Showing posts with label COINBASE’S. Show all posts
Showing posts with label COINBASE’S. Show all posts

Tuesday, August 9, 2022

What Coinbase's Partnership With ICE Says About Bitcoin Surveillance

This is a viewpoint editorial by Justin Ehrenhofer, the vice president of operations and multi-coin Cake Wallet, a Bitcoin personal privacy teacher and a mediator of the r/CryptoCurrency subreddit.

Coinbase just recently came under fire after a Freedom Of Information Act demand from Tech Inquiry exposed information of its agreement to offer U.S. Immigration and Customs Enforcement (ICE) with access to its blockchain analysis tool Coinbase Tracer

Coinbase accepted offer ICE with security information on 12 blockchains (consisting of Bitcoin's). To name a few tools, ICE accessed to Coinbase's "multi-hop analysis," "Lightning network examination," "historic geo tracking information" and "deal demixing and protected deal analysis." You can see a summary of the scope in this screenshot acquired by Tech Inquiry:

To personal privacy supporters and cryptocurrency compliance specialists, the presence of these functions is unsurprising. Chainalysis, CipherTrace, Elliptic and other blockchain analysis companies have actually offered comparable services for several years. Per the chart below, ICE has actually bought licenses from Chainalysis because 2016.

When details emerged about Coinbase’s blockchain analysis partnership with ICE, Bitcoiners were left wondering how safe their data really is.

Source: Author, utilizing USAspending.gov information.

The scale of blockchain monitoring that was as soon as shrouded from public view is now ending up being extensively understood. Chainalysis, CipherTrace, Elliptic and Coinbase all promote their compliance tool offerings.

Chainalysis deals Reactor for regulators and private investigators, KYT(" understand your deal") for automated compliance screening of addresses and deals, Kryptos for top-level vetting, Market Intel for scientists and financiers, Business Data for exchanges to track their clients' activities for organization advancement, and Crypto Incident Response for victims of ransomware and other hazards. Blockchain security information is being cost compliance, research study, financial investment and marketing functions by the very same business. And there are lots of other business that offer comparable information for other functions.

The ICE Fallout

Following a wave of unfavorable press after the information of Coinbase's agreement with ICE were launched, the exchange restated that it "does not offer exclusive client information," which "Coinbase Tracer sources its details from public sources, and does not use Coinbase user information. Ever."

I'll accept Coinbase's claims on the surface area, however even if real, it is still sharing client information with the U.S. federal government.

Coinbase is needed by law to send Suspicious Activity Reports (SARs) to the Financial Crimes Enforcement Network (FinCEN) if it thinks particular activities are suspicious. These reports can consist of client details such as names, physical addresses and even cryptocurrency deal and address information, if relevant.

BitAML, a compliance speaking with business concentrated on anti-money laundering (AML) policy, has a guide for sending cryptocurrency-related SARs on its site, which you can utilize to get a feel for the info that bitcoin exchanges typically send. SARs can be applied for all sorts of things, consisting of scenarios where a consumer declines to abide by info demands.

Banks submit Currency Transaction Reports (CTRs) for all day-to-day money deposits or withdrawals over $10,000 CTRs are not presently needed for cryptocurrency transfers (e.g., withdrawals of $20,000 in BTC from an exchange platform), however FinCEN has actually promoted these in the past It's most likely that CTRs will be needed for cryptocurrencies (as they permit users to hold their personal secrets and their capability to invest the coins, hence making them bearer instruments, like money) in the future. I can't promote Coinbase or whether it has actually sent any CTRs, however Coinbase or other bitcoin exchanges might have currently sent your details to FinCEN if you have actually transferred or withdrawn more than $10,000 in BTC by means of their platforms in a single day.

If Coinbase's blockchain tracking or compliance tools show that some bitcoin deal on its platform is suspicious, it's affordable to anticipate that the exchange has actually sent a SAR. ICE can quickly utilize the blockchain analysis tool to discover suspects of what it considers "monetary criminal offenses," and after that inspect to see if Coinbase or other exchanges have actually sent SARs on those users.

