HN user

sillysaurus2

4,936 karma

sillysaurus2 at gmail.

Posts26
Comments770
View on HN
news.ycombinator.com 12y ago

Ask HN: Why would MtGox delete all their tweets if things are going to be okay?

sillysaurus2
5pts3
bitcoinwisdom.com 12y ago

MtGox price: $160 to $270 to $212 to $290 to $199 to $250 in the last hour

sillysaurus2
8pts20
iwilcox.me.uk 12y ago

Gmaxwell's “prove how (non)-fractional your Bitcoin reserves are” scheme

sillysaurus2
114pts76
www.reddit.com 12y ago

"We just took over the former Zynga offices in Dallas"

sillysaurus2
4pts0
www.mtgox.com 12y ago

Statement Regarding Bitcoin Withdrawal Delays

sillysaurus2
106pts53
www.npr.org 12y ago

Who Are The Long-Term Unemployed? (In 3 Graphs)

sillysaurus2
1pts0
phys.org 12y ago

A 21st century adaptation of the Miller-Urey origin of life experiments

sillysaurus2
1pts0
maxtaco.github.io 12y ago

How Jason Bourne Stores His Bitcoin

sillysaurus2
107pts49
i.imgur.com 12y ago

How is this QR code scannable?

sillysaurus2
7pts4
www.pxdojo.net 12y ago

Bitcoin Private Key Necromancy

sillysaurus2
199pts96
www.youtube.com 12y ago

Richard Feynman - Manhattan Project [video]

sillysaurus2
8pts0
www.ics.uci.edu 12y ago

History of Public-Key Cryptography

sillysaurus2
8pts3
eprint.iacr.org 12y ago

Elligator: Elliptic-curve points indistinguishable from uniform random strings

sillysaurus2
1pts0
data.mtgox.com 12y ago

Bitcoin $1000

sillysaurus2
12pts5
paulgraham.com 12y ago

An Alternative Theory of Unions [2007]

sillysaurus2
33pts42
i.imgur.com 12y ago

Poll results: "How many hours a day are you looking at a screen?"

sillysaurus2
4pts0
data.mtgox.com 12y ago

Bitcoin $600

sillysaurus2
75pts129
mining.thegenesisblock.com 12y ago

Bitcoin mining broke 4 Petahashes/sec, 9 days after 3 Ph/s, 10 days after 2 Ph/s

sillysaurus2
6pts2
news.ycombinator.com 12y ago

Ask HN: Should /newest show 100 posts rather than 30?

sillysaurus2
1pts0
dl.dropboxusercontent.com 12y ago

What /b/ believes about life

sillysaurus2
12pts3
www.gifexploder.com 12y ago

What causes the green line in the frame before the puck hits the camera?

sillysaurus2
53pts17
code.google.com 12y ago

Gource: Software Version Control Visualization

sillysaurus2
3pts0
www.youtube.com 12y ago

Bitcoin Development Visualized

sillysaurus2
3pts1
i.imgur.com 12y ago

Is HN's SSL cert invalid for anyone else?

sillysaurus2
2pts2
rjlipton.wordpress.com 12y ago

Mathematical Embarrassments

sillysaurus2
2pts0
news.ycombinator.com 12y ago

Ask HN: Which two books were the most influential on you?

sillysaurus2
16pts15

Honest or not, starting a startup for the sake of making money (whether that money will fund a more altruistic "end-goal" or not) is probably not the right reason to build a company.

Making money was exactly pg's reason for starting Viaweb. YC wouldn't be so hypocritical as to deny someone for advertising that as their reason, when YC itself wouldn't exist if its founder hadn't started a startup for the purpose of getting rich.

Step back and ask yourself: What are my assumptions? Why do I believe these assumptions to be true? What if they aren't true?

You have at least 50 years ahead of you. That's a long time. But the next 5 years will profoundly shape your next 50.

If that feels like too much pressure, then simply don't worry about it. It's more important to relax than to optimize your life if you're the type of person who doesn't react well to a lot of pressure.

The developer is Gregory Maxwell, aka nullc. Here's a very interesting thread in which he proposes that the bitcoin community should demand that every bitcoin exchange (and every other type of service which can hold bitcoin on your behalf, like webwallets) continually prove that they are not fractional reserve. In other words, proof that if every user of the service simultaneously tries to withdraw all of their bitcoin, then the service would be able to honor all withdraw requests: http://www.reddit.com/r/Bitcoin/comments/1yj5b5/unverified_p...

