How does Coinbase/GDAX secure Bitcoin, Litecoin, Ether?
Key Takeaways
Coinbase security measures for Bitcoin, Litecoin, and Ether, including offline storage, 2-step verification, SSL/HTTPS encryption, and employee security protocols
Full Transcript
in this video we're gonna talk about GX security anytime you're gonna use a service and you're gonna give this service your funds your your hard-earned money you're gonna want to definitely look into their security policy because that's how your funds are gonna stay safe all right so we're gonna do that in this video go to GX comm which is where we are here and then scroll down to the bottom of the page to security you would click on Security Statement first thing to notice like we talked about before we're at now Quinn makes comm slash security the reason we're at coinbase is because GD x is a coin base company they tell a security for your peace of mind we take careful measures to ensure that your Bitcoin is as safe as possible it's exactly what we want go down further and they mention this on their home page 98% of customer funds are stored offline so that means these things are not touching the internet so a hacker sitting at their computer somewhere anywhere around the world they're not going to be able to access these systems because they are offline systems offline stores provides important security measures against theft or loss this is another important piece we distribute Bitcoin geographically in safe deposit boxes and vaults around the world so what do they mean we distribute Bitcoin what they mean is they distribute the private keys to customer wallets around the world geographically so that means suppose they had all of the customer wallets just sitting on one server in say California and there was a big fire that happened and all the servers were destroyed well all the customer funds would be lost and so they've taken measures here to distribute them geographically around the globe they mentioned here again that sensitive data that that's on their servers it disconnected entirely from the internet and they talk about their encryption and their redundancy so redundancy means they have multiple copies of it they talked about here USB drives and paper backups so these are going to be the thing the offline pieces and they're redundant so that means that there's not there's no one location that if that location was destroyed then those funds will be lost because they've got it there they're redundant and they're backed up and then here they are they're mentioning that these drives and paper backups are distributed geographically around the globe so that's that distributed you have multiple locations where the same information resides so let's go ahead and scroll down and take a look they mention here 2-step verification on all accounts what is 2-step verification the first step in bare is your username and password so that's one step verification now the second step is gonna be what they say here you will enter a code from your mobile phone adding an extra layer of security so that second piece that's the second step that's that code that you're gonna get in your phone they're not calling it out here but they have two different ways of offering 2-step verification they have SMS which is when you're gonna get a text message and then they also offer the use of Google Authenticator we're gonna go over how to use these in an in a future video but until we do that video if you are using the SMS you're gonna want to switch and use a Google Authenticator because it's a lot more secure hackers can actually clone your phone they can gain access to your text messages so what you're gonna want to do is use a Google Authenticator option we'll talk about that more in future videos okay let's scroll down a little bit further now this is they're telling us that they use SSL HTTPS so we look up here we got HTTPS this means that our data transmission on this website from coinbase servers to our current machine is that data transmission was encrypted so anybody sitting in the middle capturing that data they wouldn't be able to read it and that's it says our web traffic runs entirely over encrypted SSL now now they talk about their wallets and private keys are stored using aes-256 encryption this is industry standard now scrolling down more they give us more details they're giving us details about the organization application and authentication so let's take a look they gave us two pieces of information about employees they say employees got a they have to pass a background track in order to get hired and they also say employees are required to encrypt their hard drives utilize strong passwords and enable screen locking maybe an employee takes their machine home and then their machine gets stolen it might have some information on there so they're saying that all employees have to have their hard drives encrypted and they have to use a strong password this next piece is an application piece this piece gets technical they call out the fact that they use sequel injection filters and they talk about to prevent cross-site request forgery attacks they use they verify the authenticity of the post put and delete request now if you're technical and you want to read up on cross-site request forgery attacks I'm gonna leave a link to that wiki page in the description that's what this C s RF stands for so if you wanna if you don't know about that and you want to look into it more I'm gonna leave a link in the description down below regardless of if your technical or not you can understand this they say they they rate limit it variety of actions on the site so what does that mean that means you can't look you can't try to log in a huge number of times so typically if there's a hacker and they're trying to break into your account well they're gonna have so they're gonna have a program that will be able to try to log in thousands you know a times per second what's gonna happen if they try that then they're gonna get the rate limit is gonna kick in and it's gonna it's gonna slow them down make it to where it's not really feasible for them to sit there and try to brute-force your your password and then they talked about here they whitelist attributes on all models to prevent mass alignment vulnerabilities this is another thing if you're technical we'll leave a link to this down in the description this next one authentication says they hash their passwords stored in the database they check for strong passwords on account creation and application credentials are kept separate from database and code base so what's the code base the code base is the actual source code of all their applications they're saying that their passwords that kept separate that's a good practice coinbase bug bounty program we're gonna take a look at that in the next video last thing I want to mention in this video is actually another video his videos titled fraud prevention at scale and it was a talk given by Olaf Carlson we about a year ago now even though this video is a year old is still very relevant to security at coin base because in this talk about halfway through it's a 20-minute talk about 11 minutes in he starts talking about coin base and the security at coin base and how they handle all of the things that we went over gives it a lot more detail about it and I think the way he talks about in the way he explains it he does it quite well should be sure to check out this video I'm gonna leave a link in the description down below I hope this video was helpful please like the video subscribe and support those deep Blizzard channel thank you
Original Description
Is Bitcoin, Litcoin and Ether safe on Coinbase?
Let's look at the security statements.
Be sure to check out the follow up video here (Olaf Carlson-Wee):
https://youtu.be/H_6pFWN0-Jg?t=749
Links:
https://www.coinbase.com/security
https://en.wikipedia.org/wiki/Cross-site_request_forgery
https://en.wikipedia.org/wiki/Mass_assignment_vulnerability
🕒🦎 VIDEO SECTIONS 🦎🕒
00:00 Welcome to DEEPLIZARD - Go to deeplizard.com for learning resources
00:30 Help deeplizard add video timestamps - See example in the description
05:29 Collective Intelligence and the DEEPLIZARD HIVEMIND
💥🦎 DEEPLIZARD COMMUNITY RESOURCES 🦎💥
👋 Hey, we're Chris and Mandy, the creators of deeplizard!
👉 Check out the website for more learning material:
🔗 https://deeplizard.com
💻 ENROLL TO GET DOWNLOAD ACCESS TO CODE FILES
🔗 https://deeplizard.com/resources
🧠 Support collective intelligence, join the deeplizard hivemind:
🔗 https://deeplizard.com/hivemind
🧠 Use code DEEPLIZARD at checkout to receive 15% off your first Neurohacker order
👉 Use your receipt from Neurohacker to get a discount on deeplizard courses
🔗 https://neurohacker.com/shop?rfsn=6488344.d171c6
👀 CHECK OUT OUR VLOG:
🔗 https://youtube.com/deeplizardvlog
❤️🦎 Special thanks to the following polymaths of the deeplizard hivemind:
Tammy
Mano Prime
Ling Li
🚀 Boost collective intelligence by sharing this video on social media!
👀 Follow deeplizard:
Our vlog: https://youtube.com/deeplizardvlog
Facebook: https://facebook.com/deeplizard
Instagram: https://instagram.com/deeplizard
Twitter: https://twitter.com/deeplizard
Patreon: https://patreon.com/deeplizard
YouTube: https://youtube.com/deeplizard
🎓 Deep Learning with deeplizard:
Deep Learning Dictionary - https://deeplizard.com/course/ddcpailzrd
Deep Learning Fundamentals - https://deeplizard.com/course/dlcpailzrd
Learn TensorFlow - https://deeplizard.com/course/tfcpailzrd
Learn PyTorch - https://deeplizard.com/course/ptcpailzrd
Natural Language Processing - http
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from deeplizard · deeplizard · 23 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
▶
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Install Jaxx cryptocurrency wallet on Windows 10 and verify file hash
deeplizard
Jaxx cryptocurrency wallet overview - A Blockchain Interface
deeplizard
Remove Jaxx cryptocurrency wallet from Windows 10
deeplizard
Install Jaxx cryptocurrency wallet Chrome extension
deeplizard
Send Litecoin from GDAX to Jaxx wallet
deeplizard
Send Litecoin from Jaxx wallet to GDAX
deeplizard
Backup and restore Jaxx wallet with passphrase
deeplizard
Send Litecoin to Bittrex using Jaxx and monitor confirmations with BlockCypher
deeplizard
Join a mining pool on Waves platform and lease Waves
deeplizard
ZCASH Explained | An introduction to a privacy based cryptocurrency
deeplizard
ZCash t address creation with Jaxx wallet and private key blockchain discussion
deeplizard
Buy ZCash with Litecoin using the Shifty button in the Jaxx wallet
deeplizard
Buy ZCash with Litecoin using ShapeShift - FAILURE
deeplizard
Litecoin | Jaxx | Shapeshift | zcash | failed
deeplizard
Buy ZCash with Litecoin using ShapeShift - SUCCESS even with Jaxx issues
deeplizard
Explore ZCash blockchain with Zchain block explorer
deeplizard
Zchain ZCash block explorer API - PowerShell Code
deeplizard
Zchain ZCash block explorer API - Introduction
deeplizard
Zchain ZCash block explorer API - Application
deeplizard
Coinbase's Trading Platform | Previously known as GDAX
deeplizard
Coinbase Social Security Number (SSN) Requirement Explained
deeplizard
Who owns Coinbase? Here are some KEY people
deeplizard
How does Coinbase/GDAX secure Bitcoin, Litecoin, Ether?
