Do you really want me to keep destroying your business? I will....
https://lazycoins.com/securityWe will not be using TxID's to monitor withdrawals and we will be polling our databases for negative balances before allowing withdrawals.
UHMMM shouldn't you be monitoring your own balances for withdraws so you never double spend? That is what this sentences means, it means you that you keep all addresses in a database and you check them for transactions to build your own transaction right? Instead you should use a double edit system
OR basically that sentence is BS cause why would you need to monitor transactions, the wallet you use would do that for you and you can just spend it, making sure that you keep all balances are kept in a database are correct.
Making you sound like this actually means something important....
Our withdrawal system performs cryptographic audit of user balance before admin can manually approve all withdrawal requests.
How is this done? What mechanism are you using? Cause this again just you putting words to make it sound important. Shouldn't you perform a cryptographic audit for the public meaning that each user balance is whole? Plus this would prove that you are whole. Also cryptographic audit just for you would make no sense, you would know if the site is whole or not LMAO.
Physical Security
Do you have a security guard or is it just a locked room? I am guessing it is a locked door that any bank theft can break thru
1. We will not be using TxID's to monitor withdrawals and we will be polling our databases for negative balances before allowing withdrawals.
Perhaps the above sentence is a bit to esoteric leading to the ambiguity you have experienced. We'll look into rewording it.
The sentence is making two separate statements, the first part is a direct response to the transaction malleability issue which had affected MtGox. The second part is referring to an issue which befell poloniex, their withdrawal system did not check for negative balances and thus a user could become 'overdrawn' due to other issues in the way their withdrawal code was written.
https://bitcointalksearch.org/topic/btc-stolen-from-poloniex-499580When we were developing our service we trawled through many exchange theft threads with the purpose of securing ourselves as well as we can.
2. Our withdrawal system performs cryptographic audit of user balance before admin can manually approve all withdrawal requests.
This sentence builds on the 'polling databases for negative balances' statement. We check the arithmetic of all actions the user has made since their balance was last 0. This includes cross referencing new deposits on our db with the blockchain just in case there was a large fork and our main daemon was on the wrong side past the deposit confirmation threshold.
3. Physical Security
"I am guessing it is a locked door that any bank theft can break thru
"
You've made it abundantly clear that no physical security will be enough for you so I'm guessing your preceding question was rhetorical.