your account recovery request is pending review by our staff. :( and my IP must be easy to verify * LightRider is now known as LightRider|afk MagicalTux: thank you eskimo, same message will send the first batch by tonight (japan time) thanks oh neat tokyo is only 1 hour behind me Tonight? wil do me no good. We have the national summer solstice holiday tonight. I'll be drunk like (75-80% of the country) and probably dancing around the bonfire with naked girls. And yes, tomorrow is a day of. *off what country is that, I think I need to visit Ycros: I think most of the Scandinavia has a this as a holiday. We have it bit late because of the modern calendar and some other holiday yop no wonder most people have a birthday in march 8=D EskimoBob: hahaha What happened to lulzsec? Also, when is my account going to be reviewed? I sent in the form the day it opened I mean, take your time But I really really really Don't want to miss mtgox opening Shocky: https://support.mtgox.com its all there How do I know if my claim was successful? Would it have told me if my password was wrong? would it have mattered if it did? Will the mtgox API remain unchanged? anyone could have already checked beforehand against the compromised db hm that would have made sense I would expect it to reject you if your password was wrong deego, the API seems still working but disconnected from their DBs and everything.. ah, thx ox8o deego, but they'll change it for sure.. probably not a lot just the authentication way.. maybe deego, or implement a 2 factor verification APIs when that comes up ox8o: this url: https://mtgox.com/code/data/getDepth.php leads me to the "hacked page." ooer yubikeys. are they two-factor auth key thingos? deego, as I said it's not active.. but changing the API doesn't make since unless if they add some new functions to the website deego, such as the 2 factor authentication or a more strengthen authentication algorithm ox8o: got you. https://store.yubico.com/ those are a very good idea that keys.. to russia it will be pass month and over.. and it cannot stop from hacking site or db phantomcircuit: yep, I suggested them earlier and apparently MagicalTux has already ordered some. yeah pretending to be a keyboard is particularly clever so the key can be long :) MagicalTux, lol the key doesn't need to be more than a few bytes actually phantomcircuit: are ubikeys two-factor auth? yubikeys * thermal, alone? no but combined with a separate password yes ah ok. it'll be combined with a separate password MagicalTux, how about requiring a dna sample too just to be sure * phantomcircuit trolls on out of here phantomcircuit: yea, sadly the keyboard trick isn't good enough for challenge/response. And IIRC the challenge/response they do doesn't allow you to use one key with multiple mutually untrusted parties. But the OTP mode is fine for mtgox's application. MagicalTux: why was this channel registered to LulzSecurity earlier this past day? MagicalTux: trading is working? mtgoxlive shows something, but mtgox-websocket is silence Raccoon: by a troll claiming to be lulzsec zelyony: nothing I'm fixing the data while importing the trade history will be fixed for all past trades MagicalTux: but rather, how did they attain 'founder' status/privs in here? MagicalTux, you got freenode staff to change ownership of the channel without forcing you into ##mtgox!? amazing Raccoon: I never created this channel in the first time i see im surprised they haven't closed down half of the bitcoin channels and forced them to ## yet hell even php is in ##php i take it that freenode transfered rights over to you. ok gmaxwell, challenge/response is nice, but isn't actually necessary in fact the algorithm that rsa tokens use is pretty obvious phantomcircuit: ##php is not maintained by rasmus or zend while #mtgox has the owner of mtgox.com on it ## = non official and # = official MagicalTux, technically # channels are supposed to be officially registered freenode projects phantomcircuit: we registered mtgox on freenode oh neat i think it's pretty interesting that #bitcoin-anarchy is registered to freenode-staff phantomcircuit: challenge response done differently would be nice. E.g. the server sends you random crap. You add a nonce and sign, return the nonce and the signature. This way you could have _one_ challenge response token used by many sites who could not impersonate it. phantomcircuit: but the way the token does challenge response is that it just xors a secret with the challenge and returns the sha1, so you can't have one secret on multiple sites or they can impersonate you. or, how about just using unique good-oldfashined passwords for each site and leave it to SSL to do the rest Raccoon: ... then a moron with a keyboard sniffing trojan takes all your money and you cry. any moron with a keyboard sniffing trojan already has their private keys Mtgox's private keys? Who says you even have a wallet. my point is, an infected computer is already too late. how about a two-factor authentiction app for iPhone/Android no matter what the security implimentation gmaxwell, yeah those tokens are far to cheap to build rsa/ecdsa into them similar to the Google Authenticator app Raccoon: two factor drastically closes the window for the attacker. He must intercept and act while you are authenticated because he can't replay the authentication without you. would be a lot cheaper than having to purchase new hardware I don't like iphone/android apps first, not everyone has an iphone/android :( and second, android virus could be targetting those very OTP apps he can't capture lots of keyboard data and go "oh look mtgox passwords", he would have to prepare in advance to target the site. gmaxwell: what unique identifier is used to issue and validate the challenge/response? gmaxwell: and why can't it be stolen? keyboard loggers know what site you're on. they can also transmit in realtime, la VNC the crude method is to look at the browser title text End of #mtgox buffer Thu Jun 23 01:57:23 2011