Live data from Hacker News

Coinbase: Responding to Firefox 0-days in the wild

blog.coinbase.com

1–10 of 97 posts

Re: Coinbase: Responding to Firefox 0-days in the wild

#6
post #5
post #4

This is among the critical differences between MtGox and Coinbase.

"We're not run by idiots"?

Well, sure, I suppose that's step zero. But there's a lot more work required beyond that in order to survive continuous attacks.

Re: Coinbase: Responding to Firefox 0-days in the wild

#8
Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code.

Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard.

I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

Re: Coinbase: Responding to Firefox 0-days in the wild

#10

Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

The trouble is finding someone to bribe who won’t suddenly start buying new things.
Post reply on HN