Coinbase (YC S12) seeks to bring Bitcoin to the masses
coinbase.com
coinbase.com
The newness of this stuff is overrated. The bitcoin phenomenon isn't ultimately different from phenomena described by Mackey: http://en.wikipedia.org/wiki/Extraordinary_Popular_Delusions...
As we know, each new version of speculative excess has the slogan "it's different this time". And each one is different, in some way. And you can extract various interesting particular lessons from all these newnesses - I'm sure after 2008, someone's written a deep, interesting article on the failure of the Gaussian copula but really, you didn't need to understand the heat equation and Ito's Formula to know that synthetic bonds were a problem in 2006 (I'd recommend the enlightening discussions of Doug Noland of Prudent.com from that time).
But it is important to not allow ourselves to let the details of these situations distract us from the psychological dynamics which ultimately has carried all these phenomena. This psychological dynamic allows a slightly stretching of numerous points to add up to the concrete mistakes one point can point out later as "what went wrong". And these "what went wrong then" arguments are themselves dangerous since they general are coupled with "so this time, the different thing we are doing is..." and so forth.
Essentially, understanding magician's tricks are great. But never let yourself be fooled by the belief that you know all the tricks.
And I writing with the assumption that bitcoins aren't a "medium of exchange" in any meaningful way - for example, I could directly my car for something else valuablle far more easily than I could directly trade bitcoins and cars aren't a very meaningful medium of exchange today. This is the position that I believe most serious economists take, Nobel Prize winner Paul Krugman being on record here (not that I think this is really a left-right question).
Paul Krugman and others do not see the whole point.
What is money? Money is information. That's all it is. Who owes what to whom.
So we could have a giant centralized computer system that tracks everyone's move. If we want a car, the computer could tell us how much we would have to work and serve society in order to deserve that car.
Now if we want to live in a somewhat free society, we obviously don't want to be tracked that way. In a free society, there will be different concepts to approach the money-as-information idea, each with their own advantages and disadvantages, and people would choose freely what to use.
For example, there is Ripple: http://en.wikipedia.org/wiki/Ripple_monetary_system , a peer-to-peer credit system. When its base unit is set to "hours of unskilled labor", it comes very close to an information system. While it makes much sense for steady business-to-business and buyer/supplier relationships, it is necessarily trust- and reputation-based, and thus may not appeal to everyone and be applicable in every scenario. Also some seem to be concerned that it might destroy friendships. ;)
Bitcoin's approach is different. It's obviously only information as well, but simulates a commodity, thus ensuring privacy to a large degree.
So let people understand and choose.
I am not sure what you're trying to say. The fact that money's value created by people merely believing it have value is not particularly insightful.
And I writing with the assumption that bitcoins aren't a "medium of exchange" in any meaningful way - for example, I could directly my car for something else valuablle far more easily than I could directly trade bitcoins and cars aren't a very meaningful medium of exchange today. This is the position that I believe most serious economists take, Nobel Prize winner Paul Krugman being on record here (not that I think this is really a left-right question).
Don't buy that assumption. For example, the majority of libertarians at Porcfest actually use bitcoin as a medium of exchange. The other money of choice are precious metals, which are beaten out by the more convenient bitcoin. BTW, how exactly can I pay my VPS with cars instead of bitcoin?
Ideas/products with excessive speculation have failed in the past. Therefore, this product will fail.
I disagree with that. It suffers from survivor bias (or actually non-survivor bias). Mackey doesn't discuss ideas with excessive speculation that ultimately succeed. The internet in the 1990s and the California gold rush both had excessive speculation, but ended up being successful... so no one refers to them as 'extraordinary delusions'.
Are you sure about that? Bitcoins are easily divisible, a car isn't. Yes, you can take your car apart but the sum of the parts is worth much less than the whole car. Bitcoins can be easily transported and even transferred internationally. Exporting a car incurs a lot of overhead in transport fees and taxes. Even selling a car to someone on the other side of a large country might end up being too expensive.
No matter what you think of bitcoin, it should be compared to existing national currencies, gold, etc. I like the concept of bitcoin, but I believe that even risky currencies like those of (say) Mexico, Turkey, etc are a better bet than bitcoin.
The opposite, actually, is true. It's not very intuitive, but yeah; I've got a '96 Nissan maxima with unrepaired body damage and what sounds like a suspension problem that I've gotta get rid of. If I wanted to sell it fast? I think I'd have a hard time getting four hundred bucks for it. (I mean, if I drove it into a car buying business and wanted to walk away with cash) But, the salvage yard where it would end up? I bet they'd make that much back selling all the windows and tires... then what they'd get for the other parts would be gravy.
I think the key to understanding this is that selling a car all at once is way less effort than selling each part individually. Sales takes effort and we're only measuring value within the context of a sale.
(nothing to do with bitcoin; I just think that this is an interesting way to point out that the way we measure value ends up giving us some non-intuitive answers to how much a thing is worth.
Bitcoins already have some concrete uses - gambling & drugs namely ;) And these uses won't disappear. There are also some more legitimate uses for Bitcoin coming up. Virtual goods for example.
I wonder how many people learned a lesson from Ginko Financial collapsing [1] (a little hand wavy but around $750,000 USD pyramid scheme) and weren't conned in real life.
1 - http://www.wired.com/gaming/virtualworlds/news/2007/08/virtu...
1. Start centralized bitcoin depository.
2. Fail to provide any loss protection.
3. "get hacked"
4. Profit.That and for me the main blocker of Bitcoin is how to exchange my currency (MXN or EUR) into Bitcoins.
Let's pretend for a minute that we're dealing with a non-FDIC insured bank (like some of the original online banks), with none of the regulatory controls that obviously provide a lot of protections.
Let's pretend for a minute that the bank stupidly keeps all of its holdings as cash that are held on site at the bank. It doesn't use notes or other securities for transactions, only cash. Let's pretend that the bank also self-insures those holdings (which basically means no insurance).
Okay, so I compromise the bank's security, take every bit of cash. I disappear to some island in the Pacific with every last cent.
How badly is the bank screwed? How badly are the customers of the bank screwed?
Actually, not that badly. I only wiped out the bank's reserves. That means both the bank and its customers have a short term liquidity problem, but not necessarily a significant asset problem.
A regulated bank would have 10% of all deposits in its reserves. Unregulated banks often have far less, but let's pretend it is 10%. The bank loses 10% of its value. If it can stay solvent, then nobody loses any money, but it might take a few days before people can make withdrawals (which could cause a bank run, but that's a whole different problem). If the bank can't stay solvent, it goes bankrupt, and depositors become creditors. It'll take a while to resolve the legal process, so liquidity is killed, but when it all ends, depositors are going to get back something close to 90% of their money back.
The key thing is that the bank lends out most of the money it takes in. Even if you rob the bank of all its cash, the bulk of the "assets" of the bank are all the IOU's from lendees, which is value that is really hard to "steal", because lendees tend to only pay their lender, and then tend to do so in installments over a great deal of time.
THIS IS WRONG: Hacking Coinbase would be more akin to hacking say Visa, and redirecting all payments to you instead of the intended merchant.... if Visa's transactions were all cash based, instead of credit based... and Visa was unregulated... and even then it is kind of different because Visa is a middle man between two banks...
UPDATED: Okay, I just read they are actually storing the bitcoins in the cloud, rather than just exchange the coins between the two parties.... So actually, it's not like hacking Visa, unless Visa didn't reconcile their transactions with its customers for extended periods of time and held all of the float as cash.
The problem is that the current Bitcoin "banks" aren't really banks. They're more akin to socks under a mattress than a bank.
At a very basic macro economist level, banks have two functions:
1. They are a place for clients to place their money. To incentiveize this behavior, they pay those clients interest on the money in their accounts to keep it there.
2. They take that money and give out loans to people, and charge interest over the time it takes to repay the loan.
In a healthy economy, the two feed each other. Broadly speaking, the circulation of currency works like this: People/businesses take out loans. That money is used to buy things (houses, cars, short term equipment expenses, etc.). The businesses that are paid for the goods/services pay their employees, who put the money into the bank. Note that even in this situation, banks aren't entirely necessary, because people could just buy stuff, which goes to employers, who pay employees, who buy stuff...
Bitcoin does not have either economy yet. Right now, it's used just to buy things, with BTC being converted to a "real" currency(USD, Euro, etc.) on both ends. So it's really just a single directional currency. So, right now, if I wanted to operate a Bitcoin bank, I'd have to convert it to USD or some other currency, and keep it totally separate from my liquid BTC wallets to mitigate the risk of getting hacked and the wallets getting stolen. Unfortunately, that's incredibly risky, because I would then have to deal with the exchange rate between BTC and USD.
If someone breaks into the MTGox, they'll be only able to steal the "reserve". To get to the real money, the MTGox admin has to physically go into a vault (safe), and retreive its contents.
The markets are more resistant to currency shift than enterprises are to getting off XP and IE6. BTC will always fail because everyone is to lazy to get rid of the dollar as the reserve currency.
All it takes is enough people using it.
Bitcoin "depositories" open up a pretty big can of worms if they convert their assets. Part of the point of using bitcoin is not to have to use other assets.
They could start lending bitcoins, but that's going to invite a lot of scrutiny, particularly from the regulators.
In any case, Bitcoin offers the ability to do exactly this: Open a completely unregulated financial institution with no accountability. Looking at this site, the first question in my head was "Where are your coins stored?" Second was, "What are the limits, and how, exactly, do you guarantee funds will transmit since every country in the world has different limits, regulations and KYC disclosures required to make that possible?"
The answer for Bitcoin businesses thus far has mostly been "don't worry about it". In Bitcoin that's slang for "I'm using my bank account, my buddy's bank account, my girlfriend's bank account...and I swear you'll get your money on time until you don't, and I'm gone, and you're fucked."
This looks to be yet another one. No news here.
We'll start keeping a majority of funds in cold storage as deposits grow (we're still in beta at the moment). And I think you're right a firm policy on this would be needed about loss of funds and what is covered. I'm interested in the idea of getting insurance through Lloyds of London or something along those lines, but haven't pursued it yet (we've just been building the prototype).
I worked on fraud prevention at Airbnb previously and we had lots of money flowing through the site and stored with us, so I'm familiar with best practices around this. I also have a healthy respect for what can go wrong, and I think as we grow we'll go through regular security audits (and much more scrutiny as we pursue licensing as a money transmitter). You certainly shouldn't trust us on face value though, it's something we'll have to earn over many years.
Please encrypt the private keys with a key K derived from the users' passwords. When a user logs in, your server-side code can compute K and access the bitcoins. When a user logs out, the server should forget K, erase it from RAM, thus leaving the bitcoins securely encrypted on-disk. Not even an attacker getting access to your infrastructure, not even you(!), could steal the bitcoins when the user is not logged in.
Not a single online wallet service actually does it this way, the right way, sigh... This mechanism could have prevented numerous thefts: MtGox, MyBitcoin, Bitcoinica, etc.
For power users, if they forget their pw, they lose their coins. Period. That's the option I would use, as someone who never lost an important pw thanks to my use of redundant password safes.
For other users, when creating an account, coinbase.com could email them a "key recovery" file (or mail them a physical QR code), with instructions to keep it permanently stored in a safe place. This key recovery file would be K encrypted with a unique IV and a key known by coinbase.com, who would not keep a copy of the key recovery file. This would satisfy all my requirements: coinbase.com would be unable to steal/access the users coins, and an attacker merely getting access to the key recovery file would be unable to do anything with it.
In this case instead of just encrypting private keys with K (derived from user's password), you encrypt private keys with K and encrypt K with user's password. You also encrypt K with your own master key which is stored offline. You could either retrieve K manually or through a rate-limited API.
However, Estragons point about it only slowing down the attack still holds, although in Bitcoinicas case the loss would be much less, since they discovered the attack early. "not even you(!)" however is false.
Are you re-investing some of the deposits, and the ones that you don't touch are in this so-called "cold storage"? If yes, what percentage do you keep in cold storage, and why don't we get interest if you reinvest some of our deposits?
What you're describing is called fractional reserve lending and we definitely aren't doing that.
But very cool site. Bitcoins are one of the things that drew me back into programming, and I'm grateful for that. (btw, are they still using json rpc for interprocess communication? it got a lot of flack, but I liked the API) But I got fed up with the volatility and the people it was attracting about a year ago and left it behind. It's good to see a legitimate business like yours getting involved (and with the ycombinator name, too!). Maybe I'll check it out again. There's a huge amount of potential there.
EDIT: My bad, I see that the parent comment was talking about fractional reserve lending. I only looked at the comment directly above your remark about reserve lending. Yeah, I'd stay away from fractional reserve lending since it's an anathema to almost everyone who uses bitcoins.
As for legitimate businesses there´s plenty. We´ve (mullvad.net) been accepting bitcoins for two years, but then again we were probably the first corporation and full-time business to do so :)
I've also paid some very professional developers and designers for high-quality work using bitcoins. Personally, I'd love for btc to take off more, since I'm a freelancer and do lots of work for overseas clients, and get hit with lots of banking fees. Btc is a fast and easy way to pay freelancers, and could be a great way to get paid by clients.
Nonetheless, I an easyjust got sick of all the hoopla surrounding Bitcoin and the constant Bitcoin heists, combined with the cluelessness of so many Bitcoin developers regarding security (not the core developers, but all the devs trying to build Bitcoin-related businesses). But perhaps it's time to give it another try.
What? Why not?
This does not apply to cloud services with serious security considerations, such as AWS. It has IAM as well as second factor authentication. However, in Bitcoinica's case, both Linode and Rackspace don't seem to be a good choice to host wallets: Linode hack was actually a result of their customer service system compromise (i.e. possibly any support agent can reset the root passwords). While Rackspace Cloud's support staff couldn't log out the hacker and preserve the servers even when the hack was detected and password being changed.
These are really basic security features that cloud services are lacking.
You made a good point that things can be upgraded as you grow. Please do that. It's exactly what I intended to do when I launched Bitcoinica last year. But after I sold the company last year, no one really think it's an urgent thing to do because there were no performance issues, no availability issues and everything went just fine. It's important to stick to the plan, and preferably allocate a fixed portion of revenue for upgrading security features and doing audits.
I'm glad to give you more information so that you can make better decisions (just drop me an email). I have been leading Bitcoinica for half a year (until the handover in April) and I had some experience in running a Bitcoin site that scaled quite well. I'm working on a non-Bitcoin project at the moment but I really want Bitcoin to succeed.
The above is also very easy for someone (like me) to say when you´re not in the middle of it. You want to grow your business, and the benefits of working on security are hard to measure. I get it. That´s when you need to ask yourself what your priorities are, and if you´re in the business of selling turnips, or handling valuables such as bitcoins.
Brian, you are where Zhou Tong was a while ago, although there´s no hype around your service yet. It has great potential, especially with the backing of PG et al. Please don´t make the mistake of putting security on the back burner. If anything you should use it as your primary selling point.
If you´re comfortable with it, subject your internal architecture to public scrutiny. If you´re not, think really hard before you say "trade secret".
How do you seceure yourself for something like that?
Probably by being careful.
Second rule: Hire a security expert and a thief. The former to keep you safe and the latter to break in before the real ones so the expert can fix the holes.
Btw, I like the service.
They probably won't be able to pass the money transmitter certification on AWS, so presumably they'll migrate eventually.
Apparently they are now, yes. Last I checked they weren't and were saying their cloud services were inherently uncertifiable, due to the architecture.
The PCI firms I know probably would not have passed them.
Er... bit of a stretch
I sent his previous post looking for a co-founder to friends because Brian looked seriously formidable. Best of luck to him.
Also, how will you comfort your customers when you get hacked and their funds are gone? That is not a hypothetical thing to ask, but very real and has happened before in the cloud-wallet bussiness.
Anyone who wants to get started with bitcoin, I suggest using the client Electrum. Written in python, light, quick and secure.
We'll start keeping a majority of funds in cold storage as deposits grow (we're still in beta at the moment). I worked on fraud prevention at Airbnb previously and we had lots of money flowing through the site and stored with us, so I'm familiar with best practices around this. I also have a healthy respect for what can go wrong, and I think as we grow we'll go through regular security audits (and much more scrutiny as we pursue licensing as a money transmitter). You certainly shouldn't trust us on face value though, it's something we'll have to earn over many years.
