Hacker News new | past | comments | ask | show | jobs | submit | turboroot's comments login

It's interesting to note from page 30 of the criminal complaint, StackOverflow was able to record "Ulbricht [changing] his registration email [...] to 'frosty@frosty.com'".

Why do sites like StackOverflow keep audit logs of your account information?


Among other reasons, to stop spammers and trolls from evading their bans/restrictions.


More likely historical database backups


Actually, it's almost certainly as the other person stated - for administrative moderation purposes. There is no other purpose to maintaining historical backups of this sort of data. Especially not when that costs money.

When I built a site that existed for a very long time, was very popular, and involved monetary transactions, I had to track nearly everything. IP addresses, address changes, email changes. Everything I could think of. This was then utilized when I suspected someone of fraudulent behavior. I could pull up an administrative screen that compared data in an archive copy (where I dumped the older information for just this purpose and to specifically keep it inaccessible to the outside world for user security purposes). With that, I could see whether several users were actually the SAME user. I even tracked things like user-agent string and detected screen resolution.

A lot of pieces of data can come together to provide more than circumstantial evidence that someone is shilling, trying to feedback-bomb another user, and so on. Enough correlated points of data can confirm suspicions like this. You'd be surprised how many people use an email address for one account, change that address, then create a second account with the email address they used to have on the first account and then use the second address to drive up the value of their stuff by shill-bidding against another user on their own item.


Don't forget user support. It's not all that uncommon for someone to forget their account, lose a password, or an email address. Circumstantial evidence can support ownership of the account, and let us fix things for them.

There are also errors on our end like account merge bugs, moderation mistakes, dropped/flagged/whatever recovery emails, and so on. Keeping additional historical data can help us recover in those cases.

If you're smart about what you track it's not that much data; we record most changes to user records into a history table (likewise, and for the same reasons on post records). Keeping traffic logs around and queryable forever would be really, really expensive though. We keep some around, but only really recent stuff is easy to query (about 2 days) since that tends to be what's needed when reproducing bugs. I don't even think we have all traffic history, and old stuff would require digging a tape out (if we even move those to tape like we do with DB backups, I honestly don't know; it's never come up).

Moderation is a good reason to keep lots of data around, you're right, but it's not the only one.

Disclaimer: Stack Exchange, Inc. employee.


Because they can.

Most FX brokers do not "exchange money", that is in the sense that you can withdraw the quote currency. Because of this, they don't have to deal with money laundering.

FX brokers and MtGox also have different business models. Brokers usually make money off their spreads, slightly adjusting their quotes in their favor. Traders on MtGox trade directly with other users, not against the company. This attracts different crowds.

Fiat is also not as volatile as Bitcoin. A .35% fee on Forex would completely devastate profits. Meanwhile, Bitcoin rises and falls 10% on a good weekend.

Bitcoin exchanges would be comparable to stock exchanges like NYSE or NASDAQ, except volume is lower in the tens of magnitudes.


FX brokers like LMAX, while still targeting retail investors, make money (almost) exclusively on commissions, rather than adjusting the spreads.

Many liquidity provision strategies are also infeasible given the unreliability of the APIs available and the high fees, and in general many intraday strategies that work in other markets and would work with lower commission for bitcoins are devastated by such high fees.

As for stocks, if your volumes are decent, trading costs are negligible. With bitcoin exchanges, that does not seem to be the case...


Vagrant supports VMWare, but not Parallels yet.


Oh? I just tried to get one with the instructions on their github page, and it said the box type was vbox. Are the vmware versions kept elsewhere?


He was talking about Vagrant (the tool CoreOS uses to distribute VM images)...

Also, I think you can just make a directory in the `~/vagrant.d/boxes/coreos` folder called "vmware" and copy over the vagrant file, box.ovf and the metadata.json. Then you just edit the metadata to have a vmware provider and the box.ovf to reference "../virtualbox/<<theimage>>"

I however do not have a vagrant vmware license and cannot test this theory.


Wow. I got voted down for this? You guys are great. :/


Before CoinLab shifted gears and got sued by MtGox, what this guy got fired for was exactly CoinLab's startup: monetizing games through Bitcoin mining.

Needless to say, with Bitcoin ASICs on their way back then, this wasn't exactly a sustainable business model.


to be nitpicky, Gox was sued by CoinLab for breach of contract (handing CoinLab the US market for a comission)


Oops, I didn't see what I had typed in. Thanks for correcting me. :)


I use Private Internet Access.

You can create an account anonymously and pay in Bitcoin, and not leave a paper trail. That's exactly what I did.

Their policies state that they do not log, but I personally find this questionable. Much torrent traffic goes through their network, and I couldn't imagine how they respond to complaints sent by media companies to their US servers. They claim that they use "proprietary technology" to deal with abuse, but that seems only to be with blocking outgoing DoS attacks.

However, policies of "not logging" aren't particularly new to [many providers](http://torrentfreak.com/which-vpn-providers-really-take-anon...), so I'm not really concerned.

It may also be useful to note that they've been supportive of the Bitcoin community. They host BitcoinTalk, and were also one of the first VPNs to accept Bitcoin.


The answer is not black and white, although there are certain indicators that make an email very likely to be malicious.

In this case, record the ultimate destination of the link in an isolated browser session (to prevent a possible CSRF attack), then make your judgement from there.


This was on for a while when I was on Chrome's dev release channel. It annoyed me, so I switched to beta.


Welcome to 2013, where footers and headers make up 90% of the content. :)


You are right, we can do better. Expect a change of the public shares pages soon!


I signed up for Joyent yesterday, and was quite impressed with the performance. It's probably on par with Linode.

The price is reasonable: $21/month for a 512 MB instance, and free 20,000 GB bandwidth!

In addition, they offer freaking 2-factor authentication! That says a lot when the only ones I know of offering such are AWS and SoftLayer.


You created an account to post this on a thread about a competitor to Joyent? Funny.


Why? Is it not appropriate? I assumed I could offer hosting alternatives since my post's parent author was asking for "thoughts".

I don't work for Joyent, and I just signed up for them 2 days ago. Apologies if my post seemed like blatant advertising.


Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: