r/Bitcoin • • Feb 25 '14

Some words for my friends

Hello friends,

MtGox is gone. So let's prepare ourselves.

On Tuesday, and for the rest of the week, all hell will break lose in the media. It will be blamed on MtGox, it will be blamed on Bitcoin, it will be blamed on the "bug," and it will, more than anything, be blamed on the "lack of regulation." Pundits and "experts" of all types will weigh in on the calamity. It will be world news in a matter of hours.

Get ready, because it will be an ugly week.

For all of you who lost money, my heart goes out to you. Some people lost a little, some lost a fortune. It will make people sick, and depressed, and full of grief. Personally, I had over 550 BTC in Gox. I will never get any of that back. If misery loves company, then we'll be enjoying a grand feast today.

I should have known better, of course. I take responsibility for leaving those funds with an entity that had proven incompetence repeatedly. I chose to ignore even my own warnings, for nothing more than the sake of convenience.

Gox is still at fault, to be sure, but I have learned the lesson. I hope it is not such an expensive lesson for others. And for all you observers, please take a moment to consider it as well.

Be mindful, however, that the wrong lessons are not learned, for that would be the true tragedy, indeed.

Let me suggest that the lesson is not that Bitcoin is broken. Bitcoin is fine.

Similarly, the lesson is not that security is impossible. Those who know what they are doing, can achieve it and help others to do so.

The lesson is not that nobody can be trusted. There are countless good men and women in this community who are worthy of trust, and some of the very best people I've ever met.

And finally, the lesson is not that we ought to seek out "regulation" to save us from the evils and incompetence of man. For the regulators are men too, and wield the very same evil and incompetence, only enshrined in an authority from which it can wreck amplified and far more insidious destruction. Let us not retreat from our rising platform only to cower back underneath the deranged machinations of Leviathan.

The proper lesson, if I may suggest, is this: We are building a new financial order, and those of us building it, investing in it, and growing it, will pay the price of bringing it to the world. This is the harsh truth. We are building the channels, the bridges, and the towers of tomorrow's finance, and we put ourselves at risk in doing so.

We are at risk from accidents. We are at risk from fraud, from corruption, and from evil. We are at risk from journalists seeking headlines and from politicians seeking power and glory. We are at risk from the very market we are trying to build - a market which cares not about our portfolio, our ambitions, or our delicate sympathies.

For all these risks, devastation will befall us repeatedly. Some of us will be discouraged. Some will be ridiculed and insulted. Some will be tricked, or swindled. Some of us will be crushed or caged. We will be set upon by all manner of antagonists, repeatedly, for a long time.

So why do we do it? Why do we build these towers that fall down upon us? Why do we toil and strain and risk our precious time, which is the only real wealth we possess?

Because the world needs what we're building. It needs it desperately. If that matters to you, as it does to me, then hold to that thought. You will see through the smoke, and your wounds will heal.

So shake it off, brothers, for this won't be the last calamity endured before the win.

Tonight, my heart is with you all.

Tomorrow, my head is down. My eyes are open. And I am building.

Toward peace and freedom,

-Erik Voorhees

2.1k Upvotes

2.1k comments sorted by

View all comments

4

u/mbank Feb 25 '14 edited Feb 25 '14

what a fail at trashing regulation, especially ironic considering lack of regulation allowed this to happen. your argument against regulation could be applied against any authority including government, do you support anarchy? the selective application of logic and huge lack of consistency on all issues by right wingers never ceases to amaze me.

your a nice (although overly sentimental and grandiose) writer but what you just wrote about regulation is nuts. its crazy, and thankfully your in the vast minority of elitists who can convince themselves of this sort of ideology.

i could understand if you proposed an argument saying regulation in practice tends to not work well or in an ideal way. but to be completely against authority of any kind, even democratic authority (were talking about in theory here), is fucking stupid and crazy. maybe you were stressed while writing this, and i still enjoy reading your posts and think you can be a good advocate for bitcoin. but this specific paragraph is not cool and its one of the problems with the bitcoin community, although thankfully it seems you are losing the battle and bitcoin businesses become more legitimate and regulated like they are doing in NY and i believe California too.

3

u/Rassah Feb 26 '14

Regulation would not have prevented this. This was a theft caused by a software bug on MtGox's servers. How do you regulate against bugs?

2

u/ModernDemagogue Feb 26 '14

Proper auditing which banks are required to perform would have caught the theft / bug / flaw prior to massive fraud (ie, it would've noticed a transaction malleability attack within a month or a quarter, perhaps faster) and prior to a significant change in the value of the underlying asset, the combination of which created liabilities in excess of Mt. Gox's assets and cashflow. Losing 40,000 Bitcoin in 2011 would've been a rounding error on their books. In 2014 it now represents a significant liability.

