{"type":"rich","version":"1.0","author_name":"npub1g6vxlp4e0nyhs2dqxxcryztyf5f5hyuaq93nw4r87zcnv0sdsa0qqsl5wd","author_url":"https://nostr.ae/npub1g6vxlp4e0nyhs2dqxxcryztyf5f5hyuaq93nw4r87zcnv0sdsa0qqsl5wd","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2016-08-06\n📝 Original message:On Sat, Aug 6, 2016 at 11:39 AM, s7r via bitcoin-dev \u003c\nbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\n\u003e * reversal of transactions is impossible\n\u003e\n\nI think it would be more accurate to say that the requirement is that\nreversal doesn't happen unexpectedly.\n\nIf it is clear in the script that reversal is possible, then obviously the\nrecipient can take that into consideration.\n\n\n\u003e * keep private keys private and safe. Lose them, it's like losing cash,\n\u003e you can just forget about it.\n\u003e\n\nKey management is a thing.  Managing risk by keeping some keys offline is\nan important part of that.\n\n\n\u003e * while we try hard to make 0-conf as safe as possible (if there's no\n\u003e RBF flag on the transaction), we make it almost impossible or very very\n\u003e expensive to reverse a confirmed transaction.\n\u003e\n\nBitGo has an \"instant\" system where they promise to only sign one\ntransaction for a given output.  If you trust BitGo, then this is safe from\ndouble spending, since a double spender can't sign two transactions.\n\nIf BitGo had actually implemented a daily withdrawal limit, then their\nsystem ends up similar to cold storage.  Only 10% of the funds at Bitfinex\ncould have been withdrawn before manual intervention was required (with\noffline keys).\n\nWho will accept\n\u003e such an input and treat it as a payment if it can be reversed during the\n\u003e settlement layer?\n\n\nObviously, if a payment is reversible, then you treat it as a reversible\npayment.  The protection here relates to moving coins from the equivalent\nof cold storage to hot storage.\n\nIt is OK if it takes longer, since security is more important than\nconvenience for coins in cold storage.\n\n\n\u003e The linked page describes that merchants will never accept payments from\n\u003e 'vaults', and it will take 24 hours for coins to be irreversible moved\n\u003e outside the 'vault'.\n\n\nThis relates to the reserves held by the exchange.  A portion of the funds\nare in hot storage with live keys.  These funds can be stolen by anyone who\ngets access to the servers.  The remaining funds are held in cold storage\nand they cannot be accessed unless you have the offline keys.  These funds\nare supposed to be hard to reach and require manual intervention.\n\nI think this is a wrong approach. hacks and big losses are sad, but all\n\u003e the time users / exchanges are to blame for wrong implementations or\n\u003e terrible security practices.\n\u003e\n\nSetting up offline keys to act as firebreaks is part of good security\npractices.\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160806/7bcdc140/attachment-0001.html\u003e"}
