Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Q: Why didn’t you hire experienced professionals? A: We tried, but we didn’t have money and also often they turned us down. A former Financial Services Agency bureaucrat approached us once last year, but he declined our offer at the end."

I'm pretty sure what happened here is a professional was interested in helping out, got a look at the books and ran.



Someone somewhere is thanking his stars that he had the sense to run, and didn't get caught up in this criminal prosecution.


I regretfully can't tell you the context, but suffice it to say the following was once said in Tokyo: "I do not want to be one of the 100 closest gaijin to that office when shit goes down." (The Japanese immigration agency is occasionally - oh wait they still have my renewal form at the office? - zealous in their execution of their statutory duty to remove undesirable foreigners from Japan.)


You don't need to look at the books for that. Imagine you got that offer. Millions going through the accounts that you have to protect, secure in online and offline environment, monitor, ideally have complete control over access logs, think about relevant company certifications that may be required because you deal with money one way or another. And you need to have some practical banking knowledge on top of that. If anything goes as bad as it did, it could be your name in that article instead of the company owner.

With no inside knowledge of the books, how many people would you think need to be on the security side of that company and how much would you request to get paid? I'd definitely go with (10+)x amount a very well paid person gets in other companies.


I think somebody ever wrote about an interview experience for an IT position at MtGox on reddit - it was very close to what you imagined.


Do you have a link to that? It sounds like an interesting read!



Here you go: http://www.reddit.com/r/Bitcoin/comments/1x9gue/my_protest_a...

Editing code in production on a financial services platform? Wow.

Note that his/her interviewer actually shows up in the thread a bit farther down to confirm the story.


>Editing code in production on a financial services platform? Wow.

Heh. This happens on good ol' USD platforms as well. You'd be surprised (horrified).


There have been a few people in /r/asknetsec recently saying they are in charge of a bank's security and needing help with very basic things. I hope for their sakes they move on before everything hits the fan.


He also wrote his own SSH daemon in PHP and was planning to issue it as a library.

https://web.archive.org/web/20140226001727/http://blog.magic...


Didn't have the money yet apparently spent a million dollars developing his Bitcoin Cafe in the lobby of the building.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: