Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not until I see a security audit will I believe any exchange is secure. I believed Mt. Gox had "resolved" the basic issue of password hashing back when they were compromised until I found out they were using a home-grown "run sha512 1000x" solution.

That, plus I know as a programmer I like to think I'm disciplined enough to be a secure programmer until my software is audited or pentested. Then I realize how naive I really am.

Like I said, I'm not trusting any exchanges until I start seeing rigorous security measures (more than "security is our #1 priority" bullshit) in the form of audits, pentesting, and etc...

That said I also know very few people that actually use their personal BTC wallets and encrypt it with GPG + a two factor challenge (to avoid the possibility of key loggers).



Not until I see a security audit will I believe any exchange is secure

definitely! Everyone saying "im secure" must also say "the X will prove it"


Better yet, assume it's not secure and don't store funds there. Deposit, trade, withdrawal.*

*does not apply to day traders




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: