Showing posts with label It’s. Show all posts
Showing posts with label It’s. Show all posts

Thursday, March 13, 2014

, , , , , ,

Overstock’s Bitcoin Purchases Account For Less Than 1% Of Revenue, But It’s Growing

Since Overstock.com started to accept Bitcoin as a purchase currency, the company has received a good press for its efforts to support the nascent cryptocurrency. Working with Coinbase to process Bitcoin, Overstock.com announced that it crossed the million-dollar sale mark in the currency earlier this month.

A report out this morning better details how Overstock.com is faring with Bitcoin now that the novelty of its acceptance of the digital payment method has cooled. After the day one sales number, according to Overstock.com CEO Patrick Byrne, Bitcoin has settled in the “$20k to $30k” range, and is “gradually increasing from there.”

Let’s use the $30,000 sum, given that the company is seeing a ramp in the numbers, and if we are going to predict revenue we might as well give ourselves some room to wiggle. Let’s find out if Bitcoin is moving the needle for the company.

For calendar 2013, Overstock.com had revenue of $1.304 billion. Given that the company’s revenue is quite seasonal, we don’t want to use a fourth-quarter number to compare current Bitcoin sales run rates. So let’s take the quarterly average for the company as a starting point. That gives us a 90-day figure of $326 million, or $3.6 million per day.

$30,000 next to $3.6 million is a very small drop in the bucket. In fact, it works out to 0.83 percent. After the Sturm und Drang of the Bitcoin integration, the dollar amount is somewhat minor.

Now, its early days for both Bitcoin itself and even Overstock.com’s integration thereof, so don’t take the above as indicative of failure. More that the network for Bitcoin purchases remains modest, despite Bitcoin itself having a very high market cap.

I’ve been looking at Bitcoin volume for some time. Food for thought: Total Bitcoin in circulation is worth $7.9 billion. In the past 24 hours, Bitcoin had volume of only $18.5 million. That’s about 0.23 percent daily turnover. Picking a random stock, say, Groupon, we see that its volume as a percentage of its similar market cap is 3.7 percent daily. That’s about 16 times as much as Bitcoin sees. I think this is the impact of having around half of all Bitcoin owned by fewer than 1,000 people.

That wealth concentration means that the number of people who have enough Bitcoin to purchase items at Overstock.com is smaller than you might expect. That said, the larger Bitcoin network — so far as I can tell — is growing daily. So, expect to see Overstock.com move six figures a day in Bitcoin sales by the holiday season.

IMAGE BY FLICKR USER MARCEL GRIEDER UNDER CC BY 2.0 LICENSE (IMAGE HAS BEEN CROPPED) 



View the Original article

Saturday, January 4, 2014

, , , , , ,

Snapchat Says It’s Improving Its App, Service To Prevent Future User Data Leaks

Snapchat has released an official post about the recent leak of 4.6M usernames and phone numbers from its servers. The post blames what it says was ‘abuse’ of its API on the leak, but acknowledges that the way that it stores the information made it possible for a database of numbers to be used to sniff out usernames and match them up.

Changes will be made to both Snapchat’s apps and the service in order to prevent future leaks including being able to opt out of the Find Friends feature that uses phone numbers.

Snapchat says that it was notified of the possible security risk (publicly) in August and took some steps to correct it including limiting the speed at which its API could be queried. In what is one of the most cringe-worthy security moves in recent memory, Snapchat posted a response late last month to claims of risk that outlined just how a hacker might be able to match usernames to phone numbers.

In the post, they said “Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way.”

That is exactly what the group behind the leaked SnapchatDB.info database says that they did. The result was a trove of 4.6M Snapchat accounts matched up with usernames and phone numbers.

Despite partially redacted phone numbers and usernames, matched conveniently in an online repository, Snapchat says that “no other information, including Snaps, was leaked or accessed in these attacks.”

Notably, Snapchat’s public response to this hacking does not include an apology of any sort to its users who have had their user names or phone numbers publicly exposed. Perhaps its an effort to avoid an admission of guilt, but it still feels like a bad effort.

The person(s) responsible for releasing the names and numbers told Techcrunch that “raise the public awareness around the issue, and also put public pressure on Snapchat to get this exploit fixed. It is understandable that tech startups have limited resources but security and privacy should not be a secondary goal. Security matters as much as user experience does.”

The group says that they were following the research of Gibson Security, who gave a detailed account of how such an exploit could be accomplished to ZDNet in late December. The researches came forward after they say that they approached Snapchat and got no response from them on the matter. Snapchat’s statement today appears to confirm that its reverse engineered API was used to obtain the user info.

As our own Josh Constine mentioned about this issue late last month, Snapchat’s first mistake was to not take the efforts of ‘white hat’ hackers seriously. If Gibson Security did indeed approach Snapchat far in advance of going public, their revelations should have been taken seriously and acted on with vigor.

Snapchat’s first blog post on the issue in December acknowledged the potential vulnerability publicly and noted that some countermeasures had been put into place. But, in the same breath, it noted that there was still a method that could be used to accomplish this kind of leak. Yet it didn’t fix it.

Now, Snapchat says that it will add an opt-out to its apps which will allow people to choose not to appear in the Find Friends feature after they’ve used their phone number for verification purposes. It says it is also ‘improving’ the rate limiting it used to throttle API requests previously and adding ‘other restrictions’ to address future attempts to abuse the service.

Here’s the full post from Snapchat:

When we first built Snapchat, we had a difficult time finding other friends that were using the service. We wanted a way to find friends in our address book that were also using Snapchat – so we created Find Friends. Find Friends is an optional service that asks Snapchatters to enter their phone number so that their friends can find their username. This means that if you enter your phone number into Find Friends, someone who has your phone number in his or her address book can find your username.

A security group first published a report about potential Find Friends abuse in August 2013. Shortly thereafter, we implemented practices like rate limiting aimed at addressing these concerns. On Christmas Eve, that same group publicly documented our API, making it easier for individuals to abuse our service and violate our Terms of Use.

We acknowledged in a blog post last Friday that it was possible for an attacker to use the functionality of Find Friends to upload a large number of random phone numbers and match them with Snapchat usernames. On New Years Eve, an attacker released a database of partially redacted phone numbers and usernames. No other information, including Snaps, was leaked or accessed in these attacks.

We will be releasing an updated version of the Snapchat application that will allow Snapchatters to opt out of appearing in Find Friends after they have verified their phone number. We’re also improving rate limiting and other restrictions to address future attempts to abuse our service.

We want to make sure that security experts can get ahold of us when they discover new ways to abuse our service so that we can respond quickly to address those concerns. The best way to let us know about security vulnerabilities is by emailing us: security

View the Original article

Sunday, December 29, 2013

, , , , , , , ,

Snapchat Downplays Phone Number Matching Hack, Says It’s Added New Counter-Measures

Following security researchers publishing a way to match Snapchat usernames to phone numbers, Snapchat has published a skimpy statement making the hack sound impractical and noting “We recently added additional counter-measures and continue to make improvements to combat spam and abuse.”

Earlier this week ZDNet published an in-depth write-up of how white-hat Gibson Security researchers had tried to notify Snapchat of a way hackers could connect usernames to phone numbers for use in stalking, but were ignored. The GibSec team then published the exploit publicly on Christmas Eve. Read ZDNet’s post for full details on how the hack works.

Snapchat hadn’t provided a public statement until now, and what it’s offered isn’t very satisfying. “Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way. Over the past year we’ve implemented various safeguards to make it more difficult to do.” It goes on to note it’s added more barriers to the use of this hack.



View the Original article

Monday, December 23, 2013

, ,

It’s A Wonderful Life, For A Few Of Us

So where were we? Oh yes: everybody hates us. San Francisco’s recent Google-bus and “homeless trash” kerfuffles are symptoms of an increasingly broad, deep, and bitter anti-tech animosity. The Economist predicts: “The tech elite will join bankers and oilmen in public demonology.” The New York Times concurs: “Tech workers have, rightly or wrongly, received the blame. Resentment simmers.”

Such ingratitude! What’s wrong with these warped, blinded haters?

…Well, OK, it might be the very real sense that these days, with software eating the world, if you’re not in tech, or you’re not already rich, then you are probably basically screwed for life. “We are in the midst of the worst rental affordability crisis that this country has known.” Unemployment remains high, and many unemployed “may simply give up looking for jobs once their benefits lapse.”

Meanwhile, US income inequality today is the highest that it’s been since 1928 — which matters especially because “the decline in middle-class incomes owes as much to rising inequality as it does to the depressed state of the economy.” The NYT recently highlighted a Brooklyn neighborhood where

the top 5 percent of residents earn 76 times as much as the bottom quintile … addicts gather outside a food pantry a block from $2 million brownstones

The economic doldrums have hit Europe, too, outside of Germany. Don’t even get me started on Spain or France: and as for the UK, well, the BBC recently reported that, for the first time, “More working households were living in poverty in the UK last year than non-working ones … low pay and part-time work has prompted an unprecedented fall in living standards.”

So just go get a good education! Right? Sorry, no. Even if you have a Ph.D.:

The academic job market is structured in many respects like a drug gang, with an expanding mass of outsiders and a shrinking core of insiders. … Academia is only a somewhat extreme example of this trend, but it affects labour markets virtually everywhere. One of the hot topics in labour market research at the moment is what we call “dualisation.” Dualisation is the strengthening of this divide between insiders in secure, stable employment and outsiders in fixed-term, precarious employment.

Hell, even law school is a disaster nowadays. And total American student-loan debt exceeded $1.2 trillion this year. At that price, for many people, paying for higher education is almost like dumping your life savings into a lottery, or a casino; great if it works out…but absolutely crippling if it doesn’t.

So everyone can move to the tech sector! Again, sorry, no — or at best, not any time soon. You cannot reasonably expect to retrain significant numbers of people into skilled engineers, and there’s little-to-no room for the unskilled. (Unlike most fields, bad software engineers actually add negative value to the projects they work on.) Engineering is hard. Most people aren’t any good at it.

So people who aren’t rich, and aren’t in tech — the vast majority, I hasten to remind you — will increasingly become part of the precariat:

This is not just a matter of having insecure employment, of being in jobs of limited duration and with minimal labour protection, although all this is widespread. It is being in a status that offers no sense of career, no sense of secure occupational identity and few, if any, entitlements to the state and enterprise benefits that several generations … had come to expect as their due.

Meanwhile, the rich, as a class, are behaving with their usual elegance, taste, and restraint. Finding new ways to evict tenants so they can charge higher rents. Reshaping corporations into what The Economist calls “distorporations.” “Ruining art for the rest of us.” And it’s hard to wander amid San Francisco’s new-growth luxury boutiques, artisanal coffee shops, and opulent social events without getting the sense that techies, too, are making decadent hay of today’s inequalities. I mused the other day on Twitter:

Sometimes I feel like we in SF/LA/NYC live in the modern-day Belle Epoque. Which is, to be clear, a backhanded compliment at best.—
Jon Evans (

View the Original article