deeplizard
Coinbase | HackerOne bug bounty program
deeplizard
Is Bitcoin safe at Coinbase/GDAX?
deeplizard
Coinbase Login Demo Using Google Authenticator (2FA)
deeplizard
Coinbase Pro - GDAX | Trading Interface Overview
deeplizard
Coinbase gives $10 in Bitcoin | Watch this before signing up
deeplizard
Coinbase around the globe | What countries are supported?
deeplizard
Order book explained | Trading concept to know
deeplizard
Bid/Ask spread explained | Trading concept to know
deeplizard
Maker vs Taker | Trading concept to know
deeplizard
Market Orders are Always TAKERS (HIGHER FEES)!
deeplizard
Buy as a MAKER (LOWER FEE) on Coinbase Pro - GDAX | Limit Order - Part 1
deeplizard
Buy as a MAKER (LOWER FEE) on Coinbase Pro - GDAX | Limit Order - Part 2
deeplizard
Time-in-force explained | Trading concept to know
deeplizard
Stop order explained | How to stop a loss | Coinbase Pro - GDAX
deeplizard
Stop Order on Coinbase Pro - GDAX | What the WARNINGS Mean
deeplizard
Market price vs Last price | Trading concept to know
deeplizard
Stop Order on Coinbase Pro - GDAX | How it is ACTIVATED
deeplizard
Stop-limit order | How to set the limit | Coinbase Pro - GDAX
deeplizard
Flash CRASH Part 1 | ETH/USD currency pair traded at $0.10
deeplizard
Slippage explained | Trading concept to know
deeplizard
Flash CRASH Part 2 | How did Coinbase Respond?
deeplizard
Buy side stop-limit order | Crypto trading strategy for buying a breakout
deeplizard
Buy side stop-limit order | Triggering under the market price
deeplizard
What is an order book?
deeplizard
What is a market?
deeplizard
What is an exchange?
deeplizard
What is a broker-dealer?
deeplizard
Keras prerequisites
deeplizard
Change Keras backend to Theano
deeplizard
#1 Order types and parameters | Trading on Coinbase Pro - GDAX
deeplizard
Trading strategy for stopping a loss | Don't trade all at once!
deeplizard
#2 Order matching engine | Trading on Coinbase Pro - GDAX
deeplizard
Batch Size in a Neural Network explained
deeplizard
Deep Learning playlist overview & Machine Learning intro
deeplizard
Artificial Neural Networks explained
deeplizard
Regularization in a Neural Network explained
deeplizard
Create confusion matrix for predictions from Keras model
deeplizard
More on: Security Basics
View skill →Related AI Lessons
⚡
⚡
⚡
⚡
Want to get started with deep learning
Reddit r/deeplearning
Building a Deepfake Detector From Scratch — What Nobody Tells You
Medium · Deep Learning
Unfolding the Meandering Path: High-Dimensional Invariance and the Flat 2D Plane of Neural…
Medium · Deep Learning
Implementing Neural Style Transfer from Scratch: The Project That Started It All
Medium · Deep Learning
Chapters (3)
Welcome to DEEPLIZARD - Go to deeplizard.com for learning resources
0:30
Help deeplizard add video timestamps - See example in the description
5:29
Collective Intelligence and the DEEPLIZARD HIVEMIND
🎓
Tutor Explanation
DeepCamp AI