Coinbase Vault
blog.coinbase.com
blog.coinbase.com
Also, in case a particular bankruptcy proceeding taking place in Tokyo hasn't demonstrated it enough, "cold storage" is attributed with vastly more security by Bitcoiners than is warranted. If implemented correctly it minimizes Bitcoins lost by one genre of attack, but have no doubt, there are many, many more ways to lose your Bitcoins.
My guess is this is primarily marketing designed to convince people that keeping Bitcoins is safe and secondarily a product decision to reduce loss caused by poor user password management rather than by sophisticated attacks.
I tried their support, but they never really tried to help. While their vault seems like a good idea, I would not trust them with my bitcoins anymore :-/
That being said I don't trust any third party with any of my wallets full stop at the moment.
What if you run into a bug? From my experience I would not expect to get any qualified help.
Briefly checking the Coinbase TOS reveals this:
> 8.2. Arbitration; Waiver of Class Action. EXCEPT FOR CLAIMS FOR INJUNCTIVE OR EQUITABLE RELIEF OR CLAIMS REGARDING INTELLECTUAL PROPERTY RIGHTS (WHICH MAY BE BROUGHT IN ANY COMPETENT COURT WITHOUT THE POSTING OF A BOND), ANY DISPUTE ARISING UNDER THIS AGREEMENT SHALL BE FINALLY SETTLED ON AN INDIVIDUAL BASIS IN ACCORDANCE WITH THE AMERICAN ARBITRATION ASSOCIATION'S RULES FOR ARBITRATION OF CONSUMER-RELATED DISPUTES AND YOU AND COINBASE HEREBY EXPRESSLY WAIVE TRIAL BY JURY.
I'm not sure that you can get someone to sign away basic property rights in a contract.
Analogously, if I lose my password to my bank's website, I bet I can legally force them to return my funds.
There was an interesting article about this in the NYT recently. Apparently arbitration clauses do have a decent chance of standing up to challenge. It's discomforting because when all the vendors in a space have the clause there is no way to have your right to trial.
http://www.nytimes.com/2014/07/19/your-money/a-closer-look-a...
It's even more dubious in finance because you not only agree to arbitration, but you agree to arbitration by the private financial regulatory organization Finra. Think about that--to get a brokerage account you must agree to arbitration through Wall Street's self-funded watchdog. Unsurprisingly Wall Street has a great track record in winning.
They are 1000x more proficient and professional than MtGox ever was (not that that's saying much...)
The entire point of two factor authentication is that it's impossible for someone to access your account without knowing your password and having access to your code generator. You chose to lose your code generator by getting a new phone without backing it up, AND you removed the phone backup that was provided for you.
This is like getting a new keychain, throwing out your old keys, then getting angry at your bank because you can't get into your safe deposit box.
You could ask for 2FA code confirmation before removing a backup phone.
Or you could decline removing the only backup phone available, requiring at least one backup phone on file.
Users always screw up, it's software's (developer's) job to deal with it.
What's the point of cryptocurrency if you enter your email + full name?
Coinbase is not at all known for caring about privacy or pseudonymity. They've become somewhat of a counterpoint to how BTC started out ideologically. They are building a mainstream, government regulation friendly business.
Contacting support yielded no results at all. I had to go through my bank, close my account (which is a nightmare in itself), and get the money refunded via the bank's fraudulent ACH reversal process.
I would not trust this company.
I think the Copay wallet from Coinbase's competitor, Bitpay, does true multi-signature.
Coinbase's current solution is a significant improvement for people who must use Coinbase for some other reason, I suppose. Anyone else should think about the advantages of true multi-sig on the blockchain
I see what they are trying to do here but why not just simply approve/deny transactions? Time delay seems a bit weird.
I don't know much about it but if it's delayed by 1-2 hours attacker can simply make request at 4AM in the morning.
> Up to 97% of bitcoin is stored entirely offline in geographically distributed safe deposit boxes and private safes.
Again, I know what they are trying to do here but this does not make me feel safe. Drop the hardware and you have potential data loss.
How are the logistics? Are they going out on the same truck to multiple locations? Etc.
Just seems a bit too high level and does not contain any context.
The offline storage is likely done in such a way that no one storage location is critical. This is easy to achieve with cryptography.
They very well know the risks involved with sending your bitcoin savings to an address you don't control and they make no effort at all of alleviating any of the concerns.
There's no mention at all of how you can verify they actually control the bitcoin you gave them to, even though there's been schemes for doing this for years.
You might as well send your money into a black hole.
If some guy on the street corner offered to watch all my cash in a secure facility for free, I would worry a little bit.
For as much fun as banks can be, they do provide some pretty good oversight and legal protection. The dude on the street corner, not so much.
Banks, like Coinbase, make their money from other services their customers invariably end up using (ATM/withdrawal fees, credit card fees, etc).
You just write down these words and store them in a safe place, and you will always be able to recover your coins.
(This doesn't prevent against your computer being hacked, of course, but it does encrypt your private keys and require a password before sending anything, which is reasonable.)