"I think that as a community we should start demanding these services continually prove that they are not fractional reserve. We cannot effectively eliminate the need for trust in these sorts of services, but we can certainly confine the exposure and eliminate a lot of this drama. With Bitcoin it's technically possible to prove an entity controls enough coin to cover its obligations— and even to do so in ways that don't leak other business information, and so we should. But this isn't something specific about MTGox, it's something we should demand from all services holding large amounts of third party Bitcoins. I wouldn't even suggest MTGox should do it first, rather— it sounds like a great move for their competition to differentiate themselves."

Here's the takeaway:

"This would leak the total holdings, and some small amount of data about the number of accounts and distribution of their funds, but far far less than all the account balances. Importantly, though— it could be implemented in a few hundred lines of python."

In case anyone from Coinbase is reading: you have a unique opportunity to be the first webwallet service to implement this, and thereby make the entire bitcoin community instantly fall in love with you. It would also set a minimum standard of quality for webwallet services in general, which would add a lot of value to the bitcoin ecosystem. It seems like this might be a pretty big business opportunity.

Agreed. How could Gox imploding result in a better bitcoin world? I'd lose a ton of money, so my little world would be directly worsened. The price of bitcoin is now about $500, but it likely would've stayed >$650. And now people will forever use this as an example of why bitcoin is dangerous: financial unregulation is dangerous.

It will be just another page in history, yes, but it's a painful one. Personally I still believe Gox will ultimately be okay since everything still has a logical explanation, but hypothetically it seems hard to believe that Gox self-destructing would be anything but bad news.

Ah yes, here's another website that stores "encrypted passwords." What's an encrypted password, again?

More seriously, why is the social convention to lie in these situations? Why not just say what methods they were actually using?

I suppose it's possible they were storing encrypted passwords. But then an attacker would be able to break all of them at once.

More seriously, if the software was set up to retransmit bitcoin after a "failed" transfer, then that service could be exploited automatically. Mostly, this wasn't a social attack. The seriousness was that many services were set up to retransmit automatically, and did lose a lot of money automatically.

The plugin folder is writable by current logged in user so a trojan dropper can easily load a malicious plugin.

Maybe I'm missing something, but if you allow for the fact that a virus is already on your system, then you've already lost. It'd be one thing if iTunes was allowing the equivalent of root escalation, but it doesn't sound like it's even doing that.

http://paulgraham.com/trolls.html

News.YC is, among other things, an experiment to see if this fate can be avoided. The sites's guidelines explicitly ask people not to say things they wouldn't say face to face. If someone starts being rude, other users will step in and tell them to stop.

It sounds like we're going to be stuck with d0 for awhile. If they get banned, I assume they'll create a new account and do this all over again. I'm at least hoping they'll be reasonable.

I suppose Gox could be buying up all the goxcoins less than $300. But then you'd see a decrease in future volume until the volume reaches zero. They wouldn't do that, because they're not smart enough to pull it off without anyone noticing.

What you did was completely against the rules: http://ycombinator.com/newsguidelines.html

When disagreeing, please reply to the argument instead of calling names. E.g. "That is an idiotic thing to say; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."

There is no interpretation to be made there. You willfully ignored it.

I didn't think you were new to HN, judging by your comment history, but I wanted to give you the benefit of the doubt. Perhaps you've been banned before. Perhaps you feel your new identity gives you a vantage point from which to snipe at others. But either way, would you please clean up your writing?

I think this is the problem:

"There's too much woo and too many chipped shoulders and opportunists these days and they need a smackdown."

You feel you're on a mission, and that your mission supersedes following the rules. It doesn't.

I apologize that my original comment was lightweight and lacking sources. If I make such a claim, I should back it up with sources. I'm about to fall asleep though, and I don't remember where precisely I saw it.

Within the last couple months, there was a pretty big discussion featuring BSD licensers vs GPL licensers. If I remember correctly, the GPLers were saying that by using BSD, one enables software freedoms to be taken away, and therefore BSD and MIT licenses should be strongly opposed.

There's a lot to learn from genetic diversity

Good comment. Hopefully this leads to some thought-provoking material...

rather than applying the racism badge to it every fucking time and ignoring it to pacify some over-sensitive idiots.

... Oh. Nevermind.

EDIT: I see that you're new to HN. Please don't write in such an inflammatory style. In addition to being against the rules, it's also ineffective.

It's almost impossible to imagine someone reading their comment and misunderstanding them, unless they were bad at reading English.

The point you're trying to make is based on the mistaken assumption that they were being unclear. They weren't. Nothing was obscured. No one seriously believed that they meant to imply ownership instead of "you are."

They also weren't doing technical or business writing. It was empathy, which is sometimes helpful.

Actually, you comprehended them just fine. This is why I'm saying people are prejudiced. A prejudice is when people aren't consciously aware of why they're mistaken.

Counterexample: https://news.ycombinator.com/item?id=2483053

Replace Drew's intentional lack of capitalization with this "your/you're swap," and you've got the same situation.