Coinbase might not straight share client information with ICE, however they share consumer information where needed with FinCEN, which can share it with ICE. It stands to factor that ICE is extremely much utilizing the Coinbase tracing tool to assist track and find out the identity of specific Coinbase consumers.

You will not get a notification that your details is shared in a SAR. SARs are clearly needed to be secret Exchanges and banks are restricted from alerting you. Depressingly, as compulsory filings, none of this mass information collection needs a warrant.

Your 'Proprietary' Data Is Public

People must comprehend that the only really "exclusive" details to Coinbase is the info you share straight with it. When you deposit and withdraw cryptocurrencies, you produce public records that are typically trivially traced. If you withdraw bitcoin from Coinbase to your noncustodial wallet, Coinbase's tool will likely reveal that deal leaving Coinbase.

IP address security is a big market by itself. Bitcoin nodes are eventually public servers. When you send out bitcoin, the deal requires to make its method into a public database. Business run Bitcoin nodes to gather the very first IP address they can discover connected with a deal Oftentimes, this provides these business an excellent concept of your rough geographical area and often even your house IP address.

That's right: your house IP address, your wallet addresses and every deal you ever make can be public details that is examined, packaged perfectly and offered as tools to police. Per USAspending.gov, ICE alone has actually gotten access to these by providing agreements presently valued at $6 million. The FBI and IRS have actually provided agreements to 4 analysis business for $135 million and $17 million, respectively. The FBI agreements have a possible overall worth of over $40 million. Throughout all of these firms and others, the expense to taxpayers might be as high as $79 million.

Anger Against Coinbase Isn't The Solution

You might be mad with Coinbase at this moment. Do not be.

Well, a minimum of do not simply be upset at it. Chainalysis has actually made a lot more cash from ICE and other companies throughout the years that Coinbase has, and if Coinbase didn't offer ICE this tool, ICE might construct it itself.

So you ought to actually be mad at blockchains that allow the mass security of all this deal details, and be mad at the warrantless mass security managed with SARs and CTRs.

So, what do we do from here? It takes 3 things to make it possible for much better Bitcoin personal privacy:

  1. Set the record directly about the effectiveness of these tools. They make it possible for mass monitoring on almost whatever you finish with your bitcoin. Stop eluding and accept that a personal privacy issue exists for the 12 noted blockchains (consisting of Bitcoin's and Ethereum's), along with almost all others.
  2. Incorporate significant and considerable modifications to break these tools. Conceal the IP addresses being utilized to relay deals much better with tools like Dandelion++. Conceal the quantities, addresses and deal charts. Bitcoin requires much better default personal privacy defenses to prevent this mass security. It's practically difficult to eliminate these tools entirely, however we can meaningfully lower their security scope by following Monero's steps, for example, of making it possible for sane personal privacy defaults throughout the board, not simply for users of a specific niche tool.
  3. Stop utilizing controlled entities that require to report SARs and CTRs. Utilizing a noncustodial wallet to send out more than $10,000 in bitcoin might avoid your info from being shared immediately.

Why Does This Matter?

Bitcoin supporters have actually promoted the effectiveness of BTC for remittances to El Salvador and other nations. Bitcoin is definitely beneficial in a number of these scenarios. Lots of migrant employees are going to be frightened off by Bitcoin's openness and the millions of dollars being put into tracing Bitcoin deals every year. It's more difficult for ICE to target private users of the conventional, central remittance system than it is for ICE to observe every bitcoin payment to discover lots of going to El Salvador exchanges, IP addresses and services.

Migrant employees frequently get away hazardous circumstances back house. No matter your political views on migration, one ought to comprehend how somebody in this scenario would take terrific care in securing their personal privacy for worry of being deported.

