Post
Topic
Board Bitcoin Discussion
Re: Bitcoinica MtGox account compromised
by
Phinnaeus Gage
on 24/07/2012, 04:55:09 UTC
Even if it was the original hacker, according to genjix the LastPass PW was not compromised. The password was the MtGox API key and that key was stored in the source that the Rackspace hacker would have had access to, but how likely is it that if you had 5 guesses you would choose an API key buried in the source vs attempting one of the other passwords that you did compromised to see if it was a duplicate of those?

Which is what most people assume they did.  You get 5 attempts before it locks you out for 5 minutes and sends an email.  If the list of compromised passwords the hacker had wasn't especially long, then they didn't have a lot to lose by trying the duplicates - if one of them was right, there was every chance they'd be into the LastPass account before anyone read the email.

Quote
Any time a hacking fiasco happens, it basically turns into a witchhunt, because people feel extremely powerless.

This is equally true when conventional companies go out of business.

How would the hacker know beforehand it it was even worth getting into the account to get a look-see. First, he would have to know the account existed then, by happenstance, find the PW(s), then try them, all the long not only hoping that it works, but that it was all worth his time.

~Bruno~