It seems like people are just prejudiced, and are so prejudiced that they feel justified in calling people out on a forum under the guise of "helping" them.

Yes, grammar is powerful, but this isn't a situation where it matters. They were expressing empathy. They weren't writing a press release. And we can't seem to find it in ourselves to avoid bikeshedding this thread.

This comment thread is toxic, and it's regrettable that you created it. Look at the replies you've engendered. Quibbling over grammar is not why most people read HN.

Drew Houston writes without capitalization. Would you say the same to him? Ideas are what matter, not apostrophes.

Probably not. CloudFlare only makes sense for websites because they can cache content, resulting in a more responsive website and better user experience. Games can't be cached, so whatever protections they can offer will come at a downside of having to use CloudFlare servers instead of servers designed to host games.

Also, DDoS isn't a big deal for most games. (MMOs, yes, but not most games.) If a gameserver is DDoSed, then a few dozen or a few hundred people are going to be unhappy. Whereas if a website is DDoSed, then tens of thousands of people will be unhappy at a minimum. Since most games aren't really affected by DDoS, it doesn't make much business sense for CloudFlare to try to offer gameserver protection. The market probably isn't big enough to warrant diverting CloudFlare time and resources.

Airbnb provides a lot of help for people without a lot of money. I would've been in a bad position if not for Airbnb.

Dropbox has made my life a lot less stressful.

HN gives us all so many opportunities. For example, the monthly "who is hiring?" threads. If anyone is suddenly stricken with a run of bad luck, then they can make a post about it and the community will come together to at least offer them work. People here like talent, and can find ways to use it. Most other places aren't like that. And imagine a world with only Reddit.

Also, imagine a world with no HN and no Reddit.

YC has made seed funding more accessible, and given founders more power. The VC's had the upper hand before YC. Now the VCs seem to be closer to servants than masters. If I decide to do a startup, that will impact me.

Probably some other things I haven't thought of off hand.

But if you asked me for the one reason why it didn’t work out, the truth is that it just wasn’t fun anymore

Is YC fun? Not the dinners. The work you're there to do.

It seems like doing a successful startup is closer to this than to fun: https://news.ycombinator.com/item?id=7222850

Maybe in the wake of a failed startup I deluded myself into thinking great teams are predicated on great friendships, a truism that no longer holds absolute truth.

Perhaps there's a misunderstanding of what a friendship is in a business context. The cofounders have to have been friends for quite awhile, otherwise the stress will tear them apart. But they probably don't have to be dear friends, or the kind of friend you hug. It's just business.

to those like me who held the institution on a pedestal

This seems the central issue. YC is ultimately about business. It's awesome, it's changed the world and my life, but having expectations that it's going to be fun and that you're there with dear friends seems off the mark. But I've never done YC, so this is just speculation on my part.

You're an awesome person. Thank you for your concern.

The last thread helped me come to peace with the situation. Thanks to the community's commentary, the obvious was made clear: There's no scenario in which it's ever helpful to become emotional about bad luck. It's over and done with, and there's nothing that can change it. Getting upset will only make life worse. Instead, why not choose to be content with all that hasn't been lost?

It took awhile for me to let go of what-if's and past mistakes. But what ultimately changed my perspective was reflecting that I live in a life of luxury and comfort compared to most people on the planet. That's when I realized that most of my feelings until now have been rooted in selfishness. What percentage of people have had the opportunity to even make any investments whatsoever? It was silly not to have realized how lucky I've been.

It took some soul searching, but...

If Gox turns out to close, I will lose some coins. Oh well. It's just some money, and at least I'll have served as an example of what not to do.

After researching the issue for a couple days, I've turned up a few things to boost my confidence in the situation.

First, Tux (the owner of MtGox) has been participating in the Github discussion about getting a "normalized txid" implemented ASAP to address the malleability issue.

Here's the github discussion: https://github.com/bitcoin/bitcoin/pull/3656

Here's the latest comment from Tux (8 hours ago):

"Just to update this thread, it seems that this discussion is mostly stale now. We (at MtGox) will implement this new hash index in our transactions database and start working with it (we will announce a maintenance as we will have to stop bitcoin deposits too during the database schema update) and will start providing this new hash when customers are withdrawing bitcoins, litecoins, or any other coin based on Bitcoin we may support in the future.

We will also provide an API that will allow our customers to use this hash to retrieve the transaction hash as seen in the blockchain once the transaction is confirmed, and will hope others (blockchain.info?) will index this value one day.

We also invite other exchanges and businesses which may need to keep track of bitcoins they send to use this same method, since dealing with multiple variations of the same thing wouldn't be very productive."

As of an hour ago, blockchain.info has implemented the proposal. Here's an example of a "normalized txid": https://blockchain.info/ntxid/3c0b247b0f9107309c603441f0411b...

