Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Mt. Gox login is back (mtgox.com)
66 points by aroman on March 18, 2014 | hide | past | favorite | 30 comments


Be careful. It's entirely possible Mt Gox has been hacked -- it wouldn't be the first time.

EDIT: No 2FA, no https, and all data shown has already been stolen by hackers. I'm assuming it's probably real, but still -- be careful.


It seem to have https now, and Firefox reports a legitimate certificate. So at least there's that. :)


Legitimate (according to the rather dubious standards of SSL certificates), but it's not the same certificate they used to use, issued to Tibanne Co.


At least it is the same CA, DigiCert (AFAIK). DigiCert has fairly high standards so they probably examined closely when a different org requested an EV cert for that domain. For what that's worth.


Yes, you're probably right, I just recall very clearly that they had emphasized in all of their security warnings to check for the certificate from Tibanne Co, and the current certificate is not.


If they don't have a zero day browser exploit, is there any reason I need to be worried? (Assuming I use different passwords for everything)


I don't know how their infrastructure works, but if they use your password to unlock your wallet this could be a phishing attack. Either way, the money is probably as good as gone anyway.


This was what I was thinking, there were the folks who hacked the place and dumped out the data and scribbled on Carpeles log, what better way to get the passwords to peoples wallets then to put up a phish on MtGox's own servers and have anxious users provide it. People log in, give their password, check their wallet and then poof all the coin gets moved out somewhere else. Seems pretty doable if you already have control of their infrastructure.


Yes, this could be true.i was able to login using bogus account details earlier https://news.ycombinator.com/item?id=7419657


I have an interesting question. Currently my AUD$ balance is displaying as $0. However in December and Febrary I had asked to withdraw $1,000 and ~$400 to my Australian bank account. Those transfers were taken from my balance, but merely sat as 'confirmed' rather than 'processed'. What happened to my money?


Also missing €400 that I had initialed a withdrawal in February 14.


same here, I mourn 2700€ missing in action.

My late December withdraw arrived my bank 3 days before MtGox closed, btw., but I am not to positive if the money is still on it's way.


Misleading title, Mt. Gox is offering to accept login credentials and display pre-bankcruptcy balances.


Still a lot more "back" than a blank page.


They took off the two factor auth which was previously required to get into my account.


They also removed deposits and withdrawals (sorry for being snarky... I do understand you probably feel violated again now that your balance information is available to anyone who had half of the security info that used to protect it)

But, there is no further danger that your login will be used to steal funds from your account.


I have low hopes for retrieving my 0.00770912 BTC that were in there (I really don't know why I even had that much in there, but upon logging on... it seems I may have).

But at the same time, I didn't see this page coming. I wonder why its there? What would one do with this knowledge except feel uncomfortable?


The smart money is on at least one person whose job description is Serious Business and was in a position of authority said "Wait, you owe people hundreds of millions of dollars... and that fact is only recorded by you, on a system which is currently inaccessible to the creditors? And they don't have paper statements or anything? OK, that gets fixed. TODAY. No, your reason for not doing it is not a reason not to do it."


Now that I think of it... if you had used this as an "investment", could you take it as a loss on your taxes?

UPDATE: Checked with accountant, he's checking into it more, but very likely that you could take it as a casualty/theft loss for 2014. Will update more later.


I just want them to delete my data.


Amen. Particularly the passport scans and other personal information.


Yeah, that's my major worry too.

I am 95% sure that I never sent them a passport scan. I remember getting as far as scanning it into my computer before my "what-the-fuck-am-I-about-to-do-ometer" went haywire. But it was a long time ago and I can't be 100% sure that I didn't send it to them. I'd really like some way of finding out.

The only email I ever got from them was a "thanks for registering, please confirm your email address" email, so I think that means I never took it past that point (there's no "thanks for verifying your identity" email).


I wouldn't touch this with a ten foot pole. The Gox code and DB where accessed, who's to say some hackers aren't recording your password and now your email is compromised too?


>Mt. Gox login is back

In other news: I have a bear trap that is back and ready for anyone to stick their hand in.


My balance is correct


Get ready for more stealin'.

It was dumb to trust an exchange with your coins in the first place, dont make the same mistake again,

My advice to all bitcoiners, unless your bitcoins are in your wallet on a computer you own, it is not your bitcoins.


You cannot trade there anymore, it's only to check your account balance.


I have to disagree.

Its only to check their account balance. Not yours.


does this mean users who had coin could get their coin[s] back? --- i think not (with the bankruptcy n' all)

so login or no login, i don't see the point

i think it's appropriate if i quote: 'frankly dear i dont give a damn'


We're in the money... we're in the money... da da da da da da da da da da da daa.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: