Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

141–150 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#141

Earlier quoted context omitted.

If you say so. It’s the same thing, even if it’s more comfortable to believe it’s not. It helps to frame it this way, because once you accept that you’d do that, you’re more likely to accept you would do something unethical for a billion dollars if it had no consequences to you. And from there, it’s a binary search to determine exactly what your price is. Would you be able to say you wouldn’t lie to your wife if it m…

If you believe everyone has a price shouldn't your goal be to not find your own? (Like, work to avoid creating the situation where you have to compromise, if possible)

That’s a very interesting question. Thanks for that.

The way I view it is that it’s important to seek out yours ahead of time -— to game out different scenarios, and to consider whether you would do X or Y if forced to choose. That way, when you’re in a situation where you feel like compromising, you’ll remember your limits.

In other words, I was less tempted to act unethically in the moment than I would have been if I’d been surprised by the opportunity.

This is especially important in scientific circles. It’s often trivial to falsify data, and the rewards for doing so are generally high. It’s also not always an active, conscious decision; it’s easy to make small mistakes that have favorable outcomes for yourself.

The exercise has helped me steer far away from any of those. I’ve watched peers fall into a trap that I’d label “scientific hype,” i.e. claim that you’re doing something impressive when in reality you’re nowhere close. This is a very easy mistake to make, and if I hadn’t mentally found my boundaries ahead of time then I’d have been vulnerable to making the same error. Or I may have stayed silent when my peers were doing something naughty.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#142
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Wow, really cool to see this. I remember your name from seeing it in Cydia all the time when I was 11 and had my iPod 2 haha.

Congrats on the bounty, glad to see you don't plan on blowing through it mindlessly :) With a worldwide diversified ETF portfolio you should be able to live off of this amount of money indefinitely.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#143

Earlier quoted context omitted.

Wow, that's depressing. I was in jail with a guy who was a total mess. Nice, but seemed pretty mentally-disabled. One day a new guy came on the block. "Wow, what is George doing in here?" "You know him?" "Yeah, I know him. He is one of the greatest musicians I ever met. He can play any instrument like a savant. I knew him a few years ago, just after he inherited $4m when his father passed. He ended up getting in drug…

Interesting: I knew a guy that came into a lot of money. A serious lot. And he found that he had a whole entourage of new friends. Fancy house, gurus, admirers, tons of interesting investment proposals most of which he accepted. And when he died and the accounts were made up it was all gone. Everything. Not a single person around him that did not in some way take advantage of him. I still have a hard time getting aro…

Something similar happened to Tony Hsieh, founder of Zappos (acquired by Amazon for $1.2B), though he still left a considerable fortune after death.

https://news.yahoo.com/zappos-founder-tony-hsieh-didnt-17410...

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#144
post #93

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Poor people aren’t stupid

You mean they aren’t stupid by necessity or that there isn’t a correlation on the population level?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#146

Earlier quoted context omitted.

Rich people of HN, is this true? I’d always heard each million is worth about $50k a year. Was that just during boom times, or simply mistaken?

> Not even close. There's no reliable way to get a fixed income, and inflation is very high. The market historically has been going up, so at least historically it's been reliable to get a fixed income. I don't think $2M is sufficient to retire very early, mostly because of bad years and that your initial capital loses value over the years, but it can generate a nice income and most people can have something on the s…

> least historically it's been reliable to get a fixed income

"Fixed Income" is more about structurally reliable and consistent returns, rather than historical average returns.

An outlier bad year can easily wipe a huge percentage of capital invested in stock--but the younger you are, and the more buffer you have, the less likely this is to be a problem. But don't mistake that for fixed income!

Fixed income usually refers to interest rate products, and as mentioned above in this thread, the inflation-adjusted rates have been pretty bad. Pretty much since the start of Quantitative Easing, I believe.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#147
I remember walking down the main street in my hometown on my way to drink at a bar and seeing saurik and some friends at a bars all with their laptops out and hacking on something. What caught my eye was a terminal open and a Vim session. I walked up and we all chatted for a bit. Back in the day you didn't run into that very often where we lived so it was pretty cool to see. That boosted my conviction for my choice of IDE and I started bringing my laptop out to the bars in the evenings as well. Years later my friend and I built a business and pretty much all the code was written in the evenings at one of those bars. You can be social and code at the same time it turns out, and coding prevented me from drinking too much while I was out. No real morale to the story, just an anecdote I wanted to share. That said, congrats on the bounty saurik!

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#148
post #42

Earlier quoted context omitted.

So how many lambos are you buying? More seriously, will you keep it in the bank and extract $100k a year the rest of your life? What are you going to do?

I do not expect to make any major expensive lifestyle changes as a result of having more money (and to the extent to which I have already been being paid better recently due to working on Orchid, I have only barely done so and usually only quite temporarily), which I realize disappoints some people who had wanted me to post a concrete picture of something expensive I purchase to help motivate others to reach for bug…

Unless you live in the sticks, you probably aren’t “wasting” your money by using rentals and Lyft.

The problem with a car is for most people it’s their most expensive or second most expensive capital asset, yet has a very low utilization rate (often less than 5%). If interest rates rise their op ex in servicing it (fuel, insurance, loan interest) will exceed that!

A few years ago I sold all my cars. I found I only drove at all a few times a week at most (walk/bike instead). Like you I switched to ridershare/rent and it was fine. My motivation wasn’t really to save money but just eliminate the hassle of having all those cars.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#149
post #21
post #17

Earlier quoted context omitted.

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

Hah! When I added SSL to my site a few days ago, I really cranked those settings hard trying to optimize for "security" on the Qualy's SSL Server Test. Do you know what the most secure cipher suite you actually support is (and are you sure the issue isn't that you aren't merely using a particularly-out-of-date copy of Firefox)?

As a data point, the Mozilla "SSL Configuration Generator" seems to be well regarded:

https://ssl-config.mozilla.org

I tend to use it for generating config's for static Nginx sites, though it can do much more. :)

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#150
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Really cool to see Saurik posting here casually. You’re work on Cydia when I was 12 years old is what got me into programming in the first place. Nice work!

No post body was provided.
Post reply on HN