4 ms·
Seems to be a recurring theme recently. Evidently too many developers inexperienced in proper security are building these things. You would have thought after e
by highace 13y ago
Seems to be a recurring theme recently. Evidently too many developers inexperienced in proper security are building these things. You would have thought after everything that has happened so far that people would take a long hard look at their security measures.
- stcredzero 13y agoSecurity is hard, especially computer security in the absence of trusted/trustable systems. (Yes, it's a deliberate devil's advocacy, but it should be said.) We should ask ourselves why the existing government banking systems are secure. In part, it's because nothing is simply trusted and everything is double checked. In part it's because criminals have tried all manner of things, giving the system a chance to develop collective experience dealing with all manner of attacks. In part, it's because the law makes it a poor economic choice to engage in many kinds of criminal activity. Then ask, how many of these things are true for bitcoin? Then perhaps ask, could I provide these things, and make money while doing so?
- PeterisP 13y agoMy (completely pulled out of thin air) opinion is that there is no way that startups populated by young, hip developers can build a proper system for handling money. You need to have a baggage of a thousand bizarre things how these systems can be violated, unless you want to repeat the same mistakes - and that comes with time and experience. There are literally at least hundred thousand developers who have worked for 20+ years on financial systems - the industry employs a lot of them. If you're going to be storing money of other people, picking up a random such guy - even completely mediocre, boring one - would at least bring up the many issues that are taken for granted in 'that world' but nonobvious if you're not from the financial industry.
- dragonwriter 13y ago> My (completely pulled out of thin air) opinion is that there is no way that startups populated by young, hip developers can build a proper system for handling money. At least not if they are populted solely by young, hip developers. Those developers can probably build the system, but what they can't do is specify and validate the system. So, those young, hip developers need to at least spend some time talking to some experienced domain experts. Or, you know, keep repeating every failure in the history of finance and banking that has led up to the industry practices and government regulations they are ignoring. Sure, you can likely find better solutions to some of those problems, but it would be better if you at least "anticipated" the well-known, obvious problems and solved them, rather than repeating them first.
- dscrd 13y agoMoreover, these things should be built upon the certainty that somebody smarter than you, the coder, might be interested in free money, and that the software will be broken. Only with that mindset can one build a system that doesn't screw over every legit customer when it happens.
- PeterisP 13y agoAhh, the default finance mindset is a bit different - first, assume that your own employees, managers, sysadmins and developers would be interested in free money. Design the system, processes, checks and audits according to that - and it covers most of the precautions against outside hackers as a natural consequence. If you start a BTC exchange, write half of the initial code yourself, have access to the servers and own the company - then you should ask a simple question: could I myself steal funds undetected? If you're an investor, could the CEO/founder steal funds undetected? If the answer is yes, you have work to do. There are some theft options by privileged people that can't be realistically prevented, but you can make sure that those scenarios would be detected within a day, and thus those privileged people simply wouldn't do it to avoid jail.
- dscrd 13y agoEven better.
- danielweber 13y agoIt's not just "inexperienced in proper security." People very experienced in security would still have problems with this, because the irreversibility means the slightest mistake is doom. Writing bitcoin software should be like writing crypto: you aren't smart enough, so don't try.