Live data from Hacker News

OptiFi Program Incident Report

medium.com

41–50 of 158 posts

Re: OptiFi Program Incident Report

#42

Can you change the title of this submission to match the title of the post please? Normally people change titles when the original is sensationalised however the opposite is true in this case.

It sounds like a bunch of people are going to pay for the cost to users of their own mistake out of their own pocket, so if they follow through with that we should probably applaud the move?

If they welch on it that’s another matter, but the stated time is tomorrow so…so far so good?

Re: OptiFi Program Incident Report

#43

Commands like that really need a confirmation prompt and a command line switch to override like --do-as-i-say (long form only). Good example of developers being put in an end user's shoes, I hope they learn from that mistake and update their programs.

That's a technical solution to a psychological and organizational problem: when there should be no CLI in production, people still use it and get used to various errors and confirmations so much, that they ignore the signs of a catastrophe. Technical solutions never work in such cases.

And then there's a regulatory problem: investors trust their money to businesses which have not earned that trust, because of whatever magical thinking that exists on this market. At least the company seems to be able to return the money, but will it be sanctioned for this failure? There should be a regulatory incentive to do better next time.

Re: OptiFi Program Incident Report

#46

Commands like that really need a confirmation prompt and a command line switch to override like --do-as-i-say (long form only). Good example of developers being put in an end user's shoes, I hope they learn from that mistake and update their programs.

That's a technical solution to a psychological and organizational problem: when there should be no CLI in production, people still use it and get used to various errors and confirmations so much, that they ignore the signs of a catastrophe. Technical solutions never work in such cases. And then there's a regulatory problem: investors trust their money to businesses which have not earned that trust, because of whateve…

> no CLI in production

It seems like this was in the "deploy to production" stage, and there has to be some mechanism for doing that.

(It also seems unnecessarily complicated; I'd appreciate a plaintext explainer of what actually went wrong)

Re: OptiFi Program Incident Report

#47
post #16

Earlier quoted context omitted.

> Who wants to give over their financial life to a computer program? Where do you think your income and bank balances are tracked and stored? On pieces of paper?

This is missing the point to a degree that makes me think you're being intentionally obtuse, but maybe you're just ignorant so I'll bite. Banking computer errors can easily be rectified by humans, banks are regulated, your funds are at least partially guaranteed by the government (depending on where you live). The degree to which you're trusting computer programs with your finances is orders of magnitude less than wi…

CitiBank can't get the money back they accidentally transferred to another company.

https://www.bloomberg.com/news/articles/2022-08-15/citi-sues...

You can say that's an edge case today but I and OP are saying, the future will look more like crypto looks today. Not a bright future.

Re: OptiFi Program Incident Report

#48
post #26
post #5

For all its flaws (and there are countless) the one thing about the show cryptocurrency space that stands out to me as a programmer is that programming errors can be suddenly very costly (granted, in this case it was more of a DevOps blunder). Being able to very easily put a price tag on sloppy programming is intriguing to me.

You (and everyone really) should probably read some more comp.risks http://catless.ncl.ac.uk/Risks/ Certain fields have always had a high cost of programming error, including a cost in human life. It's just that cryptocurrency combines this with a first-to-market rush that's somehow still going on, encouraging a rush to error.

I don't disagree with that there have always been niche areas where there is a high cost to programming errors (like space or medical).

But with crypto, the effect is much more direct. The programmer is handling money much more directly and if something goes wrong, they are much more directly affected and not being insulated from the effects.

Re: OptiFi Program Incident Report

#49

Can you change the title of this submission to match the title of the post please? Normally people change titles when the original is sensationalised however the opposite is true in this case.

It sounds like a bunch of people are going to pay for the cost to users of their own mistake out of their own pocket, so if they follow through with that we should probably applaud the move? If they welch on it that’s another matter, but the stated time is tomorrow so…so far so good?

Tweet says 95% of the $661k funds belonged to a team member. It's unfortunate in any case.

https://twitter.com/OptifiLabs/status/1564367455220219904

Re: OptiFi Program Incident Report

#50

Can you change the title of this submission to match the title of the post please? Normally people change titles when the original is sensationalised however the opposite is true in this case.

Sounds like they only lost $661k worth, which is peanuts by comparison to most other crypto hacks/losses, probably didn't destroy the entire company since they're compensating their users, and not really worthy of the sensational title.

Apparently 95% of that money was by the company itself or employees of the company. So the loss for normal users is very limited.
Post reply on HN