Live data from Hacker News

Facebook Security Director Joins Bitcoin Startup Coinbase

techcrunch.com

31–40 of 83 posts

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#31

Earlier quoted context omitted.

Bitcoin with central key escrow is completely and utterly pointless, unless the goal is to generate a lot of waste heat from servers. > Most people aren't going to want to hold their own keys as most people can't stop their computers from being constantly infected by malware. We have cheap, secure hardware crypto tokens that rely on two-factor auth. You don't need to keep millions of dollars on a Windows PC. > Just a…

I don't see how the regulation level of Coinbase affects anything. Some people will store their keys on Coinbase. Paranoid users will use hardware wallets like Trezor. And there's a lot of options in between. The point is that its that choice (for starters) which differentiates bitcoin from Paypal. What if Paypal were to adopt bitcoin as a deposit/withdrawal method, right next to credit card and bank transfer? That w…

> I don't see how the regulation level of Coinbase affects anything.

There's no point to a crypto-currency with insecure crypto. If you have insecure crypto, you need centralized regulation. If you have centralized regulation, you don't need crypto-currency.

> The point is that its that choice (for starters) which differentiates bitcoin from Paypal.

Paypal moves money in a lot of currencies, and there are lots of choices other than Paypal to move currency.

> Coinbase isn't going to take over bitcoin any more than MtGox did. I don't quite understand what you're worried about.

I think the analogy you're actually looking for is:

   "Coinbase isn't going to take over bitcoin any more than Google took over e-mail"
The decentralized nature of bitcoin is the entire point. If it's co-opted by cloud key escrow services, there's no point.

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#32
post #4

I recommend to use Blockchain.info or BitGo or GreenAddress over Coinbase if you already have Bitcoin. With those services you hold the keys to your Bitcoin, not Coinbase. With Coinbase they are in control over your Bitcoin, not you. GreenAddress is the only wallet for Bitcoin with a 2-2 model Multisig offering a Bip0032 wallet with nLocktime on the Bitcoin blockchain. * https://greenaddress.it/en/

Most people aren't going to want to hold their own keys as most people can't stop their computers from being constantly infected by malware. Just as people don't want to keep large amounts of cash in their safe, they will want someone else to take the responsibility of securing their coin. Pretty much only the tech savvy will care to even understand what a key is or care to hold their own. Bitcoin isn't a political m…

use a 2of2 or 2of3 wallet with multisig and two factor.

Even better with an anti tampering hardware wallet talking to a service provider for 2FA for most security

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#33

Earlier quoted context omitted.

Most of these services fail to clarify whether they are web-based and rely on so-called "secure" javascript crypto: eg, where their servers are sending the ephemeral JavaScript code that they claim -- but can not under any circumstances guarantee should they be compromised -- will not send your private keys to the server. Compare this to signed, native applications produced by third-parties who do not run the service…

Our FAQ https://greenaddress.it/faq we have a chrome app non minified and open source on github. That client is local and no JS can be injected as it connects via ws. Furthermore it verifies data against the electrum network and provides nLocktime transaction unlocking your funds.

1) Chrome apps can be silently updated; it's a huge security hole in Chrome's distribution model, as it removes all human oversight from the process of software distribution.

2) You control the distribution keys for the silently updating Chrome app, and your signing key, which means all you need is the end-user's signing key to empty people's wallets -- which you (or any adversary that compromises you!) can get by pushing a Chrome app update.

3) Unless you are actually pushing users to use externally downloaded, NON-AUTOUPDATING, code signed applications by default, you're making users insecure by default. An open source client on GitHub doesn't do anyone any good if your default is to strip away crypto-currency's security. This is no different than Microsoft's previous policy of shipping insecure services enabled by default.

Essentially, this boils down to "trust us" -- you control the infrastructure that protects one half of the signing keys, and you already have access to the other half.

It'd make a helluva lot more sense if a locally installed client was maintained by a trusted third-party, and it was the default user mode.

Cloud-focused web people are undermining the promise of bitcoin by simply not understanding why the cloud is so dangerous, whether we're talking about user data (creating a vast treasure trove for the government), or money.

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#34

I'm a fan of BTC and use coinbase as my central wallet of choice. Super excited about this news. I recently switched from regular banner advertisements on my site ( http://www.spaceindustrynews.com ) - cheap plug - to taking BTC donations. The BTC community has been amazingly supportive throughout the whole thing.

I'm a fan of BTC and use coinbase as my central wallet of choice. Please transfer your BTC to a wallet under your control immediately. Run, don't walk. Take it from me: it's a terrible feeling to lose your money because someone else lost it on your behalf.

You mean a wallet on your own hardware, or your own wallet on someone else's hardware like Blockchain.info?

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#35

Earlier quoted context omitted.

I'm a fan of BTC and use coinbase as my central wallet of choice. Please transfer your BTC to a wallet under your control immediately. Run, don't walk. Take it from me: it's a terrible feeling to lose your money because someone else lost it on your behalf.

You mean a wallet on your own hardware, or your own wallet on someone else's hardware like Blockchain.info?

Under no circumstances should you trust anyone to have access to your bitcoin. Do whatever it takes to accomplish that goal. Philosophically, that's one of the core reasons bitcoin is a big deal, because at no point in history has it been possible to do that until now.

If I had followed the above advice, then I wouldn't have lost a lot of money.

Given the nature of human greed, what do you think the chances are that someone who has access to >10% of a currency will simply let it sit there and do nothing with it?

Given the nature of computer security, what do you think the chances are that Coinbase is impregnable under every imaginable circumstance? What about a rogue employee? What if the founder himself steals?

Now, the question is, what's the best way to accomplish the goal of "Don't let anyone else have access to your bitcoin, ever"? There are solutions. Find one, use it. Please. Don't make my mistake.

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#36
I hope he gets them off MongoDB. I still can't believe they let me double sell without even contacting me afterwards (I sold ~10 bitcoins when it was around $800 and the site was exceptionally busy -- had USD in my Coinbase account afterwards and the bitcoins never left, and I was able to transfer both the USD and BTC out afterwards).

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#37
post #36

I hope he gets them off MongoDB. I still can't believe they let me double sell without even contacting me afterwards (I sold ~10 bitcoins when it was around $800 and the site was exceptionally busy -- had USD in my Coinbase account afterwards and the bitcoins never left, and I was able to transfer both the USD and BTC out afterwards).

Can you tell me if you know the technical limitation of MongoDB that allows a double-sell?

Is it because it doesn't have transaction integrity?

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#38

Earlier quoted context omitted.

And everyone might stop using Facebook. Or WhatsApp. Then Mark Zuckerberg would look silly. Like AOL did after buying MySpace. Is there a deeper point here which I'm not gleaning?

Didn't AOL buy MySpace after everyone stopped using it?

I don't think AOL ever owned myspace, maybe you guys are thinking about News Corp (Fox)?

But in any case, myspace was still really popular when it was sold and was still growing for a couple of years after; it didn't start getting creamed by Facebook until 2007/2008.

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#39
post #36

I hope he gets them off MongoDB. I still can't believe they let me double sell without even contacting me afterwards (I sold ~10 bitcoins when it was around $800 and the site was exceptionally busy -- had USD in my Coinbase account afterwards and the bitcoins never left, and I was able to transfer both the USD and BTC out afterwards).

This happened to me and many others on Reddit. It's something that they manually audited it seemed and I got emails about it letting me know that they would be correcting the issue about a week after it happened. Sounds like in your case they never contacted you though? Wow.

Still, it made me wonder if I could have just ran with the money and drained the bank acct they had access to... Not a good thing for an exchange to be doing.

Re: Facebook Security Director Joins Bitcoin Startup Coinbase

#40
post #36

I hope he gets them off MongoDB. I still can't believe they let me double sell without even contacting me afterwards (I sold ~10 bitcoins when it was around $800 and the site was exceptionally busy -- had USD in my Coinbase account afterwards and the bitcoins never left, and I was able to transfer both the USD and BTC out afterwards).

Can you tell me if you know the technical limitation of MongoDB that allows a double-sell? Is it because it doesn't have transaction integrity?

Mongo shouldn't be used for financial applications, it doesn't have ACID support.
Post reply on HN