<oembed><type>rich</type><version>1.0</version><author_name>npub1g6vxlp4e0nyhs2dqxxcryztyf5f5hyuaq93nw4r87zcnv0sdsa0qqsl5wd</author_name><author_url>https://nostr.ae/npub1g6vxlp4e0nyhs2dqxxcryztyf5f5hyuaq93nw4r87zcnv0sdsa0qqsl5wd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-08-06&#xA;📝 Original message:On Sat, Aug 6, 2016 at 11:39 AM, s7r via bitcoin-dev &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; * reversal of transactions is impossible&#xA;&gt;&#xA;&#xA;I think it would be more accurate to say that the requirement is that&#xA;reversal doesn&#39;t happen unexpectedly.&#xA;&#xA;If it is clear in the script that reversal is possible, then obviously the&#xA;recipient can take that into consideration.&#xA;&#xA;&#xA;&gt; * keep private keys private and safe. Lose them, it&#39;s like losing cash,&#xA;&gt; you can just forget about it.&#xA;&gt;&#xA;&#xA;Key management is a thing.  Managing risk by keeping some keys offline is&#xA;an important part of that.&#xA;&#xA;&#xA;&gt; * while we try hard to make 0-conf as safe as possible (if there&#39;s no&#xA;&gt; RBF flag on the transaction), we make it almost impossible or very very&#xA;&gt; expensive to reverse a confirmed transaction.&#xA;&gt;&#xA;&#xA;BitGo has an &#34;instant&#34; system where they promise to only sign one&#xA;transaction for a given output.  If you trust BitGo, then this is safe from&#xA;double spending, since a double spender can&#39;t sign two transactions.&#xA;&#xA;If BitGo had actually implemented a daily withdrawal limit, then their&#xA;system ends up similar to cold storage.  Only 10% of the funds at Bitfinex&#xA;could have been withdrawn before manual intervention was required (with&#xA;offline keys).&#xA;&#xA;Who will accept&#xA;&gt; such an input and treat it as a payment if it can be reversed during the&#xA;&gt; settlement layer?&#xA;&#xA;&#xA;Obviously, if a payment is reversible, then you treat it as a reversible&#xA;payment.  The protection here relates to moving coins from the equivalent&#xA;of cold storage to hot storage.&#xA;&#xA;It is OK if it takes longer, since security is more important than&#xA;convenience for coins in cold storage.&#xA;&#xA;&#xA;&gt; The linked page describes that merchants will never accept payments from&#xA;&gt; &#39;vaults&#39;, and it will take 24 hours for coins to be irreversible moved&#xA;&gt; outside the &#39;vault&#39;.&#xA;&#xA;&#xA;This relates to the reserves held by the exchange.  A portion of the funds&#xA;are in hot storage with live keys.  These funds can be stolen by anyone who&#xA;gets access to the servers.  The remaining funds are held in cold storage&#xA;and they cannot be accessed unless you have the offline keys.  These funds&#xA;are supposed to be hard to reach and require manual intervention.&#xA;&#xA;I think this is a wrong approach. hacks and big losses are sad, but all&#xA;&gt; the time users / exchanges are to blame for wrong implementations or&#xA;&gt; terrible security practices.&#xA;&gt;&#xA;&#xA;Setting up offline keys to act as firebreaks is part of good security&#xA;practices.&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160806/7bcdc140/attachment-0001.html&gt;</html></oembed>