Flexcoin is shutting down
flexcoin.com
flexcoin.com
People moan that NFC has been "just around the corner" for the best part of a decade, and some even think that it has missed its opportunity (it hasn't, btw), because it has taken so long to bring to market. This is largely because of the in-built security, and the demands it places on participants' business models.
These Bitcoin exchanges and other service providers, on the other hand, seem to have been put together with great haste. They seem to have little-to-no oversight, a high risk profile, untested systems, not much institutional experience -- and there's no safety net for customers.
It illustrates why the "old" financial services industry is so cautious when it comes to electronic money. "Move fast and break things" may work for all sorts of businesses, but it's not a good mantra if you're handling money.
Bitcoin exchanges seem to be trying to rebuild the wheel while touting they're not wheels.
There are many layers to banks and exchanges, including security and risk reduction, which add to the overall operational cost. These exchanges either thought they were exempt to these same issues or they thought they could skate by without addressing them.
It's almost an agency effect - "If other exchanges aren't doing it, why should I increase my costs by doing it?" This line of thinking and deferment of responsibility is what leads to financial crises.
Parent poster is talking about Non-Fiat-Currencies.
edit: oh, sorry I thought it was obvious, but I say "seriously" because how could you seriously think this bitcoin topic is about Near Field Cmu.....
PSA: Don't peacock.
Another bit of irony... http://i.imgur.com/KurgdXp.png
But seriously, sorry to those who lost coins here. Also sorry to the folks of flexcoin, the timing couldn't be worse. Can't say it enough; cold-wallets and private key that's exclusively in your possession.
Only you can prevent forest f- er...bitcoin thefts.
"We have taken every precaution to defend your bitcoins from hackers and/or intruders. However, Flexcoin Inc is not responsible for insuring any bitcoins stored in the Flexcoin system. You are entering into this agreement with Flexcoin Inc. You agree to not hold Flexcoin Inc, or Flexcoin Inc's stakeholders, or Flexcoin Inc's shareholders liable for any lost bitcoins."
Also, one can argue that if they had truly taken every precaution then either intruders would not be able to break in or they are prepared for such a scenario. Evidently, neither was the case.
In other industries standards and "recommendations" exist to state a set of measures companies have to set up in order to be "secure"
Also, even if you take every reasonable precaution, there's still a possibility that your systems can be broken into.
Corporate formalities alone don't prevent piercing the corporate veil.
Sure, but undercapitalization alone can with certain types of creditors, and gross undercapitalization can be a significant factor in favor of piercing the veil in other cases.
And actively concealing a known "leak" of funds held in trust for customers arguably goes far beyond mere negligence.
Not alone, it doesn't routinely.
> It's a tort.
Anything that produces civil liability is a tort. It wouldn't be much of a veil if anything that was a tort routinely pierced it.
Also, it's not really true that anything that produces civil liability is a tort, is it? Civil liability also arises from contract law.
That's not about piercing the veil (which protects shareholders from liabilities incurred by the company), that's just individual liability independent of the corporate existence of corporate liability. And your right, but negligence liability requires that the individual agent owes you a duty of care and failed it; even in the case where corporate negligence toward a harmed party is easy to establish, individual negligence of a particular corporate agent toward the same party may be much harder to establish. And, again, such liability is a completely different issue then the corporate veil.
> Also, it's not really true that anything that produces civil liability is a tort, is it? Civil liability also arises from contract law.
True, but I think the general point still stands that the corporate veil would be pretty flimsy to start with if it didn't generally include protection from liability arising through tort.
Are there such things? In practice, are they a significant portion of the banking market?
That's because there's a huge security net provided by the general public against the fuck-ups of banks, no matter how big.
Oh, I don't disagree with him/her.
All of these companies have been operating as if keeping heaping wads of cash behind the counter was fine, merely because it was convenient.
Then implement the vault as offline storage (encrypted files burned onto DVDs and physically stored in a vault for example).
You wave your hands in the air and say 'they wait', but there goes all your speed and cost advantages.
A cash register has things incoming and outgoing. It's not constantly draining all day. You might need someone to run to the bank to get a bunch of pennies or a bunch of singles to make change.
(And with the "cold storage" concept, it's free and instantaneous to move money into your own cold storage whenever your till gets over a certain amount.)
edit: some small percentage of customers would be a smarter measure than some specific number.
