Quantopian's community platform is shutting down. Please read this post for more information and download your code.
Back to Community
Post-mortem of 2013-11-15 security breach

FYI, I've posted on our blog a detailed post-mortem of the security breach we experienced on 2013-11-15.

Regards,

Jonathan Kamens
V.P. of Operations
Quantopian

Disclaimer

The material on this website is provided for informational purposes only and does not constitute an offer to sell, a solicitation to buy, or a recommendation or endorsement for any security or strategy, nor does it constitute an offer to provide investment advisory services by Quantopian. In addition, the material offers no opinion with respect to the suitability of any security or specific investment. No information contained herein should be regarded as a suggestion to engage in or refrain from any investment-related course of action as none of Quantopian nor any of its affiliates is undertaking to provide investment advice, act as an adviser to any plan or entity subject to the Employee Retirement Income Security Act of 1974, as amended, individual retirement account or individual retirement annuity, or give advice in a fiduciary capacity with respect to the materials presented herein. If you are an individual retirement or other investor, contact your financial advisor or other fiduciary unrelated to Quantopian about whether any given investment idea, strategy, product or service described herein may be appropriate for your circumstances. All investments involve risk, including loss of principal. Quantopian makes no guarantees as to the accuracy or completeness of the views expressed in the website. The views are subject to change, and may have become unreliable for various reasons, including changes in market conditions or economic circumstances.

3 responses

Any plans to start thunking sys or otherwise shimming all system calls?

Hi Simon,

I apologize for the delay responding to your comment. I needed to give it some thought before responding.

We do have plans for taking additional steps to harden the algorithm execution sandbox, and the ideas you mentioned are among those we are evaluating, but I don't feel comfortable going into additional details at this time. While we strive for transparency and don't believe in relying on security by obscurity, at the same time we also don't believe in unnecessarily making things easier for the bad guys.

Regards,

Jonathan Kamens

Fair enough, reminds of the end of Indiana Jones though! http://img.pandawhale.com/post-21790-We-have-top-men-working-on-it-Xslz.gif