I had to click on the page to de-select the input, see that it said "Your Email", and then enter my email.
The way it is now, it looks like you might simply want two passwords.
I asked the following downthread but I'm afraid its going to get buried in the muck:
"Zero Transaction Fees"???
Are you refunding the bitcoin transaction fees that are builtin to the protocol[1]? If you are going to eat that cost you should say so, it seems like a good marketing point.
So we aren't including any bitcoin transaction fees by default. If you try to send a transaction below 0.01 it will never get confirmed without the fee, so we added this user interface improvement a few days ago which gives the option of including the fee if people want to:
http://blog.coinbase.com/post/26452774981/confirming-small-t...
Coinbase will make money more like an exchange down the road, 0.5% to convert money into our out of bitcoin, but once you have your money in bitcoin there are no transaction fees (it mentions this on the homepage, but admittedly it's still a bit confusing). I wish there was a better way to distinguish between an exchange fee and transaction fee (to the average consumer these may be the same thing, I'm not sure).
In general, I would like to abstract out the idea of btc fees to the average user (I think it's an unnecessary complication for someone new to bitcoin). It would be much easier to just say "no fees" - this is simple and shows a clear benefit of using bitcoin. If you have to explain to people that "sometimes there are fees, but they are a lot lower, etc" it loses some of it's punch. Right now we can do zero fees and transactions still get confirmed. In the future we may be able to do it by eating the cost and have this be a cost of doing business, but that is a decision for later.
Hope it helps.
To the creators, have you considered adding a USD (or other currency) funding option? Since getting the Bitcoins is probably the biggest obstacle for most everyday consumers.
Are you refunding the bitcoin transaction fees that are builtin to the protocol[1]? If you are going to eat that cost you should say so, it seems like a good marketing point.
Currently, if you do not include a transaction fee, your transaction will get confirmed, but the first confirmation could take longer for a miner to pick it up - but it is very likely to still get confirmed.
As transactions per second increase and load is placed on the memory pool, those fee-less transactions may get lost and need to be resubmitted.
Accept a transaction for inclusion in a block: 0.0005 BTC
Relay a transaction to other Bitcoin hosts: 0.0001 BTC
A transaction can be sent without fees if both of these conditions are met:
It is smaller than 10 (SI) kilobytes (10.000 bytes).
All outputs are 0.01 BTC or larger."[1]
Put another way as bitcoin grows fee-less transactions will become rare...
[Assuming that point to point transactions that aren't doing complicated contract logic are always less than 10kB.]
How many other viable bitcoin clients are there? And what do you think the likelihood of you fee-less transaction being accepted despite a flood of fee paying transactions?
Edit: electrum can be fully run offline as in you can monitor your balance without a network connection AND you can write transactions that can then be injected into the blockchain by a networked connection. But the electrum client at no time needs to be connected to the network.
Additionally, a networked computer can contain a deseeded wallet (no keys) for securely monitoring your off-line balances.
A year ago, when I was looking around, there was none. I have no real qualms about dropping a few bucks into BTC, but I have to be confident that I can exchange it for the ability to pay my bills.
Payments is a great starting point for a mainstream bitcoin serice. The user isn't going out too far on a limb to use the service because it's just a payment. This could increase the chance of adoption, and lessen the impact of something going wrong in the early days.
I'm really impressed with folks trying to make a service like this work. I find any opinionated naysaying to be really boring. Can't wait to see how it turns out. Hope there is enough traction to put it all to a real test.
It's one of those ambitious projects, that, even if failure is in the future, it's still a worthwhile project.
Obviously this doesn't flow with the spirit of Bitcoin and why it was designed but I think it's what will be necessary for it to start gaining wide spread use.
Now, as for why would you use a system like this instead of one based on conventional currencies, well, don't ask me!
But as for preventing your identity from being linked to your BTC wallet? There's probably no way to prevent that if the service provider is under US jurisdiction.
The more hops through a wallet (which can be created dozens of times), adds more plausible deniability and separation to any purchase.
