3 ms·
Unfortunately not right now. We're looking at this from a startup's point of view, and putting our SaaS code on github isn't something we're looking ATM. We wil
by codelitt 12y ago
Unfortunately not right now. We're looking at this from a startup's point of view, and putting our SaaS code on github isn't something we're looking ATM. We will be work on releasing an API for others to use.
- atoponce 12y agoThat's very unfortunate. With the revelations of Edward Snowden against the NSA, and the ability to call into questions the ethics of cloud computing and their providers, startup cloud companies that don't provide their software code under a copyleft license won't do well in the long term, I suspect. The fact that personal and financial data will be hosted on your company servers, tying names and accounts to Bitcoin transactions and wallets, all doesn't pass the smell test, if the code isn't open for inspection. Of course, there is nothing preventing your company from putting up placebo code on Github, that doesn't actually represent what is running on your servers. I understand that, but as a show of good faith, it would do your company more in the long term by opening the code in addition to providing an API. Anyway, good luck.
- codelitt 12y agoExtremely valid concerns. We're trying to be as secure as possible — personal data is strongly encrypted in our database, we're using tokens instead of bank details to keep things more secure, we're implementing 2FA for logins, and we're using perfect forward security for SSL. Unfortunately, though, money laundering law mandates that we need to record personal information so there's little we can do to get around the name <=> bitcoin address issue. We have ideas (like company-specific encryption for bitcoin addresses where only employers can decrypt addresses) but it's a long way out, even if we do implement it.
- krapp 12y agoYou're correct in stating that it's impossible to truly "verify" the source code of a website - essentially, it's a remotely hosted black box unless you have direct file access to the server. But this seems to suggest that if you can't trust a site which doesn't publish its source code, you also can't trust a site which does - that "show of good faith" means absolutely nothing.