Post
Topic
Board Bitcoin Discussion
Re: Mt. Gox Hack claims
by
finack
on 19/06/2011, 17:12:18 UTC
MagicalTux has already responded to these false claims via IRC:

While I'd agree that it seems likely the offer of the database for sale is a fake and just intended to shake confidence in Mt. Gox given all of the other activity that's going on, MagicalTux's response doesn't instill much confidence. In fact suggesting things like salted hashes would protect the passwords and no suspicious logins found sound exactly like the kinds of reports that come in early from actual intrusion victims. Most salted hash schemes in use won't protect people with weak to crack passwords, which will be about 99% of the users, and a SQL injection compromise which is by far the most likely approach wouldn't involve OS logins. The fact that there was a recently discovered CSRF hole lends credence to the idea that there could easily have been a SQLi. And while he may be playing dumb, he doesn't sound like he has the instrumentation in place that would even necessarily allow him to discover an intrusion like that after the fact, even if he knew what to look for.

So while it's only smart for him to categorically deny any intrusion he doesn't have direct evidence of, and I'd still rate the HN post as much more likely to be fake than real, I'd still personally change my password all the same.  Tux really couldn't give you that advice unless he'd already found and closed a flaw without tanking his business.