Bitcore Core v0.9.0 release overview
garzikrants.blogspot.com
garzikrants.blogspot.com
But regardless, great job guys.
Unfortunately the wallet handling capabilities of bitcoin-core don't scale to high numbers of wallets. Thus as an org running a service handling many wallets, it is useful to program against a lightweight client API such as bitcoinj, and then have your client peer with "trusted" bitcoin-core nodes.
The *coin ecosystem need more than one implementation, a single codebase can't cater to all uses. I should know, I'm an Apache member.
That's very different than the case where say 50% of the network is running bitcoind, and the other 50% is running btcd, and some transaction triggers an edge case in either implementation that causes one implementation to accept the transaction and another to reject it.
I think multiple compatible implementations would be great to have, but we don't have them at the moment, and in the meantime companies handling huge numbers of bitcoin transactions need a solution that works today. So I applaud the bitcoin-core team for catering to the increasingly common use case of using bitcoind only for consensus.
I do empathize with the need of solutions for today though. I was just thinking about tomorrow.
https://github.com/conformal/btcscript/commit/299dcc2fad071d...
Chain splitting bugs in btcd get fixed all the time, that's why its considered alpha quality software.
Or I suppose it could be that Mt. Gox was the problem, and now the problem has gone away.
Still, I predict that when the economy crashes again as it did in 2008, we will see many more exchanges die off, and they'll take everyone's money with them. This may harm mass adoption of Bitcoin by reducing confidence.
This seems a step in the right direction: https://news.ycombinator.com/item?id=7277865 Anyone know if any exchanges have started doing this yet?
On top of much better security, using multisignature addresses gives you answer to your second question: everyone using services like those below can check their wallet contents on the Blockchain at any given time. There's no need for the service to "prove" anything - everything is provable and exists on the Blockchain by design.
An exchange operates a limit order book, which matches and settles trades automatically. Otherwise you just have a forum where each user has to repeatedly, manually handle the logistics and security of a wide variety of payment systems. The exchange should do that, not the user.
But if that's the case for the US, what's stopping a thief to send money to an exchange like Bitstamp, buy BTC, withdraw it and then reverse the fiat payment in a similar matter?
And while it's true that on Bitalo you have to handle the fiat payments yourself, but it will be often faster to get BTC that way than to send it to an exchange, wait for them to process the deposit, and only then buy BTC.
Sending money to bitstamp requires an international wire transfer (SWIFT), those (usually) can't be reversed.
Its ACH payments which get reversed so easily (ACH is a domestic network, all in-country). That's why TradeHill shut down after a fraudulent $20k Dwolla payment, all Dwolla deposits/withdrawals are through ACH. And that's why Coinbase has to be so careful with which customers they allow to purchase bitcoins, all Coinbase deposits/withdrawals are ACH.
> And while it's true that on Bitalo you have to handle the fiat payments yourself, but it will be often faster to get BTC that way than to send it to an exchange, wait for them to process the deposit, and only then buy BTC.
Speed of a first purchase is one thing. But I'd guess that the main reason people keep funds on an exchange is because they want to day-trade, pick up cheap coins with a lucky limit order during a flash crash, or have the option to panic sell in a split second (not even a one hour wait for 6 confirmations). That kind of trading is only possible on an exchange with a limit order book, not an OTC marketplace.
I guess this problem is unavoidable short of using lots of different exchanges. Maybe there just needs to be more than one Coinbase.
The problem for exchanges especially (maybe to a lesser extent for "brokers" like Coinbase) is that they _need_ exclusive access to your bitcoins, to ensure there's no way for you to take them before they can give them to the other party in a trade. I don't see any way around this, short of exchanges trusting users to deliver bitcoins after the trade. Even with multisignature/escrow systems, there is the risk the user double-spends the coins at the same time they make a trade. (And if the exchange is able to take back the cash, or withhold it until the bitcoin transaction is confirmed, there's probably not a fair way in general to reverse the trade, is there?)
The decentralized order books in Ripple show this is solved. We don't need a central authority to match trades, no more than we need a central authority to prevent double-spends. When you post an offer to trade XRP for snapswapUSD on ripple, the XRP remains 100% in your control (until someone takes your offer and a trade is matched). Ripple shows how trade matching can be implemented as a decentralized cryptographic "contract".
Of course, this won't work with bitcoin as the native currency until somebody implements trade matching as a bitcoin contract (and exchanges like bitstamp issue bitstampUSD as colored bitcoins). And even then, there's still the fact that bitstampUSD is centrally issued and could all turn worthless the moment Bitstamp stopped redeeming it. And that has another solution (coins which track fiat-price in a decentralized prediction market).
When that kind of situation happens, people need to take the hint and stop using the service.
Trustless exchanges can work, but they generally need much more infrastructure and possible changes to bitcoin (or a side chain).
FYI, Coinbase isn't an exchange; they're an online wallet and Bitcoin broker. Exchanges are for trading, and have much much lower fees. Gox was an exchange, as is BTC-e and Bitstamp.
They create an individual wallet file for each user AES encrypted with your password. They also support 2-factor auth and auto-backups to 3rd party services like Dropbox.
"It is highly recommended you enable two factor authentication on your My wallet account. Your wallet data is still only encrypted with your password however a second authentication step will need to be passed before your encrypted wallet data is output."
There's also GreenAdress.it which has interesting security system in place using "nLockTime": http://www.reddit.com/r/Bitcoin/comments/20puhg/while_blockc...
If you trust every other aspect of their service (that they aren't capturing and storing your password, which of course they handle every time you use the service), then you can feel safe in knowing that you don't have to trust them not to spend your coins because they can't.
But only if you trust that every other part is honored.
That isn't a rational set of conditions. In the usage of Blockchain.info, they absolutely gain the capacity to capture your private keys. As does anyone who hacks the service.
And of course the reason for this is because Javascript cryptography is an oxymoron [0].
[0] - http://www.matasano.com/articles/javascript-cryptography/
So today they don't have your keys. Not to say they couldn't be malicious in the future, or get hacked, but that's not the case today. Again, as far as I know.
That's possible with multisig and GreenAddress offers 4 different kind of 2FA: Google Auth, SMS, email and Phone (robot call)