Sadly, Bitcoin does not safeguard the personal privacy of the huge bulk of its users effectively. Expect El Salvador was to take the severe (though extremely not likely) action of needing remittances in itcoin. Would this be a net favorable, breaking individuals far from centralized and managed organizations that benefit greatly off of the world's bad? Or would this be a net unfavorable, given that one, many people will utilize regulated platforms to purchase and offer bitcoin with charges anyways, and 2, the large bulk of individuals will be surveilled by opponent stars (from the point of view of prohibited immigrants) on the transparent blockchain?

The response isn't simple; there are positives and negatives, and Bitcoin will be the favored alternative for some individuals. Still, I hope that loud voices in the Bitcoin neighborhood comprehend the obstacles and threats connected with ICE seeing every deal, which they loudly promote for much better default personal privacy securities on Bitcoin to safeguard the users they state Bitcoin was produced.

This is a visitor post by Justin Ehrenhofer. Viewpoints revealed are completely their own and do not always show those of BTC Inc or Bitcoin Magazine.


Read More https://bitcofun.com/what-coinbases-partnership-with-ice-says-about-bitcoin-surveillance/?feed_id=32027&_unique_id=62f23c5141cef

Tuesday, February 8, 2022

Coinbase’s Philosophy on Account Removal and Content Moderation

Coinbase

By Brian Armstrong

In the last few years, it’s become increasingly common for tech companies to censor customers or close their accounts for a range of reasons (e.g., misinformation). Luckily, as a crypto business we don’t face this issue as frequently as a social network does, but we still need to set clear policies around acceptable use of our products. As our product suite grows, it will even include products that host user generated content like NFTs.

Our high level philosophy is that, in a democratic society, the people and their elected officials should decide what behavior is allowed and not allowed by setting laws. We think it sets a dangerous precedent when tech companies, such as Coinbase, or their executives start making judgment calls on difficult societal issues, acting as judge and jury. This approach sounds simple in theory, but in practice it is anything but.

First, it can be very complex to determine whether an activity is legal or illegal. Laws vary greatly across different countries, states, and regions. Some activities are legal only if you have a license. Some activity is in a gray area. Some unjust laws go unenforced. Like most companies, we refer suspected illegal activity to the relevant authorities, but we can’t expect to receive a timely response or opinion back from them given the many demands on their resources. Unfortunately, this puts us, along with most companies, in the unfortunate position of having to make our own determinations about what activity is legal or illegal.

Second, even if some activity is legal, it may be something that is deeply troubling to have on the platform. The world is littered with polarizing, uncomfortable, or obscene content that may still be legal. This is where companies start to exercise even more judgment on what they allow. But there is great danger of falling down a slippery slope, having to render decisions on every difficult societal issue, where you are sure to upset someone no matter where you land. Without some strong principled based approach, these decisions become arbitrary and capricious, opening the company to attack.

Finally, every company works with other companies that have their own set of moderation and deplatforming policies. For instance, for any app to be listed in the Apple and Google App Stores, it needs to play by the rules of those two companies. In the financial services world, we also work with banks and payment processors who have their own acceptable use policies. Very few companies are completely vertically integrated, with the luxury of making their own decisions in a vacuum.

So how should a company implement a reasonable approach based on the above constraints? We’ve come up with our own answer, and I want to share it here so our customers can understand it, and in case it helps other companies.

First, it’s important to differentiate our approach based on the type of product. Coinbase has a broad product suite, but for moderation purposes we group our products as either infrastructure products or public-facing products when thinking about how to moderate them. Infrastructure products enable access to basic financial services and are typically used privately by a single customer, while public-facing products often host user generated content and have social features visible to large numbers of users. Ben Thompson’s article on moderation in infrastructure illustrates how companies typically take a different approach for each of these products.

For our infrastructure products, we use rule of law as the foundation of our approach, because we believe that governments, not companies, should be deciding what is allowed in society. We also believe that everyone deserves access to financial services, and a test of legality should be sufficient for these products.

For our public-facing products, we again start with rule of law as the foundation. But assuming something is legal in a certain jurisdiction, we also go beyond this and moderate content that is not protected speech under the First Amendment. We’re not legally held to the First Amendment as a company, and the First Amendment is a U.S. focused concept only, but we’ve chosen to use it as the guiding principle of our content moderation approach because it is in line with our values and helps ensure we don’t fall down a slippery slope over time. The First Amendment has hundreds of years of case law built up, and provides a reasonable framework to moderate content such as incitement, fighting words, libel, fraud, defamation etc. David Sacks does a great job describing this approach in this blog post.

Finally, there are cases where we want to work with external partners, such as the App Stores, and need to follow their moderation policies to do so. Sometimes third party payment providers have their own policies. For payment providers, we can simply disable functionality related to that partner if there is a problem with a specific user, while continuing to offer Coinbase services. But getting kicked out of the app stores wouldn’t help anyone. So when working with partners, our approach is to be free speech supporters, but not free speech martyrs, and to make accommodations if it is essential for us to function as a business.

This is obviously a complex issue, and hopefully the above approach starts to show a path through it that doesn’t devolve into arbitrary and capricious decision making. To boil down the above approach, we ask the following questions for our public-facing products:

1. Is the content illegal in a jurisdiction in which we operate?

A. If yes, then remove in that specific jurisdiction

2. Is the content a free speech exception under the First Amendment?

A. If yes, then remove globally

3. Has a critical partner required us to remove the content?

A. If yes, then remove the content or disable the functionality of that partner for the affected user

If the answer to any of these 3 questions is “Yes” we will take some moderation action, such as taking down content and in severe cases terminating the account.

Most of this post has been about how we can create a reasonable moderation policy that doesn’t get co-opted over time, succumb to pressure, or descend into us playing judge and jury. This is important so that Coinbase is able to stand up to pressure. Of course, the decentralized nature of cryptocurrency offers its own important protections here, and those protections get stronger the more our products decentralize.

If our policy above fails, and Coinbase starts making bad judgment calls or turns evil, customers can withdraw their crypto to any other competing exchange, wallet, or custodian. Compare this to social networks today, where you can’t take your followers with you. Your data is owned by one company, in a proprietary format. The open nature of crypto protocols provides lower switching costs, which is an important customer protection, even for relatively centralized crypto products. But decentralized, or self-custodial, crypto products have an even greater protection because the company is simply providing access to something running on-chain. For instance, no one can deplatform your ENS name without taking every ENS name offline. Decentralization moves you from the slippery slope to the crypto cliff, where the would-be censor must compromise an entire blockchain to censor just one person.

Decentralization is a spectrum, and Coinbase is moving farther down this path over time, embracing self-custody with Coinbase Wallet, stepping up user education around private keys, and by investing in Bitcoin core development and web3 protocols. The more decentralization we can support, the better protection customers will have.

We believe everyone deserves access to financial services, and that companies should put appropriate controls in place to prevent censorship or unjust account closures from taking place. For centralized financial infrastructure products, we believe rule of law is a sufficient standard for moderation, while for decentralized products even greater protections can be provided by the blockchain. We also acknowledge that public-facing products deserve some additional consideration, and that the First Amendment can be used as a reasonable test or boundary. We believe this approach is consistent with our mission of creating more economic freedom in the world and with the ethos of crypto.

Companies are in a difficult position when they choose to censor or terminate a customer account. What often seems like an easy decision, especially under public pressure, turns out to have larger unintended consequences and sets a dangerous precedent for the role of private companies in society. I’m sure we won’t get it perfect with our policy above, but my hope is that we’ve laid out some principles we can fall back on when difficult decisions arise, and that investors, customers, and employees can have a better understanding of our process.

Further Reading


Read More https://bitcofun.com/coinbases-philosophy-on-account-removal-and-content-moderation/?feed_id=5609&_unique_id=6202afebefe86

Leading 7 Decentralized Derivatives Trading Platforms

Decentralized derivatives are a brand-new method for traders to trade crypto possessions without straight holding them. Read on to disc...