FTX 崩潰如何讓 Blockfolio 用戶暴露在風險之中

By Bitcoin 雜誌 - 1 年前 - 閱讀時間:7 分鐘

FTX 崩潰如何讓 Blockfolio 用戶暴露在風險之中

The data necessary to analyze previous Blockfolio entries is now mixed up into the massive cryptocurrency exchange’s collapse.

This is an opinion editorial by Morgan Rockwell, founder of Bitcoin Kinetics.

I'm not concerned with Sam Bankman-Fried allegedly 獲得貸款 from Alameda, which was actually FTX customer funds wired through Alameda to be credited on FTX. I'm not concerned with the moral compass of the 名人 investors who gave billions to a kid they didn't really know or understand, yet endorsed with wealth and credibility. I'm not very concerned with the financial and 市場效應 許多公司、交易所和交易員出於某種原因以任何形式依賴 FTX。

I'm most concerned with Sam Bankman-Fried getting the personal identification information of millions of customers, and using that data to do chain analysis on the Blockfolio app he purchased which was used by many Bitcoiners and cryptocurrency holders as a tracking tool of Bitcoin, Ethereum and other watch-only cryptocurrency wallets.

資料來源:Google圖片

If you aren't aware, Blockfolio was an app that was used by many Bitcoin holders and other cryptocurrency holders to keep track of the exchange rate or the prices of their coins held in cold storage or on wallets that they only wanted to be watching and not have actively on a hot wallet on their mobile device. Storing the wallet addresses actually were not even needed on the app. You could just put in a amount of a certain cryptocurrency that you wanted to watch and say that you had — but there was also a feature to connect to exchanges to keep track of all of your coins across all of the exchanges you had them on in one app. This was the beauty of Blockfolio as it didn't necessarily ask for too much personal identification information other than an email to help keep track of your account so you can log in from multiple devices.

我們中的大多數人都像我一樣開始意識到 Sam Bankman-Fried,因為 購買的 Blockfolio 由一個名為 FTX 的新成立實體創建。 幾週後,Blockfolio 應用程序更名為 FTX 應用程序,現在有了自己的交易所。 我們假設,它還有一套新的“了解你的客戶”規則、反洗錢政策、新的服務條款,以及由 FTX 持有的自己的託管錢包。

您可以在此處查看 30 年 2017 月 XNUMX 日起 Blockfolio 的服務條款:

資源: Blockfolio 隱私政策 2017

Blockfolio 熱切地爭辯說他們沒有也永遠不會出售用戶數據。 Blockfolio 甚至嘗試使用 ID 散列機制對用戶進行去標識化,甚至不讓自己識別並將用戶組合連接到電子郵件地址; 這顯然在購買並轉換為 FTX 後從未發生過。

在這裡您可以看到新的 FTX 隱私政策的顯著差異:

資源: FTX 隱私政策 2022

FTX 服務條款中很少提及個人身份信息,這是與隱私政策不同的文件。

資源: FTX 服務條款 2022

作為參考,如果您以前從未閱讀過公司的服務條款或隱私政策,我強烈建議您喝杯烈性啤酒,享受這個詞湯!

This all has brought up questions around this merger and the acquisition that happened in the cryptocurrency industry only a few years ago. I am concerned because after the fallout of this exchange, FTX going bankrupt and all of its assets potentially being put up for auction, I would like to know the state of the personal identification information that FTX had been forced to gather because of KYC and AML laws. My concern is the vast amount of information gathered including passports, phone numbers, IP addresses, home addresses, cryptocurrency wallet addresses, email addresses, passwords and government IDs. All of these could be sold at auction as customer data or customer profiles to whoever finds them valuable.

資料來源:FTX 隱私政策(合併、出售或其他資產轉讓時的披露)

Now the assets held by FTX whether they were actually real cryptocurrency such as bitcoin or made up tokens built on another layer one network such as ethereum are not too important in this conversation in my opinion. What is important is the data, the privacy data, the data mining operation that could have or will be done on all of this data FTX had gathered on customers either it was done by them or it will be done by whomever buys this data at auction. Even more so, the jurisdiction of that data is open to anywhere on earth.