You're still making a fundamentally invalid comparison: with cash, your security threats are still limited to people who are nearby and have both the time and means to move large amounts of currency. Bitcoin allows anyone in the world to steal amounts which would require a large team with dump-trucks in the real world even if the bank completely screwed up their security design.
http://news.yahoo.com/mtgox-opens-call-centre-500m-bitcoin-l...
That's a lot of duffle bags to haul.
What we're actually talking about, however, is like being able to teleport into a bank anywhere in the world, wave a magic wand which converts everything on the premises into tightly packaged $100 bills, and teleporting back out of the country. In the real world, running out the door with a bunch of duffel bags and people shouting tends to attract a lot of attention and make escape a lot harder than closing a network connection.
Just as an example, Bank of America has over $2 trillion in deposits. If any minimally significant portion of that amount goes missing, it's pretty easy to track just due to scale. There are policies in place that ensure any transaction above a certain size gets looked at. If there are too many large transactions in a day, that gets investigated too. In exchange for having these safeguards in place, the government is willing to guarantee these deposits in the form of FDIC insurance.
Banking regulation is a good thing, especially when you're talking about an anonymous currency where transactions can't be rolled back.
EDIT: Just wanted to add that while Bitcoin itself probably will never be a globally significant currency, some form of cryptocurrency is likely to obtain relevance. But some people are going to get burned along the way, and these are the risks that you need to accept if you want to dabble in what amounts to unregulated banking. The regulations exist for a reason.
My uninformed intuition tells me it's more likely that there will be a Gold and a Silver - one better, one worse, each used for different things.
It's basically like carrying cash: you can walk around with $10,000 in your pocket, but if someone robs you and gets away, you're out $10,000. If someone steals your credit card, the bank has fraud protection measures in place that limit their losses, and they often can roll back transactions. Unless you impose a similarly regulated structure on top of Bitcoin (where banks are super-secure and won't transfer large amounts of BTC without an auditable authorization chain so people become personally liable for any fraud that may occur) you're not going to be able to solve these problems.
Deflation is a bigger issue, in my mind. The algorithmic scaling of Bitcoin basically ensures that it will either not be very much in demand at all, or it will become increasingly scarce relative to demand over time. This creates an incentive to buy and hold Bitcoin as its value has tended to go up over time. However, most of the modern economy is based on the assumption that money today is worth slightly more than money tomorrow. This creates pressure to spend or invest, rather than hold onto currency for any reason other than liquidity. If Bitcoin remains popular, it won't be because of its virtues as a currency.
Plus there is that whole thing of regulations about bank responsibilities.
(I am not a banker.)
According to the FDIC, for most banks theft is covered by the banks insurance policy (they refer to it as a "banker's blanket bond") which also covers loss (of money) by fire, flood, and even things like embezzlement etc.
So until BTC exchanges/etc actually have insurance policies (literal policies, not figurative "insurance policies") the risk seems higher.
Also worth considering - I remember reading about a bit coin site that uses a Safe Deposit Box to store the majority of its holding "offline", but safe deposit boxes aren't insured by either FDIC (even in the event of bank failure) or by the bank, so if their safe deposit box is breached (either as a theft or just damage) there is no safety net.
What exactly is a hot wallet/storage?
A cold wallet is one where the keys are kept offline and not plugged into anything, eg, a printout, or a USB key.
Bitcoin developers haven't quite cottoned onto the wisdom of separating these functions architecturally. (One of many advantages is "If your matching system is compromised, you shut it down and investigate, but no money actually leaves. The settlement system is in your back office and much more protected than the matching system, because the settlement system doesn't have to talk to customers directly.")
Bitcoin developers instead have developed a security pattern called hot wallet/cold wallet, where BTC which are available to the system are "hot" and BTC which are not available to the system are "cold." The idea is that, in any given day, you might only require 2% or so of your company's total reserves to go in or out. You keep the private keys to, say, 5% of it on the live system. That's your hot wallet. You keep the private keys to the remaining 95% somewhere else. That's your cold wallet. Even if your live system is rooted, you should not (the thinking goes) lose the private keys to the cold wallet.
The Bitcoin community widely believes that this pattern is sufficient to prevent events like the recent Mt. Gox debacle, where the system was compromised and both the hot wallet and cold wallet were drained.
Doesn't that violate the real time nature of bitcoin then? I have built e-commerce settlement systems in the past and I thought that the big challenge with bitcoin was always the instantaneous element.
BTW: Bitcoin isn't a real-time system. The community widely believes it is, but people who actually understand what is happening would say "cough Yeah by 'real-time' we mean 'an hour later' cough."
