Live data from Hacker News

BTC Stolen from Poloniex

bitcointalk.org

81–90 of 136 posts

Re: BTC Stolen from Poloniex

#81
post #71

The comments on the bitcointalk thread are interesting. Here you have a bunch of people who have just lost 12% of their funds and most of them are totally ok with that . If you are looking for evidence that bitcoin supporters are driven more by ideological reasons than economical ones, here is a pretty good example.

Eh, there's a lot to be suspicious of, but people have gotten locked out of a portion of their funds, with a promise by this guy who they previously trusted to make it up.

Apparently it's only $50,000 ("only"), meaning no individual lost tens of thousands of dollars.

It's unfortunate that this guy being upfront with everyone puts him above average, but it does, so his business will probably continue, such as it is.

Re: BTC Stolen from Poloniex

#82
post #56

I know everyone is gleefully using the failure of three poorly-coded Bitcoin exchanges to crow about the many wonders of regulations. However, has anyone stopped to ask why so many exchanges are poorly-coded? No, it's not because everyone in Bitcoin adores PHP. I've met some of the most capable coders among cryptocurrency enthusiasts. Go check out Conformal's btcd, or any of Jeff Garzik or Warren Togami's projects, o…

My suspicion is that simply removing barriers to entry for more cautious folks would not effectively resolve this sort of problem. Methodical people who take their time in engineering ironclad software systems backed by rock-solid accounting practices don't get first mover advantage, and they might not have bottom lines capable of supporting the kind of fee structures that would allow them to compete effectively with faster, sloppier businesses.

An unstated major premise of the "wonders of regulations" argument is that regulations exist because sometimes the hand of government is needed to handle situations where the invisible hand is a demonstrable failure.

Re: BTC Stolen from Poloniex

#83
post #55

The missing link for bitcoin is coverage under something like the Uniform Commercial Code- a system that specifies general principles governing transactions and the framework for their completion and resolution of conflicting claims. Caveat emptor is not a foundation for a currency.In practice bitcoin's very anonymity makes it a more attractive target for theft- bitcoins come pre-fenced. As Patio points out, the bitc…

In practice bitcoin's very anonymity makes it a more attractive target for theft Also the fact that the people making software seem incompetant when it comes to technology.

Eh, I'm not sure they are incompetent. They are, however, swimming in a sea where the slightest mistake is lethal.

Some people see these stories and think "ha, I could do better than that!" Other people see these stories and think "can I really be sure that I haven't made even one fatal mistake?"

All software engineers write bugs. All software engineers write security holes. For most of us, the fatal flaw doesn't irrevocably wipe out a bunch of people's life savings.

Re: BTC Stolen from Poloniex

#84
post #57

Look: every startup gets owned up somehow in its first year or so. If you think your company hasn't, I have an adage about the sucker at the poker table for you. I'm not sure how many people on HN really understand this, because every thread I read about Bitcoin companies having security problems features highly-voted comments expressing shock at how bad their security must have been. No: this problem is universal. T…

Perhaps any online Bitcoin service is going to have to expect a certain loss rate due to hacking and budget accordingly. Just as credit card issuers expect to charge off some percentage due to fraud. The trick is to keep that loss rate manageable. It's clear that many of the same features that Bitcoin users like about it also make it attractive to criminals.

Re: BTC Stolen from Poloniex

#85
post #2

Seems to be a recurring theme recently. Evidently too many developers inexperienced in proper security are building these things. You would have thought after everything that has happened so far that people would take a long hard look at their security measures.

My (completely pulled out of thin air) opinion is that there is no way that startups populated by young, hip developers can build a proper system for handling money. You need to have a baggage of a thousand bizarre things how these systems can be violated, unless you want to repeat the same mistakes - and that comes with time and experience. There are literally at least hundred thousand developers who have worked for…

> My (completely pulled out of thin air) opinion is that there is no way that startups populated by young, hip developers can build a proper system for handling money.

At least not if they are populted solely by young, hip developers. Those developers can probably build the system, but what they can't do is specify and validate the system. So, those young, hip developers need to at least spend some time talking to some experienced domain experts.

Or, you know, keep repeating every failure in the history of finance and banking that has led up to the industry practices and government regulations they are ignoring. Sure, you can likely find better solutions to some of those problems, but it would be better if you at least "anticipated" the well-known, obvious problems and solved them, rather than repeating them first.

