Live data from Hacker News

The Resolv hack: How one compromised key printed $23M

chainalysis.com

171–174 of 174 posts

Re: The Resolv hack: How one compromised key printed $23M

#171
post #168

Earlier quoted context omitted.

Most "crypto" products aren't even crypto but custody accounts. But that doesn't change the fact that blockchains that can be controlled by specific entities unanimously are a joke of a crypto.

There are just some things that are unsolved. For example, a smart contract can't act as an oracle for many types of external event. There's no way around that. Doesn't mean it's not valuable to make the rest of your product trustless. Reducing the keyholders matters. Unless you think NSA key escrow is also cool because hey, one person, somewhere, has the key, so why not the whole government?

Exactly. It is the same. One person or the whole government; it is the same, when it matters.

Re: The Resolv hack: How one compromised key printed $23M

#172

Earlier quoted context omitted.

How does crypto solve this? You still have to send the funds and hope they give you the car - it's exactly the same as a bank transfer.

Because the transfer is done instantly and every party can verify it. Just like cash.

Intra-bank transfers are instant, so is PayPal/Revolut/Zelle or whatever else, and many inter-bank transfers are also instant or very nearly so in the EU. None of these, except maybe cash, protect you from someone sinply not delivering the physical good (car + car keys) after the transfer completes.

From a legal standpoint, the bank transfer speed is anyway irrelevant - you first sign a sale contract that makes the car yours and the money theirs, before anything actually exchanges hands. If one party fails to deliver the money or the other fails to deliver the good, they are anyway liable. With instant transfers, the buyer is more likely to get scammed; with delayed transfers, both the buyer and the seller are equally as likely to get scammed - that is the only difference.

Re: The Resolv hack: How one compromised key printed $23M

#174
post #110

Earlier quoted context omitted.

> took a private key from KMS They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.

^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM. There's no shortcut to MPC/multisig with 3+ keyholders.

[dead]
Post reply on HN