Post
Topic
Board Service Announcements
Re: [Payout Updates] Bitcoinica site is taken offline for security investigation
by
realnowhereman
on 19/06/2012, 11:20:16 UTC
I'm on my third "shouting into the void" email to them now.

All I'm trying to establish at the moment is a method of secure communication.  I get nothing back.

There aren't enough hours in the day to give a meaningful response to the emails sent to verify@bitcoinica.com

How many fewer emails would you get if you communicated more though?

I'm on my third attempt, and I am probably not the noisiest customer you have.
  • Post a GPG key for verify@bitcoinica.com
  • Reply to emails with an encrypted secret URL that sets a flag in your claim database
  • Ta-da.  Secure bi-directional communication established.
  • The above could be automated... "hours in the day" becomes irrelevant

Your claim page solicits additional supporting information on verify@bitcoinica.com and yet you provide no method to let us do that securely.  You've just experienced what happens when email gets subverted... you don't seriously expect anyone with any security consciousness to email you copies of their passports, bank account information, or in fact any personal information at all?

Again: GPG KEY.  GPG KEY.  GPG KEY.  Then push reply, write "received" and push send.