Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm a BitCoin skeptic with the best of them. But this is breathtaking.

That's one thing about bitcoins. There's no FDIC or SIPC watching your back. It's the wild west with train robberies and stage coach heists in all.



It's interesting to consider why that is. I could start a BitCoin deposit insurance company, for example: you'd pay me X% of your balance each month, and I'd make you whole in the event of fraud.

Of course, I'd want all sorts of regulations on how you set this up; I might sell you some kind of extra-secure system for managing your balance, for example. At that point, the market would basically be putting a price on BitCoin security.

Obviously, my deposit insurance scheme could go broke, if I price it wrong. That's theoretically a risk with SIPC. It's not a risk with the FDIC, since that is ultimately backed by the government's ability to print an unlimited amount of money.

So it might make more sense to say that deposit insurance is a feature of unstable currencies: if anyone's dollar-denominated debt can be 100% guaranteed by the government, then the value of everyone's dollar-denominated assets will face an inflation tax to pay for this guarantee.


Maybe I'm missing some detail of the scheme you're proposing, or have some fundamental misunderstanding of bitcoin, but if bitcoin is anonymous and untraceable, how do you prevent insurance fraud?


You could only insure bitcoin that is stored in a wallet that you control (i.e. act as a bank).


Wouldn't this also defeat the purpose of BitCoin in the first place? And by "purpose" I'm referring to the whole "anonymous, untraceable" aspect of it. It's very much like cash - it's anonymous, yes, but also if it gets stolen there's not much you can do about it.


It would be nice to have that option. "Anonymous, untreacable, and un-recoverable, or not-so-anonymous, somewhat traceable, and recoverable."

Plus, I'd bet that you could create an onion router-style arrangement with multiple off-shore banks in different jurisdictions.


The thing I find more dangerous than that is anyone with your wallet.dat file can go and do whatever with your account.

There really should be additional checks. Having to sign your transfer requests and allow people to impose a voluntary delay on their transactions to allow time for cancellation would help significantly.


My wallet is on an IronKey - in order for me to use it I have to plug it in and decrypt it. I also backup my wallet on a NAS server but the wallet is encrypted with GPG.

Gotta protect your data!!


Where do you back up your GPG private key? Where do you store the passphrase for the key? It's a long chain of vulnerabilities in any well architected system that must be addressed. This seems acceptable for a big company, but for an individual to have to go through all these steps just to protect their money seems arduous.


And it's simple to run a keylogger after a brower/flash/pdf/java exploit to grab your password, isn't it? Not even admin/root access is needed.


Not if you have a secure means of input in your OS. OSX does, for instance, you can turn it on in the Terminal application and no loggers will see what you type.

Unless they install as a kernel extension, then you're screwed. But that requires a password.


or a bog standard privilege escalation bug


of course. But now we're talking something significantly more complicated than a keylogger, and more fragile as it probably relies on glitchy behavior.


FDIC or SIPC don't cover you if you have stacks of cash that get stolen.

This guy wasn't using a bank, he wasn't encrypting his wallet, so that is inevitable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: