Earlier quoted context omitted.
And I think that's exactly the point. Cryptocurrency promoters endlessly talk up how it's part of a decentralized wave of the future. But in practice it's quite centralized, and the incentives point in that direction for the future. That's one of the points made very well recently by Moxie Marlinspike: https://moxie.org/2022/01/07/web3-first-impressions.html
It’s not centralized though, crypto.com is one of many exchanges. Anybody can create an exchange, and a failure in one exchange doesn’t propagate to the rest of the network. Do you consider a website breaking a single point of failure for the internet?
Crypto.com accounts had unauthorized withdrawals
231–240 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#232Re: Crypto.com accounts had unauthorized withdrawals
#233Earlier quoted context omitted.
Banks do not work this way. Banks have insurance policies, both private and federal, that would cover the losses.
> Banks do not work this way Yes, they do. > Banks have insurance policies, both private and federal, that would cover the losses. The federal insurance policy covers you if, after operating this way (or for some other reason) the bank ends up without money to cover your account (and, the regulation that comes with the insurance means that it's more likely that the Federal government will force the sale of your bank…
> But banks still operate as described (and using some of their pool of assets to buy private insurance is functionally the same as just adjusting the balances of people it is compensating for losses and increasing risk to others by doing so, except it smooths things a bit over time at the expense of higher average cost.)
It's really not. Customer deposits are segregated from the operating accounts in accordance with applicable law. You're not suggesting they're taking payroll out of customer deposits are you?
Re: Crypto.com accounts had unauthorized withdrawals
#234Earlier quoted context omitted.
crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it. Anyone know how the do auth on the app? For users in the US there is no way to…
> it was just an email to click a link, An e-mail with a link to actually click? Does anyone else see those flashing red lights and hear that alarm klaxon? Please do me a favor and drop those assholes like a bad habit. They are going to cost you whatever assets of yours they have in their control.
Re: Crypto.com accounts had unauthorized withdrawals
#235I'm confused. Ostensibly the tradeoff for crypto is that only you know the secret factors that allow you to spend money, but there is no possibility of reversing a fraudulent transaction. If you give the keys to someone else, you lose the first condition, which was the benefit, but keep the second condition, which was the drawback. There was no reason to give anyone anyone else your keys!
I like how when my credit card gets a fraudulent transaction, all I have to do is push a button on my phone and it magically goes away. This is a major, major benefit of having a central authority.
Re: Crypto.com accounts had unauthorized withdrawals
#236Earlier quoted context omitted.
Maybe, but I think you can make a case for the opposite too. Without exchanges, there'd be no crypto. Exchanges are the only reason 99% of people who have crypto can figure out how.
Especially with mobile devices taking over. An increasing number of people don't even have a laptop or desktop to hold a whole blockchain on. Even an iPhone 13 Pro with 1TB of storage would lose 10-20% of its space to that. That isn't going to improve. The more popular it gets, the faster it grows, and it would compete with all the other storage needs that also grow. Get someone to load up and maintain a whole blockc…
Re: Crypto.com accounts had unauthorized withdrawals
#237Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…
Crypto.com is on par with FTX, Binance, Celsius, Coinbase and we have many varying examples of their valuations and supporting revenues and balance sheets.
$30mm irrecoverably stolen with zero liability for the hacker? No problem for the user experience or health of the company these days.
Re: Crypto.com accounts had unauthorized withdrawals
#238Earlier quoted context omitted.
It’s not centralized though, crypto.com is one of many exchanges. Anybody can create an exchange, and a failure in one exchange doesn’t propagate to the rest of the network. Do you consider a website breaking a single point of failure for the internet?
It’s not centralized though, chase.com is one of many banks. Anybody can create a bank, and a failure in one bank doesn’t propagate to the rest of the market.
But yes, I would agree that banks are about as decentralized as crypto exchanges. But that's kind of the point, you shouldn't conflate exchanges (or banks) with the currency itself.
Re: Crypto.com accounts had unauthorized withdrawals
#239Earlier quoted context omitted.
How is this a single point of failure? The issue was limited to a subset of users keeping funds in a Crypto.com wallet. Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
And I think that's exactly the point. Cryptocurrency promoters endlessly talk up how it's part of a decentralized wave of the future. But in practice it's quite centralized, and the incentives point in that direction for the future. That's one of the points made very well recently by Moxie Marlinspike: https://moxie.org/2022/01/07/web3-first-impressions.html
Have you considered that you are in the wrong decade? Its year .. 13..? Its time to be up to speed on this.
If you run into a proponent that is also conflating these things you should simply correct them about the difference between onchain activities and third party centralized service providers, which means educating yourself first.
The only reason the hacker gets to keep the funds and have no civil or criminal liability is because of them using the actual decentralized rails and uncensorable contracts such as Tornado.cash
Re: Crypto.com accounts had unauthorized withdrawals
#240The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…
> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…