Re: BTC Stolen from Poloniex

#86
post #84
post #57

Look: every startup gets owned up somehow in its first year or so. If you think your company hasn't, I have an adage about the sucker at the poker table for you. I'm not sure how many people on HN really understand this, because every thread I read about Bitcoin companies having security problems features highly-voted comments expressing shock at how bad their security must have been. No: this problem is universal. T…

Perhaps any online Bitcoin service is going to have to expect a certain loss rate due to hacking and budget accordingly. Just as credit card issuers expect to charge off some percentage due to fraud. The trick is to keep that loss rate manageable. It's clear that many of the same features that Bitcoin users like about it also make it attractive to criminals.

I don't think you should handwave this. Companies have hot bitcoins because they need them to cover transaction volume. Their "hot" liability scales with their business. When you're six months old, a 50k loss (more accurately: the requirement to redeem BTC that start with a market value of 50k) kills your company (or the rational incentive to continue pursuing your company). When you're a year old, 100k does the trick.

This isn't a problem bitcoin companies outgrow; it's a problem that festers as the company gets more successful. Do you go out like Flexcoin did, or like MtGox? Either way: you eventually do get taken out.

Re: BTC Stolen from Poloniex

#87
post #2

Seems to be a recurring theme recently. Evidently too many developers inexperienced in proper security are building these things. You would have thought after everything that has happened so far that people would take a long hard look at their security measures.

It's not just "inexperienced in proper security." People very experienced in security would still have problems with this, because the irreversibility means the slightest mistake is doom.

Writing bitcoin software should be like writing crypto: you aren't smart enough, so don't try.

Re: BTC Stolen from Poloniex

#88
post #2

Seems to be a recurring theme recently. Evidently too many developers inexperienced in proper security are building these things. You would have thought after everything that has happened so far that people would take a long hard look at their security measures.

My (completely pulled out of thin air) opinion is that there is no way that startups populated by young, hip developers can build a proper system for handling money. You need to have a baggage of a thousand bizarre things how these systems can be violated, unless you want to repeat the same mistakes - and that comes with time and experience. There are literally at least hundred thousand developers who have worked for…

Moreover, these things should be built upon the certainty that somebody smarter than you, the coder, might be interested in free money, and that the software will be broken.

Only with that mindset can one build a system that doesn't screw over every legit customer when it happens.

Re: BTC Stolen from Poloniex

#89
post #86
post #84

Earlier quoted context omitted.

Perhaps any online Bitcoin service is going to have to expect a certain loss rate due to hacking and budget accordingly. Just as credit card issuers expect to charge off some percentage due to fraud. The trick is to keep that loss rate manageable. It's clear that many of the same features that Bitcoin users like about it also make it attractive to criminals.

I don't think you should handwave this. Companies have hot bitcoins because they need them to cover transaction volume. Their "hot" liability scales with their business. When you're six months old, a 50k loss (more accurately: the requirement to redeem BTC that start with a market value of 50k) kills your company (or the rational incentive to continue pursuing your company). When you're a year old, 100k does the tric…

I didn't mean that to come off as hand-waving. I think this is a very serious issue that is going to require a complete rethinking of security practices. Perhaps it won't ever be solved satisfactorily, but I wouldn't rule out ingenuity of developers to at least reduce the risk to manageable levels.

Re: BTC Stolen from Poloniex

#90
post #56

I know everyone is gleefully using the failure of three poorly-coded Bitcoin exchanges to crow about the many wonders of regulations. However, has anyone stopped to ask why so many exchanges are poorly-coded? No, it's not because everyone in Bitcoin adores PHP. I've met some of the most capable coders among cryptocurrency enthusiasts. Go check out Conformal's btcd, or any of Jeff Garzik or Warren Togami's projects, o…

For whatever reason, decentralised cryptocurrencies seem to be a very polarized subject.

As somebody in the financial markets regulatory space, your comment aligns with my own thoughts - there is a middle-ground: a balanced but essentially prudent view of Bitcoin and altcoins that is seldom seen in these threads full of naive ideals and cynical strawmen.

Another aspect of this middle-ground viewpoint: both of these polarized sides seem to be focused exclusively on fully automated Bitcoin-based systems. I find this highly unlikely.

If Bitcoin-based systems do become popular, there is no reason to imagine they won't involve some human (e.g. back office settlement systems with STP rules, payment tests and 4-eye reviews of breaches) and legal elements (e.g. declare your BTC addresses to your government tax office, KYC/AML compliance for exchanges, etc.) to solve certain problems that have been in the news lately.

Post reply on HN