Too bad my comment contributes nothing to the post and it's gonna go to the bottom. Oh well..
Also did you mean shopping card or shopping cart? I can't resolve either from context and shopping card is not commonly used.
Still, centralizing a decentralized system is like trying to tame a wild animal. I can be done, but expect to get bit.
Props to Coinbase for changing the looming black top bar anyway.
With all the password hash leaks going on these days, am I the only one paranoid enough to create a long, random password?
Bitcoins have already been destroyed to the tune of about 80,000 BTC from disk failures, lack of backups, and forgotten keys. We will already never reach 21 million bitcoins in circulation.
Brian Armstrong: good question
Brian Armstrong: two thoughts on that
Brian Armstrong: one would be an automatic withdrawal rule they could setup
Brian Armstrong: so it just gets converted automatically when it arrives and deposits once a day or something
Brian Armstrong: the other is that i think the exchange rate volatility is largely a short term problem, volatility decreases as volume of transactions increases
Brian Armstrong: so if you believe btc volume of transactions will be much higher in 5 years, then exchange rate volatility will be much lower
→Makes sense, Saw the site mentioned on hacker news, so that means you'll probally mentioned on slashdot at some point
→^.^
Brian Armstrong: at least that is my guess :)
Brian Armstrong: hope so
Brian Armstrong: maybe I should submit it?
Brian Armstrong: haven't slashdotted in a few years
→heh, you could try, though slashdot seems to be consolidated to a few power submitters lately, might try reddit?
→http://www.reddit.com/r/bitcoin would be a start?
→http://news.ycombinator.com/item?id=4177605 that's the article mentioning you btw
Brian Armstrong: already submitted :)
Brian Armstrong: http://www.reddit.com/r/Bitcoin/comments/vswkw/silicon_valle...
→Where bitcoin could REALLY take off is CPU usage cycles
→Since bitcoin is fractional
Brian Armstrong: oh yeah, tiny amounts
→Instead of charging pennies per cycle, you could specify exact amounts per clock
→so instead of 1 penny per second
→.00001 per clock or whatever is the better value
→It'd be alot more precise
→It must be interesting to start a company like this. Are you / your company registered in the united states? And if so, How do you feel about their reaction to bitcoin?
Brian Armstrong: yep that'd be interesting for sure
Brian Armstrong: we're incorporated in delaware (U.S.)
Brian Armstrong: based in california
Brian Armstrong: we have the backing of really good investors who want to see innovation happen
Brian Armstrong: as long as we pursue licensing as a money transmitter (same as facebook credits, paypal, etc) i think we'll be ok
Brian Armstrong: it will def be controversial though
→I wonder how mt.gox handles it
Brian Armstrong: they are incorporated outside the U.S. (Japan I believe)
→nods
→Well, If it's ok with you, i'll post this to the hacker news article and see what kind of discussions it generates? Only with your permission of course! =^.^=
Brian Armstrong: sure, that'd be fine with us!
On the other hand, are these guys storing my wallet safely? How about my balance (please god, don't store it as a float)? How about my password? If they're not launching with two-factor auth I won't even give it a chance (and likely ever, honestly).
I've gotten progressively more and more pessimistic about these sorts of sites even though I like the idea of BitCoin as a currency. If security isn't heavily discussed and visible (2FA, do it!) at the launch, it will be hard for me to take this seriously.
They are rounded, and doing arithmetic on such numbers leads to compounded rounding errors that you don't want to see when dealing with money.
Another problem is that the mantissa of floating point numbers is limited (52 bits for doubles), which can lead to truncated numbers, another big no no.
Also, all Bitcoin calculations are supposed to be done in integer Satoshis.
And I really don't mean to pick on you, but that this isn't better known is why I worry when I see random sites popup offering financial services.
Personally, I have no idea why they didn't just use Google Authenticator and implemented OATH/TOTP on their own servers. Relying on a third-party for authentication seems a very bad idea, specially when there's an open algorithm that is essentially just feeding a secret and the current unix time to an HMAC-SHA1.
The AllThingsD article linked from the page mentions that the company is part of the current Y Combinator class.