Live data from Hacker News

New York to Bitcoin Startups: Get Permission

techcrunch.com

51–59 of 59 posts

Re: New York to Bitcoin Startups: Get Permission

#51
post #34

Earlier quoted context omitted.

off the top of my head fingerprints are used for banking, old fashioned wire transfers, and passports Fingerprints are not routinely collected in the United States to open bank accounts, send or receive wire transfers, or request passports.

Has policy changed? I could swear I had to give a fingerprint last time I opened a bank account in person, and when I got my passport. I suppose that was fifteen years ago...

I have never given a fingerprint to open a bank account.

Re: New York to Bitcoin Startups: Get Permission

#52
post #21

Earlier quoted context omitted.

There is a difference between: * Coinbase: A startup that holds millions of dollars worth of bitcoin for mostly consumers * The reddit tip bot: a non-profit community tool that explicitly discourages holding more than a dollar or two * Blockchain: A startup that holds no money for anyone, but writes and serves software that helps people hold their own money online. Do you think all three of these groups should go thr…

Professional auditing and security testing should be necessary for any piece of software from which it's possible to drain large sums of money, regardless of who's running the software or holding the money. In fact, I'd argue anything less constitutes an ethical breach on the part of the lead engineer(s). I'm not really sure why that particular regulation is so onerous in any of these situations, since any responsibl…

yes, it should. should that shouldness be codified into law and help entrenched market participants stay entrenched? because while I do see millions spent on bank software security, wellsfargo.com is still an enormous joke.

Re: New York to Bitcoin Startups: Get Permission

#53
post #52
post #21

Earlier quoted context omitted.

Professional auditing and security testing should be necessary for any piece of software from which it's possible to drain large sums of money, regardless of who's running the software or holding the money. In fact, I'd argue anything less constitutes an ethical breach on the part of the lead engineer(s). I'm not really sure why that particular regulation is so onerous in any of these situations, since any responsibl…

yes, it should. should that shouldness be codified into law and help entrenched market participants stay entrenched? because while I do see millions spent on bank software security, wellsfargo.com is still an enormous joke.

I'm referring only to the specific case of regulations which cover engineering practice (as opposed to more industry-specific regulations, for instance, which I don't know enough to comment on).

In these cases, absolutely yes! The shouldness should be codified into law.

The best mechanism (regulation vs. after-the-fact culpability; specific legislation vs. using existing frameworks, etc.) is debatable.

But companies who cause public harm by not following best practices (either intentionally or due to poor trained engineers) should be held legally responsible for preventable disasters. Just like it's done in many more mature (as in older) engineering fields.

Re: New York to Bitcoin Startups: Get Permission

#54
post #21

Earlier quoted context omitted.

Professional auditing and security testing should be necessary for any piece of software from which it's possible to drain large sums of money, regardless of who's running the software or holding the money. In fact, I'd argue anything less constitutes an ethical breach on the part of the lead engineer(s). I'm not really sure why that particular regulation is so onerous in any of these situations, since any responsibl…

> Professional auditing and security testing should be necessary for any piece of software from which it's possible to drain large sums of money, regardless of who's running the software or holding the money. In fact, I'd argue anything less constitutes an ethical breach on the part of the lead engineer(s). Would you include web browsers, OSs, system libraries and such in that definition? All those can steal users mo…

> All those can steal users money if compromised.

Not in a vacuum; they have to be deployed in a setting where that's possible.

> Would you include web browsers, OSs, system libraries and such in that definition?

It's sort-of a moot point, because the major products in all of these areas are routinely analyzed from a security perspective. Apple and Microsoft both spend a lot of money on security, and security researchers spend lots of time and effort auditing linux.

> If so, who do you suggest be responsible for that in an open source project?

The organization deploying the software in a security-critical setting should follow best practices when selecting and maintaining components.

There's a significant difference between engineering failures that happen even when you've followed best practices, and very preventable engineering failures that happen only because you've not followed best practices. Just because perfect security isn't possible doesn't mean we should give up entirely and not even both sanitizing input, for instance.

Additionally, OS vendors should not encourage users to use their software in security-critical settings unless the vendor is following best practices w.r.t. security. This is where I could see some bitcoin projects getting into trouble.

Re: New York to Bitcoin Startups: Get Permission

#55
post #34

Earlier quoted context omitted.

They are a little dated these days of course, but off the top of my head fingerprints are used for banking, old fashioned wire transfers, and passports. They want to be able to connect you to those things, and the fingerprint was the private key signature [1] of the 20th century. Which, IMO, isn't "so 1984" because those are historically all major fraud avenues. [1]: http://en.wikipedia.org/wiki/Digital_signature

off the top of my head fingerprints are used for banking, old fashioned wire transfers, and passports Fingerprints are not routinely collected in the United States to open bank accounts, send or receive wire transfers, or request passports.

Many banks will request a fingerprint to cash a check if you do not have a preexisting relationship with the bank.

Re: New York to Bitcoin Startups: Get Permission

#56

Earlier quoted context omitted.

Absolutely, 100% it does. Because it helps to prevent a business from building its profit model around 100,000 people abandoning $1 each.

Policy is always about tradeoffs. Is it your stance that the creator of Reddit tip bots should have to register fingerprints with the FBI, hand over personal financial info, send quarterly reports with to the Superintendent with audited financial statements, collect the real identities and physical addresses of all senders and recipients, assign a compliance officer, hire an outside firm to do pentesting, get permiss…

Yes, that is exactly my stance. Find another hobby outside of playing with people's money.

Re: New York to Bitcoin Startups: Get Permission

#57

> 1. Submit fingerprints of all founders (and employees) to the FBI and disclose personal financial information of founders and officers to NY State. > 2. Require them to hold an undetermined amount of U.S. dollar funds in bonds or trusts. Startups will not be able to predict the bonding or capitalization requirements until after they apply, making it difficult to project expenses or raise money. > 3. Conduct expensi…

>>4. Hand over any untouched user assets to NY State after five years as “abandoned property.” So if you hold bitcoin in an account for 5 years, the state will steal it from you by force?

No, if an account is inactive for five years, and the company is unable to contact the account holder, it's turned over to the state to hold. The state publishes a list of unclaimed property and provides a process that the owner or other appropriate party can use to claim their property. You can see how it works in New York at https://www.osc.state.ny.us/ouf/.

Re: New York to Bitcoin Startups: Get Permission

#58

Earlier quoted context omitted.

Policy is always about tradeoffs. Is it your stance that the creator of Reddit tip bots should have to register fingerprints with the FBI, hand over personal financial info, send quarterly reports with to the Superintendent with audited financial statements, collect the real identities and physical addresses of all senders and recipients, assign a compliance officer, hire an outside firm to do pentesting, get permiss…

Yes, that is exactly my stance. Find another hobby outside of playing with people's money.

... or do it somewhere else than in New York State, I guess?

Re: New York to Bitcoin Startups: Get Permission

#59
This will only further the ambitious goals of DACs (Distributed Autonomous Corporations).

This is all kind of amusing. 1) Government architects Internet in a decentralized fashion so that it survives damage from a nuclear attack. 2) Government tries to control Internet and fails because Internet, being decentralized, routes around control because it is seen as damage. 3) Bitcoin is pure Internet money.

The math isn't that hard here. This should be interesting...

Post reply on HN