Pages:
Author

Topic: TradeHill - Who we are - page 8. (Read 42352 times)

sr. member
Activity: 420
Merit: 250
June 20, 2011, 10:09:26 AM
#91
We're back again, trade away!
Shoot, I wish I had funded my TradeHill account.... I'd be buying like mad!

My prediction: you're unlikely to see bargains like this ever again.  Potential buyers are stuck with no money in their accounts.  It'll take days to get money into TradeHill.

Then again what do I know.

You can wire it in the same day or if you have money in your Dwolla it's almost completely automated.
newbie
Activity: 52
Merit: 0
June 20, 2011, 10:02:24 AM
#90
oh don't worry, there will be plenty of bargains to be had over the next week. You cannot have an episode like this and then have a stable market, things will be as volatile as ever.
sr. member
Activity: 266
Merit: 250
June 20, 2011, 09:58:55 AM
#89
We're back again, trade away!
Shoot, I wish I had funded my TradeHill account.... I'd be buying like mad!

My prediction: you're unlikely to see bargains like this ever again.  Potential buyers are stuck with no money in their accounts.  It'll take days to get money into TradeHill.

Then again what do I know.
member
Activity: 98
Merit: 10
June 20, 2011, 09:45:24 AM
#88
We're back again, trade away!
newbie
Activity: 59
Merit: 0
June 20, 2011, 09:29:22 AM
#87
Staying closed until security has been thoroughly reviewed == a damned good reason.

TH *will* be targeted, if it hasn't been already, and personally I'm much happier that they're not taking any risks rather than opening.
member
Activity: 98
Merit: 10
June 20, 2011, 09:27:30 AM
#86
The longer the exchanges are closed, the more bitcoins lose credibility.  Restore confidence back to the market, and reopen the exchanges.
newbie
Activity: 57
Merit: 0
June 20, 2011, 09:24:48 AM
#85
Yea we now have 2 major exchanges closed, 1 of them for no good reason? Please post some kind of update.
full member
Activity: 180
Merit: 100
June 20, 2011, 09:24:08 AM
#84
Maybe they are too scared to open up before Mt.Gox
member
Activity: 98
Merit: 10
June 20, 2011, 09:22:50 AM
#83
Someone forget to turn the trading switch back on?  Please update the website if there is a new reopen time Tradehill
sr. member
Activity: 308
Merit: 250
June 20, 2011, 09:19:52 AM
#82
When is it coming back up? Sad
newbie
Activity: 58
Merit: 0
June 20, 2011, 09:10:07 AM
#81
Hey, Great news about getting a Security Audit.

Umm, just dont give them "Read-only" access to our passwords, it doesn't end well. Wink
newbie
Activity: 27
Merit: 0
June 20, 2011, 08:59:27 AM
#80
I have a few questions.

Did you hire a Security Professional?  A real one?  What are his qualifications?  What kind of testing, tools and monitoring has been put in place?

Have you implemetned a realistic Security Strategy, like "Defense in Depth".  Is each layer of the IT infrastructure down to the database is protected with ACL's and the minimum privileges possible.

Do you require users to have good pwd,  at least 16 characters long, digits, letters and special characters along with digital certificates. 

do you run your operations on a real Unix system?  Solaris or OpenSolaris are secure by default.  They are also "special " enough that not many hackers have expertise to penetrate it and it has very good support and Security features built in. 

Is your system hosted in the cloud? 

Are you using a well designed and professionally managed database?  Is this database being operated in the most secure manner possible?  Can you prove it and show evidence of an audit?

Everything should be logged and the logs monitored for attacks. 

Do you offer all users a digital certificate with your exchange being the CA. 

Is your entire operation behind a commercial firewall appliance and do you use a secure DNS?

What SEIM monitoring tools are in place?  You should have an SEIM monitoring solution from a reputable company.  I used AlienVault to gain experience but something even better might be a commercial offering.  Trustwave comes to mind that will audit your system and provide some certifications as to your compliance with all provisions of the NSA recommendations, and any other applicable authorities like the big exchanges. 

I think if you put this in place and let it be known upfront what is going on then you could easily attract as much business as you could handle.  With the best security in the bitcoin exchange arena you could charge more for trades and still get more customers.  With as much security as mentioned here it should be no problem for a big insurance agency like Loyds or whomever to insure each account and each trade to at least 250K bitcoins at a time or better.

You are going to be the number one target if you are successful.  Plan on it and plan on getting hit and have a plan to recover.

This is going to be a huge business with any luck and being the most secure will get you all the business you handle.
sr. member
Activity: 282
Merit: 250
June 20, 2011, 01:41:01 AM
#79
I recommend a function to allow us to change our email associated with our account as well.
newbie
Activity: 28
Merit: 1
June 20, 2011, 01:17:10 AM
#78
Come on guys! This conspiracy theory that Tradehill did the attack is just a little too wiled, don't you think? The U.S. Government, probably not but maybe. Lulzsec, much more likely. Tradehill, not very likely.

It's just an opportunity, that spammer who sent you all referrals knows that.
sr. member
Activity: 420
Merit: 250
June 20, 2011, 12:16:11 AM
#77
When will tradehill open back up for trading?  It says a few hours on the website, but it's been 6...  I'd just like to know if it'll be 1 hour or 10 before we can start trading again?

They just updated their website:
We expect to resume normal operations 06/20/11 10 AM Eastern.

Thanks, beat me to it.
sr. member
Activity: 420
Merit: 250
June 20, 2011, 12:15:04 AM
#76
When are you going to be able to provide a timeline for things like a full security audit and features like two factor auth that you mentioned on onlyonetv?  I understand that you won't be able to commit to specific time for features or a consultant you haven't hired, but a date when you will be able to would be nice.

We have 3 people (internally) looking in to our security as I post this. We're not going to release the two factor authentication without extensive testing but I am going to say we will release an ETA as soon as we have it and this is a top priority.
member
Activity: 98
Merit: 10
June 20, 2011, 12:13:57 AM
#75
When will tradehill open back up for trading?  It says a few hours on the website, but it's been 6...  I'd just like to know if it'll be 1 hour or 10 before we can start trading again?

They just updated their website:
We expect to resume normal operations 06/20/11 10 AM Eastern.
legendary
Activity: 2156
Merit: 1072
Crypto is the separation of Power and State.
June 19, 2011, 11:59:17 PM
#74
With the proper authorizations many people can perform a penetration test of the web site.  It should be fairly easy to run one, or contract to do it, and publish the results.  It would certainly be worthwhile to have some evidence of security in place. 

Some people can do the pen testing without authorization but not legally from the USA.

That's right Ivan. 

If a site won't publish the results from one or more of the readily-available penetration testing services, you should assume that their code is ready to be opened up by hackers like a tin can of sardines with a pull-tab.
legendary
Activity: 1400
Merit: 1005
June 19, 2011, 11:49:29 PM
#73
When will tradehill open back up for trading?  It says a few hours on the website, but it's been 6...  I'd just like to know if it'll be 1 hour or 10 before we can start trading again?
member
Activity: 126
Merit: 10
June 19, 2011, 11:09:07 PM
#72
When are you going to be able to provide a timeline for things like a full security audit and features like two factor auth that you mentioned on onlyonetv?  I understand that you won't be able to commit to specific time for features or a consultant you haven't hired, but a date when you will be able to would be nice.
Pages:
Jump to: