Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

101–110 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#101

Earlier quoted context omitted.

>But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid. Seems like just an opinion to me, and a poorly opinionated one at that.

Can you name any examples of cryptocurrencies being used that are not scams, ponzi schemes or for speculative purposes? All I see are people holding coins and not using them at all for anything else other than 'I want coin to go up'.

Helium has practical uses - a cheaper alternative to cellular data for stuff like Lime scooters.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#102
post #93

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Poor people aren’t stupid

If you're poor and gambling, then you're making a stupid financial decision. So the odds of you being financially stupid seem likely to be high.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#103

Earlier quoted context omitted.

I have no problem with white hat hackers, I'm saying more power to them in the broken web3 space, which that is a complete scam. However, I can use USD, GBP or any fiat currency in my local grocery store. Can I use Bitcoin, Shib, Doge, or even Orchid at my grocery store without waiting hours in the queue for the transaction to complete and no huge fees?

Not yet, but I don't think that we're too far away from using USD, GBP or any fiat currency as a unit of account at the POS and letting software handle ensuring that the buyer loses whatever assets they want to pay in and the seller receives whatever assets they want to be paid in. But that's orthogonal to how quickly the maintainers of these tokens can make changes in response to threats.

So no then?

Over a decade later and I still cannot use any of them at the restaurant or without waiting in the queue for the transaction to settle and paying more for the fees than the goods itself.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#104
post #42

Earlier quoted context omitted.

So how many lambos are you buying? More seriously, will you keep it in the bank and extract $100k a year the rest of your life? What are you going to do?

I do not expect to make any major expensive lifestyle changes as a result of having more money (and to the extent to which I have already been being paid better recently due to working on Orchid, I have only barely done so and usually only quite temporarily), which I realize disappoints some people who had wanted me to post a concrete picture of something expensive I purchase to help motivate others to reach for bug…

For what it’s worth - I love that you have this perspective. There’s absolutely nothing wrong with just saving the money.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#105
post #87
post #21

Earlier quoted context omitted.

Hah! When I added SSL to my site a few days ago, I really cranked those settings hard trying to optimize for "security" on the Qualy's SSL Server Test. Do you know what the most secure cipher suite you actually support is (and are you sure the issue isn't that you aren't merely using a particularly-out-of-date copy of Firefox)?

Seems to be because of Fedora hardened policy and your site might be supporting SHA1 for use in signatures. One of the three changes with the default tweaks policy that probably makes sense https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2... When I set the crypto policy in Fedora to Legacy, which lifts those restrictions, I can visit your website. Chrome doesn't have this problem in Fedora because it ship…

Interesting! I had went out of my way to add support for TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384--because I consider older versions of Safari critical for my audience--but the way I did that dragged in TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA; I've gone ahead and filtered out SHA1 (so maybe / hopefully this will help).

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#106
post #93

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Poor people aren’t stupid

No post body was provided.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#107
post #93

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Poor people aren’t stupid

[deleted]

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#108
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

No post body was provided.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#109

Earlier quoted context omitted.

Rich people of HN, is this true? I’d always heard each million is worth about $50k a year. Was that just during boom times, or simply mistaken?

Not even close. There's no reliable way to get a fixed income, and inflation is very high.

>no reliable way to get a fixed income

You could buy an annuity from an insurance company. A quick Google search shows that $2mil should buy a 40 year old about $70k/year for the rest of their life.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#110

This just proves how insecure the blockchain / web3 / cryptocurrency space is. It's good to see white hat hackers in this space trying to fix what is already broken. But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid.

Tell me you don't know what DeFi is without telling me you don't know what DeFi is.

What is the process of getting your money back from a hacked DeFi project?

Why do I have to pay more fees to swap tokens on decentralised exchanges making them unusable, and how exactly is DeFi decentralised?

Post reply on HN