Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

21–30 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#21
post #17
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

Hah! When I added SSL to my site a few days ago, I really cranked those settings hard trying to optimize for "security" on the Qualy's SSL Server Test. Do you know what the most secure cipher suite you actually support is (and are you sure the issue isn't that you aren't merely using a particularly-out-of-date copy of Firefox)?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#22
post #17
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

No such issue under Firefox 97 on NixOS; are you using a recent version of firefox + ssl lib?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#23
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Cool hack and writeup!

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#24
post #18

Earlier quoted context omitted.

Surely someone with the skills to find bugs like these would be an expert in cashing out on those bugs?

Those skills are unrelated.

Yeah... and as the person in question who found and exploited this particular bug ;P, I can definitely state that I would not feel comfortable betting the rest of my life on my ability to safely launder a giant pile of crypto back through to fiat (and then, further, keep that secret for the rest of my life, which shouldn't be downplayed).

I am much happier being able to get a bunch of clean money and then be able to give talks on the subject at conferences and get a lot of "street cred" in the tech community for my effort than spending the rest of my life wondering if there's someone from a real-world mob out there trying to hunt me down to recover the $100M I "owe them".

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#25
post #21
post #17

Earlier quoted context omitted.

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

Hah! When I added SSL to my site a few days ago, I really cranked those settings hard trying to optimize for "security" on the Qualy's SSL Server Test. Do you know what the most secure cipher suite you actually support is (and are you sure the issue isn't that you aren't merely using a particularly-out-of-date copy of Firefox)?

If his browser doesn't support any of the ciphers you have enabled, that's a problem with his version of Firefox and/or his default TLS library. These ciphers have been around for years and are supported by even some pretty old browsers.

Your TLS config is good for now, unless another padding oracle attack comes along and makes those CBC ciphers weak again, or some other vuln.

(your cert is expiring next month btw, might be a good opportunity to set up LetsEncrypt)

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#27
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

But you should have sat on it, laundered it through FBI honeypots and then made a rap album about it !! What have you done telling them about it :D

Pretty sure this is referencing the $3.6B hack https://news.ycombinator.com/item?id=30260787 where the wife is a rapper.

Though it's pretty weird that I wasn't sure whether you were referencing geohot's (another infamous hacker, mentioned in the article) rap songs at first: https://soundcloud.com/tomcr00se

Not sure why it's a thing for prominent hackers to have aspirations to become soundcloud rappers.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#29
post #24
post #18

Earlier quoted context omitted.

Those skills are unrelated.

Yeah... and as the person in question who found and exploited this particular bug ;P, I can definitely state that I would not feel comfortable betting the rest of my life on my ability to safely launder a giant pile of crypto back through to fiat (and then, further, keep that secret for the rest of my life, which shouldn't be downplayed). I am much happier being able to get a bunch of clean money and then be able to…

The whole assumption that your ethics have a pricetag attached is faulty, it's not as if the choices were 'commit crime / get bounty'.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#30
post #12
post #11

Earlier quoted context omitted.

This is $2 mil of clean money. > This could’ve easily been a bug worth hundreds of millions of dollars That doesn't mean that you could find someone to give you $100 mil, clean or unclean.

We have atomic swaps to monero now, cleaning your stolen eth is easier than ever.

How are you going to turn that into actual goods and services though? You'll still need to go through an exchange with KYC and AML and the IRS will still be asking questions.
Post reply on HN