Why is ntxid important? Because for most practical purposes, ntxid cannot mutate. The recent attack was possible because people were able to mutate txids by changing the signature. So, "txid" includes the signature, but "ntxid" doesn't. Therefore ntxid is immune to the previous malleability attack vectors.

So what else boosts my confidence? Well, another aspect is that Gox support personnel have been in #mtgox almost 24/7 answering questions. They often don't have answers that people are seeking, but they have been professional and helpful to the best of their ability given the current situation.

A third thing that boosts my confidence is that Gox has, conservatively, made at least 120k bitcoin in profit from trade fees. It's more likely in the range of 440k. So even if they lost an ungodly amount of bitcoin, such as 70k, they will still have more than enough to cover the losses.

To expand on this third point, people have expressed at least two concerns about whether Gox has enough coins. The first concern is whether Gox has enough coins to cover the losses they suffered. For example, perhaps they've been paying themselves a massive salary, and perhaps they lost more than the amount of profit they had remaining. People feel that the press release was designed to drive down the price of bitcoin, perhaps to sell high and buy low in order to grow their bitcoins by enough to cover the losses. But this doesn't make sense, because bitcoin's price rapidly recovered on all the other exchanges. This method wouldn't have been able to net them more than a few thousand btc. Plus, their own buy order would influence the price itself. The logic of "Gox issued an accusatory press release to drive down the price" doesn't seem to hold up.

The second concern is that people believe Tux will use this as a way to get out of bitcoin entirely and retire. I don't know Japan's law, but people seem to believe Gox is the equivalent of a limited liability corp, which is of course designed to limit personal liability in the event of a massive screwup such as the one Gox has suffered. People say that since there was no malicious intent by Gox, then Gox may simply be closed down without much penalty to Tux.

But if that were the case, then Tux's behavior would become very different very quickly. It seems pretty likely that Gox has, by now, calculated how many coins they've lost. Tux knows whether they're solvent. If they aren't able to cover losses, why would he be participating in Github? Why is he seemingly working so hard to resolve the issue? In that situation, "keeping appearances" isn't valuable. His time would be better spent speaking with lawyers and crafting his legal defense. This doesn't seem to be happening.

So at this point we know the malleability exploit was real and that Gox really was bitten by it. We know they responded to the exploit in the only way that they were able: by suspending withdraws before further coins were siphoned out of Gox's systems. We know that Gox aren't making any exceptions to this withdraw suspension, not even for customers with large bitcoin holdings. (To me, this seems quite fair.) We know that Tux has been personally working with the bitcoin devs to push through a proposed fix to the protocol, and we know that the proposal has already been implemented in blockchain.info's website.

Lastly, and most persuasively, we know that the expected value for Tux to reopen Gox is the massive amount of trade fees he stands to earn in the future. This incident will shake people's faith in Gox, but people are fickle, and if just 30% of their user base sticks with Gox then that means in another few years Gox will have earned 30% of "a massive amount of profit from the trade fees." That's still quite a bit of profit, and profit is better than no profit. Since Gox stands to earn at least another $million USD in trade fees over the next few years, then that's a million reasons for him to continue operating the exchange.

Tux's behavior is roughly the opposite of what you'd expect from someone who was about to shut down their business.

I had the option to sell my bitcoins in my MtGox wallet for 80% of their value. For example, if I transfer 1 bitcoin from my Gox wallet to their Gox wallet, then they would send me 0.8 btc to my external wallet address in return. But I chose not to sell off my Gox bitcoin, because the probability of Gox closing seems much less than 20% due to all of the above reasons. I'm going to wait it out.

The reference client certainly doesn't do this on spends. Why would gox have implemented it in this way? It doesn't make any sense at all.

I've been researching the details of this disaster. Here's what I've gathered. This info came from Greg Maxwell, a bitcoin core developer. He got his information from the owner of MtGox himself:

Gox implemented custom wallet software to deal with massive transaction volume. The reference client wouldn't cut it for their purposes. For what it's worth, Greg agrees with the decision to write custom software for high-volume exchanges. It seems pretty likely that other exchanges have also implemented custom bitcoin software stacks.

In the scenario where Gox detected that a transaction failed, they automatically reissued the transaction. But that was based on the faulty assumption that the transaction hash couldn't ever mutate. This flaw was exploited to siphon bitcoin out of Gox.

This doesn't matter very much for Gox because, conservatively, they've made at least 120k BTC in profits from trade fees. More likely in the range of 400k. So they'll be able to cover the losses.

But this means it's entirely possible that other exchanges and web services with custom software stacks were hit hard by the malleability event, just like Gox was. It depends whether they were automatically reissuing transactions. If so, then they probably lost money.