How was this ever going to end any other way? Imagine how preposterous the idea of storing $650mm in USD in a random game studio's checking account would be.
How was this ever going to end any other way? Imagine how preposterous the idea of storing $650mm in USD in a random game studio's checking account would be.
But it's decentralized.
(Do the same hand movement as if saying "It's got electrolytes")
I’ll see if I can find it.
https://www.reddit.com/r/btc/comments/7opi7w/the_idiocracy_o...
* It's decentralized *
Oh, crap.
Reminds me of the line in 30 Rock:
"Gentlemen, we have moved our customer support offices to a part of India that has no telephone service. We're now providing the same quality of service at zero the cost".
I'm stealing this.
https://www.smithsonianmag.com/science-nature/copper-virus-k...
[0] https://www.theguardian.com/law/2022/feb/14/us-bitcoin-case-...
In the regular financial world you can at least reverse the transaction. With crypto, is there anything you can do?
Imagine the following scenario: bank A sends $100M to bank B, which then sends it to bank C. By "reversing" the A->B transaction, all you're doing is making bank B on the hook for the $100M. Bank B will obviously not be very happy about this, and if you try to force it through some legal means, this will effectively amount to stealing $100M from bank B and its customers.
Reversing erroneous transactions is a useful feature of regular financial system, and lack of it in blockchains often poses huge and avoidable practical problems. At the same time, this in no way should be seen as panacea for restoring stolen money, neither in real financial systems, nor in blockchain.
Yes. A friend of mine is a branch manager for a major bank. She's one of the people who has to deal with unhappy customers victimized by scams. Recently, she had a customer who wanted to send a significant amount of money to a country in Southeast Asia. That's not unusual for a California bank. Then the customer showed up at the branch in tears. It turned out the customer was being victimized by a "relative in trouble" scam. Fortunately, the receiving bank had flagged the account at their end as suspicious, and hadn't yet let the recipient withdraw the funds. This allowed the transaction to be clawed back. It took phone calls, messages, management signoffs, and work by people in multiple banks to unwind the transaction, but the money was back in the customer's account in the US in a week.
Reversing a fraud transaction in the banking system is a rare event, and not easy, but it is often possible for a few days after the event.
I've certainly had banks call me and explain the nature of wires, in an attempt to prevent me from financially foot-gunning.
Yes, there are flaws in the real world financial system as well.
Yet, we’ve heard of more of these scams in years of crypto than in decades and centuries of banking.
And no one has still provided an explanation of why crypto is better than the established working system other than “it’s decentralized” except as we find repeatedly, it’s not decentralized.
Of course, the best way to find out why something is not done a certain way, is to try doing it that way.
Who supervises the supervisors?
because the govt cannot ban you from receiving payments if they dont like you.
Who is talking about criminals? Just because you expose the misdeeds of US govt does not make you a criminal.
> There's nothing about Crypto that changes that. It's just another system.
You can still receive payments in Crypto even though the govt forces the bank and credit card providers to close your account.
Its not just the US govt who wants to control your life, other govts want to do it to.
Payments might be a joke to you but there are many people whose life depends on it.
https://cointelegraph.com/news/how-are-afghans-using-crypto-...
404 BTW
So your argument is that cash is also used by criminals so cash should be banned. Do you realise how ridiculous that sounds now apply the same logic to crypto.
In an analogous situation, suppose I go to a physical store and buy a TV, only to find that it doesn't turn on. I have the right to return it to the same store that I bought it from, and to receive a full refund. Nobody at that store manufactured or designed the TV, so why should they take the financial hit for a broken TV? Except that without that financial incentive, the store has little reason to bargain with their suppliers about defective merchandise, and the supplier has little incentive to fix a defective product.
Yes, but it's only one of the incentives they're facing. Another one is to provide useful and convenient service to its customers.
Try to think more about the example I provided. The account in bank A is victim's, while accounts in banks B and C are owned by the fraudster. The transfer from A to B is fraudulent, but the transfer from B to C is perfectly legitimate as far as B bank knows: the name on the destination account in bank C might even be exactly the same as in bank B, so why would bank B have any suspicions? At best, it could reject incoming transfer from bank A if it had suspicions (which, by the way, why would it have?). Would you want to be a customer of a bank that can just reject incoming transfers, so that you have trouble getting paid?
Finally, consider that bank C might then allow the fraudster to withdraw the proceeds in cash. Bank C might be foreign, and B communicates with it through SWIFT, and might simply refuse reversing the transaction, or again might already have sent the funds to bank D in yet another country. The point is that you cannot treat regular financial transactions as reversible either. They might be reversible sometimes, especially if everyone involved acts in good faith, but there is no guarantee.
> In an analogous situation, suppose I go to a physical store and buy a TV, only to find that it doesn't turn on. I have the right to return it to the same store that I bought it from, and to receive a full refund.
That's not really an analogous situation. Here's what would be closer: imagine you order a specialty TV online from China. The retailer A orders a company B that manages it warehouse to pack it on a truck of company C that specializes in LTL, which then ships it to company D which coalesces LTL freight into packed containers, then puts on containers owned by a shipping company E, which ships them across the Pacific to port authority F, then we have a shipping company in G in states, another truck company H to ship it to train yard H that gets it to LTL company I's warehouse, which then is passed on to courier company J, an independent subcontractor K of which finally gets it to your front door. Then your TV doesn't work, and you want to return it.
Will you try to unravel the chain back the same way it arrived? Are you going to find the subcontractor K, and have him ship it back to courier company J, to send it back to the LTL company K etc? No, you'll go straight for the original retailer. Similarly, with financial fraud, you'd need to go straight for the fraudster.
Well ... some kinds of transferring wealth are legally harder to reverse after the first transfer.
In the United States, an old-fashioned way of moving money between people, the "check", has behavior specified in Uniform Commercial Code Article 3, Negotiable Instruments.
Article 3 is worth a read; it has filled in a lot of gaps for me about the bare-minimum legal requirements associated with activities like writing a check, post-dating a check, negotiating a check, stopping payment, etc. (In practice banks may do more than the minimum for customer service but it's interesting to understand the basics).
One of my favorite parts is the "holder in due course" rule ("§ 3-202. NEGOTIATION SUBJECT TO RESCISSION.")
If a check gets endorsed a couple of times and a new person takes it in good faith, then that new person is a holder in due course. Some remarkable things happen: even if the check has gotten a stop payment or has otherwise been dishonored, a holder in due course now has the right to the money promised by the check.
I wondered why the law would set up such a convoluted way of making certain payments irreversible. My dad explained:
"""[A] a widely accepted legal framework for negotiable instruments was critical to trade in the era before electronic payments. The problem is convenience - how can a buyer safely pay for goods or services without carrying around a lot of cash? The holder in due course rule basically lets the buyer's bank rely on the form of the negotiable instrument (including a genuine signature) without risking a claim for wrongful payment based on other facts about the sale it can't know."""
So -- can someone take advantage of this behavior to turn a dubiously valid check into an irreversibly one, and get the money?
Yeah! Totally! There's a guy named Robert Triffin who is, like, famous for buying dodgy checks at below their value, cashing them, and suing to get his money when the payor refuses to pay up. I don't have firsthand info about this, I just read news articles, but I think he gets a decent ROI. (See e.g. http://appellatelaw-nj.com/the-first-triffin-case-of-2011/
P.S. Some of my other favorite things about this instrument in the UCC:
* a signature is any mark you intend to be your signature (§ 3-401);
* a check can be written with almost any text and in almost any format on whatever you want (§ 3-104);
* checks can go stale six months after the datestamp but banks can choose to honor them anyway (§ 4-404);
* writing a future date on a check doesn't legally prevent it from being cashed unless you also tell your bank about the postdating in the same way you would make a stop payment order ( § 3-113, § 4-401 )
* If you have a dispute with someone about how much money they owe you for a service, and they give you a check, you can cash the check and write "without prejudice" to indicate that you aren't agreeing that this is the correct amount owed but you do want their money (§1-308). UNLESS the payor has written on the check "a conspicuous statement to the effect that the instrument was tendered as full satisfaction of the claim" (§ 3-311), in which case cashing that check discharges your claim. Which all frankly seems like a mess.
Every transaction that is occurring now on the chain will be invalidated.
That means you can't even reverse a single transaction you will have to reverse one transaction and ALL other transactions that happened after the one you want to reverse.
If that happens too often why would I want to to transact on a chain that is under constant threat to be forked off?
But the answer to "why would I want to to transact on a chain that is under constant threat to be forked off" is even simpler: It's because, in this hypothetical, the regulatory environment you operate in gives you no other choice. Unless you and everybody you transact with has the ability to boycott or subvert the regular financial system entirely (e.g. you're doing entirely black market transactions), then you'd have to fall in line if a government that was crucial to your operations or your downstream supplier's operations required it.
On a regular PoW blockchain you will have to recalculate all the hashes according to the difficulty which will up to the miners.
But even if you could, it's an absolute technical nightmare.
To build an analogy that somehow fits. If you have git repo and you find out that a particular commit that you want to undo, what do you do?
- Rebase all changes to an earlier commit, remove the faulty commit and recalculate all commit hashes that follow it.
or?
- Create a new commit that reverts the old commit.
In reality you opt for option 2 99.99% of the time. The only reason you would ever want to remove a commit from history is if you accidentally exposed information to an audience that is not supposed to see it.
Nevertheless on a public blockchain all transactions would be invalidated and that indeed is a problem.
Because everyone who received coins would have to wait again for n confirmations in order to be sure they got their money. In theory nobody should be able to add a double spend transaction to the pool but I wouldn’t bet on it.
That’s what I mean with technical nightmare.
You would have to make sure to properly identify all transactions. Possibly take down the system, exclude a single transaction. Make sure that the miner who will find the next block will include the right transactions. Make sure of that for the following block. I don’t see that happening with a large coordination effort, meaning: centralization.
And when you come to that conclusion you should probably take a step back and rethink “why are we doing all of thatch blockchain stuff when we need to rely on a central authority?”
I think blockchain is going to eventually die for that exact chain of reasoning.
Or you would need to make more crypto cover those... Which then would destroy the whole deflationary idea with likes of bitcoin...
Could I recover $100k that got stolen? What about $10k? $1k?
https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery
They investigate and try to recover the money they can, but it's not always successful.
https://decrypt.co/93874/11-biggest-defi-hacks-heists
I looked up the first six (#11-#6) projects on this list and I didn't see that in any of those cases the perpetrators have been caught nor the funds returned. I could be missing something though.
Conclusion? Far less effort spent on BTC cases and far less thefts resolved.
See also http://go/hackernews/item?id=30838572 and https://en.wikipedia.org/wiki/Financial_crisis_of_2007%E2%80...
Individual consumers, who we all know are extremely knowledgeable and informed on all topics interacting with their lives, should weigh the increased risk of total loss against generally lower prices. And then in the event they unluck into in the total loss case, they should just shrug their shoulders and accept that they were lucky.
I find it hard to argue that "asbestos and lead paint" are the same kind of individual choice as a bank or unregulated drugs.
> Giving $650mm in USD to a random company is still infinitely safer than doing so with crypto.
Chris Roberts has a very interesting opportunity he'd like to propose to you...
This is a poor comparaison. This Starbuck money cannot be "stolen".
Being a victim of fraud is not "voluntary" in any meaningful way.
Voluntary or not is a red herring. The word this discussion is looking for is authorized.
The transfer was authorized by the account holder. They were defrauded. But when they made the transfer, then intended to do so. (The situation is murkier with credit card transactions, at least in America, because they chose to accept a role in dispute resolution.)
The $625mm drained out of Axie's account wasn't authorized by Sky Mavis. That's a different type of fraud than being ripped off.
But that's a different case than money being "drained" from an account by someone else.
But even then, if you store $650 MM in a Bank of America account, that money is protected against being stolen by BOA's anti-fraud software, laws, the trillions of dollars of assets BOA has.
And that shows the difference in how each is protected.
If A has a TV, B steals the TV and sells it to C, who sells it to D...then the TV is still returned to A, and D is out of luck.
It protects again bank failure. If the one's assets are drained from the bank, as long as the bank has not failed, it will have to make the account holder whole.
That's why a company would be stupid to hold $200M at Podunk Bank of Littletown, KS but is perfectly fine to hold it in a DDA account at Bank of America, Citi or Chase
For one thing, most business accounts do not hold 9 figures in cash.
Inflows and outflows are likely to be predictable, so you can set flags for certain thresholds.
A 9 figure transaction would absolutely be noticed, and possibly flagged before it was permitted to continue.
Since 16 year olds can hack into auth providers like okta and then hack into microsoft and steal source code, and this crypto stealing endless happens, there's just not good electronic security. But what is good is I can go to my bank in person and fix things. It would be so much harder for someone to get fake id. I actually have a personal relationship with my advisor at my 401k. Those things do give me some additional security, at least I think so.
They tried to use some of that digital money (in another electronic format) in a digital game, but the game got hacked and now those dollars are someone’s else dollars.
The hacker may have some difficulty transforming digital money into paper bills, because KYC, but he can launder it like old school people used to and have some.
Crypto provides exciting new ways to do that, too. First send it through a mixer service. Then, invest in some new NFT project. Six months later, oh nice, someone bought your NFT for 10x what you paid for it. What a great investment.
also there are all sorts of checks when you try to wire or withdraw more than $10,000, not to mention wire hundreds of millions. Such transaction will manually cross a desk of at least 2 different bank managers.
Anecdote time. My wife and I have a shared checking account that got hacked and drained. First her debit card got skimmed. Then the perp called USAA a half dozen times claiming to be her and asking for account credentials. Finally they got a helpful account rep to reset the password, disable MFA, and tell them the username. Yep. You heard that right. Social engineering works even on bank tellers who should know better.
Fortunately it's just a daily use account and I'm paranoid, so there was only 5K they could access there. USAA owned up to the whole thing and restored the funds, but now they punish my wife with a 10-minute interrogation to prove her identity if she ever has to get them on the phone for a legitimate reason.
Convenience and security are often in direct competition with each other. Almost all of us would expect convenience in this situation. You should know better more than most the cost of choosing convenience and even you want that convenience. Is there any wonder why businesses select convenience over security?
If the company is going to provide some level of support to people they haven't verified, that support will be abused as a means of passing the verification.
Back when this happened, that was my first question to USAA and one for which the security guy didn't have a ready answer, though probably it boils down to some version of "we are heavily regulated and continue to rely on software built for mainframes."
There are so many possible ways to mitigate the risk which should be triggered well before a half dozen attempts finally gets to a teller credulous enough to believe their excuses for ignorance.
How is that punishment? If USAA knows you or your wife were a target of somewhat sophisticated attack that ultimately broke their security barriers, wouldn't you yourself actually want some extra protection? If anything, this is a positive sign for USAA, I doubt with my Bank of America anyone would care with any sort of extra layers of security if my account would ever get hacked in a sophisticated way.
I can't explain why it took many consecutive withdrawals in a short time, in a city that I've never visited, 3000 miles away from the most recent use of the card, to trigger USAA's protection algorithms.
USAA did finally take care of it. My biggest beefs with them are 1) they dragged their feet a couple days on the investigation until I called them myself (I'm the veteran, my wife is not, and they were much more responsive to me), and 2) they really do punish my wife for something not her fault. You know those questions you get which are sourced from your credit file? What street did you live on, what's your mortgage payment, things like that? That's what they ask every time, after asking for a secret password and PIN code to be used for phone calls.
I'll give them credit though, for actually sharing the gory details with me once they were done tracking down everything, and admitting that one of their own employees had broken their rules and handed over the credentials to my wife's account.
The mechanisms for restoring the charge on your credit card are much stronger than on your debit card. And a credit card is a FUTURE charge, so you have time to fix the problem. Whereas a debit card is your CURRENT money, so it's just gone unless you get it back.
I do not understand why people use debit cards linked to their actual bank account out in the world. Paying bills securely through the utility is the only thing we use that for.
It's not paranoia when they really are out to get you...
Because this advice is USA only. All of my credit cards (well... two) are linked to the bank account and I don't even think there's a way to get a credit card without bank connection.
Given how quick and painless it is to transfer money between accounts, leaving substantial amounts of money in accounts linked with mechanisms that can remove that money is insane to me.
1. My debit cards allow me to directly import transactions into my personal accounting software while my credit cards don’t; and
2. when I shop online, my debit cards allow me to use them as a 2nd factor (using a USB card reader) while my credit cards require either an iOS or Android device for 2FA.
You’re right in that a credit card is a future charge and debit isn’t. But are debit cards really so much more insecure? What threat model do you have in mind?
Credit cards also come with all sorts of benefits. You can easily get 1-2% off all purchases through cash-back or gift card rewards. You can get free insurance with car rentals. Many cards also offer an extra one year warranty on most purchases, so if you paid for your laptop or phone with your credit card and it dies just outside of the manufacturer warranty, you might still be covered.
Citation needed.
The scenario you described will absolutely fall under most card networks' transaction dispute rules. In day-to-day spending a debit card is just as safe as a credit card when it comes to fraud or malicious merchants.
The only time a credit card will be better is grey areas where a card network dispute doesn't succeed, in which case the law in most countries forces the credit card provider to eat the loss. In some of those cases, the reason why a credit card chargeback succeeds is not necessarily because you are right (if you were, the dispute process would've succeeded anyway) but because the amount is too low for the issuer to care so they just eat it to not have to investigate and/or litigate the issue.
If your debit card gets compromised, your rent check bounces.
Plus, frankly, banks are generally more protective of THIER money than YOUR money.
I guess that depends on the bank and the country you live in.
Well, or to use it with sites that require 3D Secure, but that’s still something to help the merchant not you.
EU-wide regulation requires all banks to force 2FA onto their customers for logging into their accounts.
(Apologies, saw the wrong parent comment) How many utilities, credit card companies require a checking account for autopay? How many times have you thrown out an old checkbook that contains routing and account numbers on a carbon copy pages?
Bank accounts are not especially secure, we mostly hope to limit the risk/reward calculation for hacking them and basic security controls.
In my experience, this is getting better! I now have all but one of my bills being paid by my credit card. Used to be that the utility companies made you pay extra and use a third party service if you wanted to use your credit card.
Not all, though. Verizon, for example, will let you pay with a credit card, but they give a substantial discount if you use a debit card instead. For obvious reasons. I hope that does not become normal. I'm used to Verizon being scummy, I hope it doesn't become the default behavior for the other utilities I pay for.
In Britain, most people¹ pay bills (electricity, water, phone, internet, insurance, car loan, credit card etc) by "Direct Debit"². (Most European countries have a similar system with similar guarantees, but this one is described in English.)
If anything should go wrong, the bank must fix it. There's a list of direct debits in the bank's interface, and they can be cancelled/suspended with one click (or by phoning or going to the bank).
It isn't perfect (see 3 from two weeks ago) but that sort of problem is rare enough that it was reported in newspapers.
¹ "Direct Debits are used by nine in ten UK consumers to pay some or all of their regular bills".
² https://www.directdebit.co.uk/DirectDebitExplained/Pages/Dir...
³ https://www.moneysavingexpert.com/news/2022/03/tsb-customers...
I tell you this story in the hopes that it helps you recognize if you have similar flaws in your own security.
I used to run a VNC server on my home PC (flaw 1). Chinese hackers discovered it and spent three weeks brute-forcing the password (flaw 2). Once in, they installed TeamViewer to allow themselves future access. Then, they logged in at 3am and used my browser-saved PayPal credentials (flaw 3) to paypal themselves $5k from my linked chequing account (flaw 4).
I discovered this several days afterwards when I saw the withdrawals hit my bank account. I then found a few further pending Paypal transactions, and pieced the rest together from VNC and router logs.
Thankfully my credit union believed me that I didn't authorize the transactions and reversed them, making me whole again.
But damn, it's a scary feeling having someone break into your computer, not knowing what they might have looked at or accessed. Very similar to having your home broken into.
https://www.cnbc.com/2019/09/11/email-wire-fraud-cost-26-bil...
We talk about eth/btc as if they're just covering the function of the checking account, but it's also covering the function of the checks, wire transfers, ACH transfers, etc. So for a real comparison you'd have to count up all the related fraud from legacy checking accounts and their various mechanisms to move money between them.
The idea of buying game credits and trading them in game makes sense, but you would want the game publisher to have root on the ledger so that if there was a hack they could reverse it.
In other words, you'd want the game publisher to run their game on a centralized database, like MMOs have been doing for decades.