…
Act II: thousands of men and women sign up to be brave with semi-retired Jason Bourne.
…
Act III: “we regret to inform you that our security protocols are a disaster”.
221–230 of 321 posts
…
Act II: thousands of men and women sign up to be brave with semi-retired Jason Bourne.
…
Act III: “we regret to inform you that our security protocols are a disaster”.
Earlier quoted context omitted.
> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…
Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.
Once it enters their hands, the money isn't really “from” a particular account in any tangible way.
> If i had a account there, i wouldn't allow them to use my money to cover this.
An account is just a record of funds to which you are entitled; there are certain types of relations where someone keeping money for you legally needs to keep it segregated from other funds of theirs, but crypto.com doesn't have that kind of relationship with account holders. If they don't provide you with your funds when you ask, you can try legal action to recover it, but you don't have a veto on whether they update the entry recording someone else's balance to make them whole after a hack, even if that increases the risk that they won't have your money when you want to withdraw it.
I am a cyber security consultant for startups. The first thing that I communicate is that just by not being in crypto you have drastically lowered your risk profile. Attackers care a lot about what they can get to if they are able to breach your security.
Eh, yes of course, what are you saying really? Is there some deeper point I miss? Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?
For most finance companies, if they have a whoopsie and lose money to a software boo-boo, they'll just reverse the transaction. Times when such a transaction cannot be reversed (https://www.bloomberg.com/news/articles/2021-03-19/citigroup...) are the extremely rare exception, and are adjudicated by a civil court.
Whereas if a crypto company has their wallets breached, it's almost certainly immediately irreversible.
It seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive
Why do you think everything tends to centralize? To keep things localizable.
...Until that backfires anyway. Thank you 2008.
Earlier quoted context omitted.
Eh, yes of course, what are you saying really? Is there some deeper point I miss? Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?
People generally don't understand how vast the difference is. The pro crypto narrative has pushed the idea that "Blockchain is more secure" because "it cannot be edited" when in reality that feature makes it much more of a target for attackers because once they transfer the coins the transfer cannot be edited. In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancell…
That's why attackers never go after credit card numbers, right?
I think non-revertible payments do not really make a big difference to attackers, it just makes value extraction more efficient. Some percentage of fraudulent transactions will always make it through. So long as the funds accessible to the attacker are sufficiently large, it's still a juicy target. 10% of 200 megadollars is still 20 megadollars.
I agree with @capableweb2. They're an attractive target because they are a financial company with control over lots of value, not because of anything to do with cryptocurrencies in particular.
(and missed out on settlement too! and domain name apparently is being re-used, ugh)
Earlier quoted context omitted.
This... Is literally how banks work.
Banks do not work this way. Banks have insurance policies, both private and federal, that would cover the losses.
Yes, they do.
> Banks have insurance policies, both private and federal, that would cover the losses.
The federal insurance policy covers you if, after operating this way (or for some other reason) the bank ends up without money to cover your account (and, the regulation that comes with the insurance means that it's more likely that the Federal government will force the sale of your bank to one that does have extra money to cover your account even before that happens.)
But banks still operate as described (and using some of their pool of assets to buy private insurance is functionally the same as just adjusting the balances of people it is compensating for losses and increasing risk to others by doing so, except it smooths things a bit over time at the expense of higher average cost.)
Earlier quoted context omitted.
Calling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.
I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.
It has been painfully admitted. But you know what I am going to say if you're storing your crypto life-savings or JPEGs on an exchange: Not your keys, Not your coins and certainly not your NFTs.
It's almost like we need a centralized authority that can undo these withdrawals and a know your customer paper trail.
Nah... Probably never catch on.