資料來源:FTX 隱私政策(國際數據傳輸)

As someone who has personally worked on coin analysis concepts and technology for the United States Military, as well as consulted on this for the Department of Defense as a so called "subject matter expert," I can personally attest that it is very easy to correlate a person to their Bitcoin wallet address using nothing more than the amounts of bitcoin held on specific addresses, as well as the device data that is keeping track of those specific amounts on specific addresses — this is simple SIGINT, MASINT or HUMINT, all of which are different forms of intelligence gathering.

資源: 維基百科搜索 HUMINT

If you are keeping track of any bitcoin on any wallet over any Bitcoin explorer that is looked through a browser or app on any device, phone, laptop or tablet, there is now a record that will be connected to the IP address, the MAC number, the SIM phone number, the VOIP number, credit card number, home address and any other personal identifying information that is attached in any way to this device. I know this because Edward Snowden leaked documents showing that the NSA had a program called XKEYSCORE 和應用程序被使用像 橡星 及其子程序 猴子火箭 to specifically keep track of Bitcoin users at the NSA.

Source: https://theintercept.com/2018/03/20/the-nsa-worked-to-track-down-bitcoin-users-snowden-documents-reveal/

Now what I'm getting at is this data that FTX was forced under AML and KYC law to be gathered. This is potentially one of the largest gatherings of this type of data in the cryptocurrency industry ever done in history. This data, combined with coin analysis information related to bitcoin, ethereum and other cryptocurrency amounts being tracked by the previously titled Blockfolio app has created a situation where KYC data personal identifying information can be now superimposed over Blockfolio email addresses, UTXOs and watch addresses that plenty of people used on Blockfolio without any personal information being divulged to the app.

So this means that people that used Blockfolio to keep track of the amount of cryptocurrency they had, wanted to buy or were keeping track of for whatever reason will now be able to be correlated to very detailed personal identification information. The concern I have is not whether FTX and its hundreds of subsidiaries were keeping track of this information from Blockfolio or using it in any way, but that their vast new pool of customer information and data will be binded in the future to the Blockfolio data. I don't assume FTX was intelligent enough to do this for any purpose such as advertising, or data sharing with a hedge fund like 羅賓漢 被抓到了,但我確實認為他們可能考慮過將這些數據出售給執法機構、廣告商或情報界的參與者,因為 SBF 表示 FTX 對監管機構和執法機構敞開大門。

我們現在需要考慮的是,當 FTX 的資產進行拍賣時,他們將會拍賣,不僅數字貨幣和代幣以及許可證將被出售給某個新的一方,而且將是客戶本身、個人身份信息以及本可以或將要對這些數據進行的海量數據挖掘。

I was never an FTX user, I never created an account with FTX or FTX.us and I never wired any money to Alameda. Unfortunately, because of my longevity in the Bitcoin space, I used Blockfolio like many Bitcoin users before me to keep track of the amounts of Bitcoin I had in multiple locations and their total value. Now that data that I thought was private will be connected to KYC data of anyone I know, interacted with over a wire and any device they used, especially if through multiple connections it leads back to FTX in any way.

What we need to do now is ask the serious questions and not focus on the financial obligations or mishandlings of SBF and FTX. But we must ask who has this data? What has been done with this data and who will be owning this data in the future? The reality is FTT dissolving into nothing isn't a "Force Majeure Event," so most of the users are screwed.

資料來源:FTX 2022 年服務條款

If this at all concerns you or involves you, I would suggest we all find the proper channels to protect ourselves from the worst case scenario from this fallout of data. This is the biggest problem with KYC and AML laws,because after all of this financial chaos, there is now a criminal-run exchange that is in possession of millions of people's personal information about their devices, their homes, their financials and more, all available to the highest bidder.

筆記:

Blockfolio TOS 和隱私政策轉到 FTX.com 網站上的死鏈接,但我找到了 2017 版。
您必須通過 Zendesk 登錄才能查看丟失的 Blockfolio TOS/PP 以及新的 FTX TOS/PP,這意味著我必須提供電子郵件和 PPI 才能查看文檔.

This is a guest post by Morgan Rockwell. Opinions expressed are entirely their own and do not necessarily reflect those of BTC Inc or Bitcoin 雜誌。

原始來源: Bitcoin 雜誌