Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

171–180 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#171

Earlier quoted context omitted.

Can you name any examples of cryptocurrencies being used that are not scams, ponzi schemes or for speculative purposes? All I see are people holding coins and not using them at all for anything else other than 'I want coin to go up'.

Speculative investment is not the same as a Ponzi scheme. Not so subtle goalpost moving there.

The are used for both.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#172

Earlier quoted context omitted.

You are still moving the goalposts. My statement is pretty simple: ethical people exist. You countered with "Everyone’s ethics have a price tag. It’s better not to pretend otherwise, since it clarifies a lot of human behavior." And have been moving the goalposts ever since. The fact that unethical people exist was never up for debate.

I had to scroll up and re-read to make sure we were on the same page. Since you’re misquoting yourself, it sounds like you don’t want to have this debate, or you may not have realized what you said. But “The whole assumption that ethics have a price tag attached is faulty” is not at all the same thing as “ethical people exist.” It’s not a pedantic distinction; one is debating whether people will take compensation for…

The distinction is pedantic because you are making it so.

Whereas in fact it is anything but pedantic.

"The whole assumption that ethics have a price tag attached is faulty"

For everyone.

> But we’re past the point that readers are having a nice time reading this.

You seem to be in a habit of projecting your own feelings onto everybody else.

> If you’d like to continue, I’m happy to do so, but we need to restrict ourselves to a high caliber of debate, if only for HN’s sake.

Suit yourself.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#173
post #134

Earlier quoted context omitted.

Gambling is not a human right, no one deserves to be able to waste resources they have no matter how much they may or may not enjoy it.

What? So startups should not be allowed? 90% of them fail after all. The odds of a startup being successful is literally gambling.

I feel like the difference is that companies are generally intended to be a concerted effort of one or more individuals, as opposed to an actual roll of the dice.

Like without getting into nits, you can actually directly effect the direction and value of a company, but you can't affect the roll of dice or the output of a random number generators.

Risk in and of itself doesn't imply the entire thing is gambling; that said, investing by itself would be way closer to gambling in that context, imo

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#174

Earlier quoted context omitted.

Interesting: I knew a guy that came into a lot of money. A serious lot. And he found that he had a whole entourage of new friends. Fancy house, gurus, admirers, tons of interesting investment proposals most of which he accepted. And when he died and the accounts were made up it was all gone. Everything. Not a single person around him that did not in some way take advantage of him. I still have a hard time getting aro…

Something similar happened to Tony Hsieh, founder of Zappos (acquired by Amazon for $1.2B), though he still left a considerable fortune after death. https://news.yahoo.com/zappos-founder-tony-hsieh-didnt-17410...

That's on yet another level. But the parallels are eerie. I wonder how common this is.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#175
post #150

Earlier quoted context omitted.

Really cool to see Saurik posting here casually. You’re work on Cydia when I was 12 years old is what got me into programming in the first place. Nice work!

Quoted post unavailable.

No post body was provided.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#176

Earlier quoted context omitted.

>But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid. Seems like just an opinion to me, and a poorly opinionated one at that.

I think it's a bit pointless to argue about whether cryptocurrencies are Ponzi schemes or not. What I would say is that most cryptocurrencies have no fundamental value, and are therefore bubbles. I don't know what the term is for when someone deliberately creates an asset bubble with the intention of profiting from it. It's something like a very long-form, deliberative pump-and-dump.

I agree that the majority of cryptocurrencies are vaporware at best and deliberate scams at worst, but to claim that "All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid" is outright wrong.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#177

Earlier quoted context omitted.

They revert the money (if they like you), but usually if money flows one way, something else flows the other way, and they can't revert that half of the fraudulent transactions without great expenditure. Often it's not worth it and they just write it off and the whole economy bears the cost. I'm not saying it's a better or worse plan than whatever might happen under an alternative system, but just that it's not exact…

I think your premise is fundamentally wrong there. Say I buy something my credit card but it's never delivered. My bank will reverse that transaction - exactly because half of the transaction never occurred. The way that the credit card system works in the US is fundamentally biased towards consumer protection, because that's an explicit policy objective. The same with the Direct Debit guarantee in the UK, or the var…

The lack of agility shows up when I buy something with your credit card number. It gets delivered, and then the bank reverses the transaction because they later learn that I'm not you.

Now I get a bank-subsidized thing and you're not missing any money. It creates a drag on the whole economy, because instead of doing productive work to get the thing, it's often easier to play games with the system.

The fact that credit cards use a symmetric key to authorize spend is a glaring flaw. The technology to fix it (asymmetric key cryptography) has been around for decades. But instead of fixing it, the credit card companies just keep writing off the instances of fraud.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#178
post #164

Was it paid cash or in ETH?

The bounty amount was denominated in USD and is being paid in USDC (a stable coin, which is means it is intended to map effectively 1:1 with--in this case--USD).

At the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#179

Earlier quoted context omitted.

I strongly disagree with that. You really can't claim to speak for everybody.

If you don’t play ball in certain parts of the world, you end up in a river. The price tag is just different. Yours would likely be family or close relatives. I think you’d take money to do something untoward if that was the alternative. Almost everybody would. And there’s nothing wrong with admitting that.

> If you don’t play ball in certain parts of the world, you end up in a river. The price tag is just different.

Aside from the problems of this statement being a completely vague and unspecific and extreme hypothetical, isn’t there a problem with switching from talking about incentives to talking about threats? Being threatened with death isn’t the same as being offered money, and this ground has been well covered by philosophers who point out that there are things wrong with “admitting that” as you call it. Calling it a price tag seems misleading at best. There’s further a massive problem with suggesting a person’s ethics might be based on what someone threatening them with death wants them to do, no? If the action isn’t something you are choosing to do, and isn’t something you would do if not threatened, for any amount of money, then why would you consider it your actions or part of your ethics?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#180
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

This post openly advocates being an accessory to fraud to maximize profit.

The true value of exploits is NOT the cost of the damage they could do, because that externalizes various costs to the perpetrator: evade law enforcement for the rest of your life, lose access to friends and family, become a high-value target for traditional organized crime, etc. For many people that is a net negative, even for a 9-figure payout. And that is a good thing, I think.

Post reply on HN