We have detected a security breach. Services are temporarily suspended
instawallet.org
instawallet.org
If you lost money today I feel for you, but seriously, it's your own damn fault. A Bitcoin is only yours if it was last sent to an address that is yours, and an address is only yours if no one else knows what it is - in other words, you have to have generated it anew on a secure, malware-free computer, and avoided ever putting the wallet file on any computer that has malware or that is not yours.
Seriously, stop it, you fools.
Or, alternatively BTC embraces the same banking industry setup it is trying to get away from.
That said, I don't disagree with what you are saying (and upvoted) - just pointing out some implications.
Not sure there is as big as a difference between BTC and the current as people would lead you to believe. Emphasis on as since there obviously are differences - at least until new laws get thought up and passed.
1) The value of your card is unlikely to be stolen by a hacker, unless you make an online purchase.
2) If someone spends the value of your card, you have recourse
3) Bitcoin is used to store much large amounts of money than you likely had on your VISA card
Nope. Look at everything you can do with your online bank account. Transfers to other accounts, wires, bill pay, stop payments, ACH (if you're lucky), etc. What's the common there? All those transaction are reversable. This makes it hard for hackers to steal money from banks, they need an unwitting third party (mule) to accept an account transfer, and then go to a branch or ATM to withdraw cash.
So it's not like your online banking accounts are secure, you can purchase any number of stolen online banking credentials from trojan/botnet operators. The price for those accounts is quite low, because the real effort is in finding unwitting mules.
The problem with bitcoin, is that bitcoin transfers are irreversable. So banks will never be able to protect bitcoin wallets effectively, because they can't rely on being able to reverse transactions for compromised accounts.
I worked in a bank designing systems at one point. Even with methods to retrieve money lost through fraudulent transactions, they still had monthly 'Fraud' budgets much larger than my salary for money they couldn't retrieve. Imagine BTC services 'Fraud Budget' when all transactions are non-reversible.
Banks do have a massive advantage in 'Practical' security as well in the form of a 'big stick' aided by the government. Since the practical risks of fraud against a bank are much higher than fraud against an online BTC service (who is the FBI more likely to help), the exposure would be much bigger.
Near everyone I know, regardless of age, does their banking online. I don't see how this is any different than a username/password being stored on some banking server, and getting stolen.
Best case? You boot to a clean ISO, make a wallet, generate an address, write down the public/private key, transfer all your btc to it, and call it a day. There is no digital trace, and you have a paper wallet.
If your bank is hacked you as the user are not liable for the loss. Online transactions are traceable and reversible. Banks are heavily regulated and the legal regime is well defined. Etc etc etc.
Having your online banking hacked is a bit like being mugged on the way out of the bank. Having an online wallet service hacked is like someone driving in a truck, emptying the vault and leaving without a trace.
Insurance.
Insurance works on risk profiles. Insurance also works by limiting exactly what situations they do and do not cover (see: All the people who 'thought' they had flood insurance over the years).
Something tells me insurance is going to be a lot more expensive for BTC, which can have a range of impacts that will make it unpalatable for the average consumer, if they or online services can even get (try insuring a Audi R8 under an 18 year old's name...)
Either case, I don't think 'Insurance' is going to be the magic thing that will make BTC as viable as traditional currencies.
Actuaries happen to be quite good an quantifying risk. If the price is right, someone will be willing to insure it. An insurer with a specialist background in systems and security could do well.
The actual problem is the implications of underwriting a fiat currency with a "real" currency.
So really, so far the most secure way to store Bitcoin is either to encrypt private key and only then store it somewhere, or print it out, store it in a safe and remove all traces from the computer. Better yet - use a locally hosted javascript app to generate the pair and never write it to disk, from where it could be recovered even after deletion.
I'm now working on developing a Bitcoin platform that will enable you to do exactly this - your private keys will be generated on your computer, encrypted with PBKDF2-derived passphrase from your password and only then stored on our servers. This way no one except you can ever touch the coins.
[1] https://bitcointalk.org/index.php?topic=164143.msg1716794#ms...
[2] http://blockchain.info/address/1LrPYjto3hsLzWJNstghuwdrQXB96...
http://blockchain.info/address/1BcCo1dNztEjMtzxFTbtQuZEuK1Nk...
http://blockchain.info/tx/f0dba606f4d245c49a165035eabe345794...
Says it was sent FROM cold storage that's not a good sign.
[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.
The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.
from https://bitcoin-central.net/
All is fine then I guess
Neither is Strongcoin who had all their wallet labels leaked recently, some of which users had decided to type in the hints for their key passwords.
If I remember correctly Instawallet is a ruby/rails app run by the same people who do Bitcoin-Central.net. If you look at their other app Instawire you see lot's of ruby gems used, in a financial application, not good.
EDIT.. bitcoin-central.net is also down
Ultimately we probably need insured, trusted third parties to hold keys, such that even if there is a breach, someone financially viable is on the line to reimburse.
Individuals holding their own keys may be a nice dream, but its highly impractical for most people if they have a significant portion of their wealth in bitcoin. Certainly there will be very high net worth people and security maniacs who want to hold their own keys, but I believe most people will want a third party to guarantee them.
Or use the Armory offline wallet to store them on an encrypted non-networked storage, print the keys, do the above.
I'm not talking about techies, early adopters, and fanatics. I'm talking about buckwild and clerks.
You'd want to also make sure the printer isn't storing memory of those keys that were printed.
Some weird startup out of Europe is splitting up $2mil worth of coins on 3 USB encrypted sticks, using Shamir's secret sharing as the master key to decrypt (this according to Bitcoin magazine). Sounds like a bad idea I don't trust wear leveling drives that could fail taking all your coins with them
You could make say, 6 USB drives, any 3 which can recovery your wallet. As long as no more than -half- fail you would then be fine. And you can set either number as high or low as you like, of course.
And it's not like wear leveling should come in to play if you aren't actually writing to them.
1. Keep your own self-generated, backupable and recoverable wallet without dependency on any third party babysitting services that are being consistently broken into (and your money is lost). Electrum wallet is recommended as it also allows you to export "master public key" using which you may launch your own online store business and accept bitcoins as a payment without risk of losing money if someone hacks your online store.
2. Use third party service only for buying and selling bitcoins. As soon as transaction is complete - transfer bitcoins back to your own wallet.
3. Have a will so your loved one could get a hold of coins. Just in case.
Your online store key, you should be using some sort of script to generate receive payment addresses offline and stick those in a db. The payments should go to a cold wallet you can either with a serial cable send a txn or manually enter the signed transactions, but that's just my paranoid security
edit : back online
The founder said it was fixed but who knows
If it is, it's obvious that the instawallet guys have no business handling your money.