Ruxum: Wall Street-Level Security Comes to Bitcoin
techcrunch.com
techcrunch.com
I can sum up my take on this by saying I've never heard of "Trust Guard".
(An attacker could exploit that in a number of ways. Here's a simple one: create a site with a domain name that looks really similar. http://secure.trustt-guard.com or something, it doesn't matter. When a user visits, autosubmit a form to https://secure.trust-guard.com with the malicious payload; the first thing it does is hide the error message and incorrect username. The user then enters username/password and attacker reads the values and sends it back to his site.)
What's worse, I can't find any way to report this. Does anyone see a link?
Oh dear.
The (short) audio clips on their site are... interesting. Trust Guard's emphasis/value appears to be sales conversions, not security per se.
https://www.trust-guard.com/category-s/3.htm
First sentences from the two co-founders:
"We really really try to help our customers increase their conversion rate"
"People spend a lot of time and a lot of money getting people to their site then they don't do the things that increase conversion"
If that's not Wall Street-level, I don't know what is.
The first startup I worked for was a PCI-compliance company. So I can tell you that the only way to sell "PCI-compliance" is that the credit card companies require it, and the only way to differentiate your service is by hyping the conversions it will help with. The reason is that these companies are fundamentally selling a check in the checklist that their customers otherwise do not care about. (Alas, even requiring people to care about security doesn't actually make them care about security.) For their front page, this isn't necessarily a surprise, it really doesn't tell you anything about the company either way.
Now, XSS on their front page... conclude away.
Apparently they don't run their security scanner against their own website ;-)
I also read the security policy at https://x.ruxum.com/security . It's nice and all, and does sound to be off on a better track, but being really, really secure is hard. I'm not saying they haven't succeeded, I really don't know (or much care). I'm just commenting on how phrasing it as if it's a done deal, rather than a goal, is cognitively hazardous.
https://twitter.com/#!/ruxum/status/86827701381496833
In other words, https://secure.trust-guard.com/certificates/www.ruxum.com
Personally, I don't consider that to be "Wall Street-Level Security."
"Security measures have been built into the design and setup of our infrastructure." tells you absolutely nothing. Neither does "Disasters are never nice events and we hope they don’t happen. We also expect one will happen and have plans to recover when it does." (although it's not strictly a security issue either).
edit: this is not my repo!
Have shared it with the team.
We are making some chenges to the bitcoin client to make our centralized exchange more secure, but a distributed exchange is a promising model too.
We ended up not pursuing that route as we didn't find a user friendly way of decentralizing the deposits and withdrawals.
Will get back to you later to discuss your repo and maybe we can work together in the near future. Good luck with your project!
(Don't ask me why a business that's trying to get itself taken seriously as a financial exchange would choose a name containing the word "camp".)
Anyway, for the moment, as far as security goes, these new exchanges don't necessarily need "Wall Street-level" security; they just need to be perceived as probably being more secure than Mt. Gox, which, given recent events, shouldn't be difficult.
But to attract traders, they also need liquidity, which they don't have much of yet.