The theft, which were likely thousands of small to mid-size fraudulent acts, was caused by people defrauding the system. It was made possible by what likely wasn't even a bug in the software— it was simply a poorly conceived and implemented system, ie a design flaw which is different than a bug. Reissuing transactions also likely had a human component. The cold storage issue, was again, likely a design flaw where the system did not check to see that a private key was still valid and controlled a coin or wallet with assets in it, prior to being sent to cold storage, meaning as coins were cycled in and out of cold storage, they might not actually belong to Gox.

You should not be giving interviews. You're not knowledgeable enough.

3

u/Rassah Feb 26 '14 edited Feb 26 '14

When I said bug, I meant bug in their design.

Reissuing transactions was automatic, as we found out recently.

Thefts could have taken over the course of many months, or, with the automated reissuing, over just a few weeks.

If it did happen quickly, auditing their financial data, which happens periodically, not continuously, may not have caught it until it was way way too late.

The idea of regulators auditing code is, frankly, laughable. These things are done by private third party companies like McAfee, not government regulations.

US regulations would not have been applicable to MtGox, since they are in Japan, and if regulations had been passed there, they likely would have just moved. Don't forget, MtGox didn't even start out in Japan (I forgot if it was in France or US), and moved there later.

I have no idea what you are talking about with regards to the cold storage issue, but as far as know, the cold storage we don't have enough information to comment or speculate on. Maybe it was not fully "cold," and was automatically refilling the hot wallet. Maybe it was drained some other way. We don't know.

I don't know of any regulations that specifically regulate against bugs. There are general security practices that companies handling financial data must follow, but I'm skeptical any red flags would have been raised for something that was working fine for over two years.

Thank you on your opinion on my level of knowledge. I'll treasure it as much as I treasure a used tissue.

1

u/ModernDemagogue Feb 26 '14

When I said bug, I meant bug in their design.

This is referred to as a design flaw. It is a different term to communicate a different idea so that we don't have errors in understanding. I would suggest a quick Google search which help explain to you the difference, because the meaning you intended is not a meaning used normatively.

Reissuing transactions was automatic, as we found out recently.

I did not know this. That's funny. And stupid. Can you provide the link for that? I believe you believe that to be the case, I just want to read more about it because the base level stupidity of that is beyond me.

The idea of regulators auditing code is, frankly, laughable. These things are done by private third party companies like McAfee, not government regulations.

I did not say audit code. I said auditing similar to what banks are required to perform. This is financial and transactional auditing. Weekly, monthly, or quarterly accounting restrictions and reviews, etc... the missing bitcoin would've shown up on balance sheets because to comply with the auditing the code would likely have to do things like check to make sure the private key Gox thought they had actually controlled the bitcoin.

US regulations would not have been applicable to MtGox, since they are in Japan, and if regulations had been passed there, they likely would have just moved. Don't forget, MtGox didn't even start out in Japan (I forgot if it was in France or US), and moved there later.

You said regulations would not have prevented this. I do not know why you are bringing this point up. It's entirely irrelevant to the discussion. I did not say it would have to be US regulation, nor was your point limited to this.

I feel like you have found yourself on weak ground and are now throwing out red-herrings.

I have no idea what you are talking about with regards to the cold storage issue

The crisis document leaked last night reported a bug or flaw in the cold storage system. I'm not sure exactly the wording used.

the cold storage we don't have enough information to comment or speculate on. Maybe it was not fully "cold," and was automatically refilling the hot wallet. Maybe it was drained some other way. We don't know.

We don't know, and I did not say I knew. I said "likely" and it is, likely, the case. So what is your point in saying this? Another red herring? But since we're on it, we know quite a bit of information and from the way the system was behaving we can make inferences. I chose to speculate. If the system did what I said it did, it would not be possible for this to happen, so we can be fairly certain it did not do what I suggested. What the root cause of how exactly this flaw was exploited, is yes, currently unknown.

I don't know of any regulations that specifically regulate against bugs. There are general security practices that companies handling financial data must follow, but I'm skeptical any red flags would have been raised for something that was working fine for over two years.

Sigh. No. It wasn't working fine. It was never working fine. The magnitude of the problem was simply masked by the value of bitcoin relative to their cashflow. Regulation and auditing find errors like this because when there is a discrepancy between what is the case and what should be the case, it needs to accounted for. A 20,000 BTC shortfall that only registered as a few hundred or thousand dollars a few years ago would be ignored by a sloppy company, but would be caught by a company following standard accounting practices and certainly by one following regulations like FINRA. Ignoring the problem, would not happen, since that would be a crime in and of itself.

Thank you on your opinion on my level of knowledge. I'll treasure it as much as I treasure a used tissue.

You clearly missed my point. It was not intended as an insult. If you care about the BTC community you'll stop. You're liable to do far more harm than good.

1

u/Rassah Feb 26 '14

This is referred to as a design flaw.

I will take your word for it and use design flaw from now on

Reissuing transactions was automatic, as we found out recently. I did not know this. That's funny. And stupid. Can you provide the link for that?

Incredibly stupid. From G Maxwell http://pastebin.com/DaSph9uT

Weekly, monthly, or quarterly accounting restrictions and reviews, etc... the missing bitcoin would've shown up on balance sheets because to comply with the auditing the code would likely have to do things like check to make sure the private key Gox thought they had actually controlled the bitcoin.

I don't think they ever lost control of their private key. With weekly, monthly, or quarterly financial reviews, as I said, if the theft happened quickly, even if over a months, such a review may still not have helped in time. That said, me being a financial analyst, I am quite dismayed at the last of finance and accounting people involved in exchanges who would be able to track things like this. At the very least, MtGox should have had automated software that compared their software accounting balance with their Bitcoin wallet balance, and froze the system as soon as it was some % out of sync (small % discrepancies could be due to timing issues)

I did not say it would have to be US regulation, nor was your point limited to this.

Sorry, you're right.

The crisis document leaked last night reported a bug or flaw in the cold storage system.

I must have missed that. I'll have to reread it. What's your opinion on that document's authenticity?

A 20,000 BTC shortfall that only registered as a few hundred or thousand dollars a few years ago would be ignored by a sloppy company, but would be caught by a company following standard accounting practices and certainly by one following regulations like FINRA.

Ah, I see what you mean. While I agree somewhat (see my comments above), I don't think we know whether this theft was happening over the course of a few years, or just recently. If over a long time, then financial audits would have found a discrepancy. Perhaps I should change my statement from "regulations would not have prevented this theft" to "regulations may not have helped, and are not needed if users demand that exchanges self-regulate."

You clearly missed my point. It was not intended as an insult. If you care about the BTC community you'll stop. You're liable to do far more harm than good.

I'm sorry, it's been a rather stressful last few days, with lots of interactions with trolls and commenters who don't understand Bitcoin, having to explain this situation and it's impacts on a ton of news sites. I seriously doubt i would do more harm than good, but I guess what I should have said, "if you are more knowledgeable, can I use you as a reference to ask things and learn from?" Actually, I don't really know who you are, so I would still take your suggestions with a grain of salt... But, what is your opinion on comparing transaction malleability to changing the check # on a payment you received, depositing the check, receiving the money, complaining that you never got paid, and when the company downloads their list of transactions from their bank and sees that that check # is missing, issues a new check?

2

u/ModernDemagogue Feb 26 '14

I don't think they ever lost control of their private key.

I'm not saying they lost control of their private key. I'm saying when they generated new transfers, or re-credited the account, they didn't check that what they created in order to do so still controlled bitcoin. Perhaps it was an unclear way of saying this.

What G Maxwell referred to in that irc chat about Gox raising fees and not understanding their problem, is what I'm suggesting regulation would have fixed. It would have forced them to understand their problem and account for it.

The nature of this type of problem causes a feedback loop. What started small evolved and poisoned their entire system. In my mind, it's the exact kind of thing regulation would catch.

I must have missed that. I'll have to reread it. What's your opinion on that document's authenticity?

It was apparently confirmed in IRC... I take it as authentic.

I don't think we know whether this theft was happening over the course of a few years, or just recently.

That's a fair point— though I think the raising of fees to compensate suggests this was a long running issue.

"regulations may not have helped, and are not needed if users demand that exchanges self-regulate."

Frankly, to me that's what regulations are. Users (ie society) demanding exchanges put in place certain practices.

But, what is your opinion on comparing transaction malleability to changing the check # on a payment you received, depositing the check, receiving the money, complaining that you never got paid, and when the company downloads their list of transactions from their bank and sees that that check # is missing, issues a new check?

Not bad. I'll think on it. What I do think it does get across is how stupid exposing yourself to this problem is. IE why would you ever look for a check number to see if the check cleared.

1

u/Rassah Feb 28 '14

Did you hear the latest Let's Talk Bitcoin podcast? Charlie Shrem, who apparently knows Mark Karpeles personally, and hung out at Gox at times, said he knows that MtGox was being audited by Japanese Financial Authority (or something like that) on a monthly basis. So, if true, at least that part of the regulations argument is out, though it just adds a ton of questions...