Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

81–90 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#81
post #71

Earlier quoted context omitted.

Do you think that a bank or a government would've handled fixing such a flaw as well has optimism did? All tokenization schemes are ponzi scams including USD, it's just that some use violence to stay relevant, and other use bug bounties.

Banks or stock exchanges would just revert any bad transactions like they do with most scams, thefts, or accidents. It is built into the current system by design.

They revert the money (if they like you), but usually if money flows one way, something else flows the other way, and they can't revert that half of the fraudulent transactions without great expenditure. Often it's not worth it and they just write it off and the whole economy bears the cost.

I'm not saying it's a better or worse plan than whatever might happen under an alternative system, but just that it's not exactly a clean solution either.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#82

Earlier quoted context omitted.

Don’t forget about taxes. Most of it is getting taxed at least 37%

Not on capital gains. At least in the US that’s only taxed at 15% with no tiering. The deck is stacked for the investment class

You’re wrong in many different ways:

- Long term vs short term

- different rates

- state capital gains taxes

In this case, with the receiver being a CA resident, he pays almost certainly more than 50% in taxes on this bounty.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#83
post #44

Earlier quoted context omitted.

5% yoy risk-free is optimistic, realistically he can count on 50-60k. Close to fuck-you money but, for a lot of people, not there yet.

Rich people of HN, is this true? I’d always heard each million is worth about $50k a year. Was that just during boom times, or simply mistaken?

> Not even close. There's no reliable way to get a fixed income, and inflation is very high.

The market historically has been going up, so at least historically it's been reliable to get a fixed income. I don't think $2M is sufficient to retire very early, mostly because of bad years and that your initial capital loses value over the years, but it can generate a nice income and most people can have something on the side that generates some extra money as needed. With $4M I would be more comfortable retiring at 40 let's say, depending on cost of living of course.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#84
post #42

Earlier quoted context omitted.

I do not expect to make any major expensive lifestyle changes as a result of having more money (and to the extent to which I have already been being paid better recently due to working on Orchid, I have only barely done so and usually only quite temporarily), which I realize disappoints some people who had wanted me to post a concrete picture of something expensive I purchase to help motivate others to reach for bug…

Please read this thread to see the pitfalls that might potentially lie ahead: https://www.reddit.com/r/AskReddit/comments/24vo34/comment/c... It's about winning the lottery but still applicable to some extent, and shows how people's lives go horribly wrong.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#85
post #41

Earlier quoted context omitted.

No. This was neither ETH, nor the Ethereum blockchain. Nor does this imply more issues indeed exist today.

From the bounty: "The Summary On 2/2/2022, I reported a critical security issue to Optimism—an "L2 scaling solution" for Ethereum—that would allow an attacker to replicate money on any chain using their "OVM 2.0" fork of go-ethereum (which they call l2geth)." No - sorry - ETH doesn't get a 'pass' on this. The 'Rest Of The World' is tired of the Crypto Scam Delusion masquerading as something reasonable and watching th…

By definition an "L2 scaling solution" is not the Ethereum blockchain.

Ethereum itself clearly is a secure blockchain given the fact that it has not been exploited directly ever, as far as I am aware. Smart contracts running in the EVM obviously have exploits galore, but that is different from Ethereum itself being vulnerable. Just like it is different when the Java Virtual Machine itself has an exploit (uncommon) vs when a program that runs in the JVM does (very common).

You can of course argue that the lack of inherent soundness / correctness in Ethereum smart contracts makes the entire chain less useful since running smart contracts is kinda the whole point, but then you should make that argument rather than saying dumb things like:

> ETH was an insecure blockchain

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#86

Earlier quoted context omitted.

If you say so. It’s the same thing, even if it’s more comfortable to believe it’s not. It helps to frame it this way, because once you accept that you’d do that, you’re more likely to accept you would do something unethical for a billion dollars if it had no consequences to you. And from there, it’s a binary search to determine exactly what your price is. Would you be able to say you wouldn’t lie to your wife if it m…

Yes, but that's not what we're discussing, because then I can counter with: "Would you sell your mother or your children at any price?" And I hope - admittedly, that's speculation - I know what the answer to that would be. So this is now an absurd discussion, whereas it started off from a rational point of view: there exist such people whose ethics can not be corrupted. The fact that you believe this is not the case…

People did in fact sell their children when faced with hard times, by the way. The 1920’s era was rough. https://www.ranker.com/list/story-behind-photo-of-children-f...

You are asking what I would personally do. But it’s better to think of limit cases that everyone would do — such as lie to their wife for a billion dollars. Since it’s guaranteed you fall into the bucket of “everybody”, that means you can locate your ethical price tag.

It’s helpful for people to do this mental exercise. At least, I find it comforting knowing my own price tags in advance.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#87
post #21
post #17

Earlier quoted context omitted.

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

Hah! When I added SSL to my site a few days ago, I really cranked those settings hard trying to optimize for "security" on the Qualy's SSL Server Test. Do you know what the most secure cipher suite you actually support is (and are you sure the issue isn't that you aren't merely using a particularly-out-of-date copy of Firefox)?

Seems to be because of Fedora hardened policy and your site might be supporting SHA1 for use in signatures. One of the three changes with the default tweaks policy that probably makes sense https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2...

When I set the crypto policy in Fedora to Legacy, which lifts those restrictions, I can visit your website.

Chrome doesn't have this problem in Fedora because it ships with its own SSL/TLS specific things bundled (or something along the lines, didn't care to get deeper in the topic).

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#88

This just proves how insecure the blockchain / web3 / cryptocurrency space is. It's good to see white hat hackers in this space trying to fix what is already broken. But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid.

>But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid.

Seems like just an opinion to me, and a poorly opinionated one at that.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#89
post #17

Earlier quoted context omitted.

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

No such issue under Firefox 97 on NixOS; are you using a recent version of firefox + ssl lib?

Yes. Seems to be because of a hardened policy setting in Fedora, as per my previous comment https://news.ycombinator.com/item?id=30322615

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#90
post #32
post #30

Earlier quoted context omitted.

How are you going to turn that into actual goods and services though? You'll still need to go through an exchange with KYC and AML and the IRS will still be asking questions.

IRS doesn’t care as long as you pay taxes on the money. KYC and AML? Just lie that you mined the monero on a now defunct pool. I have a plenty of coins that I genuinely acquired in such manner and haven’t had issues selling them. The bank only cares about hearing a vaguely consistent story, they aren’t cops. The KYC stuff will only become a problem if you get caught via some other means, because lying to the bank is…

> IRS doesn’t care as long as you pay taxes on the money.

Lol, you never actually handled the sums the submission is about right? The IRS will definitely ask questions about where the money you spend come from, if you end up on their radar. And if the answer is not satisfactory, they will grill you on it.

Post reply on HN