FTX stored private keys to crypto assets in plaintext, without access controls
twitter.com
twitter.com
- Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identification".
- Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account.
- Credit card numbers are similarly a private number used as a public number, and printed on plaintext on the card.
Is there any effort working on bringing asymmetric encryption to these systems or to replace them that has a reasonable chance of working?
We also don't even need to change this aspect of traditional banking in order to add strong asymmetric encryption in front of the system. That would nip most fraud in the bud, and if nothing else save a lot of effort that goes into fraud schemes, prevention, and reversal.
Large business transactions generally (not always, obviously) do not have the sense of urgency that would require fast settlement. There's some market maker stuff that benefits from fast settlement, but that's not exactly a reason to push whole new system out to everyone.
The biggest "benefits" of crypto are not benefits to the average consumer going about their daily life. Instead of dealing with fraud you'd have to deal with customer service issues for actual customers who forgot/lost their keys. And, honestly, you'd probably have to deal with more fraud. Your phone gets hacked, your keys get stolen, and then what… all your money is irreversibly gone?
Why would they expect this? It seems like the slowness is the only thing keeping the game from growing legs and walking away from the humans playing it.
If there were more of a delay, like the maturity rate of whatever bonds, SVB would be fully functional today.
FTX, as long as nobody looked too hard they probably could have lost the few billion they had left while keeping everyone happy.
Bank runs… always blame the customers.
Making things faster will be good for some people, bad for others. Not clear if better on the whole.
It’s also probably better to keep it slow to prevent impulse decisions (let me put all of my money into dogecoin, it’s mooning now)
But the current system works well enough in the vast majority of cases. And the fixes to the problems you list would add considerable complexity. I don’t think it’s actually that clear that fixing these problems would have a net positive effect on the world.
0: https://www.globenewswire.com/en/news-release/2022/03/23/240.... 1: https://www.bankrate.com/finance/credit-cards/credit-card-fr...
The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelances routinely print it on their invoices sent out to clients, have it as part of their e-mail signature, or even prominently feature it on their website.
What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. An accountholder can literally click a button on their bank's app or website and they get the funds back immediately, no questions asked, within 8 weeks of the original debit date.
This, in turn, means that it is in the initiating party's self-interest to only accept this form of payment in high-trust situations, and not just like a low-fee replacement for credit and debit cards that shifts some amount of fraud risk to the accountholder or their bank.
It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied.
AFAIK, the US works the other way around.
This depends on your bank, mine allows them by default.
"Positive pay" is available for checking accounts in the US, though I've never heard of it used outside of business accounts, and only then by request (and probably extra fees).
That's not the case in Germany, at least.
Be right back, asking some German friends for their bank account numbers.
Jokes aside, you're probably wrong. There's NO way I can just pull money from their bank account just by knowing their bank account number.
What GP says is accurate.
> Do you mean that if I know a German bank account number I can just withdraw money for me?
You most likely can't, because if you have to ask this you don't have an agreement with a SEPA Direct Debit originating bank that lets you :)
And even if you decide to open one now: Given the risks involved for the originating bank, they will heavily scrutinize your business case and demand considerable collateral and/or payout time limits.
Let's say I have account number 1234 and my name is John Doe.
You're telling me that, no strings attached, no repercussion, Mike Hacker can set up a large recurring payment from my account, without my approval?
I'd need solid proof of how that would work.
The thing that’s being missed here is that direct debits can be disputed in the same way a credit card payment can, and by default the customer wins. Their money will be refunded immediately by the bank, who will then go after you to get it back.
> You're telling me that, no strings attached, no repercussion
This bit:
> by default the customer wins. Their money will be refunded immediately by the bank, who will then go after you to get it back.
sounds a lot to me like repercussions :-)
This is the same as a credit card - you can charge any card with just the number and a couple of basic details, however if there's a complaint "I found these CC details on a random website" isn't accepted, you need to show the card holder agreed to the charge. If you don't provide the evidence the transaction is reversed.
I obviously don't care about people sending me money, I care about people requesting money from me.
Individuals can't do it and business can only <<ask>> for money, that's different.
Same applies to SEPA direct debit. Here in Sweden most (all?) banks requires the customer to sign digitally before any direct debit mandate is created.
Additionally, you need to have a direct debit agreement with your bank to be able to initiate a direct debit. You need to show at least some legitimate banking history (and a government-issued ID) to get one, and they come with limits on how many and how much you can debit per period, and your bank will terminate the agreement if your reversal rate is higher than normal.
> the "we debited 1c on your account" thing
This doesn't actually work with SEPA Direct Debits, since there is no such thing as "disputing a reversal" or "compelling evidence": If the accountholder says "funds back, please", the involved banks have to oblige.
In fact, direct debits are so reversible/non-final that it's SOP for bankruptcy managers to claw back all of the last 8 weeks' worth of direct debits drawn on a bankrupt person's or entity's account, which can be quite surprising for debtors.
In other words, it's possibly a better mental model to think of direct debits as a request for a wire in 8 weeks that gets earmarked for approval by default if enough funds are present, but that accountholders can cancel at any point in time, as far as finality (but not liquidity) is concerned.
There is no technical channel for the former within the SEPA Direct Debit framework (i.e. the first time the payer's bank learns about a mandate is with the first direct debit), so I'm wondering if this is a different/domestic direct debit scheme.
The largest related issue I believe is that the use of “knowledge databases” by credit bureaus (and all of the companies and governments that trust credit bureaus).
Each of these has been solved, but until the last system using the inferior authentication is upgraded, they all remain weak points. I have argued that the US (or each state) should create a digital certificate system similar to Estonia’s “digital residency card” or S Korea’s online transaction signing (although hopefully not implemented as an ActiveX control for Internet Explorer 5).
The EU is actually federating systems like that under an umbrella of regulations and technical services called eIDAS [1]. I haven't been able to use it in too many places yet, but if it takes off (which is a pretty load-bearing "if", to be clear), I think it could be an important step towards making these systems usable internationally.
Especially the US, which seems to prefer to handle ID card issuance at the state or even municipal level, could benefit from a federated approach like that – assuming that people would be willing to trust their local/state government to that extent, in any case.
We have too many religious people who fear government ID cards are the “mark of the beast”. We still can’t get all states to migrate to RealID, which includes a digital verification method within the ID (something stronger than a barcode).
I have an Apple Card. The only text on the card is my name. I think a lot of bank cards are starting to do similar stuff.
It isn't foolproof, though. Someone somehow was able to charge against the card, a couple of months ago.
It got so annoying on a recent trip, I just reverted to using another conventional credit card. The Apple Card is generally fine any time I use tap to pay from the phone, but the physical card simply isn't as reliable as some other cards I have that generally "always work" abroad. I've even had restaurant staff treat me very suspiciously over the blank card.
Its also an odd card in that the physical card itself has no tap-to-pay functions at all; of course Apple want you to use the iPhone it can't operate without to do this part instead. Again though, if I do have to hand over the card, in Europe people will of course try and tap it instead of a swipe and once again confusion reigns.
Oh and if a server drops the card, it makes the most irritatingly loud clang being a small metal object - I would happily go back to plastic for the card!
A check is simply a contract -- a promissory note. Like any contract you wouldn't sign it with someone you didn't trust, right?
(Obviously that statement, while true, is risable these days. But I remember a Bogart film in which he was setting a debt at a casino so asked the owner for a check -- he filled in not only the amount but his name, address and bank).
All the info on your check is just printed there as a convenience to you, or at least used to be. Until ~20 years ago physical checks were still sent back to your bank where they would check the signature, which could take a while! I think since the 72 hour rule went into place (and sending checks physically no longer allowed) the format was set by regulation
Put elsewise, the salient feature of a check is that your trust in that bank backstops your lack of trust in the bearer of the checking account.
(Right? Or did I misunderstand your trust model perhaps?)
And the writer is trusting you not to modify the check or otherwise fraudulently use the account info (in my parents’ time the check didn’t have account numbers on it so this was less of a risk).
The only backstop the bank offered was to verify the signature against the signature card and refuse the check if it looked suspicious. I think the same is still true today.
* I worked for Atari back when Warner owned them (1980s). Congress had required that companies offer direct deposit, but the minimum was they only had to offer it to you if you banked at the same bank as the company. So Atari’s payroll came out of a small bank in Sunnyvale with only one office. The rest of us got paper paychecks on Friday. Even if you went to the bank before 3 on Friday it wouldn’t be processed until Monday, which meant they’d send the physical checks to Synnyvale to be validated. Warner got to use the float on the money while all that was going on.
The literal answer to your question is, no, probably not.
It's not that it's impossible, it's that a lot of the technical talent required for doing it at every financial institution that would need to, is deployed elsewhere (some of it in finance, but not in the improving-security part of it).
This is by design: millions of Americans believe that the clunkiness of the SSN protects them from tyranny.
It's tempting to make this all "about crypto."
But crypto's just a technology. Maybe it ends up being a thing, maybe it doesn't. The fundamentals remain, and one of the present fundamentals is that (along with good old fashioned grift) stupid and terrible cybersec practices run rampant still.
Just here point out that the issue is that it's enough to have the bank account number to issue a request to withdraw money from that account, and not that the bank accounts numbers are listed.
Less fun, but far more important, is to note how incredibly (infinitely?) subtle this satire is: https://news.ycombinator.com/item?id=22352840
Techincally, it is in no way better than crypto. The only difference is that in real financial system there is a strong legal cover for all the technical and security fuckups. Like, stealing from bank by exploiting their 10-years old Windows XP ATM connected to the internet is 10-years-in-jail offence, while stealing crypto may be hard or impossible to prosecute in many jurisdictions.
You get to write your own new stuff in crypto, there aren't excuses for fucking up on best practices
This is one of the inherent contradictions of crypto. If the ultimate goal of crypto is to create a financial system that is free of government control, then that system must also be free of the justice system because that's the government too.
Asking people whose salaries are paid for with tax dollars to help you recover stolen crypto while simultaneously trying to avoid taxes and government oversight is so ironic.
The latter usually care about 100% APR on dollar and other scammy promises, and not about any real crypto benefits. When they get burned, they want government to step in and regulate.
The former don't care much that system allows to scam people (the "it's your fault if you were scammed" attitude), they care more that it's free from regulations.
Are they? I'm not so sure.
Could you elaborate? The whole selling point of cryptocurrencies seems to be to start from scratch, without those pesky KYC/AML and tax laws.
Traditional banking is not a natural law. It's man-made.
The benefits cryptocurrencies have over traditional banking seem to all come either directly or indirectly from the extent to which they do not have the man-made rules and laws.
Basically: It is hard to send money from A to B because of laws.
The set of people who like cryptocurrency is not small. The number of anarchists is vanishingly small. People want anarchism (complete freedom) and unregulated cryptocurrency until someone else uses that anarchism against them, and then they want regulation, post-facto.
It's not different people. It's the same people at different times; the times they're affected and the times they're not.
> The set of people who like cryptocurrency is not small.
There are two sets of people who like cryptocurrency. First ones like crypto because of better yields than traditional bank accounts or investments. But they want to live in a miracle pinky unicorn world where they can have better yields risk-free by having government protections. Other than better yields, they're completely fine with traditional banking system.
Second ones like crypto because it allows for easy money transfer from A to B. These people don't care much about yields, they cannot transfer money via traditional ways for various reasons, and they want governments to stay away from crypto as long as possible.
> It's not different people. It's the same people at different times; the times they're affected and the times they're not.
That's your assumptions about some people. Sure, from my side it's also only assumptions and personal anecdata, but most of the guys I know that use crypto for something useful wants government to stay away from it as far as possible, despite all the scams around. Some of them lost money on FTX, and that didn't change their position.
Yes, I agree that there are many many people out there who don't care one bit for e.g. bitcoin itself, but would be perfectly happy buying a regulated ETF that tracked the price of bitcoin.
I implicitly did not count these people as "liking cryptocurrencies". What they like is money, in particular fiat money.
> These people don't care much about yields, they cannot transfer money via traditional ways for various reasons, and they want governments to stay away from crypto as long as possible.
These are the people I was referring to, who want "no regulation" when they want to do something fine, but "full regulation" if and when they get screwed.
They want insurance only when things go poorly, and see insurance as a waste of money the days when they don't have accidents.
Would you say being in favor of HTTPS or encrypted messaging is equally incompatible with believing in a justice system?
But the thing is people want fast and anonymous payments, but don't acknowledge that traditional banking isn't doing that so well (especially in the US) because of laws people want even more.
E.g. given the choice of easier international payment or fighting mob money laundering, people will say the latter.
Well, they'll say both, but cryptocurrencies only even try to do the former. (Failing, because it's anything but easy for almost everyone)
As for your HTTPS analogy: mass surveillance is less law enforcement and more spy agency shit.
Even for messaging, the messages are rarely the harm. For money the moving of money is the harm.
In the communist sense: the government should not control the means of production for jeans or crypto.
In the social welfare sense: the government should "control" whether people are allowed to steal others' jeans and crypto, and the government should "control" whether you can abuse children in connection with your jeans or crypto company.
You can play with the meaning of the word, but whatever meaning you choose, jeans and crypto shouldn't be treated any differently.
Of course you do. You want asbestos to be banned in the clothes you buy. You want labelling of material to not be lies. You want child labour banned. You want slavery banned. You want trademark protection. You want the factory to not dump toxic waste in the nearby river.
And you say "well, of course I want that, but not... I dunno..." and give some hypothetical. Well, the same with cryptocurrency. If you think you want to get rid of all financial regulation, including AML/KYC, then I don't think you've thought about the issue for more than a fleeting moment.
Do you agree that, even though the government does not itself manufacture a pair of jeans using taxpayer money, the government can still prosecute theft of those jeans? If so, it should not be a stretch to understand that even though the government does not issue a certain private sector money, it can still prosecute theft of that private sector money.
So in this analogy the government should regulate cryptocurrency mining (production), import, export, domestic transfer, exchange, disposal, loans, etc…?
In other words, you're saying that cryptocurrencies should be treated as goods, not monetary instruments?
I'll give you the benefit of the doubt and say that's not quite what you mean. It sounds like you (and I've heard this from other pro-cryptocurrency advocates) want to carve out a new type of asset, basically with the exact purpose to avoid all existing legislation.
This common argument says that it's just like money, but should not be regulated as currency. It's actually much more like a commodity, but should not be regulated like one. It can act as a security, but should definitely not be regulated like one.
Commodities are subject to sales tax/VAT at delivery. Cryptocurrency's delivery is instant, or never. That's not clever avoidance, that's just trying to eat your cake and have it too.
That's not what I'm saying either. Crypto is just mundane property (like jeans), and property already has plenty of legislation around it. Existing laws work just fine. For example, capital gains applies equally as much to jeans as crypto (if for some reason your jeans appreciated 100x in value and you sold them).
The original comment I replied to claimed crypto should be entirely free of the justice system - THAT would actually be a new legal classification. Afaik the government has never before exempted any kind of property from theft laws. I only posted to point out that inconsistency.
As far as classifying it more specifically, I don't have strong opinions. Gensler says BTC is a commodity and ETH is a security--that sounds fine to me, ship it. I'll let the regulators regulate.
I'm just pushing back against this idea that private sector money must exist outside of the law and outside of the justice system—because the anarchy approach is clearly absurd.
Sure, but then you're either saying that cryptocurrencies are securities (not commodities), and to be regulated as such, or you want to harmonize laws on commodities and securities.
So your analogy with jeans is not very clear to me. Cryptocurrency (a security?) is just like jeans (a commodity)?
> I'm just pushing back against this idea that private sector money must exist outside of the law and outside of the justice system—because the anarchy approach is clearly absurd.
I entirely agree with this. But like I said cryptocurrencies try to play a language game to avoid being classified as anything that's currently regulated, in order to be as unregulated as possible.
E.g. the reason people use bitcoin instead of western union to send money (to the extent that they do) boils down to the laws that exist to prevent, investigate, and "reverse" crimes. The laws were written such that they can be enforced by the (needed) middleman. Bitcoin doesn't (for this transaction) require a middleman, so the law, the implementation of the intention, doesn't fit well.
But people who call this "savings" are ignoring why the law exists. There was never an intention to punish or burden western union. It was an intention to safeguard (or track, or whatever) the movement of money.
…or commodities, or securities, or whatever a given cryptocurrency should be classified as.
I agree that theft is theft. But movement of financial instruments and commodities is also already covered by the law.
In some countries your primary home is exempt from capital gains (or taxed lower than capital gains). But that doesn't mean that you can take your physical stock certificates, stack them in the form of a shed, sell it, and thus avoid capital gains. Yet this is basically what cryptocurrencies try to do, all while saying that they're "more efficient". It's not, it's just word games.
Is it a security? A commodity? I don't know! But neither does the US government. The CFTC and SEC are fighting a turf war. The CFTC calls them commodities. The SEC calls (most of) them securities. The IRS has created a brand new category called "digital assets". Who is right? If the government can't tell you, I sure can't.
I can infer there must be some legal justification for the current treatment. Even if you think Coinbase is playing fast and loose with the law, the old school players like Fidelity also don't charge sales tax on bitcoin, and I guarantee you they're not going to risk their core business over crypto. I am curious now how their lawyers would answer some of your questions.
Anyways it's been an interesting conversation, thanks for sticking around after the thread died. You've given me some stuff to think about.
In other words, one can agree with certain roles for government (e.g. justice system) while not agreeing with others (e.g. managing money). I don't see the irony or the contradiction.
This just isn't true, government participation can be found throughout the entire US economy. Import and export controls, labor force participation and visas, a massive small business loan portfolio, R&D investments in things like clean technology (e.g. Tesla was initially funded by a government clean energy grant), on and on and on. The assertion that the government just lets the economy run itself is laughable.
> In other words, one can agree with certain roles for government (e.g. justice system) while not agreeing with others (e.g. managing money). I don't see the irony or the contradiction.
It's not a question of what the ideal role of government should be, the question hinges on the government's legitimacy and ability to do things like collect taxes (which is an important function of a government). Lots of participants in crypto believe that taxation is theft and that government is an inherently wasteful entity, all while continuing to enjoy the largely invisible benefits that government policy and enforcement provides them. This is the contradiction.
EDIT: The government is the only reason that FAANG and other tech companies aren't bringing in foreign software developers who will work for $15/hr en masse. You know that if they could, they 100% would.
> Lots of participants in crypto believe that taxation is theft and that government is an inherently wasteful entity, all while continuing to enjoy the largely invisible benefits that government policy and enforcement provides them. This is the contradiction.
What you've described are anarchists. They are a small minority and certainly do not advocate for more government involvement. Most Bitcoin advocates simply think that Bitcoin is much needed competition to government money (fiat) while still believing in a government-run justice system.
> EDIT: The government is the only reason that FAANG and other tech companies aren't bringing in foreign software developers who will work for $15/hr en masse. You know that if they could, they 100% would.
If you really believe that, I can see why Bitcoin would make you nervous.
Never heard of them. They are incredibly effective at living up to their name.
> They still don't trust banks
Neither do I. I also don't trust my cell phone provider or the grocery store or the company that makes the web browser I use.
> the banks have once again proven themselves to be untrustworthy.
That's because they are. That's why we have a system of laws and regulations in place which kinda work at keeping them from screwing over most people, most of the time. But not always and not everyone. It is a work in progress.
It used to be non-banked, because in 1990 in Romania there were no commercial banks.
Trust me, being non-banked/under-banked is not better.
What you want is decent banks, not no banks at all.
The alternatives are all awful from a combination of peace of mind, convenience, etc.
people born from 1928 to 1945
I assume you are trying to hint about the Great Depression and the banking crises that went with it?Crooks typically believe and disbelieve their own bullshit simultaneously, which is even more nonsensical, but that's just criminal thinking at work. None of this is particularly confusing to criminal prosecutors, just the same ol' same ol'. SBF is going to jail, and if he doesn't switch his plea soon he's really going to jail...
A lot of column inches are dedicated to making it seem that way; however, I have a sneaking suspicion that there's _always_ money in the banana stand.
For any entity with a sufficient amount of power, stupidity is indistinguishable from malice.
(I've worked at startups and we did better. No access to the cloud provider without a time-based escalation. Secrets in secrets managers. Passwords rotated regularly. Mandatory 2FA. Signed commits. But it would probably still look god-awful if we were a finance company!)
(Demanding that crypto keys be stored in Google Drive is the kind of suggestion you'd make if you were planning on stealing all the money, I guess.)
https://www.forbes.com/sites/javierpaz/2022/12/02/crypto-exc...
How ethical are you really? Could you actually resist that temptation? Do you think all your co-workers could too?
What a fiasco.
Plus the nagging suspicion that you'd fuck up or never be able to use it in a meaningful fashion.
I'm not saying I'd be surprised if some one took advantage, but I don't think it would be most folks natural inclination.
I 100% guarantee that there will be a major hack, from a major app, at some point in the future where it turns out that all seed generation was not in fact random. Honestly, it's probably already happened multiple times and they just haven't gotten caught. Those stories where people claim that all their crypto got stolen even though they never shared their seed—you know the stories that everyone always dismisses as, "You must have let someone else see it." Well, some of those are probably true.
When you generate a private key through an app you are 100% trusting that the person who published that version of that app did not do something trivially easy like decide to generate all seeds from a known incremented input. You'd never know. And if that person caught caught internally the company is far more likely to cover it up, because otherwise they will collapse overnight.
That doesn't mean there won't be hacks and backdoors though.
You also need to build them from the codebase yourself if you want to be completely sure that you're running the code that's visible (though maybe there's a better way to verify this with Android/iOS apps?)
There is every incentive for someone to cheat here. There is very little risk, and the potential reward is basically infinite. I can slip a few lines of code in that grant me access to every wallet generated. Worst case I get caught and fired. Best case no one ever knows.
Assuming your employer isn't in on it and you get caught, what are they going to do? Seriously, think about it. If they acknowledge this in anyway the company is OVER. The best course of action is fire you, push a new release and just pray that you don't drain the wallets of the victims in a way that raises too much suspicion.
You either generate seeds from source you audited or maybe trust a hardware wallet that has been sufficiently audited. App-based wallets get new releases on a daily basis. The security is a joke.
Maybe I'm just clueless, but what solution could exist to verify that the code running on your phone doesn't differ from a given codebase (that also can't be faked)?
We can build Brave for any platform, which happens to have a wallet, but there's still no way of knowing whether what I built matches what's on the apple store. At least on Android there's F-Droid, which builds and releases from the source. Seems like that's as close as we can get to user-friendly and verifiable right now.
My solution is Safe[0] with multiple signers (different software/hardware for each one). Probably overkill, but when you are your own bank...
For example, Metamask is source-available and you can add it to your browser from the git repo rather than the chrome extension store.
You can also add it from the chrome extension store and inspect the source to ensure all files match the build, before adding any private key material to it.
I was arguing in a comment recently[1] that browser extensions should be required to be source-available, and the chrome store should take a role in verifying the bundle matches the build process defined with the source code.
It's alarming to me that this is not already the state of things, but as it is it perverts incentives for extension developers to a horrific degree.
Bitpay's "copay" wallet used only 64-bits of randomness for the nonces in their signatures, making it trivial to recover the user's private keys.
That wallet was "open source" -- but it doesn't much matter if its open source if no one competent is reading or reviewing the code.
They never announced the vulnerability-- they fixed it and the person who introduced it quietly parted ways with the company (he surfaced again later as part of conman Wright's team, ... I'm not sure if that increases my estimate the the vulnerability was intentional or if it was just incompetence).
You can get a trezor which is open source.
https://twitter.com/molly0xFFF/status/1645197258873270276
https://www.courtlistener.com/docket/65748821/1242/1/ftx-tra...
Analogy in a old bank with cash or gold is hot wallet = cash that tellers have on hand, cold wallet = vault in the back that has everything else.
But if you're an exchange handling billions of dollars of customer assets, the requirements should probably be higher. The text implies that many employees at the company had access to the password vault, for example. Also, shared password vaults that I've seen tend to have functionality like the ability to share a password externally (something you probably don't want!), relatively low logging abilities (while it would probably be a good idea to track each and every time a crypto key was accessed and who acccesed it), etc.
At least that's my guess at what they meant — perhaps someone had deeper knowledge and can share that.
Pure incompetence was the shining jewel of cryptocurrency. Hilarious.
That crosses the line and goes deep into "willful negligence" territory, in my view.
The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock.
The term "irresponsible" doesn't quite do justice to it.
Unbelievable.
Nov. 12 — Saturday: FTX hacked for most of its remaining crypto
Y'all be the judge.
Never understood what people saw in SBF.
Er, that's the thing that pushed you over the line? Not all the fraud and crime?
Really. At that point one should have the decency to declare your outfit a religion, and stop paying taxes.
Just like the “very easy math” that they all touted that was all that was needed to manage the entire thing
This is a failure of security and risk management. Making a guild or licensing requirements for software engineers may or may not be a good idea, but it wouldn't have addressed this problem.
But even if it would have in the abstract, FTX played fast and loose with so many other rules, I wouldn't expect them to abide by those either.
I know what the real answer is, but I am curious of the response.
A lot of people are making the assumption that gross incompetence reigned supreme with FTX, and that does seem like the likeliest explanation, but another potential explanation is deeply devious criminal activity.
They could have preplanned this behavior. If they were ever caught doing anything really bad, they had "plausible deniability" by being so loosy-goosy with security and best practices. Everybody from a rogue employee to hackers could be blamed by them if the shit ever hit the fan and they could have some kind of defense that they were so disorganized that they didn't really know what happened.
You might be able to distinguish this by looking at how SBF's own personal crypto funds were managed. If he knew enough to manage his own crypto in a saner way, then you could probably make a case that dysfunction in FTX was by design because he knew better and didn't do it.
If they were a bank they would realize their growth is beyond their competence and bring in boring big bank security experts with some of the huge profits on the even more massive holdings.. But there were no legal profits on holding all these assets because they promised to be something better than a bank, making its money from risking your assets, so that was just done illegally leaving no above the table accounts for legitimate operation costs. (A friend of SBF with an illegal loan will obviously keep your keys safe.)
How could an honest company that takes negligence seriously compete? It is like the opposite of regulations as barrier to entry. How do you sell things for less than the Mafia's laundering operation?
Of course, but the qualifier I used is "make a case".
Obviously, nobody can ever read SBF's mind, but the government might have enough to prosecute him from this angle if they could prove that he knew better from his behavior with his own holdings, but didn't do things in a certain way for FTX's holdings.
Former FTX US President Reportedly Quit After ‘Protracted Disagreement’ With Bankman-Fried - https://www.coindesk.com/business/2023/04/09/former-ftx-us-p...
> ...
> According to the report, another employee in the exchange’s legal department was “summarily terminated after expressing concerns about Alameda’s lack of corporate controls, capable leadership and risk management.”
> Alameda wasn’t even clear on what its own positions were, “let alone hedging or accounting for them,” Ray's document reads. A June 2022 portfolio summary, which was supposed to show Alameda’s makeup of crypto positions, was reportedly fabricated after employees were allegedly instructed by an unnamed higher-up to “come up with some numbers? Idk.”
> At one point, according to the report, Bankman-Fried told employees:
> “Alameda is unauditable. I don’t mean this in the sense of ‘a major accounting firm would have reservations about auditing it’; I mean this in the sense of ‘we are only able to ballpark what its balances are, let alone something like a comprehensive transaction history.’ We sometimes find $50m of assets lying around that we lost track of; such is life.”
---
I'm not sure "devious" is the right word choice. Criminal activity - yes. I suspect they knew they were criminals to some degree but were grossly incompetent when it came to managing it.
It feels more like a constant stream of lies to support the ongoing fraud rather than devious.
I want that life. No, seriously, let me find even just $5M laying around, just once.
I mean, what do you need to have between your ears to even remotely consider losing, and then finding, 50 millions of someone else's money as normal? Such is life? Where? Other than in government agencies, of course.
And that might be equivalent to a penny to a significant chunk of the global population that doesn't have more than $2-4 to their name
You sound shocked! shocked! to find gross incompetence going on in a place where the accounting system is an Excel spreadsheet manually maintained by the CEO himself, with entries like "Hidden, poorly internally labled fiat@ account" (sic) purportedly worth $8 billion.
Private keys in plaintext in the shared Google Drive that the entire company has access to? That is the least surprising news I've heard today.
I don't recall who said it, but it seems to fit.
But I stole it. I didn't make it up.
This is FTX we're talking about. That line is far far far in the rear-view mirror.
https://news.ycombinator.com/item?id=32077583
The test of all these security exploits are in the exploiting. In practice, you can run wild and nothing will happen. My HN password was 000000 for years.
Your HN password doesn't provide access to your money, never mind other people's money.
And they had a lot of crypto to take.