Earlier quoted context omitted.
> Genuine question here: isn’t it a standard security practice to avoid committing keys (or other secrets) to repos? When you deal with high value amount of cryptocurrencies, you have a hardware wallet so things like these are not even possible in the first place, as the keys are safely stored in the hardware. Storing anything on disk (unencrypted at that) that corresponds to $40K is basically begging to be stolen fr…
Then you need to read through any file in any revision. Because if you have a newer commit with the secrets removed they are still in the history.
Developer posts secret key on GitHub, loses $40K in 2 minutes
41–50 of 93 posts
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#42> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#43Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#44> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#45So you can still offer any random shitcoin and make money with it. Seriously, I've got the wrong job.
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#46Earlier quoted context omitted.
An EMP taking out the entire world power grid would be a complete disaster for everyone. Goldbugs and people with cash in their mattresses included.
I don't disagree with you that it would be a disaster, I'm just saying that fundamentally crypto is not a store of value. But don't listen to me, I only deliberately burned my early Bitcoin after evaluating it on its merits, weeks after it came out. Nothing, repeat nothing, has ever moved the needle on my opinion of crypto, although I will say that cryptobros will not stop at anything to try and convince people that…
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#47Earlier quoted context omitted.
> Genuine question here: isn’t it a standard security practice to avoid committing keys (or other secrets) to repos? When you deal with high value amount of cryptocurrencies, you have a hardware wallet so things like these are not even possible in the first place, as the keys are safely stored in the hardware. Storing anything on disk (unencrypted at that) that corresponds to $40K is basically begging to be stolen fr…
Then you need to read through any file in any revision. Because if you have a newer commit with the secrets removed they are still in the history.
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#48Genuine question here: isn’t it a standard security practice to avoid committing keys (or other secrets) to repos? Edit: and what’s the best practice here? Is it using a key management system of some sort? (I’m thinking of scenarios where you might need to deploy your code + secrets on a remote server, say to authenticate with a third party API)
Protecting high-value cryptocurrencies is particularly hard, and as much as crypto people like to say "not your keys, not your coins", the reality is far more nuanced, and the average person is much better off using a well-known platform like Coinbase. Even hardware wallets are not as simple as people thing to use safely.
(If you're building cryptocurrency apps, never upload wallet private keys to cloud KMSs. Instead, generate wallet keys using the KMS itself, and use those wallets for small "in-transit" funds only. Think of them like bank branches, when you manually transfer small amounts of funds securely from a set of central wallets.)
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#49Some cryptocurrency isn't a safe store of value to begin with, so he was probably ready to lose that at any moment anyways. Worse way than most to lose it, but he doesn't sound too bummed out.
>Some cryptocurrency isn't a safe store of value to begin with... If I may, I would posit all crypto is not a safe store of value to begin with. An EMP taking out the entire world power grid would render crypto pretty useless almost immediately, while gold will just sit there. Even paper money is resistant to decentralized unwindings as they are physical and people are conditioned from birth to accept their value.
And most of the gold owned in the world is not in someone's basement, but as a line in a database; so you can wave goodbye to that as well.
Re: Developer posts secret key on GitHub, loses $40K in 2 minutes
#50> a memecoin coded using the artificial intelligence chatbot has already found success within the crypto space. So you can still offer any random shitcoin and make money with it. Seriously, I've got the wrong job.