Earlier quoted context omitted.
I'm surprised anyone reading this story wouldn't conclude that the real takeaway is to just not engage with cryptocurrency at all. This ecosystem is so convoluted it just turns me off at every level.
I woke up this week to dozens of comments on a video from a speaker at SaaS Connect 2017 (previously known as The Small Business Web Summit) to learn she was arrested and charged by the DOJ this week for laundering $4.5 billion in crypto. https://www.justice.gov/opa/pr/two-arrested-alleged-conspira... Billion! Since this is an allegation, we must presume innocence. However I still cannot imagine what planet would ent…
Social engineering scam that nearly cost me all of my ETH
321–330 of 423 posts
Re: Social engineering scam that nearly cost me all of my ETH
#322Earlier quoted context omitted.
no it's not a bad thing at all. it's not a systemic failure, it's division of labor and people need to stop being willfully ignorant of economics. Lawyers are good at reading contracts, Facebook is good at running servers. Medium is good at publishing your things and getting you ad revenue. sending http and json over the internet is just as neutral of a technology as the blockchain. the reason people build centralize…
No-one is better off concentrating power in a centralized authority with the scale and (lack of) accountability of Facebook. Specialization doesn't come into it, although it is worth observing: your comment presupposes that in order to benefit from specialization, one must subject themself to exploitation.
they don't stay there because they are being exploited, it's because centralized platforms reach many customers and automate away a lot of the problems that you'd have if you had to set that infrastructure up yourself and pay for it.
If you're a creator you stay on Youtube because you get a sustainable income. They can do that because they're centralized. If you run your own peertube instance and pay more in server costs than you make in ads that isn't a solution.
And these simple economies of scale will always exist regardless whether your software runs on a server or a distributed blockchain vm.
Re: Social engineering scam that nearly cost me all of my ETH
#323I can get behind cryptocurrency and stuff, but the idea that anyone can write a contract that says "I get to do what I want with your money" and then build their own custom, one of a kind UI with no way to limit what the user thinks the button does for you to sign such a transaction, it's got to be the biggest, most massive security hole I've ever seen brushed off. You want me to put the title to my house on it? You…
1) Spend more tokens than the amount you approved. 2) Spend any other tokens besides the specific type that you approved. (E.g. can’t steal your NFT or USDC) 3) Spend tokens at any other wallet address even if you own those other addresses (and creating a new address for a specific purpose is trivially easy)
In addition the only approve() technology is already being replaced with the modern EIP-2612 standard. (USDC already implements it.) In this workflow instead of pre-approving a contract, you sign a specific transaction-specific message. With EIP-2612 you know exactly how much you’re spending on each transaction and there’s zero after the fact risk.
Re: Social engineering scam that nearly cost me all of my ETH
#324Note; dude has $123M in aave wrapped ethereum that he almost granted a scammer access to. Scammers ripping off scammers. Why would you waste time with open source aircrafts. Aircrafts are a regulated thing. Nobody wants to fly in your science project. Put some of that 123 million into starting an actual company. DAOs are bullshit.
That's a horrible take on a legit person and project.
Re: Social engineering scam that nearly cost me all of my ETH
#325Earlier quoted context omitted.
There are checks in place to make difficult to buy an SSL certificate for the official domain of a bank. At least Chrome tracks malicious websites. By comparison, there seem to be no checks in place to prevent writing an ethereym contract that drains a victim’s wallet.
Actually most web3 wallets have their own version of "safe browsing" and track malicious/phishing web3 websites.
Re: Social engineering scam that nearly cost me all of my ETH
#326So I don't know anything about crypto, but stories like this make me think that crypto can never become mainstream. I have been programming since 1970; I worked for major computer companies; I was a computer science professor; I have apps on the App Store. In spite of all of this, I have not the foggiest idea, even after reading the thread, how someone who offers to give me something can use the gift to steal from me…
I'm still not convinced that Ethereum isn't just a strange RPG that people who don't really want to play are accidentally getting involved in.
Re: Social engineering scam that nearly cost me all of my ETH
#327Earlier quoted context omitted.
I'm surprised anyone reading this story wouldn't conclude that the real takeaway is to just not engage with cryptocurrency at all. This ecosystem is so convoluted it just turns me off at every level.
Taking a high-velocity ride in a cage of aluminum? I don't want to engage with that at all. I am so surprised that safety measures such as airbags and seat belts are discussed. Obviously cars are too dangerous to exist.
I don’t understand at all how wheels move and what is that round thing near my chest and what do with it. Maybe it’s the fifth wheel. Or why fuel is needed, I can’t even find a mechanic who will look under the hood for me if I can’t. Also since my last car could use my ATM card and sign my cheques I had to be extra careful when turning on the ignition and had to see the gps log whether it drove to my bank when I was taking the afternoon nap.
There was no service warranty and guarantee with the car at all. I had to hire an entire division of technicians and engineers to use it. I think few lawyers and auditors as well.
In fact it felt I also needed a PhD in all things automobile to use my car.
Most importantly I can’t see in front of me at all. Front is opaque. I just drive hoping I don’t run someone over or something doesn’t run me over and my car.
Re: Social engineering scam that nearly cost me all of my ETH
#328> a DAO working to build open-source VTOL aircraft and air taxi protocol The most reasonable conclusion is that the hacker was sent from the future to try to avert the creation of DAO-controlled flying cryptodrones.
Re: Social engineering scam that nearly cost me all of my ETH
#329Earlier quoted context omitted.
Actually most web3 wallets have their own version of "safe browsing" and track malicious/phishing web3 websites.
There isn't much point if domains and contracts are being setup for the sole purpose of spearfishing a handful of whales.
Re: Social engineering scam that nearly cost me all of my ETH
#330Earlier quoted context omitted.
See also: the "Chinese Robbers" fallacy[1] -- just because you can find a ton of examples of fiat fraud, doesn't imply its worse -- without context it only implies its the most common form of currency. [1]: https://www.lesswrong.com/s/XsMTxdQ6fprAQMoKi/p/DSzpr8Y9299j...
Yes, that's called "base rate neglect" or "base rate bias." In a twist of irony, you can see another example of it in the distribution of terms reinvented by internet rationalists :-)
> Most people think of stereotyping as “Here’s one example I heard of where the out-group does something bad,” and then you correct it with “But we can’t generalize about an entire group just from one example!” It’s less obvious that you may be able to provide literally one million examples of your false stereotype and still have it be a false stereotype.