top | item 19067751

(no title)

tonysdg | 7 years ago

Never attribute to malice that which can be explained by incompetence. A small-ish exchange, run by a small number of developer-employees, with limited computing assets. I can easily see someone making the argument that moving cold wallets to an encrypted, offline company machine would (1) free up resources that could be used elsewhere and (2) would make a less obvious target for hackers. Follow that up with no backups -- because let's face it, most individuals and probably a lot of small businesses have no backups -- and voila: you get a bus factor of 1.

discuss

order

jobigoud|7 years ago

Backing up sensitive stuff is an art in itself. You have to make sure the data is not accessible by the wrong person, but also that the key or password to access to the backup is itself backed up or distributed.