I'm not sure this is true. Any off blockchain transaction is basically an unsettled (and therefore reversible) bitcoin transaction. So for example, trades on bitcoin exchanges and payments between web wallets will have separate and distinct settlement phases. Generally bitcoin enthusiasts gloss over this though, because they don't like the idea of reversible transactions.
The current maximum transaction rate for the bitcoin networks is something like seven transactions per second. So either they'll have to figure out how to increase that or move to a more conventional clearing and settlement system if bitcoin-as-a-payment-network ever takes off in real size.
What? I'm not entirely sure that I understand this correctly: Do you say that the whole bitcoin network, with all that computing power, can't compute more than 7 transactions per second?
See here: https://en.bitcoin.it/wiki/Scalability
Altcoins which have chosen blocktimes of say 1 minute will be able to do more transactions per second, and ones which lift the 1MB cap likewise.
Are you saying that Bitcoin-based financial systems cannot introduce a more secure settlement system without fundamental architectural changes to the Bitcoin protocol?
Or are you simply saying that nobody has apparently done so?
If the former, I would like to challenge that assumption. If the latter - what are you really trying to get at?
Most people trust places like a bank, an investment brokerage, or paypal to store money, and not have it be "lost to hackers". There are banking regulations and insurance policy that have been around for 100 years to protect people from that kind of thing.
Of course, storing Bitcoins on your laptop is even more risky than storing cash under your mattress. Someone has to physically enter my house to steal the cash, but to steal my bitcoins? All they need is a virus, spyware, out of date OS, out of date router firmware, out of date NAS firmware, a zero day exploit, etc. and they can drain me of my coins from anywhere in the world.
Then of course there is the risk of simply losing the coins. An accidental deletion. A hard drive failure. Losing a laptop or having it stolen. You have to back everything up, you have to back it up offsite, and you have to trust the offsite backup. You have to keep your machines securely locked down.
All of this requires the user to be quite tech savvy. This will never change for storing coins locally... so if Bitcoin is going to be the "currency of the future" to be used by the masses then secure banks and exchanges have to be a thing. They also have to be a thing for lending and investing, anyway.
Though I think I'd put those paper printouts with the QR codes on them in a fire-resistant box, at least.
For me this actually shows promise of real market stabillity in the long run. Image what would happen if a real bank failed in a normal country. Or image what would happen to USD if the largest world bank would fail (destroying 12% of worldwide supply of USD) and nobody would bail them out? Would the drop be worse than 10-20%?
The whole point of state-backed currency is to provide stability and make it so there's money you can trust - not some wild west cross-your-fingers system. Yes, countries have failed (e.g. hyperinflation), but at least there are extremely powerful institutions in place who's remit is to prevent that at all cost.
You can quickly and securely trade bitcoins with other people around the world with your local currency!
Sadly, I think many people trust such marketing claims, partially because they assume the people behind the site know what they are doing, they assume the laws of a developed host economy like Japan are strong enough to prevent companies from making false claims (even while the market itself is unregulated), and, most importantly, they want to believe it will benefit them.
Much of bitcoin is underwritten by illegal activity.
So then why don't these Bitcoin companies embrace ridiculous amounts of information disclosure and transparency?
Don't tell me you "take every precaution." Detail what precautions you are taking. Name an external pentesting firm that tests your infrastructure quarterly. Post their findings a few months after you have address the issues. Open Source everything that you can. Offer bug bounties paid in BTC for security issues discovered. Discuss, in detail, your hot/cold wallet storage setup. Do offensive analysis to determine the most likely attack scenarios, and publish them, along with the layer defense you have put in place to mitigate the risk.
'We got hacked by ourselves, thank you for contributing to the magnitude of our initial private offering.'
EDIT: Now that I think of it, it seems like I read somewhere that, with Mt Gox in particular, the Feds seized their ~$5M in BTC a while back by having them transfer it to a wallet under their control. Can anyone corroborate this?
Thanks. I'd never heard of Google. What a fantastic invention!
Sadly, though, it doesn't appear to help as much with vague recollections, and certainly doesn't seem to pass the Turing test where actual discussion is concerned.
In any event, it appears that I've mixed it up with Silk Road, where actual bitcoin was seized.
Turns out that it takes a bit more "Googling" (I think I've coined a new verb for this new Google thing) to determine that you have something wrong vs. corroborating that something is true.
This all gives me a new idea. I haven't quite fleshed it out yet, but I am tentatively calling it a "discussion forum".