坑爹的Mt.Gox确认密码泄漏,各位小心你们的BTC啊。

2011-06-20 06:01:42 +08:00
 lintoy
Dear Mt.Gox user,

Our database has been compromised, including your email. We are working on a
quick resolution and to begin with, your password has been disabled as a
security measure (and you will need to reset it to login again on Mt.Gox).

If you were using the same password on Mt.Gox and other places (email, etc),
you should change this password as soon as possible.

For more details, please see this:

https://support.mtgox.com/entries/20208066-huge-bitcoin-sell-off-due-to-a-compromised-account-rollback

The informations there will be updated as our investigation progresses.

Please accept our apologies for the troubles caused, and be certain we will do
everything we can to keep the funds entrusted with us as secure as possible.


The leaked data includes the following:

- Account number
- Account login
- Email address
- Encrypted password

While the password is encrypted, it is possible to bruteforce most passwords
with time, and it is likely bad people are working on this right now.


Any unauthorized access done to any account you own (email, mtgox, etc) should
be reported to the appropriate authorities in your country.


Thanks,
The Mt.Gox team
4046 次点击
所在节点    Bitcoin
15 条回复
ideeinfo
2011-06-20 06:56:39 +08:00
杯具了
wonster
2011-06-20 08:25:53 +08:00
ideeinfo 侬 好早啊
c
2011-06-20 08:37:26 +08:00
丢了BTC的应该要求去赔偿!
ideeinfo
2011-06-20 08:46:41 +08:00
@wonster 哈哈,你也在这里混啊
wonster
2011-06-20 08:48:16 +08:00
呵呵 每天都转转
ideeinfo
2011-06-20 09:06:31 +08:00
居然是香港人干的?早上google提示我的gmail帐户遭到可疑的访问,赶紧改密码

The bitcoin will be back to around 17.5$/BTC after we rollback all trades that have happened after the huge Bitcoin sale that happened on June 20th near 3:00am (JST).

One account with a lot of coins was compromised and whoever stole it (using a HK based IP to login) first sold all the coins in there, to buy those again just after, and then tried to withdraw the coins. The $1000/day withdraw limit was active for this account and the hacker could only get out with $1000 worth of coins.

Apart from this no account was compromised, and nothing was lost. Due to the large impact this had on the Bitcoin market, we will rollback every trade which happened since the big sale, and ensure this account is secure before opening access again.

UPDATE REGARDING LEAKED ACCOUNT INFORMATIONS

We will address this issue too and prevent logins from each users. Leaked information includes username, email and hashed password, which does not allow anyone to get to the actual password, should it be complex enough. If you used a simple password you will not be able to login on Mt.Gox until you change your password to something more secure. If you used the same password on different places, it is recommended to change it as soon as possible.

SERVICE RETURN

Service will not be back before June 20th 11:00am (JST, 02:00am GMT). This may be delayed depending on what is found during the investigation.
wonster
2011-06-20 09:11:24 +08:00
恩 不错 比抢银行来的刺激
ideeinfo
2011-06-20 09:35:02 +08:00
还好我的gmail密码没有到处用,否则就惨了
fantianyi
2011-06-20 09:49:16 +08:00
@ideeinfo "早上google提示我的gmail帐户遭到可疑的访问,赶紧改密码"
我也有同样情况,google 安全上做得不错。
mrkschan
2011-06-20 11:09:15 +08:00
@ideeinfo 不一定是香港人,在香港租 server 很簡單..
ideeinfo
2011-06-20 11:39:41 +08:00
看这个链接,mtgox事件的timeline: http://blog.zorinaq.com/?e=55

这段有意思,感谢这位google的兄弟,服务台太贴心了:
The only positive news amongst all this is that Mike Hearn, a prominent Bitcoin community member, and part of the Google abuse/anti-hijack team, proactively forced a password change on all the Gmail accounts that were found in the leaked MtGox account list.
est
2011-06-20 11:45:31 +08:00
Bank robbery IRL, oh wait, not IRL.
est
2011-06-20 11:54:13 +08:00
reddit上的BLEAOURGH的内涵回复:

Look on the bright side: nobody in the Bitcoin mining community is going to have the processing power to make brute forcing these unsalted passwords in a reasonable amount of time feasible.
ideeinfo
2011-06-20 12:10:06 +08:00
TrageHill开始抢客户了,哈哈

Dear Sir or Madam,

A few hours ago the Bitcoin trading website Mt Gox has been hacked. Malicious individuals have been able to obtain a database containing usernames, email address and encrypted passwords. This information has been posted publicly on the internet.

As a Bitcoin supporter I'm now sending a message to every email address contained in the hacked database. This is to warn you that your username, email address and password have been leaked. I therefore strongly advice you to change your passwords. If you have used the same password on different websites it's highly recommended to change your password on all of your accounts!

For a more secure alternative to Mt Gox, the community appears to be moving to TradeHill. So this is no reason to lose faith in Bitcoin itself. It must be seen as a warning that not every website can be trusted with your data however! Their link is http://www.tradehill.com/?r=TH-R15683 (Note: You can remove the Referral Code when registering if you want!) This is certainly not the only website where you can exchange Bitcoins, also check out http://www.thebitcoinlist.com/dp_bitcoin/bitcoin-exchange/


Sincerely,

A Bitcoin supporter
1CWSjov2N7ix41bZ8bJfHXkdLLbkUsG9Y7
ideeinfo
2011-06-20 12:10:38 +08:00
@est 确实很内涵 :-D

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/14706

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX