Difference between revisions of "Secure Trading"

From Bitcoin Wiki
Jump to: navigation, search
m (All:)
(Best Practices with trading: Grammar/spelling typos)
Line 45: Line 45:
 
==Best Practices with trading==
 
==Best Practices with trading==
 
===Use Bitcoin-OTC===
 
===Use Bitcoin-OTC===
* Always require the user to become registered with #bitcoin-otc
+
* Always require the user to become registered with #bitcoin-otc.
 
* Require a signed message from the fingerprint quoted at: http://bitcoin-otc.com/viewgpg.php
 
* Require a signed message from the fingerprint quoted at: http://bitcoin-otc.com/viewgpg.php
  
 
===Make sure both parties agree to the terms of the trade with signed messages.===
 
===Make sure both parties agree to the terms of the trade with signed messages.===
 
* Get a PGP signed quote, and check the signature.
 
* Get a PGP signed quote, and check the signature.
* Send a PGP signed recept.
+
* Send a PGP signed receipt.
This allows either party to go public if the trade has become sour.  Stopping your trading partner from claiming the details of the agreement were somehow different.<br />
+
This allows either party to go public if the trade has become sour and stops your trading partner from claiming the details of the agreement were somehow different.<br />
  
Search the Bitcoin Forum for the username of the person that you are trading with, check if the user has provided constructive and usefully advice to other parties.  And importantly check for any claims that the user has scammed.
+
Search the Bitcoin Forum for the username of the person that you are trading with. Check if the user has provided constructive and useful advice to other parties.  And, most importantly, check for any claims that the user has scammed.
  
 
===Use an escrow===
 
===Use an escrow===

Revision as of 04:58, 4 April 2011

Secure Trading Online

This topic is a guide in how to set up your online identity and best practices for trading with others in the Bitcoin community.

Introduction

Within the Bitcoin community, many are very careful with their security and identity. This is because of two main reasons:

  1. There is no violent body to cover your back for you. Or more simply there is no courts to seek assistance from if your transaction sours.
  2. One’s reputation is the most important thing that any user has; traders will take very little risk with new users who have not proven themselves. (as they could just be last week’s scammer with a new identity)

The bitcoin community uses a few tools to help protect their privacy, and thus identity. The first and most important is a Secure Computer.

Before proceeding please make sure you have completed the Securing Your Computer guide, this guide assumes that your computer is secure both physically and in software.

Creating a secure Identity

The first step is to create a cryptographically secure public-private key-pair. This will be used as the basis of keeping both your wallet secure (see Securing your wallet), and your identity secure.

Creating your first PGP key-pair

A PGP key-pair does two very important functions.

  1. Sign information with an unforgeable signature
  2. Decrypt things that other people encrypt for you

This allows you to both conduct business privately (encryption), and give out promises that you cannot deny making (signature).

Microsoft Windows:

This contains all the key management and generation tools for Microsoft Windows.

All:

  1. Install Thunderbird: https://www.mozillamessaging.com/en-GB/
  2. Setup your email account with Thunderbird.
  3. Install the Enigmail plugin for Thunderbird: https://addons.mozilla.org/en-US/thunderbird/addon/enigmail/

Upon loading Enigmail, Thunderbird will ask you to make a new ‘identity,’ follow this wizard and you will have created your identity.
You should backup your private key in a secure place. Secondary, you should create a revocation certificate and store that in a different secure place (maybe print it out and store it in your fire safe).

Register with [#bitcoin-otc]

Follow the guide here: http://wiki.bitcoin-otc.com/wiki/Using_bitcoin-otc

Register the same username at the popular places:

Use a strong and different password for each of these places, keeping your passwords in a secure place. This will allow other people in the community to track you across the different Bitcoin related sites. Also making identity theft online more challenging.

Best Practices with trading

Use Bitcoin-OTC

Make sure both parties agree to the terms of the trade with signed messages.

  • Get a PGP signed quote, and check the signature.
  • Send a PGP signed receipt.

This allows either party to go public if the trade has become sour and stops your trading partner from claiming the details of the agreement were somehow different.

Search the Bitcoin Forum for the username of the person that you are trading with. Check if the user has provided constructive and useful advice to other parties. And, most importantly, check for any claims that the user has scammed.

Use an escrow

Trading might benefit from an escrow such that bitcoins are disbursed only after contract terms have been met.

A popular online escrow is ClearCoin.

Found in Bitcoin's community are trusted individuals willing to act as independent, third-party escrow brokers.