Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

191–200 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#191

Earlier quoted context omitted.

I had to scroll up and re-read to make sure we were on the same page. Since you’re misquoting yourself, it sounds like you don’t want to have this debate, or you may not have realized what you said. But “The whole assumption that ethics have a price tag attached is faulty” is not at all the same thing as “ethical people exist.” It’s not a pedantic distinction; one is debating whether people will take compensation for…

The distinction is pedantic because you are making it so. Whereas in fact it is anything but pedantic. "The whole assumption that ethics have a price tag attached is faulty" For everyone. > But we’re past the point that readers are having a nice time reading this. You seem to be in a habit of projecting your own feelings onto everybody else. > If you’d like to continue, I’m happy to do so, but we need to restrict our…

I'm saddened that a repeat of our debate from seven years ago won't be forthcoming today. https://news.ycombinator.com/item?id=8901682 I was looking forward to it.

If you ever do want to probe deeper into the question of ethics vs cost, I think it would be interesting. But since you keep talking about me rather than the idea, the interest feels one-sided.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#192
post #2

It's not just any white hat hacker, it's saurik who was behind the original jailbreaking tools for iOS and the creator of Cydia, the unofficial app store back then. He is also now the "CTO" (if the term applies) of a well-known blockchain-based VPN, Orchid. Edit: He has a great write-up about the vulnerability and its discovery on his blog: https://www.saurik.com/optimism.html (which was on HN a couple days ago)

CXO titles in organizations do not exist without a board of directors. Businesses otherwise simply have members, managers, employees, contractors or vendors, or volunteers. You can pretend you're a CEO/CTO, but if you answer to no board, you're not.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#193

Earlier quoted context omitted.

My 'goalposts moved' detector just twitched.

If you say so. It’s the same thing, even if it’s more comfortable to believe it’s not. It helps to frame it this way, because once you accept that you’d do that, you’re more likely to accept you would do something unethical for a billion dollars if it had no consequences to you. And from there, it’s a binary search to determine exactly what your price is. Would you be able to say you wouldn’t lie to your wife if it m…

[deleted]

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#194
post #53
post #42

Earlier quoted context omitted.

I do not expect to make any major expensive lifestyle changes as a result of having more money (and to the extent to which I have already been being paid better recently due to working on Orchid, I have only barely done so and usually only quite temporarily), which I realize disappoints some people who had wanted me to post a concrete picture of something expensive I purchase to help motivate others to reach for bug…

> I can't imagine myself buying a pointlessly extravagant car; and, sadly, now is a bad time to buy a car anyway Get a fun car that can be a hacking project :) I was suggested a police car by a friend. They are cheap at auctions, more or less well maintained (tax payer money) and have interesting internals (check sites like https://www.dippy.org/upgrade/dipcop.html ) especially for electrical circuits where a police-…

> I was suggested a police car by a friend. They are cheap at auctions, more or less well maintained (tax payer money)

Except that

1) a lot of them are Dodge Chargers which are terribly unreliable

2) they spend incredible amounts of time idling, which isn't good for the engine of a sports car

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#195
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Thank you for Cydia!! Like another commenter here, it also made a big impression on me!

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#196

Earlier quoted context omitted.

I think your premise is fundamentally wrong there. Say I buy something my credit card but it's never delivered. My bank will reverse that transaction - exactly because half of the transaction never occurred. The way that the credit card system works in the US is fundamentally biased towards consumer protection, because that's an explicit policy objective. The same with the Direct Debit guarantee in the UK, or the var…

The lack of agility shows up when I buy something with your credit card number. It gets delivered, and then the bank reverses the transaction because they later learn that I'm not you. Now I get a bank-subsidized thing and you're not missing any money. It creates a drag on the whole economy, because instead of doing productive work to get the thing, it's often easier to play games with the system. The fact that credi…

In the situation you describe, the one who is "out" is the merchant. In the card-not-present situation, the merchant has the option to use tools like CVV and address validation to reduce the risk in the transaction, and always has the option to decline a transaction that seems risky.

That seems, to me, like a sensible risk balancing approach. In the cryptocurrency "all sales are final" world - you're the loser. I don't really see that the economic drag is larger one way or the other.

AFAIK the use of symmetric key cryptography in card capture and payment processing is not in any way a significant factor in payment card fraud - where do you get that information from?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#197
post #102
post #93

Earlier quoted context omitted.

Poor people aren’t stupid

If you're poor and gambling, then you're making a stupid financial decision. So the odds of you being financially stupid seem likely to be high.

If I'm about to be evicted or declare bankruptcy, does having $1 really change anything? Meanwhile, does having a small chance of staying in my house change anything?

It's easy to say "well, lotteries have a negative expected payoff". And that's true, but it can still have a less negative payoff than a payday loan or having your car repossessed.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#198
post #101

Earlier quoted context omitted.

Can you name any examples of cryptocurrencies being used that are not scams, ponzi schemes or for speculative purposes? All I see are people holding coins and not using them at all for anything else other than 'I want coin to go up'.

Helium has practical uses - a cheaper alternative to cellular data for stuff like Lime scooters.

I was looking into Helium yesterday due to news coverage. "Proof of coverage" is a bunch of hot air, sorry. It's not resistant to Sybil attacks and GPS location is easily forged. Seems like a scheme to push hardware units that will topple once the token value runs out.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#199
post #30

Earlier quoted context omitted.

How are you going to turn that into actual goods and services though? You'll still need to go through an exchange with KYC and AML and the IRS will still be asking questions.

Or, the criminal could buy goods and services with the monero directly. The IRS will ask questions of those people, but not the black hat "security researcher".

I want a mansion. How do I buy that with monero?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#200
post #41

Earlier quoted context omitted.

No. This was neither ETH, nor the Ethereum blockchain. Nor does this imply more issues indeed exist today.

From the bounty: "The Summary On 2/2/2022, I reported a critical security issue to Optimism—an "L2 scaling solution" for Ethereum—that would allow an attacker to replicate money on any chain using their "OVM 2.0" fork of go-ethereum (which they call l2geth)." No - sorry - ETH doesn't get a 'pass' on this. The 'Rest Of The World' is tired of the Crypto Scam Delusion masquerading as something reasonable and watching th…

This was a critical success for Optimism's bug bounty program, if anything? No one got rug pulled. Optimism's liquidity could have been drained in the worst case, and still ETH L1 would remain unaffected.
Post reply on HN