Live data from Hacker News

Social engineering scam that nearly cost me all of my ETH

twitter.com

401–410 of 423 posts

Re: Social engineering scam that nearly cost me all of my ETH

#401

Earlier quoted context omitted.

I think that fits more into "ridiculous economic Chinese finger trap" than "security feature." It's similar to calling gold's physical weight a security feature, but at least there's a consistent and non-economic relationship between how much gold you have and how hard it is for someone to pick it up and walk away with it. (It's also not immediately obvious that "more electricity" is needed to attack it, since a hand…

Larger pools doing that would be subtracting energy from the honest side, and adding it to the dishonest side, so the logic still holds

> Larger pools doing that would be subtracting energy from the honest side, and adding it to the dishonest side

Why would that be the case? It isn't necessarily zero-sum; the more realistic scenario is that the remaining honest participants ramp up their energy consumption in an attempt to prevent the attack.

But that's still only the most boring of the many, many latent threats to Bitcoin. Solar flares and electronic warfare strike me as more interesting.

Re: Social engineering scam that nearly cost me all of my ETH

#402

Earlier quoted context omitted.

Please explain to me how embedding a Turing complete programming language inextricably from a currency adds anything of value that is not offset by the pitfalls of regular users needing to not only know how to code but understand the entire ecosystem that the currency interacts with.

If you are always concerned about the pitfalls of your stupidest user, you will make a product that is only suitable for stupid users. When you stop worrying about that, and can actually start to deploy advanced technology for your advanced users. You can weight your argument however you want, all technology will fail some class of user. Me, I’ve been playing with this and various tech for a decade now and the sky is…

Okay, but you didn’t answer my question. I’m not talking about the "dumbest user" - I’m talking about a regular person who is currently paid in dollars and understands how to use a debit card. What benefits does making money programmable provide that is not offset by this person having to take time out of their day to audit every transaction and understand how the code making up the transaction interacts with all of the systems it touches?

Re: Social engineering scam that nearly cost me all of my ETH

#403

News flash: you were social engineered into buying ETH in the first place.

Please don't post this sort of generic flamebait to HN. It leads to repetitive, predictable, and ultimately nasty threads. And of all the classic flamewar topics this one is probably the most predictable—just what this site is not supposed to be for (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...).

If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it. Note this one:

"Avoid [...] generic tangents."

Re: Social engineering scam that nearly cost me all of my ETH

#404

Earlier quoted context omitted.

Eth is a premine scam sure, but the dude has $130M Of it, so I don’t think he is crying over that part

Given your username and how salty you are, I'm going to assume you invested in Bitconnect and lost everything b/c you didn't do your own research.

Please don't cross into personal attack. We ban accounts that do that, and we've had to warn you about this kind of thing before.

https://news.ycombinator.com/newsguidelines.html

Re: Social engineering scam that nearly cost me all of my ETH

#405

News flash: you were social engineered into buying ETH in the first place.

I paid off all my student loan debt and bought a house last summer because I got scammed into buying ETH about 2 years ago. Thanks for your insight though.

Could you please stop posting unsubstantive and/or flamebait comments to HN? It's not what this site is for, and it destroys what it is for.

In case it helps: the first two comments you posted with this account (a couple weeks ago) were much more substantive and much more along the lines of what we're looking for.

https://news.ycombinator.com/newsguidelines.html

Re: Social engineering scam that nearly cost me all of my ETH

#406

Earlier quoted context omitted.

If you are always concerned about the pitfalls of your stupidest user, you will make a product that is only suitable for stupid users. When you stop worrying about that, and can actually start to deploy advanced technology for your advanced users. You can weight your argument however you want, all technology will fail some class of user. Me, I’ve been playing with this and various tech for a decade now and the sky is…

Okay, but you didn’t answer my question. I’m not talking about the "dumbest user" - I’m talking about a regular person who is currently paid in dollars and understands how to use a debit card. What benefits does making money programmable provide that is not offset by this person having to take time out of their day to audit every transaction and understand how the code making up the transaction interacts with all of…

You got me. The tech is useless, it’s actually a giant fraud perpetrated by public traded corporations to steal our precious fluids. The miners are actually watt vampires. Numbers don’t actually exist, it was a trick invented by the ancients. Blockchains just convert pudding into breakfast. Enjoy meat juice day!

Re: Social engineering scam that nearly cost me all of my ETH

#407

Earlier quoted context omitted.

If you think it's so easy, maybe you should do it to demonstrate. If you mean that it'll become easy enough over time, that's an assumption I don't buy.

Similar software already exists.. https://ens.domains/ as does other blockchain software handling tons of value.. It was probably thousands of talented dev hours, who said it was easy? Just curious are you at all familiar with smart contracts in general?

ens.domains just sounds like selling plots on the Moon, or names of distant stars. It only matters to those who buy in. Current system domains are cheap and work fine for most people. If your local government is oppressive and won't let you own a domain, you can't really solve that political problem technologically.

My understanding of smart contracts is that it's like a distributed virtual machine of consensus. A single program that runs on all the networked computers, all executing the same set of functions on the same set of data producing the same result. But it's slow and expensive, because it's "trustless", and it turns out that trust is very valuable and embedded in our traditional methods, and people get scammed left and right because they think trustless means they don't need to trust, but that's a lie.

Re: Social engineering scam that nearly cost me all of my ETH

#408

Earlier quoted context omitted.

Larger pools doing that would be subtracting energy from the honest side, and adding it to the dishonest side, so the logic still holds

> Larger pools doing that would be subtracting energy from the honest side, and adding it to the dishonest side Why would that be the case? It isn't necessarily zero-sum; the more realistic scenario is that the remaining honest participants ramp up their energy consumption in an attempt to prevent the attack. But that's still only the most boring of the many, many latent threats to Bitcoin. Solar flares and electroni…

To be fair, most human technology is vulnerable to these. The nice thing about a distributed ledger is that as long as one copy remains it can be bootstrapped back to full form. One Pi sitting in Africa could do it. Try that with your banks SQL db backups, which all tapes disks and ssds were erased in the solar storm.

Re: Social engineering scam that nearly cost me all of my ETH

#409
post #20

Note; dude has $123M in aave wrapped ethereum that he almost granted a scammer access to. Scammers ripping off scammers. Why would you waste time with open source aircrafts. Aircrafts are a regulated thing. Nobody wants to fly in your science project. Put some of that 123 million into starting an actual company. DAOs are bullshit.

That's a horrible take on a legit person and project.

Did you take a look at arrowair.com? Everything about that screams "art project". None of it makes sense. There are extreme engineering, economic, and legal challenges to doing have of what they are proposing, so the first thing they are investing in are their crypto projects? Because crypto crypto future future?

I don't necessarily think the author is a scammer, but the whole project is the equivalent of "I'm going to launch a rocket to the moon" and then the first thing you do is open a nice website and launch a new token.

Re: Social engineering scam that nearly cost me all of my ETH

#410
post #340

Earlier quoted context omitted.

> when he went to stake his NFT, they asked for an approval for spending aETH from his wallet. Approvals such as this are normal when interacting with smart contracts, since the contract has to be "delegated" responsibility over the tokens in order to move them. However, what wasn't normal is that the approval was actually for Aave ETH. I'm a reasonably technical dude (senior data engineer at GAMMA/FAANG/whatever we'…

It is a specific technical detail of how ERC-20 tokens work. Your wife/brother/kids etc make transfers online from their bank account without knowing the technical details of how that transfer works. Ideally wallets would have better UX where concepts like this could be handled safely and in an accessible manner. I think crypto isn't really ready for general consumption yet.

This discussion tells me once again that crypto today is similar to you have access to the backend systems of the bank and you can write database commands in sql that change things in your account records. It's insane low level access system. Transferring ownership of money via a webpage that has a source and destination on your bank webpage is understandable at a certain level. Is that the right source, is that the right destination. But you can put in 100,000 instead of 1k or 10k by accident. That's very different than if you click the 'ok' button it runs say random javascript like commands that the destination of the money wrote up.

You can't ever expose that level to end users without it being an endless fraud source for people.

Post reply on HN