Bitcoin Forum
May 10, 2024, 09:05:29 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Exchange Standards Framework  (Read 998 times)
Tommo (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
April 04, 2014, 04:29:45 AM
Last edit: April 12, 2014, 05:27:04 PM by Tommo
 #1

In light of the recent Mt.Gox debacle, I'm looking for some help in coming up with some sort of Standards Framework which exchanges should follow in order to minimise the potential for hacks, dodgy accounting, etc so that users of the exchanges compliant with the framework can feel safer trading bitcoins or other cryptos.

Lets start with listing some safe and unsafe features:

[Safe Features]
- Operating in a politically stable and crypto friendly jurisdiction
- KYC/AML adherence
- Dedicated hardware
- DDoS resistant
- Minimal alteration of Bitcoin Core, alterations independently reviewed
- Regular software audits and performance review
- Cold storage, manual access only
- Hot wallet size algorithmically determined by standard deviations of withdraws
- 100% reserve
- Regular financial statements, fiat + crypto
- 2 factor authentication
- Separation between read-only and execution APIs (https://bitcointalk.org/index.php?topic=556810.msg6065434#msg6065434)
- Separation between trade and wallet APIs
- Exchange transactions all performed on chain (operationally possible?)

[Unsafe Features]
- ?

For clarity I'll add/remove features here later depending on census. Let's self regulate.
1715375129
Hero Member
*
Offline Offline

Posts: 1715375129

View Profile Personal Message (Offline)

Ignore
1715375129
Reply with quote  #2

1715375129
Report to moderator
1715375129
Hero Member
*
Offline Offline

Posts: 1715375129

View Profile Personal Message (Offline)

Ignore
1715375129
Reply with quote  #2

1715375129
Report to moderator
You get merit points when someone likes your post enough to give you some. And for every 2 merit points you receive, you can send 1 merit point to someone else!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715375129
Hero Member
*
Offline Offline

Posts: 1715375129

View Profile Personal Message (Offline)

Ignore
1715375129
Reply with quote  #2

1715375129
Report to moderator
1715375129
Hero Member
*
Offline Offline

Posts: 1715375129

View Profile Personal Message (Offline)

Ignore
1715375129
Reply with quote  #2

1715375129
Report to moderator
Initscri
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 759


View Profile WWW
April 04, 2014, 07:11:42 AM
 #2

[Unsafe Features]
- "Fancy" APIs


Define what you mean by "Fancy"?

I don't believe all API's are bound to be defined as Unsafe.

It depends on the company or developer developing the API and their code, what practices and what safety precautions they use.

----------------------------------
Web Developer. PM for details.
----------------------------------
Tron
Full Member
***
Offline Offline

Activity: 588
Merit: 107


View Profile
April 04, 2014, 08:15:04 AM
 #3

I would like to suggest that exchanges have the option of read-only API Keys. Or limited to viewing trades, transactions, and balances.

This would be separate from an API Key that allows trade executions and/or withdrawals. 

Lose the "fancy API". That doesn't mean any thing. Fancy is in the eye of the beholder.

I like your other standards.  Especially the 100% reserve.
Initscri
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 759


View Profile WWW
April 05, 2014, 07:51:44 AM
 #4

I would like to suggest that exchanges have the option of read-only API Keys. Or limited to viewing trades, transactions, and balances.

This would be separate from an API Key that allows trade executions and/or withdrawals. 

Lose the "fancy API". That doesn't mean any thing. Fancy is in the eye of the beholder.

I like your other standards.  Especially the 100% reserve.


The read-only API keys could be set by a action/permission based API.

The API key creator would have the ability to choose what actions each API key can perform. All, or specific actions.

----------------------------------
Web Developer. PM for details.
----------------------------------
Tommo (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
April 12, 2014, 05:29:37 PM
 #5

We'll also need some way to perform regular transparent and minimally intrusive audits.
knightcoin
Full Member
***
Offline Offline

Activity: 238
Merit: 100


Stand on the shoulders of giants


View Profile
April 12, 2014, 07:34:02 PM
 #6

I would like to see transparency about how the exchange operates from the "front office" to "back office", rulebook, documentations etc... something like

http://www.londonstockexchange.com/traders-and-brokers/rules-regulations/rules-regulations.htm


if is open source the project should give all sources and documentations too... like buttercoin


http://www.introversion.co.uk/
mit/x11 licence 18.x/16|o|3ffe ::71
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!